Nexa People

This policy explains what personal data Nexa People handles, why we hold it, who else can see it, and what you can do about it. Nexa People is an HR and payroll platform operated by Villaex Technologies. Because we sit between an employer and its employees, our obligations differ depending on whose data is involved — so that is where this policy starts.

1. Two different roles

Almost every question about privacy on this platform resolves once you know which of these two situations applies.

  • HR records — we are the processor. Employee files, attendance, leave, payroll and documents belong to the organization that subscribes to Nexa People. That organization decides what to collect and why; we only act on its instructions. If you are an employee, your employer — not Nexa People — is the controller of your record, and requests about it start with them.
  • Our own business data — we are the controller. When you visit this website, request a demo, email support or pay an invoice, we decide how that data is used and we answer for it directly.

2. Data held on behalf of an employer

The exact fields depend on what each employer chooses to enable. In a typical deployment the platform stores:

  • Identity and contact details — name, date of birth, gender, photograph, personal and work contact details, address, emergency contacts and dependants.
  • Government and statutory identifiers — CNIC or Emirates ID (including issue and expiry dates), passport number, and payroll registrations such as EOBI, provident fund and tax numbers.
  • Employment record — designation, department, station, grade, shift, contract and probation dates, reporting line, appraisals, disciplinary entries, exit and final settlement records.
  • Attendance and leave — punch times, the daily attendance result, shift assignments, leave balances and requests, overtime and penalty calculations.
  • Financial data — salary structure, allowances and deductions, loans, bank account title and number, and generated payslips.
  • Documents — whatever the employer uploads against a record, such as contracts, certificates and ID scans.

Some of these are sensitive by law. The platform has fields for religion and marital status, and its ID fields commonly hold national identity numbers. They exist because payroll and statutory reporting in our markets ask for them. They are optional, and an employer that does not need a field should leave it empty — we do not require it to run payroll.

3. Data we hold in our own right

  • Account and billing — the details of the people who sign up, administer and pay for the subscription.
  • Support correspondence — what you send us when you ask for help, including any screenshots you attach.
  • Website and demo requests — the contact details you submit and basic technical data such as IP address and browser type. Cookies are covered separately in our Cookie Policy.
  • Security and audit logs — sign-in events, IP addresses and a record of actions taken in the platform. We keep these to investigate misuse and to give employers the audit trail their own compliance requires.

4. Why we process it

  • To provide the service the employer subscribed to — the contract we perform.
  • To meet legal obligations that apply to us, and to help employers meet theirs.
  • To keep the platform secure, prevent abuse and investigate incidents — our legitimate interest, and the employer's.
  • To bill, support and communicate with customers about the service.
  • To improve reliability and performance, using operational data rather than the contents of HR records.

Where an employer's local law requires employee consent or notice for a particular feature — location-based attendance is the usual example — it is the employer's responsibility to obtain it. Marketing email is sent only to business contacts and always carries an unsubscribe link.

5. Attendance, location and network signals

Attendance is the part of the platform that reaches furthest into someone's day, so we are specific about it. Employers can optionally restrict where the platform may be used:

  • IP restrictions— sign-in and punching can be limited to an approved network, which means we compare the IP address of the request against the employer's allow-list.
  • Geo-fencing— a punch can be required to fall inside a defined radius around a site, which means the device's reported coordinates are checked at the moment of the punch.
  • Device binding — an employee can be tied to one registered device identifier so a punch cannot be shared.

These checks are off unless an employer turns them on, and they apply at the moment of an action. The platform is not a continuous location tracker: it does not follow a device between punches, and it does not collect location in the background.

6. Biometric devices and punch data

Where an employer connects a biometric terminal, it is worth being clear about the division of responsibility. Fingerprint and face templates stay on the employer's device. Nexa People does not receive, store or process them. What we receive is a numeric punch code and a timestamp, which we map to an employee record. The daily attendance result is what we retain. The terminal itself is the employer's hardware, under the employer's control and their vendor's terms.

7. The AI help assistant

The in-app help assistant answers questions about how to use Nexa People. It is powered by Google's Gemini API, which means:

  • What is sent — the question you type, the recent turns of that chat, and matching entries from our help documentation.
  • What is not sent — your HR records. The assistant has no access to employee data, salaries or attendance; when asked about them it points you to the right screen instead.
  • Please do not paste employee data into the chat, since it will then leave our systems along with your question.

We do not use HR data to train AI models, and we do not permit our providers to train theirs on it.

8. Who else is involved

We do not sell personal data, and we do not share HR data with anyone for their own purposes. We rely on a short list of service providers, each bound to act only on our instructions:

  • Cloud hosting and infrastructure, where the platform and its backups run.
  • Email delivery (SendGrid), for notifications, approvals and password resets.
  • Google Gemini, for the help assistant described above.

Separately, our public marketing pages use the Meta (Facebook) Pixel to measure our advertising. Meta is not a processor acting on our instructions here — it uses what it receives for its own purposes too, which is why we keep it strictly off the product: it is not loaded anywhere inside the signed-in platform, and it never sees HR data. Exactly what it receives, and the cookies it sets, are set out in our Cookie Policy.

Beyond those, we disclose data only where an employer instructs us to — for example an export or an integration they configure, such as pushing payroll journals to their accounting system — or where the law compels us. If we are ever legally required to hand over customer data, we will tell the affected customer unless we are prohibited from doing so.

9. Where data is handled

Villaex Technologies is registered in the United States and operates from Lahore, Pakistan. Our team and some of our providers are therefore outside the country where an employer's employees are based, and data may be accessed from or stored in another jurisdiction. Where a transfer needs a legal safeguard, we put appropriate contractual protections in place. Employers with data-residency requirements should raise them with us before onboarding rather than after.

10. Security

The controls that matter most in a multi-tenant HR system are these: every organization's data is isolated so that one customer's users cannot reach another's; access inside an organization is governed by role-based permissions the employer configures; traffic between you and the platform is encrypted in transit using TLS; and privileged actions are written to an audit log. Our own access to customer data is limited to what support and operations genuinely require.

If you have a specific requirement around encryption at rest, key management or data residency, ask us before onboarding and we will tell you exactly what is and is not in place today. We would rather scope that honestly than answer it with a checkbox.

Accounts are yours to look after. Credentials should not be shared, and suspected compromise should be reported to us quickly — most incidents we see start with a shared or reused password rather than a broken control. No system is perfectly secure, and we do not claim otherwise; if a breach affects personal data we will notify affected customers without undue delay and support their own reporting duties.

11. Keeping and deleting data

  • During the subscription — HR data is retained for as long as the employer needs it, because payroll, tax and gratuity records have to remain available and auditable for years. The employer decides what to delete and when.
  • After it ends — we make the data available for export, then delete it from production within 30 days unless a written agreement or the law says otherwise. Backups age out on their own cycle, after which the data is gone from those too.
  • Our own records — billing and correspondence are kept for as long as tax and limitation periods require. Website and demo enquiries are deleted once they are stale.
  • On request — a deletion request that we can act on is honoured within 30 days, and we will tell you if we cannot act on it and why.

12. Your rights

Depending on where you live you may have the right to access your data, correct it, delete it, object to or restrict how it is used, and receive a copy in a portable form. How to use those rights depends on the two roles in section 1:

  • If you are an employee, contact your own HR team. Your record is theirs, and much of it you can already see and correct in the self-service screens. If they need our help to fulfil your request, we will support them.
  • If it concerns our own data about you — your account, an enquiry, our emails — write to us directly using the details below. We will not charge you for a reasonable request or make you justify it.

We may need to verify your identity first, which is a protection for you rather than an obstacle. You can also complain to your local data protection authority, though we would rather you gave us the chance to put it right first.

13. Children

Nexa People is a workplace tool that is not directed at children and we do not knowingly collect their data. Employers who lawfully employ young workers are responsible for the additional protections their local labour law requires.

14. Changes to this policy

We update this policy as the product changes. The date at the top always reflects the current version. When a change materially affects how we handle personal data, we will tell customers at least 7 days before it takes effect, so nothing important changes quietly.

15. Contact us

Privacy questions, requests and complaints can go to [email protected], and we aim to respond within 30 days.

Villaex Technologies · 22-D2, Johar Town, Lahore, Pakistan · 0323-9994066, 0324-4608194