Privacy Policy
1. About This Privacy Policy
This Global Privacy Policy (“Privacy Policy”) explains how Bluebird by ASIS handles personal information in connection with the Bluebird workforce management platform, associated websites, online subscriptions, customer accounts and support services.
Bluebird is provided by Advanced Solutions for Information Systems (“ASIS”), acting through the ASIS legal entity identified during checkout, in an applicable Order Form, subscription confirmation or invoice (“ASIS”, “we”, “us” or “our”).
Bluebird may be offered to organisations in multiple countries and jurisdictions.
Privacy and data-protection requirements may therefore vary according to:
- the Customer’s location;
- the location of the individuals whose information is processed;
- the applicable ASIS contracting entity;
- the Service configuration selected by the Customer; and
- applicable privacy and data-protection laws.
Where country-specific privacy requirements apply, they may be supplemented by country-specific notices, Data Processing Agreements or other applicable contractual provisions.
2. Our Different Privacy Roles
It is important to distinguish between two principal situations in which ASIS processes personal information.
2.1 Customer Workforce Data
When an organisation subscribes to Bluebird and uses the Service to process information relating to its employees, workers, contractors or other personnel (“Customer Data”), the Customer generally determines:
- what personal information is collected;
- why it is collected;
- how the Service is configured;
- who has access;
- how long information should be retained; and
- how the information is used within the Customer’s organisation.
In these circumstances, the Customer generally acts as the data controller, business, organisation responsible for processing, or equivalent role under applicable data-protection law.
ASIS generally acts as the Customer’s data processor, service provider or equivalent role, processing Customer Data on behalf of and in accordance with the Customer’s documented instructions.
The terminology and allocation of responsibilities may differ under applicable local law.
2.2 ASIS Account, Commercial and Support Data
ASIS may act as an independent controller or equivalent responsible party for personal information that ASIS collects for its own legitimate business operations.
This may include information relating to:
- subscription purchases;
- account administration;
- billing;
- sales enquiries;
- customer contacts;
- website visitors;
- security;
- legal compliance; and
- customer-support communications.
3. Employee and Workforce Privacy Requests
If you are an employee, worker or contractor whose information is stored within a Bluebird tenant operated by your employer or another organisation, you should normally direct privacy requests to that organisation.
This includes requests relating to:
- access;
- correction;
- deletion;
- restriction;
- objection;
- portability;
- withdrawal of consent; or
- questions concerning how your information is used.
ASIS does not independently determine whether an employee record should be amended, disclosed or deleted where ASIS acts solely as processor for the Customer.
ASIS will provide reasonable assistance to the Customer in handling valid privacy requests as required by applicable law and the applicable Data Processing Agreement.
Where ASIS is legally required to respond directly to an individual, ASIS will do so in accordance with applicable law.
4. Categories of Customer Data Processed Through Bluebird
The categories of information processed through Bluebird depend on the modules selected and the way in which the Customer configures the Service.
Bluebird may process the following categories of information:
| Category | Examples |
|---|---|
| Identity Data | Name, employee number, photograph, job title, department, reporting line |
| Government and Official Identifiers | National identification number, passport details, residency permit, visa information, employee or government-issued identifiers |
| Contact Data | Work email address, telephone number, address, emergency contact information |
| Employment Data | Employment status, contract type, start date, position, work location, cost centre, organisational unit |
| Attendance and Time Data | Clock-in and clock-out records, schedules, shift assignments, lateness, absence, overtime and working-hour records |
| Leave Data | Leave requests, approvals, balances, leave types and supporting documents |
| Payroll-Related Data | Salary-related information, allowances, deductions, payroll inputs and other payroll-related records where relevant modules are used |
| Health-Related Data | Sick-leave documentation, medical certificates or other information submitted in connection with leave or workforce processes |
| Biometric Data | Biometric templates or identifiers used for identity verification where biometric functionality is enabled |
| Location Data | Location information captured in connection with mobile or location-based attendance features, where enabled by the Customer |
| Device Data | Device identifiers, device type, operating-system information and information relating to connected attendance devices |
| Technical Data | IP addresses, browser information, login records, session information, system logs and security information |
| Audit Data | Records of actions, approvals, changes and administrative activity performed within the Customer’s tenant |
ASIS does not require every Customer to collect all of these categories.
The Customer determines which information is appropriate and lawful for its own workforce-management requirements.
5. Sensitive and Special Categories of Personal Information
Certain information processed through Bluebird may be considered sensitive, special-category or otherwise protected personal information under applicable law.
This may include:
- biometric information;
- health-related information;
- government identification information;
- precise location information; and
- other information designated as sensitive under applicable law.
Customers are responsible for determining whether they are legally permitted to collect and process such information through Bluebird.
Where additional safeguards, consent, assessments, employee notices, registrations, approvals or other measures are required by applicable law, the Customer is responsible for implementing them.
ASIS applies appropriate technical and organisational safeguards to Customer Data according to the nature and risks of the processing.
6. Biometric Data
Bluebird may support integration with attendance technologies that use fingerprints, facial recognition or other biometric characteristics for identity verification.
Whether biometric functionality is enabled is determined by the Customer.
6.1 Customer Responsibilities
Before using biometric functionality, the Customer is responsible for:
- determining whether biometric processing is lawful in each applicable jurisdiction;
- identifying and documenting an appropriate lawful basis for processing;
- providing individuals with clear and legally sufficient privacy notices;
- obtaining valid consent where consent is required by applicable law;
- determining whether a non-biometric attendance alternative must be offered;
- conducting any legally required privacy, biometric or data-protection impact assessment;
- completing any required regulatory registration or notification;
- establishing appropriate biometric-data retention periods; and
- responding to individuals exercising applicable privacy rights.
6.2 Biometric Templates
Depending on the biometric technology, device and integration used, biometric characteristics may be transformed into digital templates or identifiers used for identity matching.
Bluebird is not intended to use biometric information for advertising, profiling or unrelated identification purposes.
The exact format, creation and storage method of biometric templates may depend on the hardware, biometric technology and integration selected by the Customer.
Where biometric information is processed by third-party devices or technology providers, additional provider-specific terms and privacy practices may apply.
7. Customer Responsibility for Lawful Processing
The Customer is responsible for ensuring that its collection and use of Customer Data through Bluebird complies with applicable law.
This includes responsibility for:
- providing legally required privacy notices;
- identifying lawful bases for processing;
- obtaining consent where legally required;
- ensuring that only necessary information is collected;
- restricting access appropriately;
- determining lawful retention periods;
- responding to individual rights requests;
- complying with employment and workplace-monitoring laws;
- complying with biometric and location-tracking requirements; and
- ensuring that any instructions given to ASIS are lawful.
Where permitted by applicable law and the Agreement, the Customer may be responsible for claims, liabilities or costs arising from its unlawful or unauthorised collection or use of Customer Data.
Any indemnification obligation is governed by the applicable Terms of Service and other contractual documents.
8. How ASIS Uses Customer Data
Where ASIS acts as processor or service provider, ASIS processes Customer Data only as reasonably necessary to:
- provide the Service;
- host and store Customer Data;
- authenticate authorised users;
- process Customer-configured workforce transactions;
- provide technical support;
- troubleshoot technical issues;
- maintain Service performance;
- maintain security;
- prevent and investigate misuse;
- create and maintain backups;
- perform disaster recovery;
- perform authorised integrations; and
- comply with lawful Customer instructions or legal obligations applicable to ASIS.
The Customer’s subscription agreement, Service configuration, administrative actions and authorised support requests may constitute documented instructions to ASIS.
If ASIS reasonably believes that a Customer instruction violates applicable data-protection law, ASIS may inform the Customer and suspend execution of that instruction where permitted or required by law.
9. Use of Customer Data for AI, Advertising and Product Analytics
Unless separately and expressly agreed with the Customer, ASIS does not use identifiable Customer workforce data for:
- behavioural advertising;
- third-party advertising;
- sale of personal information;
- employee profiling for ASIS’s own purposes;
- training general-purpose artificial-intelligence models; or
- making Customer workforce data available to other customers.
ASIS may process technical, security, operational and Service-performance information to operate, secure and improve the Service, provided such processing is carried out in accordance with applicable law and does not permit another customer to identify the Customer’s employees.
Where ASIS intends to introduce materially different uses of Customer Data, ASIS will provide appropriate notice and obtain any consent or contractual authorisation required by applicable law.
10. Personal Information Controlled Directly by ASIS
ASIS may collect personal information directly in connection with its commercial relationship with Customers and users.
This may include:
- name;
- business email address;
- telephone number;
- company or organisation name;
- organisation address;
- country;
- industry or sector;
- job title;
- billing contact information;
- transaction references;
- communications with ASIS;
- support requests;
- website activity;
- IP address;
- login and security information; and
- subscription and account information.
ASIS may process this information for purposes including:
- entering into and administering contracts;
- setting up subscriptions;
- billing and payment administration;
- customer support;
- security and fraud prevention;
- communicating important Service information;
- maintaining business records;
- establishing, exercising or defending legal claims;
- regulatory and tax compliance; and
- operating and improving ASIS’s customer-facing services.
The legal basis relied upon depends on applicable law and may include:
- performance of a contract;
- steps taken before entering into a contract;
- compliance with legal obligations;
- legitimate interests;
- consent; or
- another lawful basis recognised under applicable law.
11. Data Hosting and Data Location
Bluebird uses professional cloud infrastructure providers to host and operate the Service.
The hosting region assigned to a Customer tenant may depend on:
- Customer location;
- regulatory requirements;
- contractual requirements;
- technical availability;
- subscription configuration; and
- the region selected or agreed during provisioning.
Where data-residency requirements apply, ASIS may offer or designate an appropriate hosting region where commercially and technically available.
The Customer may be informed of the applicable hosting location through:
- checkout;
- an Order Form;
- subscription documentation;
- a Data Processing Agreement;
- Customer administration settings; or
- ASIS support.
Backups may be stored in the same region as the production environment or in another approved region used for business continuity and disaster recovery, subject to applicable contractual and legal requirements.
12. International Data Transfers
Because Bluebird may operate globally, personal information may in some circumstances be processed in a country other than the country in which the Customer or individual is located.
Where applicable data-protection law imposes restrictions on international transfers of personal information, ASIS will use appropriate transfer mechanisms or safeguards as required.
These may include, where applicable:
- contractual safeguards;
- standard contractual clauses;
- data-processing agreements;
- adequacy mechanisms;
- approved certifications;
- localisation arrangements; or
- another legally recognised transfer mechanism.
Customers are responsible for determining whether their own use of Bluebird involves international transfers requiring additional legal measures.
13. Sub-Processors and Service Providers
ASIS may engage third-party service providers and sub-processors to support the delivery of Bluebird.
Categories may include:
| Service Category | Purpose |
|---|---|
| Cloud Infrastructure Provider | Hosting, computing, storage, backup and disaster recovery |
| Payment Service Provider | Processing subscription and checkout payments |
| Email Delivery Provider | Transactional email and Service notifications |
| SMS / Messaging Provider | SMS, OTP and other Customer-configured notifications |
| Monitoring and Security Providers | Infrastructure monitoring, security and operational support |
| Customer Support Infrastructure | Support-ticket and communication services where applicable |
A current list of material sub-processors may be made available through Bluebird’s website, Customer portal or on request.
Where required by applicable law or contract, ASIS will provide reasonable advance notice before appointing a new material sub-processor that will process Customer Data.
Where the Customer directly selects, contracts with or provides credentials for its own third-party provider, that provider may be considered a Customer-authorised third party rather than an ASIS sub-processor.
The Customer is responsible for reviewing the terms and privacy practices of third parties it independently selects.
14. Payment Information
Subscription payments may be processed by a third-party payment service provider identified during checkout.
Where a hosted payment page or equivalent secure payment solution is used, payment-card information is submitted directly to the payment provider.
ASIS does not intentionally store full payment-card numbers or card security codes within the Bluebird application.
ASIS may receive and retain limited payment information required for:
- transaction confirmation;
- reconciliation;
- invoicing;
- refunds;
- fraud prevention;
- chargeback handling; and
- dispute resolution.
Such information may include:
- transaction reference;
- payment status;
- amount;
- currency;
- payment date;
- payment method type; and
- masked payment information returned by the payment provider.
Payment processing is also subject to the privacy and security terms of the applicable payment provider.
15. Acceptance and Contract Records
Where a Customer accepts legal documents electronically, ASIS may retain evidence of that acceptance.
Records may include:
- document name;
- document version;
- date and time of acceptance;
- account or organisation name;
- name and email address of the person accepting;
- IP address;
- relevant order or subscription reference; and
- relevant transaction reference.
These records may be used for:
- contract administration;
- regulatory compliance;
- dispute resolution;
- payment disputes;
- chargebacks; and
- establishing or defending legal rights.
Records will be retained for the period reasonably necessary for those purposes and according to applicable legal and accounting requirements.
16. Security
ASIS maintains technical and organisational safeguards designed to protect personal information against:
- unauthorised access;
- unlawful processing;
- accidental disclosure;
- loss;
- destruction;
- alteration; and
- misuse.
Depending on the Service and hosting configuration, measures may include:
- encryption of data in transit;
- encryption of stored data where appropriate;
- logical separation of Customer tenants;
- role-based access control;
- authentication controls;
- least-privilege administrative access;
- logging of privileged administrative activity;
- backup and recovery processes;
- infrastructure monitoring;
- vulnerability management;
- security patching;
- secure development practices;
- access reviews;
- confidentiality obligations applicable to personnel; and
- internal security procedures.
No information system can be guaranteed to be completely secure.
ASIS therefore maintains safeguards appropriate to the nature, sensitivity and risks associated with the information processed.
17. Customer Security Responsibilities
Customers also play an important role in protecting personal information.
Customers are responsible for:
- managing administrator accounts;
- assigning appropriate access permissions;
- disabling former users promptly;
- maintaining secure authentication credentials;
- protecting devices used to access Bluebird;
- configuring integrations securely;
- restricting unnecessary access to sensitive information;
- reviewing audit and security logs where available; and
- notifying ASIS promptly of suspected unauthorised access.
18. Personal Data Breaches and Security Incidents
Where ASIS becomes aware of a confirmed personal-data breach affecting Customer Data for which ASIS acts as processor, ASIS will notify the affected Customer without undue delay and within any period required by applicable law or the applicable Data Processing Agreement.
Where contractually agreed, ASIS may commit to a specific notification period.
To the extent information is reasonably available, the notification may include:
- the nature of the incident;
- the categories of information affected;
- the approximate number of affected individuals or records;
- likely consequences;
- containment and remediation measures; and
- steps the Customer may reasonably need to consider.
Additional information may be provided as the investigation progresses.
Where the Customer is the controller, the Customer remains responsible for determining whether notification to affected individuals, regulators or other authorities is legally required.
ASIS will provide reasonable assistance as required by applicable law and contract.
19. Retention of Customer Data
Customer Data is generally retained for the duration of the Customer’s active subscription.
Following expiry or termination, Bluebird may provide a thirty (30) day read-and-export period, unless:
- a different period is contractually agreed;
- immediate deletion or restriction is legally required;
- the account was terminated for serious security or unlawful activity; or
- applicable law requires another retention period.
After the applicable export period, Customer Data may be deleted from active production systems.
Residual copies contained in backups will be deleted or overwritten through ASIS’s normal backup-retention cycle, subject to applicable legal obligations.
The Customer remains responsible for exporting any information it is legally required to retain before expiration of the applicable export period.
20. Other Retention Periods
ASIS may apply retention periods including the following, subject to applicable law:
| Record Type | Typical Retention |
|---|---|
| Customer Data | Subscription term + normally 30-day export period |
| Trial Data | Trial period + applicable deletion/export period |
| Invoices and Financial Records | Period required by applicable tax and accounting law |
| Contract and Acceptance Records | Contract term plus applicable limitation/legal-record period |
| Payment Transaction Records | As required for accounting, reconciliation and disputes |
| Support Correspondence | Normally up to three (3) years after closure, unless longer retention is required |
| Security and Audit Logs | According to security, operational and legal requirements |
| Website and Account Records | For as long as reasonably required for the applicable business purpose |
Specific retention periods may differ by country or Customer contract.
21. Individual Privacy Rights
Depending on applicable law, individuals may have rights relating to their personal information, including rights to:
- access;
- correction;
- deletion;
- restriction;
- objection;
- portability;
- withdrawal of consent; and
- lodge a complaint with a competent privacy or data-protection authority.
These rights are subject to applicable legal conditions and exceptions.
Where the information is contained within a Customer-controlled Bluebird tenant, the individual should normally contact the Customer directly.
ASIS will reasonably assist the Customer in responding to valid rights requests where required by applicable law and the Data Processing Agreement.
Where ASIS acts as the controller of the relevant information, individuals may contact ASIS directly using the contact details in this Privacy Policy.
22. Data Processing Agreement
Where required, a Data Processing Agreement (“DPA”) forms part of the contractual relationship between ASIS and the Customer.
The DPA may address matters including:
- subject matter and duration of processing;
- nature and purpose of processing;
- categories of personal information;
- categories of individuals;
- Customer instructions;
- confidentiality;
- information security;
- sub-processors;
- international data transfers;
- individual rights requests;
- breach notification;
- audit rights;
- assistance obligations;
- retention; and
- deletion or return of Customer Data.
The applicable DPA may be available online, through the Customer account, as part of an Order Form, or on request from support@asis-it.com.
23. Government and Regulated Customers
Government bodies, public authorities, financial institutions, healthcare organisations and other regulated Customers may be subject to additional requirements relating to:
- data residency;
- access controls;
- security;
- employee information;
- official identifiers;
- cloud hosting;
- international transfers; and
- retention.
Where ASIS agrees to such requirements, they will be documented in the applicable Order Form, DPA, security schedule, country-specific terms or other signed agreement.
No specific data-residency commitment applies solely because a Customer belongs to a particular sector unless such commitment is expressly agreed or required by applicable law.
24. Children’s Data
Bluebird is a business workforce-management Service and is not designed for use by children for personal purposes.
Customers must not knowingly use the Service to process children’s personal information except where:
- such processing is legitimately required in the context of employment, dependants, benefits or another lawful organisational purpose; and
- the Customer has established an appropriate lawful basis and complied with applicable requirements.
25. Cookies and Similar Technologies
Public Website
The Bluebird public website may use cookies and similar technologies required for:
- website operation;
- security;
- authentication;
- checkout;
- preferences; and
- other essential functionality.
Where permitted and subject to applicable consent requirements, Bluebird may also use non-essential analytics or similar technologies.
Where consent is legally required, non-essential cookies will not be activated before the required consent is obtained.
Users may be provided with cookie controls through the website.
Authenticated Bluebird Service
The authenticated Service may use session cookies and similar technologies necessary for:
- login;
- session management;
- security;
- fraud prevention;
- user preferences; and
- application functionality.
Additional information may be provided in a separate Cookie Policy or cookie-management interface.
26. Marketing Communications
Where ASIS sends marketing communications, it will do so in accordance with applicable law.
Recipients may unsubscribe from promotional electronic communications using the unsubscribe method provided in the communication or by contacting ASIS.
Service-related communications, security notices, invoices, subscription notices and other transactional messages are not marketing communications and may continue to be sent where reasonably necessary.
27. Automated Decision-Making
Bluebird may automate calculations, workflows, approvals, attendance processing and other administrative functions based on rules configured by the Customer.
Unless expressly stated otherwise, ASIS does not independently use Customer workforce data to make employment decisions about individuals.
The Customer remains responsible for:
- configuring automated rules;
- determining how automated outputs are used;
- reviewing legally significant decisions; and
- complying with any applicable rules governing automated decision-making.
28. Changes to This Privacy Policy
ASIS may update this Privacy Policy from time to time.
Material changes may include significant changes to:
- categories of personal information processed;
- purposes of processing;
- material sub-processor arrangements;
- international transfer practices;
- retention principles;
- Customer responsibilities; or
- individual privacy rights.
Where required by applicable law or contract, ASIS will provide appropriate advance notice of material changes.
Where renewed consent or contractual acceptance is legally required, ASIS will request it.
Non-material, administrative or clarification changes may take effect on publication.
Each version will identify:
- its version number; and
- effective date.
Superseded versions may remain available through archived URLs such as:
/en/legal/privacy/v1.0
29. Country-Specific Privacy Requirements
Because Bluebird is offered globally, additional privacy requirements may apply in certain countries.
Country-specific provisions may address matters including:
- controller and processor terminology;
- lawful bases for processing;
- consent;
- biometric information;
- employee monitoring;
- cross-border transfers;
- data residency;
- individual rights;
- regulatory complaints;
- breach notification;
- retention; and
- local representative requirements.
Where a country-specific privacy notice or addendum applies, it forms part of this Privacy Policy.
In the event of a conflict, mandatory local privacy law will prevail to the extent required by law.
30. Governing Contractual Framework
Privacy and data-protection obligations relating to Bluebird are governed by this Privacy Policy together with, as applicable:
- Global Terms of Service;
- Data Processing Agreement;
- Subscription and Billing Terms;
- applicable Order Form;
- country-specific privacy terms; and
- any separately signed agreement.
The governing law and contractual jurisdiction generally correspond to the ASIS contracting entity identified during checkout, in the applicable Order Form, subscription confirmation or invoice, subject to mandatory privacy laws applicable to the relevant processing activity or individual.
31. Language
This Privacy Policy may be published in multiple languages.
Where applicable law requires a particular language to prevail, that legal requirement will apply.
Otherwise, the controlling language will be the language identified during checkout or in applicable country-specific terms.
Where no controlling language is specified, the English-language version shall prevail.
32. Contact ASIS
For privacy questions relating to ASIS-controlled personal information or the operation of Bluebird, please contact:
Bluebird by ASIS
Advanced Solutions for Information Systems
Privacy Email: support@asis-it.com
Support Email: sales@asis-it.com
Telephone: 44479107 (Qatar) / 0224031965 (Egypt)
Website: https://bluebird.asis-it.com
The full legal name, registered address and registration details of the applicable ASIS contracting entity will be identified during checkout, on the applicable Order Form, subscription confirmation or Customer invoice.
Where required by applicable law, additional contact details for a local privacy representative or Data Protection Officer may be provided in applicable country-specific notices.
Document: Global Privacy Policy
Version: v1.0
Effective Date: 1 January 2026
Draft for legal review. Privacy, biometric, employee-monitoring, international-transfer, data-residency and sensitive-data requirements may vary materially between jurisdictions. Country-specific requirements should therefore be reviewed before Bluebird is commercially offered in a new jurisdiction.
