Privacy Policy

Privacy Policy – Synclo HRMS

Effective Date: 08/01/2025

At Synclo, we understand that handling employee information is a matter of trust and responsibility. As a Human Resource Management System (HRMS), we are deeply committed to ensuring that your company’s data — and your employees’ personal information — is protected, private, and used only for the purpose of enhancing your workplace operations.

This Privacy Policy explains how we collect, process, use, share, and protect the information you store and manage through Synclo.

1. Information We Collect

As an HRMS platform, Synclo handles both company-level and employee-level data. The following types of information may be collected and processed:

a. Company and Admin Data

  • Company name, industry, official email, address, logo, and setup configurations.
  • Admin names, phone numbers, and login credentials.

b. Employee Data (Provided by Employers)

  • Full name, date of birth, contact information, CNIC/passport numbers, emergency contacts.
  • Job title, department, designation, salary details, benefits, performance records.
  • Attendance logs, leave balances, overtime history, shift schedules.
  • Bank details, tax identification numbers, and other payroll-related information.
  • Employment history, probation status, resignation/termination records.

c. System Usage Data

  • Login frequency, activity logs, module interactions.
  • IP address, device type, browser, and location (where applicable).

2. How We Use the Information

Synclo uses collected data solely to support and optimize HR operations. Uses include:

  • Automating employee lifecycle tasks: onboarding, role changes, confirmations, and exits.
  • Processing payroll, allowances, benefits, and statutory deductions.
  • Generating reports for attendance, performance, HR compliance, and audit trails.
  • Customizing access permissions based on user roles (e.g., HR, Manager, Finance).
  • Providing HR analytics and dashboards to improve organizational decision-making.
  • Sending updates and alerts related to HR tasks, policy changes, and system enhancements.

We do not access your employee data for any reason other than to provide you the services requested or for technical support purposes — and only under strict access control.

3. Data Ownership & Access

Your company retains full ownership of all data entered into Synclo. As a service provider, we act as a data processor — meaning we only process your data on your behalf and under your instructions.

You can control:

  • Who within your organization accesses which modules.
  • How long data is retained for employees.
  • Which documents are uploaded, deleted, or exported.

We maintain logs of all admin/user actions for traceability and security.

4. Data Sharing & Third-Party Access

Synclo does not sell, rent, or disclose your data to any third parties for marketing or commercial purposes.

We only share data with:

  • Cloud hosting and infrastructure providers (e.g., AWS) for secure data storage.
  • Email/SMS service providers used to send system-generated HR notifications.
  • Analytics tools that help improve our product performance — all anonymized.

All third-party providers operate under data protection agreements and are bound by confidentiality clauses.

5. Security of Your Data

  • Data is encrypted at rest and in transit using SSL/TLS protocols.
  • Role-based access control (RBAC) ensures only authorized personnel access specific data.
  • Regular penetration testing, vulnerability scans, and audits are conducted.
  • Two-factor authentication (2FA) is available for admin and HR roles.
  • All system actions are logged and traceable in audit trails.

6. Your Data Rights

Depending on your location (e.g., under GDPR, PDPA, or other local laws), your organization and its employees may have the right to:

  • Request access to the personal data stored in Synclo.
  • Correct inaccurate or outdated data.
  • Export or back up data in a readable format.
  • Request deletion of certain records (subject to retention policy).
  • Withdraw consent for specific data processing operations.

To exercise any of these rights, please contact [email protected].

7. Data Retention

Synclo allows you to define your own data retention rules. By default:

  • Employee records are retained as long as they are marked “active” in the system.
  • Upon termination/resignation, records are retained based on your configured policy.
  • If your subscription is canceled, we retain data for 30 days for backup/export purposes.
  • After that, data is permanently deleted from all servers and backups.

8. Data Portability & Export

  • Export employee records, payroll reports, leave summaries, and documents.
  • Admins can initiate exports at any time without support intervention.
  • You can choose export formats like Excel, CSV, or PDF depending on the module.

9. Cancellation & Data Deletion

  • We will retain your data for 30 days post-cancellation to allow for migration/export.
  • After that, all data is irreversibly deleted, including employee records, documents, and audit logs.
  • A confirmation of deletion can be provided upon request.

10. Compliance with Local & International Laws

Synclo is designed to support HR operations in multiple regions. We are committed to staying compliant with data privacy regulations including:

  • General Data Protection Regulation (GDPR)
  • Pakistan’s Personal Data Protection Bill (PDPB)
  • UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data
  • Any other applicable labor and privacy laws

11. Changes to This Policy

We may update this Privacy Policy to reflect changes in law, technology, or our business. All updates will be posted here with a revised effective date. Major changes will be communicated to all account admins via email.

12. Contact Us

Email: [email protected]
Phone: +1 (833) 201-7494
Address: Bu haleeba gold building, office M2, Hor Al Anz East, Dubai