Privacy Policy

Last updated: 26 August 2026

This policy explains how NXORA ("we") collects, uses, stores and protects personal data when you use our platform and website. Our head office is at King Hussein Business Park, Building 23, Amman, Jordan, and we serve customers across the Middle East and North Africa. We apply data minimisation: we collect only what the service genuinely needs.

1. Our roles: controller and processor

For customer account data (user name, email, workspace details, usage logs) we act as a data controller and determine the purposes of processing.

For employee data the customer uploads into its workspace (names, salaries, contracts, leave, documents) we act as a data processor, processing it only on the customer's instructions and to operate the service. The customer is the controller of that data and is responsible for having a lawful basis for collecting it and for informing its employees.

2. Data we collect

  • Account data: name, email, hashed password, language and theme preference, workspace, role and permissions.
  • Organisation data: company name, country, currency, timezone, branches and departments.
  • Employee data entered by the customer: name, gender, nationality, contact details, contract and salary components, leave and attendance, custody items and attachments.
  • Billing data: plan, subscription status, renewal date and Paddle transaction identifiers. We never receive or store card numbers.
  • Technical data: IP address, browser and device type, sign-in times, error and performance logs, and the in-workspace activity log.

4. Payments and Paddle's role

All payments are handled by Paddle.com Market Limited as Merchant of Record. At checkout, Paddle collects and processes your financial data (card details, billing address, country for tax purposes) as an independent controller under its own privacy policy.

We receive only limited data back from Paddle: subscription status, plan, country, payment-method type or last four digits, and transaction/invoice identifiers — as needed to activate the subscription, issue invoices and provide support.

5. Who we share data with

We do not sell your data or your employees' data, and we do not use it for targeted advertising. We share it only with:

  • hosting, infrastructure and backup providers, under data-processing agreements;
  • Paddle, for payment, tax and invoicing;
  • transactional email, support and error-tracking providers;
  • professional advisers, courts or regulators where legally required;
  • an acquirer in a merger or acquisition, with this policy continuing to apply to transferred data.

6. International transfers

Data may be stored or processed on servers outside your country, including in the European Union. Where data leaves a given jurisdiction we rely on appropriate contractual safeguards (such as standard contractual clauses) with our providers.

7. Retention

  • Workspace data is retained for as long as the account is active.
  • After deletion or termination there is a thirty (30) day recovery/export window, after which data is deleted or anonymised within a reasonable period, subject to rolling backups that expire in turn.
  • Billing and accounting records are kept for the period required by law.
  • We may retain anonymised records for statistics, with no ability to re-identify an individual.

8. Security

  • TLS in transit and encryption at rest at the database provider.
  • Strict tenant isolation enforced at the database layer so one workspace cannot reach another's data.
  • Role-based permissions and an activity log for sensitive operations.
  • Passwords are stored hashed and cannot be read by us.
  • No internet system can be guaranteed absolutely secure; we will notify affected customers without undue delay of a breach affecting their data.

9. Cookies

We use cookies strictly necessary for sessions, authentication and storing language and theme preferences. We do not use advertising or cross-site tracking cookies. You can control cookies in your browser, but disabling essential cookies prevents sign-in.

10. Your rights

Subject to applicable law you have the right to access, rectify, erase, restrict or object to processing of your data, to data portability, and to withdraw consent.

If you are an employee of an organisation using the platform, your employer controls your data as controller; please direct your request to them first and we will support them in fulfilling it.

To exercise a right regarding data we control, email the privacy address below. We respond within a reasonable period not exceeding thirty (30) days.

11. Children's privacy

The platform is for business use and is not directed to anyone under 18; we do not knowingly collect their data as controller. If a customer enters a minor's data in employment records, responsibility for the lawfulness of that rests entirely with the customer.

12. Changes to this policy

We may update this policy to reflect changes in the service or the law. The updated version is published here with a revised date, and material changes are notified.

Contacting us about this document

NXORA
King Hussein Business Park, Building 23, Amman, Hashemite Kingdom of Jordan

Other legal documents