PREAMBLE & SCOPE
DORT Asia Pte. Ltd. (“DORT Asia”, “we”, “us”, or “our”) operates Xentra, a cloud-based Human Resource Management System (“Xentra” or the “Service”).
This Privacy Policy explains how we collect, use, disclose, store, protect and otherwise process personal data in connection with the Xentra website, web application, mobile application, customer accounts, employee management features, customer support, and related services provided by DORT Asia.
By using Xentra or providing personal data to us, you acknowledge that your personal data may be processed in accordance with this Privacy Policy and applicable law.
Data Controller vs Data Processor Role
For business customers using Xentra to manage their employees, contractors or workforce members, DORT Asia generally processes workforce personal data on behalf of the customer (Data Processor). The customer determines the purposes and means of processing. For personal data relating to direct account holders, billing contacts, and website visitors, DORT Asia acts in its own capacity (Data Controller).
1. ABOUT XENTRA
Xentra is designed to help businesses manage employee information, lifecycle records, attendance, leave, payroll workflows, documents, work-pass records, workforce administration, employee self-service, reporting, and compliance workflows.
Xentra is designed around a central employee record. Other workforce modules use this information to provide connected operations.
No Continuous Monitoring
Xentra is NOT designed to continuously monitor, surveil, or background-track employees.
2. WHO THIS PRIVACY POLICY APPLIES TO
This Privacy Policy applies to:
- 1.Visitors to the Xentra website;
- 2.Customers and prospective customers;
- 3.Authorised users of Xentra;
- 4.Administrators, HR personnel, managers and employees using Xentra;
- 5.Individuals whose information is entered into Xentra by a customer;
- 6.Individuals who communicate with DORT Asia;
- 7.Billing and account contacts; and
- 8.Other individuals whose personal data is processed in connection with Xentra.
Where a customer uses Xentra to process workforce data, the customer is responsible for providing appropriate privacy notices to their employees and workforce members.
3. TYPES OF PERSONAL DATA WE MAY PROCESS
The personal data processed through Xentra depends on the features used by the customer and the information provided.
3.1 Account and User Information
- Name, email address, phone number, username or account identifier;
- Authentication information, user role, company or organisation;
- Account status, login and security audit information.
3.2 Employee and Workforce Information
- Employee name, employee ID, contact details, date of birth, nationality, identification information, residential address;
- Employment type, status, joining date, probation, confirmation, department, designation, team, reporting manager;
- Work-pass information, education and qualifications, emergency contacts, employee documents;
- Bank and payment details, compensation information, salary history, attendance records, leave records, payroll information, claims or expenses, and assigned company assets.
3.3 Attendance and Location Information
Location Verification Policy
Where a customer enables location verification for attendance, Xentra collects location data ONLY when an employee performs a location-enabled attendance check-in or check-out. Xentra does NOT continuously track employee location. Minimum location data is captured solely to validate geofence and attendance rules.
3.4 Payroll and Financial Information
- Salary information, allowances, deductions, compensation history;
- Bank account numbers, payroll records, CPF-related information, SDL contributions, IRAS tax reporting records, and payslip data.
3.5 Documents
Customers may upload employment contracts, offer letters, identity documents, passports, work passes, education certificates, salary letters, medical certificates, and related HR files.
3.6 Technical and Usage Information
- IP address, browser type, device information, operating system;
- Authentication events, security logs, timestamps, error records, and service usage telemetry.
4. HOW WE COLLECT PERSONAL DATA
Personal data is collected through account registration, onboarding, employee imports, employee self-service check-in/out, leave applications, payroll workflows, document uploads, support requests, mobile app interactions, integrations, and automated security audit systems.
5. WHY WE USE PERSONAL DATA
5.1 Providing Xentra Services
To administer accounts, maintain employee records, process attendance and leave, compute payroll workflows, generate payslips, provide reporting, store documents, and run customer-configured workforce automations.
5.2 Authentication and Security
To authenticate users, protect accounts, detect suspicious activities, prevent unauthorized access, investigate incidents, and maintain tamper-evident audit trails.
5.3 Transactional Communications
To send verification emails, authentication messages, password resets, plan expiry alerts, billing invoices, and security notifications.
5.4 Customer Support & Billing
To respond to technical enquiries, process subscription payments, manage renewals, and handle billing administration.
6. EMPLOYEE AND WORKFORCE DATA (B2B CONTEXT)
Xentra is primarily a business-to-business (B2B) HRMS. When a customer uses Xentra to process workforce data:
- The customer determines the purpose and lawful basis for collecting employee information;
- The customer is responsible for providing appropriate privacy notices under the Singapore PDPA;
- Xentra processes the information strictly to provide the subscribed software services;
- Access is strictly partitioned by customer tenant boundaries and role-based permissions.
7. LOCATION DATA AND GPS ATTENDANCE
When GPS attendance is configured by a customer: the mobile app captures the device location exclusively at the exact moment of check-in or check-out to validate customer geofence boundaries.
Zero Background Location Tracking
Location is NEVER collected in the background or when the app is idle. Location capture occurs only during explicit user-initiated check-in/out actions.
9. THIRD-PARTY SERVICES AND DATA PROCESSORS
We partner with trusted infrastructure and service providers to operate Xentra:
9.1 Supabase (Database & Storage)
Provides PostgreSQL database hosting, file storage, authentication, and backend infrastructure. Xentra’s production environment is hosted in the Singapore AWS region (ap-southeast-1).
9.2 Stripe (Payment Processing)
Handles subscription billing and payment processing. Credit card details are securely vaulted directly by Stripe and never stored on DORT Asia servers.
9.3 Brevo (Transactional Email)
Delivers authentication emails, password resets, verification codes, and service notices.
9.4 Firebase Cloud Messaging (FCM)
Delivers push notifications to mobile devices.
9.5 WhatsApp
Sends service alerts such as plan expiry and subscription renewal reminders.
10. THIRD-PARTY INTEGRATIONS
Where customers enable third-party software integrations, data is exchanged strictly according to configured permissions. Customers are responsible for reviewing third-party terms and privacy policies.
11. HOW WE PROTECT PERSONAL DATA
We enforce rigorous technical and organizational security controls designed to safeguard personal data:
- Multi-factor authentication & role-based access control (RBAC);
- Row Level Security (RLS) and database tenant logical isolation;
- Encryption in transit (TLS 1.3) and encryption at rest (AES-256);
- Least-privilege access enforcement and automated audit logging;
- Regular automated backups and disaster recovery verification;
- Server-side validation for all external API events and webhook signatures.
12. MULTI-TENANT DATA ISOLATION
Xentra enforces strict multi-tenant data partitioning at both the application and database levels. A user from one customer organisation cannot access or query another customer’s data.
13. DATA RETENTION
13.1 Customer Workforce Data
Data remains accessible throughout the active subscription. Following cancellation, data is retained for a reasonable transitional window to facilitate customer export, compliance, and continuity before secure deletion.
13.2 GPS Attendance Data
Location coordinates are retained only as long as necessary for attendance dispute resolution, statutory payroll audits, and operational records.
13.3 Account Deletion (7-Day Workflow)
7-Day Deletion Commitment
Upon receiving a verified account deletion request from a customer administrator, DORT Asia will initiate and complete the deletion workflow within seven (7) days, subject to mandatory statutory tax and accounting retention requirements.
14. DATA EXPORT
Customers can export their workforce data, employee records, attendance logs, and payroll summaries during their subscription or transitional retrieval period prior to account closure.
15. INTERNATIONAL DATA TRANSFERS
Xentra’s primary production database and storage environment is located in Singapore (AWS ap-southeast-1). Where auxiliary third-party processors handle transactional data globally, DORT Asia ensures comparable protections in alignment with the Singapore Personal Data Protection Act (PDPA).
16. ACCESS AND CORRECTION REQUESTS
Individuals may request access to or correction of personal data held by DORT Asia. For workforce records controlled by an employer customer, individuals should submit requests directly to their employer organisation.
17. WITHDRAWAL OF CONSENT
Where processing relies on consent, individuals may withdraw consent at any time. Withdrawal does not affect lawful processing conducted prior to withdrawal, nor does it override statutory obligations.
18. ACCURACY OF PERSONAL DATA
We rely on customers and users to provide accurate and up-to-date workforce records. Authorised users can update and verify their information through Xentra self-service portals.
19. CHILDREN’S DATA
Xentra is an enterprise workforce management system and is not directed at children. Customers must not submit children’s personal data unless lawful under applicable employment regulations.
20. MARKETING COMMUNICATIONS
Xentra communications are strictly transactional and operational (e.g. security alerts, invoices, verification codes). Optional marketing updates can be unsubscribed from at any time.
21. EMPLOYEE PRIVACY & CUSTOMER RESPONSIBILITIES
Customer organisations remain responsible for obtaining required employee consent, issuing privacy notices, configuring role permissions appropriately, and complying with the Employment Act and Singapore PDPA.
22. DATA BREACH AND SECURITY INCIDENTS
DORT Asia maintains an incident response protocol to contain, investigate, and remediate security events. Affected customer administrators and regulatory bodies will be notified in compliance with statutory requirements.
23. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy as new features, integrations, or regulatory standards evolve. Updated versions will be published with a revised “Last Updated” date.
24. RELATIONSHIP WITH TERMS AND CONDITIONS
This Privacy Policy should be read in conjunction with the Xentra Terms and Conditions and any applicable Data Processing Addendum (DPA).
25. NO LEGAL, TAX OR EMPLOYMENT ADVICE
Xentra provides software tools and automation workflows. Nothing provided through Xentra constitutes legal, tax, accounting, or employment advisory services.
26. CONTACT US & DATA PROTECTION OFFICER
For questions regarding this Privacy Policy or data protection inquiries, contact:
DORT Asia Pte. Ltd.
18 Kaki Bukit Road 3, #03-09 Entrepreneur Business Centre, Singapore 415978
27. SUMMARY OF KEY PRIVACY PRACTICES
- Xentra is a B2B HRMS; customer organisation controls workforce data.
- Zero background location tracking; GPS recorded only at check-in/out.
- Primary database & storage hosted in Singapore AWS (ap-southeast-1).
- Stripe processes all payments securely; card credentials never stored on DORT Asia servers.
- Brevo handles transactional email; FCM delivers push alerts.
- Verified account deletion requests processed within 7 business days.
- Full support for data export prior to account closure.
Singapore PDPA Compliance Statement
DORT Asia Pte. Ltd. processes personal data in accordance with the Singapore Personal Data Protection Act (PDPA 2012) and applicable international data protection standards.