1.About this policy
This policy explains how Sabaidee HR (website and mobile app) collects, uses, stores and protects personal data. Sabaidee HR is developed and operated by NEXVORA SOLE CO., LTD ("we", "us").
We follow the Law on Electronic Data Protection and other applicable laws of the Lao PDR.
2.Who is responsible for your data
- Your employer (our customer that uses Sabaidee HR) is the data controller: it decides which data is collected and why, and it creates your account.
- We are the data processor on behalf of your employer: we store and process the data only on the employer's instructions, to run the service.
- Please send questions or requests about your data to your employer's HR team first. If they are not resolved, contact us (see "Contact us").
3.Data we collect
- Identity: full name, nickname, gender, date of birth, nationality, marital status, photo, employee code.
- Contact: phone, e-mail, address, place of birth, emergency contact.
- Employment: department, position, manager, hire date, shift, contracts, education, skills, training, performance reviews, warning letters, company assets held.
- Legal and financial: ID card / family book / passport number, social security number, tax ID, bank account, salary, payroll, tax and social security records.
- Attendance and requests: check-in/out times, leave requests (including attachments such as medical certificates), overtime, business trips, shift swaps, requests to HR.
- Location (GPS): coordinates and accuracy at the moment you check in or out in the app (see next section).
- Check-in selfie and QR (only when your employer turns them on for your work location): a front-camera photo and the QR code scanned at the workplace.
- Device and sign-in data: device ID, device name and operating system, push-notification token, IP address, sign-in times, audit log.
4.Location, camera and biometrics
- Location: the app reads your location only when you tap check-in/out, to confirm you are inside the work area set by your employer, and stores it with the time record. We do not track your location continuously.
- Camera and photos: used only when you choose to take or attach a picture (e.g. profile photo, medical certificate), and when your workplace requires a selfie or a QR scan at check-in.
- Check-in selfies: used to confirm that you checked in yourself. Taken live with the front camera (no gallery), visible only to HR and your manager, no automatic face matching, and deleted automatically after 90 days (or the period your employer sets).
- Fingerprint / face: verified by your phone itself. We never receive or store fingerprint or face data.
- Notifications: approval results, check-in reminders and company announcements. You can turn them off in your phone settings.
- You can deny these permissions at any time in your phone settings; without location, you cannot check in through the app.
5.How we use the data
- HR administration: employee records, contracts, documents, training and performance.
- Working time, leave, overtime and approval workflows.
- Calculating and paying salaries, tax and social security as required by law.
- Sending work-related notifications and announcements.
- Keeping accounts secure, preventing fraud, fixing problems and improving the service.
We do not sell personal data and do not use it for advertising.
7.Where data is stored
Data is stored on servers in Thailand. We use a provider with appropriate security measures and limit access to the people who need it.
8.How long we keep data
- For the duration of your employment and afterwards for the period set by your employer or required by law (e.g. payroll and tax records).
- Your employer can let the system automatically erase personal details of former employees after a set period (ID and bank numbers, address, photo, GPS coordinates, etc.).
- Check-in selfies are deleted automatically after 90 days (adjustable by your employer).
- When an employer stops using the service, its data is returned or deleted as agreed in the contract. Encrypted backup copies expire with the backup cycle.
9.Security
- Encrypted connections (HTTPS). Passwords are stored as one-way hashes — nobody can read your password.
- Two-factor authentication (2FA), lock-out after repeated wrong passwords, account-to-device binding.
- Role-based permissions, audit log of important actions (including who viewed salaries), a separate database per company.
- Regular, encrypted backups.
10.Your rights
- Access and copy your data (your profile in the system, or a full data file from HR).
- Correct inaccurate data (some fields you can edit yourself in your profile).
- Erase or restrict the use of your data — except data your employer must keep by law.
- Withdraw permissions for location, camera or notifications in your phone settings.
- Complain to your employer, to us or to the competent authority.
12.Changes to this policy
If we make important changes, we will update the date above and the system will ask you to read and accept the new version the next time you sign in.
13.Contact us
- Company
- NEXVORA SOLE CO., LTD
- Address
- Phonsavang Tai Village, Kaysone Phomvihane City, Savannakhet Province, Lao PDR
- info@nexvora.com.la
- Phone
- 020 9645 3615, 020 9424 6359
- Website
- nexvora.com.la