At HazirA+ (a product of EzSoft), we are committed to protecting the privacy and security of your organization and employee data. This Privacy Policy explains how we collect, process, store, and safeguard information across our web portal, mobile apps, and connected biometric hardware.
1. Information We Collect
- Account Information: Company name, company slug, business address, admin email, contact numbers, and billing details.
- Employee Profile Data: Full name, employee code, numeric biometric user ID, RFID card number, department, designation, salary structure, and bank account information.
- Attendance & Biometric Logs: Hardware punch timestamps, device serial numbers, verification status, and shift assignments.
- Mobile App Permissions: GPS Geolocation (strictly for geofenced check-in verification), camera access (for optional selfie punch verification), and push notification tokens.
2. Biometric Data Protection & ADMS Security
2.1. HazirA+ uses numeric User IDs and alphanumeric template hashes to identify employees across biometric hardware. Raw biological fingerprints are processed locally on the hardware sensor according to ZKTeco ADMS standards.
2.2. All network transmissions between hardware terminals, web browsers, mobile apps, and our cloud servers are encrypted using modern TLS 1.3 / SSL cryptographic protocols.
3. How We Use Collected Data
- To record and calculate daily workforce attendance, late arrivals, early departures, and overtime.
- To generate payroll sheets, digital payslips, and compliance reports.
- To dispatch automated SMS and email notifications regarding leaves, shift changes, ticket replies, and subscription reminders.
- To ensure account security, detect fraud, and maintain audit logs.
4. Data Retention & Deletion
4.1. Subscriber data is retained for the duration of the active subscription and in accordance with statutory labor record-keeping requirements.
4.2. Upon account termination, the Subscriber may request a full export of their attendance and payroll data. Database records are permanently purged after 90 days of inactive cancellation unless required by law.
5. Third-Party Integrations & Gateways
We work with vetted service providers for critical SaaS infrastructure:
- SMS Gateways: For sending OTPs, leave notifications, and subscription alerts.
- Payment Processors (bKash/Nagad/SSLCommerz): For encrypted payment transactions. We never store credit card numbers or PINs on our servers.
- Firebase Cloud Messaging (FCM): For real-time mobile push notifications.
6. Contact Our Data Protection Officer
If you have any questions regarding this Privacy Policy or your data protection rights, please contact our Data Protection Team at [email protected] or write to: EzSoft, House #Nilachal, Road #01, Munshipara, Rangpur-5400, Bangladesh.