Skip to content

Privacy Policy

Last updated September 30, 2026

This policy explains what personal information TINIUN handles, why, where it is stored, and the choices and rights you have. It applies to the TINIUN web application and this website.

1. Who we are and our role

TINIUN is a workforce management service operated by Zaikus Philippines (“TINIUN”, “we”, “us”), Calamba City, Laguna, Philippines.

  • For workforce data that an organization (such as your employer) puts into TINIUN — schedules, activity and attendance records, and similar — that organization is the controller and decides how the data is used. TINIUN processes it on the organization's behalf, under its instructions and our agreement with it, as a processor.
  • For information about visitors to this website and business contacts (for example, when you request a demo), TINIUN is the controller.

If you use TINIUN through your employer, questions about your workforce data are best directed to them first; we will help them respond.

We handle personal information in accordance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its implementing rules, and the issuances of the National Privacy Commission, as well as other privacy laws that apply to our customers and users.

2. Information we process

Account information

Name, work email address, job title, team, location, role and permissions, and a password (stored only as a salted scrypt hash — we never store the password itself). If your organization uses single sign-on, we receive your identity from its identity provider instead of a password.

Workforce and operational data

Schedules and shifts; status changes such as log-in, work, break, meal, training and log-out with their timestamps; attendance records and corrections; adherence calculations; exceptions and the notes on them; coaching sessions, notes and action items; time-off, shift-swap and schedule-change requests; and messages sent within TINIUN.

Technical and security information

For security, audit and troubleshooting, we record the IP address, browser user agent and a device identifier with sign-in sessions and certain actions, and our hosting providers keep request logs. This information supports features like session management, rate limiting and the audit history.

Information you send us

When you email us or request a demo, we receive your name, email address, company and whatever else you choose to include.

3. How we use information

  • To provide TINIUN: show schedules, calculate adherence, detect exceptions, deliver notifications and messages, and produce reports for your organization.
  • To secure the service: authenticate users, enforce permissions, prevent abuse, and keep an audit history.
  • To support customers and respond to enquiries and demo requests.
  • To maintain and improve the service, including troubleshooting and monitoring reliability.
  • To meet legal obligations and enforce our agreements.

We do not sell personal information, and we do not use workforce data for advertising.

Where the law requires a legal basis, we rely on performance of our contract with your organization, our legitimate interests in running a secure and reliable service, compliance with legal obligations, and — where required — consent.

4. Cookies and similar technologies

TINIUN uses only what the service needs to work:

NameTypePurpose
sp_sessionEssential cookieKeeps you signed in. HTTP-only, sent only over HTTPS, and expires at the end of your session period.
sp_deviceLocal storageA random identifier for your browser, used to label sessions and actions in the audit history.

We do not use advertising or cross-site tracking cookies, and this website does not use third-party analytics.

5. Service providers and sharing

We use a small number of infrastructure providers to run TINIUN. They process data only to provide their services to us:

ProviderPurposeLocation
Vercel Inc.Application hosting and deliverySingapore (application), global edge network
Supabase Inc.Managed database where application data is storedSingapore
Redis Ltd. (Redis Cloud)Short-lived operational data: real-time event delivery, rate-limit counters and job coordinationUnited States

Within your organization, what others can see depends on the roles your administrators assign — for example, a team leader sees their team's live status. We may also disclose information if required by law, to protect the rights and safety of our users or the public, or as part of a merger or acquisition, subject to this policy.

6. International transfers

Application data is stored in Singapore, and some operational data is processed in the United States. Where data moves across borders, we rely on appropriate safeguards as required by applicable law, such as contractual protections with our providers.

7. Retention

We keep workforce data for as long as your organization uses TINIUN, or for a shorter period your organization sets or asks for. When an agreement ends, we delete or return the organization's data as the agreement provides, except where we must keep it longer by law. Short-lived operational data is kept only for minutes to hours. Enquiry emails are kept as long as needed to respond and follow up.

8. Security

We protect information with measures including encryption in transit, tenant isolation enforced in the database, role-based access, hashed credentials, rate limiting and an append-only audit history. No system is perfectly secure, but we work to protect your data and to respond quickly to any issue. Read more on our Security page.

9. Your rights

Under the Data Privacy Act of 2012 and other applicable laws, you may have the right to be informed, to access, correct, delete or block, and receive a copy of your personal information (data portability), to object to processing, to withdraw consent, and to claim damages. For workforce data, please contact your organization, which controls that data; we will support its response. For anything else, contact us at [email protected]. If you believe your rights have been violated, you may file a complaint with the National Privacy Commission of the Philippines (privacy.gov.ph) or your local data protection authority.

10. Children

TINIUN is a business service and is not directed to children. We do not knowingly collect personal information from anyone under 16.

11. Changes to this policy

We will update this policy as TINIUN changes. When we make material changes, we will notify customers in advance, for example by email or in the application. The “last updated” date shows the latest version.

12. Contact

Questions about this policy or your information, including requests to our Data Protection Officer: [email protected], or write to the Data Protection Officer, Zaikus Philippines, Calamba City, Laguna, Philippines.