Privacy notice
Finance Department Operations Hub
This notice describes what the Finance Department Operations Hub does with personal data. It covers two groups of people: colleagues who sign in to use it, and employees whose payroll it processes, most of whom never sign in at all.
It describes the system as built. Questions about your rights under UAE law, or about who holds them to account, belong to the Finance Department rather than to this page.
What the Hub holds
If you sign in: your name and work email address, a one-way hash of your password (never the password itself), the roles and the companies and cost centres you are scoped to, when you last signed in, your interface preferences, and — only if you switch it on yourself — your two-step sign-in settings. If you use the mobile app, a device token so notifications can reach the handset.
If your payroll runs through it: the employee record the HRMS sends — identity and employment details, salary components, bank account (IBAN), the WPS person code, and the MOHRE establishment data that WPS compliance depends on.
What the Hub records as you work: an audit trail of financially significant actions — who did what, to which record, when, and from which IP address. Team chat messages and their attachments. Where the OTP router is in use, the fact that a one-time code arrived and who was authorised to see it.
Why
To run UAE payroll end to end: extract it from the HRMS, validate it, book it, post it to the accounting system, produce salary transfers and WPS SIF files, and evidence MOHRE/WPS compliance. The audit trail exists because these are financial actions on other people's pay — a record of who approved what is part of doing them properly, not an afterthought.
Where it goes
Payroll data leaves the Hub only where the work requires it:
- the HRMS, which the Hub reads payroll from;
- the AlphaPro / FinanceCore accounting system, which receives the postings;
- banks, through SIF files and transfer instructions;
- MOHRE / WPS, for statutory compliance.
The Hub also uses these services, each only for the function named:
- Microsoft 365 — the company address book, and sending account emails;
- Google Firebase — delivering notifications to the mobile app;
- LiveKit — team chat voice and video calls;
- Anthropic — the in-app assistant, for questions you choose to ask it, and drafting the minutes of recorded meetings from their transcript;
- Qashio — the corporate wallet and card feed.
Nothing is sold, and nothing is shared for advertising or analytics.
How it is protected
- Bank account numbers, WPS person codes, one-time codes and two-step secrets are encrypted at rest. A copy of the database, or a backup, does not hand anyone a usable IBAN or a working code generator.
- Passwords are stored only as a hash, and are never written to the audit trail or sent by email — an invitation carries a one-time link to set your own.
- What you can see is limited to your roles and to the companies and cost centres you are scoped to, enforced centrally rather than page by page.
- Financially significant actions require a second person: the preparer and the approver are never the same account.
- Sign-in is rate-limited, and every account may switch on two-step sign-in.
How long it is kept
- The audit trail is kept for the record. Accounts are deactivated, never deleted, because deleting one would blank out the history of everything that person did.
- One-time codes are destroyed within minutes. A background job clears the code itself as soon as it expires and keeps only the fact that a code arrived and whether anyone looked.
- Invitation links die after 72 hours and can be used once.
- Backups are taken nightly and kept as the 14 most recent daily copies plus 12 monthly copies.
What you can do
From the profile menu you can change your own password, switch two-step sign-in on or off, and — where an administrator has enabled it — choose which notifications reach your devices. To correct your own record, or to ask what the Hub holds about you, speak to the Finance Department; payroll data originates in the HRMS, so corrections are usually made there and flow through.
Back to sign in