Combocast HR
Privacy
Last updated 4 August 2026
Combocast HR is an internal system used by Combocast to administer employment records for its own personnel. It is not a public service and has no users outside the company: sign-in is restricted to combocast.com Google Workspace accounts, and an account outside that domain is refused rather than shown an empty app.
What the system holds
Employment details (name, work email, phone numbers, date of birth, hire and exit dates, job title, department, manager, employment type), leave records and balances, salary and payroll figures, performance reviews, and documents uploaded by HR or by a worker's own manager. Some of this is entered by HR; some is read from Google Workspace by an hourly directory sync.
Who can see it
Anyone signed in can open any colleague's profile and see their photo, job title, department, work email, phone numbers, the day and month of their birthday, hire date, employment type, manager and direct reports — the same for a colleague who has left, whose leaving date is shown too. A shared calendar shows who is away and when, for everyone in the company, and marks birthdays; the leave type is named only where the company shows that type to colleagues, and otherwise reads simply “Away”.
Nothing else is company-wide. The birth year, salary and payslips, and leave balances are not shown to colleagues — you see your own, and HR sees them. Pay is not manager-visible: the person you report to is not shown your salary or your payslips. Managers do see the leave of the people who report to them and the requests they are asked to approve, and probation dates are visible to the worker, their own manager and HR. HR admins see employment and leave records, and the same admins see salary, payroll and performance data — there is no narrower tier inside HR. Two payroll actions are Super Admin only: re-opening a month that has already been reported, and erasing the record that a payment was made. Administrative actions are written to an audit log.
Documents and performance reviews reach further than that, and it is worth saying plainly. The documents on your HR file — contracts, ID scans, certificates and medical notes alike — can be opened and downloaded by you, by HR, and by your own manager; your manager can also add documents to your file and delete them, while you may read yours but not change them, because the file is the company's record of the employment. A performance review that you take part in is open to you, to HR and to the person conducting it, who is normally your manager, and that includes the answers you write in your own half of it. HR can also record a past review about you that you did not take part in — a rating and notes entered by an administrator, which stay internal to HR. “Your manager” here means the person recorded as your manager in this system, where that person also holds approval rights in it.
What is sent to Pumble
The optional Pumble add-on delivers notifications to a linked Pumble account, and — where the company switches it on — one daily “who is away today” post to a shared Pumble channel. It is a private add-on, installed only in Combocast's own workspace. The governing principle is that Pumble carries awareness and the HR system carries facts — a chat message is a copy, not a view, and it persists in a third-party system with its own retention, search and workspace-admin export.
A message may contain:
- the employee's name;
- a leave-type label — the actual name only where that type is one the company shows to colleagues, and otherwise the single word “Leave”;
- the dates of the leave;
- the number of working days — withheld whenever the type name was withheld, because a duration attached to an unnamed absence is itself a disclosure;
- a link back into this system, where the full record requires signing in.
- on a request sent to an approver, how many colleagues are already away in the same window — a count only, with no names;
- on the message telling somebody their request was decided, the name of the person who decided it, and whether they left a comment — the comment itself is never included;
- where a leave is half a day, which half — morning or afternoon, or just “half day” where the record does not say which.
The following are never included in a Pumble message: the reason given for a leave request, any approver's decision comment, any salary, payroll or deduction figure, any leave balance, date of birth, phone numbers, and every performance-review answer, score and goal.
To deliver a message the system reads the Pumble workspace member list (names, emails and account ids) and stores the resulting link between a Pumble account and an employee record. A message is only ever delivered to a linked account: someone with no Pumble account is never messaged there, and their email notifications are not withheld.
That is not the same as saying nothing about them reaches Pumble, and it is worth being exact. A request for approval names the person who asked for the leave, whether or not that person uses Pumble, because it is sent to their approver and naming them is what it is for. The daily digest, where it is switched on, lists everyone approved to be away that day, in a channel the workspace can read. Both carry only what the list above allows, and both say less than the shared calendar in this system already shows every colleague — but they say it inside a third-party workspace, which is why it is written down here.
Where it is held, and for how long
Data is held in Google Cloud in the europe-west1 region (Belgium), in a managed Postgres database. The application does not connect to it over the network at all: it reaches it through Google's own Cloud SQL connector, authorised by the service account the application runs as, and the database credentials are held in Google Secret Manager and supplied to the running service rather than living in the application or in anything a browser can see. Email is delivered through Resend; sign-in is handled by Google.
Employment and leave records are kept for as long as they are needed to administer the employment relationship and to meet the company's statutory obligations. Operational logs are pruned automatically: the audit log after 730 days, the error log after 90 days (measured from the last time the error happened, whether or not anyone has fixed it), and read in-app notifications, sent emails and delivered chat messages after 180 days — the last of these because notification text quotes the leave and review content it was announcing. A message that never reached the person it was for is kept until somebody deals with it.
Your rights
You can ask what the company holds about you, ask for a correction, and object to a particular processing activity. Speak to HR, or write to team@combocast.com. Some records cannot be deleted on request — a payroll month that has been reported to the accountant is deliberately immutable, because it is the record of what was actually paid.
What this system does not do
It does not sell or share personal data with third parties for their own purposes, and does not carry advertising or analytics trackers. Performance reviews do produce numbers: a review's ratings are combined into a weighted overall score, shown alongside the self-assessment and the manager's assessment, and company-wide averages appear on the HR dashboard. Nothing is decided by those numbers automatically — the score a review is completed with is entered by the reviewer, the outcome of a probation review is chosen by a person, and no pay, probation, employment status or access in this system changes as an automatic consequence of a score.