Privacy Policy

Effective August 3, 2026

1. Introduction

This Privacy Policy explains how SoraCore β€” an HR, payroll and accounting platform operated by the SAGBRAIN group β€” collects, uses, stores, and protects information when your Organization uses the platform to manage its workforce and finances. It applies to all users (Admin, HR, Employee, Accountant, Viewer, and CA Officer roles) and to organizations operating one or more legal entities across different countries.

The SoraCore service is provided by the SAGBRAIN group companies responsible for each market: Sagbrain Bangladesh Co., Ltd. (Bangladesh), Sagbrain (Japan), and Sagbrain Global Pte. Ltd. (Singapore). The company responsible for your data depends on the country in which your Organization operates.

For most personal data in SoraCore, your Organization (your employer) is the data controller / data fiduciary and decides how the data is used; SoraCore acts as a data processor on its behalf. Where you interact with us directly β€” for example when signing your Organization up for a subscription β€” the relevant SAGBRAIN company is the controller for that limited account and billing information.

2. Information We Collect

SoraCore collects the following categories of information, entered by your Organization or generated through your use of the platform:

  • Account & profile data: name, email, employee ID, position, department, phone, address, date of birth, national identification number, and profile photo.
  • Attendance data: check-in/check-out timestamps, break durations, and GPS location captured at the moment of check-in and check-out.
  • Leave & work data: leave applications and balances, daily and overtime work reports, attendance correction requests, and manager/team hierarchy assignments.
  • Financial data (where applicable): payroll records, payslip details, invoices, expenses, and finance/accounting entries handled by Accountant and CA Officer roles.
  • Communications: notices, in-app notifications, and feedback submissions you create, including any attachments you upload.
  • Account activity: login sessions, security/presence-check acknowledgements, and preference settings such as language and theme.
  • Billing & subscription data: company details, the administrator's contact information, the selected plan, and payment metadata. Card payments are handled by our payment provider β€” SoraCore does not store full card numbers on its own servers.
  • AI assistant content: if your Organization enables the AI knowledge assistant, the documents it uploads and the questions users ask are processed by a third-party AI provider to generate answers (see "Data Sharing" below).

Special / sensitive categories. Some data carries heightened legal protection and additional safeguards: biometric and real-time geolocation data used for attendance; in Japan, the My Number (Individual Number) where your Organization records it for tax and social-insurance filings; and in Singapore, the NRIC/FIN. These are collected only where your Organization has a lawful basis, are access-restricted and encrypted, and β€” as described in Section 7 β€” are subject to country-specific rules.

3. How We Use Your Information

Information collected in SoraCore is used to:

  • Record and calculate attendance, leave balances, overtime, and payroll on your Organization's behalf.
  • Route approvals (e.g. leave, corrections, financial documents) to the appropriate HR, Admin, or CA Officer users.
  • Send you notifications, reminders, and notices relevant to your role and account.
  • Generate reports, dashboards, and exports (Excel/PDF) for your Organization's management and record-keeping.
  • Maintain the security of your account and the platform, including detecting unauthorized access.

We do not use your data for advertising, and we do not sell personal information to third parties.

Processing is carried out on behalf of your Organization and typically relies on lawful bases including performance of the employment relationship, your Organization's legitimate interests in running its business, compliance with legal obligations (payroll, tax, and labor-law record-keeping), and β€” for biometric attendance, My Number, and similar sensitive data β€” the specific consent required by the applicable law. Your Organization, as controller/fiduciary, is responsible for the lawful basis of the data it enters.

4. How Your Data Is Stored & Protected

Your Organization's data is stored in a dedicated database on secure cloud infrastructure, with encryption in transit (HTTPS) and access restricted by role-based permissions, so users only see the data their role is authorized to access. Authentication uses time-limited access tokens, and passwords are stored using industry-standard one-way hashing β€” SoraCore staff cannot view your plain-text password.

Data location. We host data in the region appropriate to your market. For Bangladesh, categories treated as "confidential" under Bangladesh law (including salary, payroll, financial, biometric and real-time location data) are stored with a copy within Bangladesh, as required by the Personal Data Protection law. For Japan, customer and My Number data is hosted in a Japan region. For Singapore, data may be hosted in Singapore or transferred abroad only under the safeguards described in Section 5.

Security measures include encryption in transit, one-way password hashing, role-based access control, tenant isolation between organizations, access logging for sensitive fields (such as national identifiers), and regular review. Where a data breach occurs, we follow the notification duties set out in Section 7.

5. Data Sharing, Subprocessors & International Transfers

Your data is only shared within your own Organization's account, visible to users according to their role. SoraCore does not sell or share your personal data with third parties for marketing purposes. We use a limited set of service providers ("subprocessors") strictly to operate the platform:

  • Cloud hosting for the database and application servers.
  • Email delivery via your Organization's configured provider (SMTP settings managed by your Admin).
  • Mapping / reverse geocoding to turn attendance check-in coordinates into a readable place name.
  • Payment processing for subscription billing (card data is handled by the payment provider, not stored by SoraCore).
  • AI provider β€” where the AI assistant is enabled, uploaded documents and user questions are sent to a third-party large-language-model provider solely to generate answers; this content is not used to train public models on your behalf.

International transfers. Where information is processed outside your country, we rely on the safeguards required by the applicable law: for Japan (APPI), transfer to a country with recognized adequacy, your prior consent with enhanced disclosure, or a recipient bound to APPI-equivalent standards that we verify on an ongoing basis; for Singapore (PDPA), ensuring the overseas recipient is bound to a standard of protection comparable to the PDPA through contractual clauses; and for Bangladesh, keeping the required local copy of confidential data and transferring only with consent or contractual necessity to a destination offering adequate protection.

6. Your Rights

Depending on your role, your location, and your Organization's policies, you can:

  • View and update your own profile information directly from your account settings.
  • Request a correction to attendance or report records through the built-in correction workflow.
  • Ask your Organization's HR or Admin team what data is held about you, or to correct or remove data, subject to record-keeping and legal obligations (e.g. payroll history required for tax or labor law).
  • Where the law provides, request access to a copy of your data, correction or erasure, restriction of or objection to certain processing, data portability, and withdrawal of consent β€” without being disadvantaged for exercising these rights.

Because SoraCore is a workforce tool used on behalf of your Organization, requests to access, correct, or delete your data should first be directed to your Organization's HR or Admin team (the controller for your employment records); we will support them in responding. You may also contact the relevant regulator: the National Data Governance Authority (NDGA) in Bangladesh, the Personal Information Protection Commission (PPC) in Japan, or the Personal Data Protection Commission (PDPC) in Singapore.

7. Country-Specific Privacy Information (Bangladesh Β· Japan Β· Singapore)

The following applies in addition to the rest of this policy, according to where your Organization and you are located.

Bangladesh β€” Personal Data Protection law (regulator: NDGA).

  • Salary, payroll, financial, biometric and real-time location data are treated as "confidential" and a copy is stored within Bangladesh.
  • Biometric and geolocation data used for attendance are collected on the basis of specific consent and are encrypted and access-restricted.
  • We keep processing records for the period required by law and notify the NDGA of a qualifying personal-data breach within the prescribed time. Platform security also reflects the Cyber Security Ordinance 2025.

Japan β€” Act on the Protection of Personal Information / APPI (regulator: PPC).

  • We specify and observe the purpose of use, and treat "special care-required" information on an opt-in basis.
  • My Number (Individual Number) is used only for the tax, social-insurance and disaster-response purposes permitted by the My Number Act. It is segregated from other fields, encrypted, masked on screen by default, access-logged, and securely deleted when the legal purpose ends.
  • We notify the PPC of a reportable breach (a preliminary report promptly and a final report within the statutory period) and notify affected individuals as required.

Singapore β€” Personal Data Protection Act / PDPA (regulator: PDPC).

  • We observe the PDPA obligations (consent, purpose limitation, notification, access & correction, accuracy, protection, retention, transfer limitation, and accountability).
  • NRIC/FIN is stored only where lawfully required for HR, payroll and tax purposes, is never used for authentication (logins, passwords or document access), and is masked and access-restricted.
  • We notify the PDPC of a notifiable data breach within 3 calendar days, and affected individuals as soon as practicable.
  • We have appointed a Data Protection Officer whose contact details appear in Section 11.

8. Data Retention

Employment-related data (attendance, leave, payroll, reports) is retained for as long as your account remains active and for a period afterward as required for payroll, tax, and labor-law record-keeping β€” for example, wage and employee records for the statutory periods applicable in Japan and Singapore, and processing records for the period required in Bangladesh. When an employee's account is deactivated, historical records are retained by the Organization rather than deleted outright, so reports, payslips, and audit trails remain accurate; sensitive identifiers such as My Number are securely deleted once the legal purpose for holding them ends.

9. Cookies & Similar Technologies

SoraCore uses your browser's local storage (not third-party tracking cookies) to keep you signed in and to remember preferences such as language and theme. See our Cookie Policy for full details.

10. Children’s Privacy

SoraCore is a workforce management platform intended for use by employees of a registered Organization and is not directed at, or intended for use by, children.

11. Data Protection Officer & Contact

We have appointed a Data Protection Officer (DPO) for privacy matters across our markets, including Singapore where a DPO is mandatory. You can reach the DPO and our privacy team at privacy@sagbrain.com.

For employment-record requests, please also contact your Organization's HR or Admin team, who act as the controller/fiduciary. Our Bangladesh registered office is: Sagbrain Bangladesh Co., Ltd., Ventura Iconia, Level 3, House 37, Road 11, Block H, Banani, Dhaka-1213, Bangladesh. Users in Japan and Singapore may contact the responsible SAGBRAIN group company (Sagbrain and Sagbrain Global Pte. Ltd. respectively) via the same privacy address.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law in Bangladesh, Japan, Singapore, or other markets. Material changes will be communicated to Organization Admins, and the "Effective" date at the top of this page will be updated accordingly.