Privacy Policy
HRMS Mobile & Web Application — Pakistan
1. Introduction
Ordinify Pvt. Ltd. (“we,” “us,” “our,” or the “Company”), a company incorporated in Pakistan, operates a Human Resource Management System (“HRMS,” the “Platform,” or the “Service”), available as a web dashboard and as native mobile applications on the Google Play Store and Apple App Store (the “App”). This Privacy Policy explains what personal data we collect through the App and web Platform, why we collect it, how we use and protect it, and the rights available to you.
This Policy is written to meet the disclosure requirements of Google Play’s Data Safety section and Apple’s App Privacy (“nutrition label”) requirements, in addition to applicable Pakistani law.
We currently offer our Services exclusively within the Islamic Republic of Pakistan. This Policy has been drafted with regard to the following Pakistani legal framework:
- The Prevention of Electronic Crimes Act, 2016 (PECA), which governs unauthorized access to data, data breaches, and related electronic offences;
- The Personal Data Protection Bill — Pakistan’s principal data protection legislation, which remains in draft/pending-enactment form as of the date of this Policy. We have proactively aligned our practices with its anticipated requirements (including consent, purpose limitation, and data subject rights) as a matter of good practice, even though the Bill is not yet fully in force;
- Provincial labour and social security laws, including the Employees’ Old-Age Benefits Institution (EOBI) Act, and Provincial/Sindh/Punjab/Balochistan/Khyber Pakhtunkhwa Employees’ Social Security Ordinances, which govern retention of certain employment and contribution records; and
- The Income Tax Ordinance, 2001 and applicable FBR regulations, which govern retention of payroll and tax-related records.
Where any of the above laws (or their successors) impose a stricter or additional obligation than this Policy, that law will prevail.
2. Our Role: Controller vs. Processor
- When your employer (the Subscriber) uses the HRMS to manage its workforce, the Subscriber is the Data Controller of your personal data, and we act as a Data Processor, processing that data strictly on the Subscriber’s documented instructions.
- When we collect data directly — e.g., app account registration, crash reports, or support requests — we act as the Data Controller.
If you are an employee using the App and have a question about your data, please contact your employer (the Data Controller) in the first instance; we support Subscribers in fulfilling such requests.
3. Personal Data We Collect
3.1 Account & Registration Data
- Name, employee ID, work email/phone, job title, department, and login credentials.
3.2 Employment & HR Data (via web Platform and App)
- Attendance, leave, payroll, performance, and other employment records entered by you or your employer.
- Bank account details for payroll processing, and CNIC or other national identity numbers where required for statutory reporting (e.g., EOBI, tax).
3.3 Data Collected via Mobile App Permissions
Our mobile App requests the following device permissions only. Each is used strictly for the stated HR purpose, and neither is used for advertising, profiling, or sold to third parties. The App does not use the camera and does not collect photographs or facial data.
| Permission | Data Collected | Purpose |
|---|---|---|
| Precise Location (GPS) | Device latitude/longitude at the moment of clock-in/clock-out | Geofenced attendance verification — confirms the employee is within an approved work site radius when checking in or out |
| Biometric / Fingerprint Sensor | See important note below (Section 3.4) | Identity verification at check-in, or to unlock the App instead of a password |
3.4 Important Note on Biometric / Fingerprint Data
Model A — On-device authentication only (recommended, most common)
If the App uses the phone’s native biometric APIs (Android BiometricPrompt / Keystore, or Apple Touch ID / Face ID via LocalAuthentication), the fingerprint template itself never leaves the device’s secure hardware enclave. The App only receives a pass/fail “authenticated” signal from the operating system — we never see, collect, transmit, or store the actual biometric data. In this model:
- Google Play Data Safety: declare biometric identifiers as “not collected” (only device-level authentication result is used).
- Apple App Privacy: declare “Data Not Collected” for Biometric/Sensitive Info, since Apple treats on-device Touch ID/Face ID matching as outside the developer’s data collection.
Model B — Server-side biometric processing (e.g., a dedicated fingerprint attendance device/SDK)
If a fingerprint scan is captured and transmitted to our servers (or a third-party biometric SDK) to generate and store a biometric template for matching, this is genuine collection of biometric/sensitive data and must be disclosed accordingly:
- Google Play Data Safety: declare under “Personal info” as applicable, mark as collected and shared only with the employer, and confirm encryption in transit and at rest.
- Apple App Privacy: declare under “Sensitive Info” (biometric data), linked to the user’s identity, not used for tracking.
[Company to confirm and retain the applicable model paragraph; delete the other before publishing.]
3.5 Automatically Collected Data
- Device information: device model, OS version, unique app instance identifiers, crash logs, and diagnostics.
- Usage data: screens visited, feature usage, session length (used to improve the App, not for advertising).
4. Purposes and Legal Basis for Processing
| Purpose | Example | Legal Basis |
|---|---|---|
| Attendance verification | GPS check-in/out, biometric authentication | Performance of employment contract / employer’s legitimate interest |
| Providing and maintaining the HRMS | Payroll, leave, performance records | Performance of contract |
| Statutory compliance | EOBI/social security contributions, FBR tax filings | Legal obligation |
| App stability & security | Crash reporting, fraud prevention | Legitimate interest |
| Customer support | Responding to help desk tickets | Legitimate interest / consent |
Sensitive categories (biometric, CNIC) are only processed where permitted by law and with Subscriber consent.
5. Google Play & Apple App Store Disclosures
This section maps our data practices to the disclosures required in Google Play’s Data Safety form and Apple’s App Privacy questionnaire.
5.1 Google Play Data Safety Mapping
| Data Type | Collected | Shared with 3rd Parties | Purpose | Encrypted in Transit | User Can Request Deletion |
|---|---|---|---|---|---|
| Precise location | Yes | No (visible only to employer) | App functionality | Yes | Yes |
| Biometric identifiers | See Section 3.4 | No | App functionality | Yes | Yes |
| Name, email, phone | Yes | No | App functionality, account management | Yes | Yes |
| Employment/HR records | Yes | No | App functionality | Yes | Yes (subject to statutory retention) |
| App activity / diagnostics | Yes | No | Analytics, crash reporting | Yes | Yes |
Note: “Photos and videos” should be declared as “Not collected” — our App does not use the camera.
5.2 Apple App Privacy (“Nutrition Label”) Mapping
| Data Category | Linked to You | Used to Track You | Purpose |
|---|---|---|---|
| Location (Precise) | Yes | No | App Functionality |
| Sensitive Info (biometric, if Model B) | Yes | No | App Functionality |
| Contact Info (name, email, phone) | Yes | No | App Functionality, Account Management |
| Identifiers (employee/account ID) | Yes | No | App Functionality |
| Diagnostics (crash data) | No | No | App Functionality |
We do not use any of the above data for third-party advertising, and we do not track users across other companies’ apps or websites.
5.3 Suggested Permission Usage Descriptions
For inclusion in your App Store / Play Store listing:
- NSLocationWhenInUseUsageDescription: “We use your location only while the app is open, to confirm you are at an approved work site when you check in or out.”
- NSFaceIDUsageDescription: “Touch ID/Face ID is used to securely unlock the app and confirm your identity for attendance check-in.”
6. How We Share Personal Data
We do not sell personal data. We share data only with:
- Sub-processors and service providers who support our infrastructure (e.g., cloud hosting, crash reporting, email delivery) under strict data processing agreements;
- Your employer (Subscriber), who can view your HR, attendance, and verification data as the Data Controller;
- Government and regulatory authorities in Pakistan where required by law (e.g., FBR, EOBI, courts); and
- Professional advisors such as auditors or legal counsel, under confidentiality obligations.
7. Cross-Border Data Storage & Transfers
While our Services are offered in Pakistan, our infrastructure (cloud hosting) may store or process data outside Pakistan. Where this occurs, we ensure appropriate safeguards consistent with PECA and the anticipated requirements of the Personal Data Protection Bill, including contractual protections and encryption.
8. Data Retention & Deletion Schedule
| Data Category | Retention Trigger | Retention / Grace Period | Deletion Action |
|---|---|---|---|
| Location check-in/out logs | Date of attendance record | 1,095 days (3 years), aligned with attendance/payroll audit needs | Permanently deleted or anonymized |
| Biometric templates (if Model B applies) | Withdrawal of consent, employee exit, or feature disablement | 30 days | Permanently and irreversibly deleted |
| End User employment records | Termination/resignation | 1,095 days (3 years) post-termination, per typical Shops & Establishment Ordinance practice | Permanently deleted or anonymized |
| Payroll & financial records | Date of transaction / tax year-end | 2,555 days (7 years), aligned with Income Tax Ordinance record-keeping practice | Permanently deleted |
| EOBI / social security contribution records | End of applicable statutory obligation | 1,825 days (5 years), or as mandated by EOBI/PESSI, whichever is longer | Permanently deleted |
| Crash logs & diagnostics | Date collected | 180 days | Auto-purged |
| Subscriber account data after termination | Contract end / closure request | 30-day soft-delete, hard-deleted at 90 days total | Purged from production and backups |
9. Data Security, Isolation & Access Framework
Our approach is built around four pillars — Access, Isolation, Confidentiality, and Deletion (“AICD”):
9.1 Access Control
- Role-based access control (RBAC): an employee sees only their own record; managers see only their direct reports.
- Multi-factor authentication for administrator accounts; full audit trails on sensitive HR fields.
9.2 Isolation (Multi-Tenant Architecture)
- Every record is scoped to a unique Tenant ID, enforced at the database query layer (row-level security), so cross-tenant access is structurally impossible.
- Environment separation between production, staging, and development; real Subscriber data is never used outside production.
- Network-level segmentation between application, database, and backup layers.
9.3 Confidentiality
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256 or equivalent), including location and biometric data.
- Regular penetration testing and vulnerability scanning.
9.4 Deletion
- Deletion follows the schedule in Section 8, executed via soft-delete → hard-delete → backup purge.
10. Your Rights
Subject to applicable law, you may have the right to:
- Access, correct, or request deletion of your personal data, subject to statutory retention requirements;
- Withdraw consent at any time for location or biometric features (noting this may disable certain attendance features);
- Object to or restrict certain processing;
- Lodge a complaint with the relevant authority once Pakistan’s Personal Data Protection Bill is enacted and a supervisory authority is established; until then, complaints may be raised with us directly or pursued under PECA where applicable.
To exercise these rights, contact us using the details in Section 13, or your employer if they are the Data Controller.
11. Children’s Privacy
Our Services are intended for business use by adults and are not directed at children. We do not knowingly collect personal data from individuals under the age of 18.
12. Changes to This Policy
We may update this Privacy Policy from time to time, including to reflect the enactment of Pakistan’s Personal Data Protection Bill or other regulatory developments. We will post the updated version with a revised “Last Updated” date, and where changes are material, provide additional notice (e.g., via email or in-app notification).
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, please contact:
- Ordinify Pvt. Ltd.
- Attn: Privacy / Data Protection Officer
- Level 11, Arfa Software Technology Park, Ferozepur Road, Lahore, Pakistan
- Email: privacy@ordinify.com
- Phone: +92 3208419845
This Privacy Policy is a template drafted for general guidance and does not constitute legal advice. Because it covers location and biometric data used for attendance, and Pakistan’s Personal Data Protection Bill remains pending enactment, we strongly recommend review by qualified legal counsel in Pakistan, and verification that your Google Play Data Safety form and Apple App Privacy questionnaire exactly match your app’s actual behavior before submission.
