Terms of Service
Last updated: February 8, 2026
1. Acceptance of Terms
By accessing or using TitoHR ("the Service"), you agree to be bound by these Terms of Service. If you are using the Service on behalf of an organization, you represent that you have the authority to bind that organization to these terms.
2. Description of Service
TitoHR is a cloud-based human resources management platform that provides tools for employee management, salary tracking, contract management, document storage, performance reviews, goal tracking, and other HR-related functions.
3. Account Registration
To use the Service, you must:
- Create an account with accurate and complete information
- Maintain the security of your account credentials
- Notify us immediately of any unauthorized access
- Be at least 18 years old or have parental consent
You are responsible for all activities that occur under your account.
4. Acceptable Use
You agree not to:
- Use the Service for any unlawful purpose
- Upload malicious content or attempt to compromise system security
- Share account credentials with unauthorized parties
- Attempt to access data belonging to other organizations
- Use the Service to store data unrelated to human resources management
- Reverse engineer, decompile, or disassemble any part of the Service
5. Data Ownership
You retain ownership of all data you upload to TitoHR. We do not claim any intellectual property rights over your content. You grant us a limited license to process, store, and display your data solely for the purpose of providing the Service.
6. Service Availability
We strive to maintain high availability of the Service but do not guarantee uninterrupted access. We may perform scheduled maintenance and will make reasonable efforts to notify you in advance. We are not liable for any downtime or data loss resulting from circumstances beyond our reasonable control.
7. Payment Terms
Certain features of the Service may require a paid subscription. Pricing and payment terms will be communicated at the time of purchase. All fees are non-refundable unless otherwise stated. We reserve the right to modify pricing with 30 days' notice.
8. Termination
Either party may terminate the agreement at any time. Upon termination, we will provide a reasonable period to export your data. After the export period, we will delete all associated data in accordance with our Privacy Policy.
9. Limitation of Liability
To the maximum extent permitted by law, TitoHR shall not be liable for any indirect, incidental, special, consequential, or punitive damages resulting from your use of the Service. Our total liability shall not exceed the amount paid by you in the twelve months preceding the claim.
10. Indemnification
You agree to indemnify and hold harmless TitoHR and its officers, directors, employees, and agents from any claims, damages, or expenses arising from your use of the Service or violation of these Terms.
11. Changes to Terms
We reserve the right to modify these Terms at any time. We will notify you of material changes by posting the updated Terms on this page. Continued use of the Service after changes constitutes acceptance of the new Terms.
12. Governing Law
These Terms shall be governed by and construed in accordance with applicable law, without regard to conflict of law principles.
13. Contact Us
If you have any questions about these Terms, please contact us at legal@titohr.com.
Annex — Data Processing Agreement (DPA)
This Annex forms an integral part of these Terms and applies whenever your organization uploads personal data of its employees, candidates or other individuals to TitoHR. It is effective from 3 August 2026. Where this Annex conflicts with the body of the Terms on matters of personal data processing, this Annex prevails.
1. Roles of the parties
Your organization acts as the data controller: it decides what personal data is uploaded and for what purpose. TitoHR acts as the data processor: we process that data solely to provide the Service to you. TitoHR does not sell personal data and does not use your employees’ personal data to train artificial intelligence models.
2. Subject matter, duration and scope
Subject matter: providing the human resources management Service. Duration: for as long as your subscription is active, plus the deletion period described in section 10. Nature and purpose: storage, organization, consultation, analysis and transmission of human resources data. Categories of data subjects: your employees, former employees, candidates and any individual whose data your organization chooses to upload.
3. Categories of personal data
Identification and contact data, employment records, compensation and contract data, uploaded documents (résumés, contracts, general documents), performance, objectives, competency and assessment data, and time-off records. Your organization decides which of these to upload and must not use the Service to store personal data unrelated to human resources management.
4. Processing instructions
We process personal data only on your documented instructions, which include your use and configuration of the Service, unless we are required to process it by applicable law. If we believe an instruction breaches applicable data protection law, we will inform you.
5. Confidentiality
Any personnel authorized to process your personal data are bound by confidentiality obligations and access it only to the extent necessary to operate and support the Service.
6. Security measures
We maintain technical and organizational measures appropriate to the risk, including:
- Encryption of data in transit and at rest; third-party integration tokens encrypted with AES-256-GCM.
- Row Level Security in the database, so every query is restricted to your organization and tenants are isolated from one another. This isolation is verified by an automated test that checks each table.
- Role-based access control, field-level permissions for sensitive data, per-country permissions, and read-only external users limited to specific sections.
- Authentication by one-time email code or single sign-on with Google or Microsoft. API credentials stored only as SHA-256 hashes.
- An audit log recording changes with their previous and new values, including when an administrator acts on behalf of another user.
- AI features operate with the permissions of the user who invokes them and can never access more than that user can.
7. Subprocessors
You authorize TitoHR to engage the subprocessors listed below, all of which process data in the United States: Supabase (database, authentication and file storage), Vercel (application hosting and scheduled jobs), Anthropic and OpenAI (artificial intelligence models, text extraction and search indexing), Google (image generation for internal campaigns, and calendar synchronization if you enable it), Microsoft (calendar synchronization and single sign-on, if you enable it), Resend (transactional email), Stripe (subscription payment processing) and PostHog (product usage analytics, restricted to internal identifiers and never employee data). We will give you advance notice before adding or replacing a subprocessor, and you may object on reasonable data protection grounds; if we cannot resolve the objection, you may terminate the affected Service without penalty. An up-to-date list is available on request at privacy@titohr.com.
8. International transfers
The Service is hosted in the United States (Northern Virginia region). If your organization or your employees are located outside the United States, using the Service involves an international transfer of personal data. TitoHR does not currently offer data residency outside the United States. You are responsible for having a valid legal basis for that transfer under the laws applicable to you, and TitoHR undertakes to sign the contractual clauses your legal team reasonably requires to support it, and to provide the information needed to document it.
9. Assistance with data subject rights
The Service provides tools for your administrators to directly access, correct, export and delete personal data, so that you can respond to requests from data subjects. Where a request cannot be resolved with those tools, we will provide reasonable assistance at your request. If a data subject contacts TitoHR directly, we will refer them to your organization.
10. Security incident notification
We will notify you without undue delay, and in any event within 72 hours of becoming aware, of any confirmed security breach affecting your personal data. The notification will describe what is known about the nature of the incident, the categories of data affected, the likely consequences and the measures taken or proposed.
11. Audits and evidence of compliance
At your request and no more than once a year, we will provide the information reasonably necessary to demonstrate compliance with this Annex, including a description of our technical and organizational measures and answers to a security questionnaire. Any on-site audit requires reasonable prior notice, must not disrupt the Service, and is subject to confidentiality. TitoHR does not currently hold a SOC 2 or ISO 27001 certification.
12. Return and deletion of data
You may export your data at any time while the subscription is active. On termination we give you a reasonable window to export, and we then delete all associated data within 90 days, unless applicable law requires us to retain it. Technical logs have defined retention windows and are purged automatically: 24 months for the audit log and 12 months for operational logs.
13. Liability and prevailing terms
Liability under this Annex is subject to the limitations set out in the body of these Terms. If your organization requires a separate signed data processing agreement, contact privacy@titohr.com.
