HRMS Mobile & Web Application — Pakistan
Ordinify Pvt. Ltd.(“we,” “us,” “our,” or the “Company”), a company incorporated in Pakistan, operates a Human Resource Management System (“HRMS,” the “Platform,” or the “Service”), available as a web dashboard and as native mobile applications on the Google Play Store and Apple App Store (the “App”). This Privacy Policy explains what personal data we collect through the App and web Platform, why we collect it, how we use and protect it, and the rights available to you.
This Policy is written to meet the disclosure requirements of Google Play’s Data Safety section and Apple’s App Privacy (“nutrition label”) requirements, in addition to applicable Pakistani law.
We currently offer our Services exclusively within the Islamic Republic of Pakistan. This Policy has been drafted with regard to the following Pakistani legal framework:
Where any of the above laws (or their successors) impose a stricter or additional obligation than this Policy, that law will prevail.
If you are an employee using the App and have a question about your data, please contact your employer (the Data Controller) in the first instance; we support Subscribers in fulfilling such requests.
Our mobile App requests the following device permissions only. Each is used strictly for the stated HR purpose, and neither is used for advertising, profiling, or sold to third parties. The App does not use the camera and does not collect photographs or facial data.
| Permission | Data Collected | Purpose |
|---|---|---|
| Precise Location (GPS) | Device latitude/longitude at the moment of clock-in/clock-out | Geofenced attendance verification — confirms the employee is within an approved work site radius when checking in or out |
| Biometric / Fingerprint Sensor | See important note below (Section 3.4) | Identity verification at check-in, or to unlock the App instead of a password |
Confirm with your development team which of the two models below applies — this materially changes what must be declared to Google Play and Apple, so getting this right is essential before submission.
If the App uses the phone’s native biometric APIs (Android BiometricPrompt / Keystore, or Apple Touch ID / Face ID via LocalAuthentication), the fingerprint template itself never leaves the device’s secure hardware enclave. The App only receives a pass/fail “authenticated” signal from the operating system — we never see, collect, transmit, or store the actual biometric data. In this model:
If a fingerprint scan is captured and transmitted to our servers (or a third-party biometric SDK) to generate and store a biometric template for matching, this is genuine collection of biometric/sensitive data and must be disclosed accordingly:
[Company to confirm and retain the applicable model paragraph; delete the other before publishing.]
| Purpose | Example | Legal Basis |
|---|---|---|
| Attendance verification | GPS check-in/out, biometric authentication | Performance of employment contract / employer’s legitimate interest |
| Providing and maintaining the HRMS | Payroll, leave, performance records | Performance of contract |
| Statutory compliance | EOBI/social security contributions, FBR tax filings | Legal obligation |
| App stability & security | Crash reporting, fraud prevention | Legitimate interest |
| Customer support | Responding to help desk tickets | Legitimate interest / consent |
Sensitive categories (biometric, CNIC) are only processed where permitted by law and with Subscriber consent.
This section maps our data practices to the disclosures required in Google Play’s Data Safety form and Apple’s App Privacy questionnaire.
| Data Type | Collected | Shared with 3rd Parties | Purpose | Encrypted in Transit | User Can Request Deletion |
|---|---|---|---|---|---|
| Precise location | Yes | No (visible only to employer) | App functionality | Yes | Yes |
| Biometric identifiers | See Section 3.4 | No | App functionality | Yes | Yes |
| Name, email, phone | Yes | No | App functionality, account management | Yes | Yes |
| Employment/HR records | Yes | No | App functionality | Yes | Yes (subject to statutory retention) |
| App activity / diagnostics | Yes | No | Analytics, crash reporting | Yes | Yes |
Note:“Photos and videos” should be declared as “Not collected” — our App does not use the camera.
| Data Category | Linked to You | Used to Track You | Purpose |
|---|---|---|---|
| Location (Precise) | Yes | No | App Functionality |
| Sensitive Info (biometric, if Model B) | Yes | No | App Functionality |
| Contact Info (name, email, phone) | Yes | No | App Functionality, Account Management |
| Identifiers (employee/account ID) | Yes | No | App Functionality |
| Diagnostics (crash data) | No | No | App Functionality |
We do not use any of the above data for third-party advertising, and we do not track users across other companies’ apps or websites.
For inclusion in your App Store / Play Store listing:
We do not sell personal data. We share data only with:
While our Services are offered in Pakistan, our infrastructure (cloud hosting) may store or process data outside Pakistan. Where this occurs, we ensure appropriate safeguards consistent with PECA and the anticipated requirements of the Personal Data Protection Bill, including contractual protections and encryption.
| Data Category | Retention Trigger | Retention / Grace Period | Deletion Action |
|---|---|---|---|
| Location check-in/out logs | Date of attendance record | 1,095 days (3 years), aligned with attendance/payroll audit needs | Permanently deleted or anonymized |
| Biometric templates (if Model B applies) | Withdrawal of consent, employee exit, or feature disablement | 30 days | Permanently and irreversibly deleted |
| End User employment records | Termination/resignation | 1,095 days (3 years) post-termination, per typical Shops & Establishment Ordinance practice | Permanently deleted or anonymized |
| Payroll & financial records | Date of transaction / tax year-end | 2,555 days (7 years), aligned with Income Tax Ordinance record-keeping practice | Permanently deleted |
| EOBI / social security contribution records | End of applicable statutory obligation | 1,825 days (5 years), or as mandated by EOBI/PESSI, whichever is longer | Permanently deleted |
| Crash logs & diagnostics | Date collected | 180 days | Auto-purged |
| Subscriber account data after termination | Contract end / closure request | 30-day soft-delete, hard-deleted at 90 days total | Purged from production and backups |
Our approach is built around four pillars — Access, Isolation, Confidentiality, and Deletion (“AICD”):
Subject to applicable law, you may have the right to:
To exercise these rights, contact us using the details in Section 13, or your employer if they are the Data Controller.
Our Services are intended for business use by adults and are not directed at children. We do not knowingly collect personal data from individuals under the age of 18.
We may update this Privacy Policy from time to time, including to reflect the enactment of Pakistan’s Personal Data Protection Bill or other regulatory developments. We will post the updated version with a revised “Last Updated” date, and where changes are material, provide additional notice (e.g., via email or in-app notification).
If you have questions, concerns, or requests regarding this Privacy Policy, please contact:
This Privacy Policy is a template drafted for general guidance and does not constitute legal advice. Because it covers location and biometric data used for attendance, and Pakistan’s Personal Data Protection Bill remains pending enactment, we strongly recommend review by qualified legal counsel in Pakistan, and verification that your Google Play Data Safety form and Apple App Privacy questionnaire exactly match your app’s actual behavior before submission.