Trust & Security

GDPR and Privacy Compliance

How IceHrm Cloud protects your company data and supports your obligations under the GDPR and the Australian Privacy Act.

Last updated 26 September 2026 10 sections
Contents
  1. Overview
  2. What is the GDPR?
  3. Australian Privacy Act
  4. Our Role
  5. How We Protect Your Data
  6. Access Control
  7. Sharing and Service Providers
  8. Monitoring and Incidents
  9. Your Data, Your Rights
  10. Contact
AES 256-bit encryptionPersonally identifiable data is encrypted before it is stored.
Stored in two locationsAll customer data is kept in at least two locations as a backup.
You own your dataRequest a copy of all your company data at any time.
Deletion on requestAsk for your data to be deleted and the service terminated.

Overview

IceHrm Cloud is operated by ICE HRM Pty Ltd, an Australian company. Our customers use IceHrm to store information about their employees and job applicants, so protecting that information is central to how we build and run the service. This page explains how IceHrm supports your obligations under the EU General Data Protection Regulation (GDPR) and the Australian Privacy Act 1988 (Cth). For full details, see our Privacy Policy and Information Security Policy.

What is the GDPR?

The General Data Protection Regulation (EU) 2016/679 took effect on 25 May 2018, replacing the EU Data Protection Directive (95/46/EC). It sets a single set of data protection rules across the European Union. The United Kingdom applies equivalent rules through the UK GDPR.

The GDPR applies to organisations established in the EU, and to organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour there. Personal data is any information relating to an identified or identifiable natural person.

Australian Privacy Act

As an Australian company, we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), including the rules on security, overseas disclosure, access and correction, and the Notifiable Data Breaches scheme.

Our Role

For the employee and applicant data you store in IceHrm, you are the controller: you decide what data is collected and how it is used. We act as your processor, handling that data only to provide and support the service and on your instructions. For our own customer account, billing and marketing data, we are the controller.

If your organisation needs a data processing agreement, please contact us at [email protected].

How We Protect Your Data

Your data is stored on virtual private servers operated by IceHrm. All personally identifiable data in our databases is encrypted using AES 256-bit encryption.

Files such as employee documents, profile images and company documents are stored in Amazon S3. Storage is private and encrypted, and files can only be downloaded through a temporary link generated by your IceHrm installation, based on the permissions of the signed-in user.

As a backup, all customer data is stored in at least two different locations with the same level of security.

Access Control

Personal data is encrypted before it is stored and can only be decrypted with a unique key associated with your installation. Under our Information Security Policy, IceHrm staff may access your installation only with your written permission, or where it is necessary to maintain the security of the service.

Sharing and Service Providers

We do not sell your data, and we do not share personally identifiable data with third parties except the service providers that host and operate the service on our behalf, or where the law requires it.

We use the following infrastructure providers. You can review their data protection commitments at the links below.

Our servers are located in the United States. Where personal data is transferred outside the EEA, the UK or Australia, we rely on appropriate safeguards, such as standard contractual clauses, as described in our Privacy Policy.

Monitoring and Incidents

All IceHrm installations are monitored continuously for suspicious activity. If a security incident affects your data, we will notify you without undue delay and give you the information you need to meet your own notification obligations under the GDPR, the Notifiable Data Breaches scheme or other applicable laws.

Your Data, Your Rights

Ownership. You own your data, and you can request a copy of all your company data stored in IceHrm Cloud at any time.

Deletion and termination. You can ask us to delete your data and terminate your IceHrm services at any time.

Individuals' rights. IceHrm lets you view, correct, export and delete employee records, so you can respond to access, correction and erasure requests from your employees.

Contact

For questions about privacy or data protection at IceHrm, please contact ICE HRM Pty Ltd at [email protected].