Privacy Policy
Last updated: 26 August 2026
This policy explains how NXORA ("we") collects, uses, stores and protects personal data when you use our platform and website. Our head office is at King Hussein Business Park, Building 23, Amman, Jordan, and we serve customers across the Middle East and North Africa. We apply data minimisation: we collect only what the service genuinely needs.
1. Our roles: controller and processor
For customer account data (user name, email, workspace details, usage logs) we act as a data controller and determine the purposes of processing.
For employee data the customer uploads into its workspace (names, salaries, contracts, leave, documents) we act as a data processor, processing it only on the customer's instructions and to operate the service. The customer is the controller of that data and is responsible for having a lawful basis for collecting it and for informing its employees.
2. Data we collect
- Account data: name, email, hashed password, language and theme preference, workspace, role and permissions.
- Organisation data: company name, country, currency, timezone, branches and departments.
- Employee data entered by the customer: name, gender, nationality, contact details, contract and salary components, leave and attendance, custody items and attachments.
- Billing data: plan, subscription status, renewal date and Paddle transaction identifiers. We never receive or store card numbers.
- Technical data: IP address, browser and device type, sign-in times, error and performance logs, and the in-workspace activity log.
3. Purposes and legal bases
- Performance of contract: creating the account, operating the platform, computing payroll, keeping records and providing support.
- Legitimate interests: platform security and fraud prevention, performance and reliability, aggregate usage measurement.
- Legal obligation: retaining accounting and tax records and responding to lawful requests from authorities.
- Consent: optional marketing messages, withdrawable at any time.
4. Payments and Paddle's role
All payments are handled by Paddle.com Market Limited as Merchant of Record. At checkout, Paddle collects and processes your financial data (card details, billing address, country for tax purposes) as an independent controller under its own privacy policy.
We receive only limited data back from Paddle: subscription status, plan, country, payment-method type or last four digits, and transaction/invoice identifiers — as needed to activate the subscription, issue invoices and provide support.
6. International transfers
Data may be stored or processed on servers outside your country, including in the European Union. Where data leaves a given jurisdiction we rely on appropriate contractual safeguards (such as standard contractual clauses) with our providers.
7. Retention
- Workspace data is retained for as long as the account is active.
- After deletion or termination there is a thirty (30) day recovery/export window, after which data is deleted or anonymised within a reasonable period, subject to rolling backups that expire in turn.
- Billing and accounting records are kept for the period required by law.
- We may retain anonymised records for statistics, with no ability to re-identify an individual.
8. Security
- TLS in transit and encryption at rest at the database provider.
- Strict tenant isolation enforced at the database layer so one workspace cannot reach another's data.
- Role-based permissions and an activity log for sensitive operations.
- Passwords are stored hashed and cannot be read by us.
- No internet system can be guaranteed absolutely secure; we will notify affected customers without undue delay of a breach affecting their data.
10. Your rights
Subject to applicable law you have the right to access, rectify, erase, restrict or object to processing of your data, to data portability, and to withdraw consent.
If you are an employee of an organisation using the platform, your employer controls your data as controller; please direct your request to them first and we will support them in fulfilling it.
To exercise a right regarding data we control, email the privacy address below. We respond within a reasonable period not exceeding thirty (30) days.
11. Children's privacy
The platform is for business use and is not directed to anyone under 18; we do not knowingly collect their data as controller. If a customer enters a minor's data in employment records, responsibility for the lawfulness of that rests entirely with the customer.
12. Changes to this policy
We may update this policy to reflect changes in the service or the law. The updated version is published here with a revised date, and material changes are notified.