Skip to content

Legal

Data Processing Policy

Last updated: 01 September 2026

§01

Overview

This Data Processing Policy ("DPA") describes how AIHR BD ("we", "us", the "Processor") processes personal data on behalf of customer organisations (each a "Controller") that use the AIHR BD platform. It supplements our Terms of Service and Privacy Policy and applies whenever a Controller uploads, stores or processes personal data through the platform.

§02

Roles of the parties

The Controller (your organisation) decides the purposes and means of processing employee, contractor and applicant personal data. AIHR BD acts as the Processor and only processes that data on the Controller's documented instructions, expressed through the configuration of the platform and any signed agreement between us.

§03

Categories of data & data subjects

The platform is designed to process the following categories of personal data:

  • Identification data (name, employee ID, photo, national ID)
  • Contact data (email, phone, address, emergency contacts)
  • Employment data (designation, department, salary, bank account, tax ID)
  • Attendance, leave, payroll and performance records
  • Device, browser, IP address and audit log information

Data subjects include the Controller's employees, contractors, drivers, applicants, dependants and authorised administrators.

§04

Purpose & duration

We process personal data only to (a) deliver and maintain the platform's HRM, payroll, attendance, fleet and reporting features, (b) provide customer support, (c) ensure security and prevent abuse, and (d) comply with legal obligations. Processing continues for the duration of the Controller's subscription and the retention windows configured on the account.

§05

Security measures

  • TLS 1.2+ for all data in transit; AES-256 at rest for database, file storage and backups.
  • Tenant isolation enforced by row-level security at the database layer.
  • Role-based access control (Super Admin, Admin, HR, Employee) with audit logging.
  • Trusted-device verification and email-based anomaly alerts for admin accounts.
  • Encrypted backups with point-in-time recovery and tested restore procedures.
  • Vulnerability scanning, dependency monitoring and least-privilege secrets management.
§06

Sub-processors

We rely on a small number of vetted sub-processors to operate the platform. Current sub-processors:

  • Lovable Cloud / Supabase — managed database, authentication, storage and edge functions.
  • Lovable — application hosting and CDN for the web front-end.
  • Lovable Emails — transactional email delivery from the updates.aihrbd.com domain.

Controllers will be notified of material changes to this list. Each sub-processor is bound by confidentiality and security obligations equivalent to those in this policy.

§07

International transfers

Where personal data is transferred outside Bangladesh (for example to regional hosting regions used by our sub-processors), we ensure appropriate safeguards are in place, including contractual commitments, encryption in transit and at rest, and access restricted to authorised personnel.

§08

Data subject requests

We will assist the Controller in responding to access, correction, deletion, restriction and portability requests from data subjects. Controllers can fulfil most requests directly from the employee record screens. For anything that cannot be self-served, contact .

§09

Breach notification

If we become aware of a personal data breach affecting Controller data, we will notify the Controller without undue delay (and in any event within 72 hours of confirmation) with the information needed to meet any regulatory reporting obligations.

§010

Return & deletion

On termination of the subscription, Controllers may export their data from the platform for 30 days. After that period, personal data is deleted from active systems within 30 days and from encrypted backups within 90 days, unless retention is required by law.

§011

Contact

For questions about this DPA or to request a signed copy for procurement review, contact .