Policyen

Privacy Policy

Privacy Policy for the Human Resources System and Application

1. Scope of the Policy

This policy applies to all personal data collected and processed by the System, which is intended for use by employees only. The System is not available to the general public.

2. Data We Collect

We collect various types of personal data necessary for managing the employment relationship and providing effective HR services. This data may include, but is not limited to:


  • Personal Identification Data: Full name, date of birth, place of birth, nationality, national ID/residency number, passport information.

  • Contact Information: Work and personal email address, work and personal phone number, residential address.

  • Employment Information: Job title, department, hire date, performance records, payroll and benefits information, termination date.

  • Bank and Financial Data: Bank account details for salary and benefit payments.

  • Educational and Professional Information: Academic qualifications, curriculum vitae (CV), work experience history, training courses, and certifications.

  • Health Information (where applicable and with consent): Sick leave reports, health insurance information (as permitted and required by law).

  • System Usage Data: Login records, in-app activity, user preferences (does not include sensitive personal information).

  • Photos and Documents: ID card photos, passport photos, personal photos (if required for employee file).

3. How We Collect Data

We collect data through the following methods:


  • Direct Input from Employees: When an employee creates or updates their profile in the System or application.

  • By the HR Department: When employee data is entered or updated by HR personnel or management.

  • System Generation: Data such as login records and activities.

4. Basis for Data Processing

We process your personal data based on the following legal grounds:


  • Performance of a Contract: Processing data is necessary for the performance of the employment contract between you and the Company.

  • Legal Obligation: Processing data is necessary for compliance with legal obligations (e.g., taxes, social security, labor laws).

  • Legitimate Interests: Processing data is necessary for our legitimate interests as a company (e.g., employee management, operational improvement), provided that these interests do not override your rights and freedoms.

  • Consent (where appropriate): In some cases, we may request your explicit consent to collect or process certain types of data (e.g., health data for specific purposes).

5. Purposes of Data Use

We use the personal data we collect for the following purposes:


  • Managing the Employment Relationship: Recruitment, payroll and benefits administration, attendance and leave management, performance appraisals, training and development.

  • Legal and Regulatory Compliance: Adherence to labor laws, tax laws, social security regulations, and other legal requirements.

  • Employee Communication: Sending important notices, company updates, and information regarding benefits and policies.

  • Improving Internal Operations: Analyzing data to enhance operational efficiency, policy development, and administrative decision-making.

  • Security and Protection: Safeguarding company and employee data, and detecting and preventing fraud or unauthorized activities.

  • Providing Functional Access to the System and Application: Enabling employees to access their personal information, request leave, view payslips, and manage other aspects of their employment relationship.

6. Data Sharing and Disclosure

We will not sell, rent, or trade your personal data to third parties. However, we may share your personal data with the following parties, as necessary and for the purposes stated above:


  • Government Authorities and Regulatory Bodies: When required by law or in compliance with a court order.

  • External Service Providers: Companies that provide services to us (e.g., payroll processing, insurance services, IT services) and are bound by strict confidentiality agreements.

  • Affiliates or Sister Companies: For internal administrative purposes (if any).

In all cases, we ensure that third parties with whom we share data adhere to appropriate levels of data protection and confidentiality.

7. Data Security

We implement appropriate technical and organizational security measures to protect personal data from unauthorized access, alteration, disclosure, or destruction. These measures include:


  • Encryption: Using encryption to protect data during transit and storage.

  • Access Control: Restricting access to personal data to authorized employees who require access to perform their duties.

  • Multi-Factor Authentication (MFA): To secure access to the System.

  • Firewalls: To protect networks.

  • Regular Audits: Conducting regular security reviews of the System to ensure the effectiveness of security measures.

  • Employee Training: Training our employees on the importance of data protection and security practices.

While we take all reasonable measures to protect your data, the security of any online data transmission or electronic storage system cannot be guaranteed 100%.

8. Data Retention

We retain your personal data for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Retention periods are determined based on the type of data, the purpose of its processing, and relevant legal requirements.

9. Your Rights as an Employee

As an employee, you have the following rights regarding your personal data:


  • Right to Access: Request a copy of the personal data we hold about you.

  • Right to Rectification: Request correction of any inaccurate or incomplete personal data.

  • Right to Erasure ("Right to Be Forgotten"): Request deletion of your personal data in certain circumstances (considering legal and regulatory requirements that may prevent immediate deletion).

  • Right to Restrict Processing: Request the restriction of processing your personal data in certain circumstances.

  • Right to Object to Processing: Object to the processing of your personal data in certain circumstances.

  • Right to Data Portability: Request the transfer of your personal data to you or to a third party in a structured, commonly used, and machine-readable format.

  • Right to Withdraw Consent: If we rely on your consent as the legal basis for processing, you have the right to withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.

To exercise any of these rights, please contact the HR Department or the Company's Data Protection Officer (if applicable) using the contact details provided below. We may ask you to verify your identity before processing your request.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Any changes to this policy will be posted on the System/Application with an updated "Effective Date" at the top. You are advised to review this policy periodically. Your continued use of the System after changes are posted constitutes your acceptance of those changes.

11. Contact Information

If you have any questions or concerns about this Privacy Policy or our data practices, please contact:

Email: cloudsnapai@gmail.com



جميع الحقوق محفوظة CLOUD SNAP 2025