← All privacy policies

Privacy Policy – Full Stack HR Platform

Last updated:

1. Introduction

This Privacy Policy explains how Index of Solutions handles data in the Full Stack HR Platform, our human resources and payroll solution deployed for customer organizations. It covers the platform itself and the implementation and support services we provide around it.

2. Scope and Roles

The employing organization that licenses the platform is the data controller for all employee data held in it: it decides what is recorded, who may access it, and how long it is kept. Index of Solutions acts as a data processor, handling that data only on the documented instructions of the customer and only to operate, support and maintain the platform.

This policy does not cover any third-party system the customer chooses to connect to the platform — such as banking portals, biometric attendance devices, or government reporting services — which are governed by their own privacy terms.

3. Data Processed

Depending on the modules a customer enables, the platform may process the following categories of employee data:

  • Identity and contact details — name, national ID or passport number, date of birth, address, phone number, personal and work email
  • Employment records — job title, department, contract type, start and end dates, reporting line, salary grade
  • Attendance and leave — clock-in and clock-out records, timesheets, leave balances and requests
  • Payroll and compensation — salary, allowances, deductions, end-of-service benefits, bank account details for salary transfer, tax and social security identifiers
  • Performance and training — appraisals, objectives, and training records where those modules are in use
  • System data — user accounts, roles, and audit logs of actions taken inside the platform

This data is entered by the customer’s HR administrators or by employees through self-service. Index of Solutions does not collect employee data independently and does not use it for any purpose of its own — it is never sold, rented, or used for marketing, profiling, or model training.

4. Where Data Is Stored

The platform is deployed into the environment agreed with each customer — either the customer’s own infrastructure or a hosted environment provisioned for them. The hosting location, backup schedule and retention period are set out in the customer’s service agreement, and that agreement prevails over this page where the two differ.

Data is retained for as long as the customer instructs and as long as local labour, tax and social security law requires records to be kept. On termination, data is returned to the customer or deleted according to the terms of the service agreement.

5. Access by Index of Solutions

Our consultants and support engineers access customer environments only when needed to deliver implementation, support or maintenance work, and only to the extent required to resolve the request at hand. Access is granted by the customer, is subject to the customer’s own approval process, and can be revoked by the customer at any time. Our staff are bound by confidentiality obligations.

Where a support request can be resolved without live data, we ask for anonymised or sample data instead.

6. Security

The platform is built and operated with the following controls:

  • Encryption: HTTPS/TLS in transit; encryption at rest in the hosting environment.
  • Access: Role-based permissions, so users see only the records their role allows.
  • Auditing: Action logs for changes to sensitive records such as payroll.

No system is completely immune to risk. If we become aware of a breach affecting customer data, we notify the affected customer without undue delay so they can meet their own notification obligations.

7. Disclosure to Third Parties

We do not share, sell or distribute employee data to third parties. Data leaves the platform only where the customer has configured an integration — for example a payroll bank file or a statutory report — or where disclosure is required by law.

8. Employee Rights

If you are an employee of an organization using the platform and you want to access, correct or delete your data, please contact your own HR department: they control the data and can act on your request directly. Index of Solutions cannot act on such a request without the customer’s instruction, but will support the customer in fulfilling it.

9. Customer Responsibilities

Customers using the platform are responsible for ensuring that:

  • They have a lawful basis for collecting and processing the employee data they enter
  • Employees are informed about how their data is used, as required by applicable labour and data protection law
  • User accounts and roles are kept current, and access is removed promptly when staff leave
  • Their configuration complies with their own internal data protection policies

10. Support and Contact

Email: y.nasser@indexofsolutions.com

Phone: +961 3 865 174

Website: www.indexofsolutions.com

Address: Cornish al Mazraa, Sabbah Center, Block B, 2nd Floor, Beirut, Lebanon

11. Updates to This Policy

We may update this Privacy Policy periodically to reflect legal, technical, or operational changes. The updated version will always be available on our website.