The short version
We process employee data on behalf of the employer that subscribes to Qadra. We do not sell data, we do not use customer data to train general-purpose models, and biometric templates never leave our infrastructure as images. Employees should raise access or deletion requests with their employer first; we support the employer in answering them.
01
Who we are
Qadra is an HR platform operated from Lagos, Nigeria. Where this policy says “we”, “us” or “Qadra”, it means the company that provides the Qadra platform, its mobile applications and its attendance devices integration.
Where it says “you”, it means either a customer administrator using Qadra to run HR for an organisation, or an employee whose records are held in a customer’s Qadra account. Sections that apply to only one of those are marked.
02
When we are the controller, and when we are the processor
This distinction decides who you go to with a request, so it comes early.
Processor
Employee records
Payroll, attendance, leave, documents, performance. Your employer decides what is collected and why. We only act on their documented instructions.
Controller
Our own relationships
Admin account details, billing records, support conversations, website analytics, demo requests and job applications sent to us.
If you are an employee and want your record corrected or erased, ask your employer’s HR administrator. If they need our help to action it, we provide the tooling and, where required, do it on their instruction.
03
What we collect
The exact set depends on which modules a customer enables. Nothing below is collected by a module that is switched off.
We do not ask for, and ask customers not to upload, data about religion, ethnicity, political affiliation, trade union membership or sexual orientation. Health information is limited to what a customer needs for sick leave and statutory benefit administration.
04
Biometric and location data
Face verification and geofenced clock-in are the most sensitive things Qadra does, so they are governed by tighter rules than the rest of the platform.
- Enrolment produces an irreversible mathematical template. The original photograph is discarded after enrolment and cannot be reconstructed from the template.
- Templates are encrypted with per-tenant keys and are never shared between customers, sold, or used to train models for anyone else.
- Location is captured as a pass or fail against the site boundary the employer configured, at the moment of clock-in and clock-out. Qadra does not track employees between punches.
- Where an employer uses an external attendance device, the device sends us a matched employee identifier and a timestamp — not raw biometric material.
- Templates are deleted within 30 days of an employee record being deactivated, or immediately on the employer's instruction.
Employers are responsible for notifying their staff before enrolment and for offering a non-biometric alternative where local practice or an individual’s circumstances require it. Qadra supports PIN, supervisor-approved and device-based clock-in for exactly this reason.
05
How we use it
We use personal data to run the service a customer has subscribed to: recording attendance, calculating pay and statutory deductions, managing leave and documents, running onboarding and performance cycles, and producing the reports and audit trails a customer needs.
As controller of our own records, we use data to bill customers, provide support, keep the platform secure, meet our own tax and legal obligations, and improve the product through aggregated, de-identified usage statistics.
We do not sell personal data. We do not share it with advertisers. We do not use customer employee data to build profiles for any purpose outside that customer’s account.
06
AI and automated decisions
Several Qadra features use machine learning: CV screening, attendance anomaly detection, payroll variance checks and document extraction. Three commitments govern all of them.
A human decides
No hiring, disciplinary or pay outcome is finalised by a model alone. Qadra ranks and flags; a person approves.
Reasons are shown
Every score or flag carries the evidence behind it, so it can be challenged on the record.
Your data stays yours
Customer data is not used to train general-purpose or cross-customer models.
Where a feature sends text to a third-party model provider — for example to summarise a CV — that provider is contractually barred from retaining the content or training on it. The current list of such providers is in section 8.
07
Lawful basis
Under the Nigeria Data Protection Act 2023, each processing activity needs a basis. For employee records the employer sets that basis; these are the ones they normally rely on.
09
Retention and deletion
When a subscription ends, the account stays available in read-and-export mode for 30 days. After that we delete production data within 60 days and purge encrypted backups within a further 35 days, except where Nigerian tax and employment law requires payroll records to be kept longer.
10
Security
Data is encrypted with AES-256 at rest and TLS 1.3 in transit, tenants are logically isolated with per-tenant keys, access is role-based down to the field level, and every record change and export is written to an immutable audit log.
Staff access to production data is limited to the smallest group that can operate the service, requires MFA, and is logged. We run encrypted backups every six hours with 35-day retention and test disaster recovery quarterly.
If a breach affects personal data, we notify affected customers within 72 hours of becoming aware, with what we know, what we are doing, and what they need to do. The full security posture is on the security page.
11
Cross-border transfers
Primary production data for Nigerian customers is held in-region. Some sub-processors — notably email delivery and error monitoring — operate outside Nigeria, so limited data crosses borders.
Where that happens we rely on the transfer mechanisms permitted by the NDPA 2023 and its implementing guidance, backed by contractual safeguards with each recipient. Customers on Custom plans can require in-region residency for all components; ask us for the current arrangement in writing.
12
Your rights
Under the NDPA you can ask for access to your data, correction of anything wrong, deletion where there is no legal reason to keep it, a portable copy, restriction of processing while a dispute is resolved, objection to processing based on legitimate interest, and withdrawal of consent where consent is the basis.
How to exercise them
If your data sits in an employer’s Qadra account, send the request to that employer’s HR administrator — they are the controller and they hold the decision. We respond to their instruction promptly.
For data we control — your admin account, billing, support history or a job application — email privacy@qadrahr.com. We acknowledge within 5 working days and respond substantively within 30 days. There is no charge unless a request is repetitive or excessive.
14
Changes to this policy
We update this page when the product or the law changes. The effective date at the top always reflects the current version. For material changes — a new category of data, a new purpose, a new sub-processor region — we email account administrators at least 30 days before the change takes effect.
15
Contact and complaints
Privacy questions, data requests and security questionnaires go to our data protection contact. If we have not resolved a complaint to your satisfaction, you may lodge it with the Nigeria Data Protection Commission.
Regulator
Nigeria Data Protection Commission
You can complain to the NDPC at any time, whether or not you have raised it with us first.
