Utso Privacy Policy
Effective Date: July 22, 2026 Last Updated: July 22, 2026
This Privacy Policy explains how InfoDigita Technologies (“Utso”, “we”, “us”, “our”) collects, uses, stores, and protects personal data in connection with the Utso platform (utso.net, utso.app, and associated services, together the “Service”). It applies to:
- Visitors to our marketing website (utso.net);
- Customers and their authorized users who administer or use the Service (“Tenant Users”);
- Individuals whose data is entered into the Service by a Customer (e.g., a Customer’s employees or CRM contacts), referred to below as “Data Subjects”.
Where a Customer enters Data Subject information (employee HR records, payroll data, CRM contacts, attendance data) into the Service, the Customer is the data controller for that data, and Utso acts as a data processor / service provider acting on the Customer’s instructions. Questions about how a specific Customer’s data is used should be directed to that Customer (e.g., your employer, if you are an employee entered into a Tenant’s HR system).
1. Information We Collect
1.1 Account and Company Information
When a Customer signs up, we collect company name, company subdomain identifier, administrator name, email, and phone number.
1.2 Tenant Data (entered by Customers)
Depending on which modules a Customer subscribes to, Tenant Data may include:
- HR/Employee data: name, contact details, position, department, branch, employment history, National ID or other identifiers a Customer chooses to store, salary and bank/payment details, leave records.
- Attendance data: clock-in/clock-out timestamps and, where a Customer connects a biometric device, biometric templates (e.g., fingerprint hash) used solely for attendance matching. We do not use biometric data for any purpose other than the attendance function the Customer enables.
- Payroll data: salary structure, allowances, deductions, tax/statutory calculations, payment records.
- CRM data: customer/lead names, contact details, deal and communication history.
- Project/Task data: project details, task assignments, comments, and file attachments.
- Budget/Expense data: budgets, expense claims, approval workflows, and associated documents.
1.3 Usage and Log Data
IP address, browser/device type, pages visited, service request logs, and timestamps, collected automatically for security, debugging, and analytics purposes.
1.4 Cookies
We use cookies and similar technologies for session authentication, remembering preferences (e.g., language), and product analytics. You can control cookies through your browser settings; disabling essential cookies may prevent login.
1.5 Payment Information
When you subscribe via a supported payment method, payment processing is handled by the respective payment provider. We store transaction references and subscription status, but do not store full payment credentials (e.g., mobile wallet PINs) ourselves.
2. How We Use Information
We use collected data to:
- Provide, operate, and maintain the Service (authentication, company account setup, HR/payroll/CRM/project functionality);
- Process payroll calculations and attendance records as configured by the Customer;
- Send transactional communications (e.g., password resets, notifications, invoices);
- Provide customer support;
- Detect, prevent, and investigate security incidents, fraud, or abuse;
- Improve and develop the Service, including through aggregated, de-identified analytics;
- Comply with legal obligations (e.g., tax records, lawful requests from authorities).
We do not sell personal data to third parties, and we do not use Tenant Data (employee/HR/CRM records entered by Customers) for advertising purposes.
3. Legal Basis for Processing
Where applicable data protection law requires a legal basis, we (or the Customer, as controller) rely on:
- Contract performance: to provide the subscribed Service;
- Consent: for optional cookies, marketing communications, or biometric data collection, where required;
- Legitimate interests: for security monitoring, service improvement, and fraud prevention;
- Legal obligation: for tax, payroll, and statutory recordkeeping requirements.
4. Data Storage, Isolation, and Sub-processors
- Data isolation: Each Customer’s data is stored in its own dedicated database for HR, payroll, project, task, budget, and attendance modules, so one Customer’s data is not accessible from another Customer’s database.
- File storage: Attachments and documents (e.g., CVs, expense receipts) may be stored with third-party cloud storage providers, depending on Customer configuration.
- Infrastructure sub-processors: We use third-party infrastructure providers (cloud hosting, database hosting, payment gateways, and communication providers for email/SMS notifications) strictly to operate the Service. These providers are bound by confidentiality and data protection obligations appropriate to the data they process.
- International transfer: Our infrastructure is primarily hosted to serve Bangladeshi businesses; where any sub-processor stores or processes data outside Bangladesh, we take reasonable steps to ensure an adequate level of protection consistent with this Policy.
5. Data Retention
- Tenant Data is retained for as long as the Customer maintains an active subscription.
- Following termination of a subscription, Tenant Data is retained for up to 30 days to allow export, after which it is deleted from production systems (residual copies may persist briefly in backups until purged under our standard backup rotation).
- Usage/log data is retained for a limited period for security and debugging purposes and then aggregated or deleted.
- A Customer may request earlier deletion of specific Tenant Data by contacting [email protected]; we will action such requests within a reasonable time, subject to any legal retention obligations (e.g., statutory payroll/tax recordkeeping periods).
- To delete a user account or a company account entirely, see Account & Data Deletion, which also explains how to request deletion without signing in.
6. Data Security
We apply technical and organizational measures appropriate to the sensitivity of the data processed, including:
- A separate database for each Customer;
- Encrypted transport (HTTPS/TLS) for data in transit;
- Token-based authentication and role/permission-based access control within the Service;
- Gateway-level access control and rate limiting;
- Restricted internal access to production systems.
No system is completely secure. If we become aware of a security incident affecting personal data, we will notify affected Customers without undue delay so they can meet their own notification obligations to Data Subjects, where applicable.
7. Special Category Data: Biometric and Sensitive Information
Biometric attendance data and any National ID or similarly sensitive identifiers are treated as sensitive data. They are:
- Collected only when a Customer actively enables the relevant feature (e.g., connects a biometric attendance device);
- Used solely for the specific purpose configured (e.g., attendance matching), not for any secondary purpose;
- The Customer’s responsibility to collect with appropriate notice/consent from the underlying Data Subject (its employees) before enabling such features, per Section 3 of our Terms of Service.
8. Your Rights
Subject to applicable law and, where Utso acts as a processor, subject to instruction from the relevant Customer (controller), Data Subjects may have rights to:
- Access the personal data held about them;
- Request correction of inaccurate data;
- Request deletion of their data, subject to legal retention requirements;
- Object to or restrict certain processing;
- Request a copy of their data in a portable format.
If you are an employee or contact whose data was entered by a Customer (e.g., your employer), please direct such requests to that Customer first. If you are a registered Tenant administrator or a website visitor, you may contact us directly at [email protected].
For account deletion specifically, including a request path that does not require signing in, see Account & Data Deletion.
9. Children’s Privacy
The Service is intended for business use by working-age individuals and is not directed at children. We do not knowingly collect personal data from children through the marketing website. Employee records processed via the HR module reflect a Customer’s own workforce and are not intended to include minors, except where locally lawful (e.g., apprentice/intern records), and remain the Customer’s responsibility as controller.
10. Cookies and Analytics
We use first-party cookies necessary for authentication and session management, and may use analytics tools to understand aggregate usage of utso.net and the Service. Where required by law, we will request consent before setting non-essential cookies.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the Service or legal requirements. Material changes will be communicated via email or an in-product notice at least 15 days before taking effect. The “Last Updated” date above reflects the most recent revision.
12. Contact Us
For questions about this Privacy Policy or to exercise a data-subject right (where Utso is the appropriate contact):
- Privacy inquiries: [email protected]
- General support: [email protected]
- Phone: +88 01304-220-033
- Business Hours: Saturday to Thursday, 10:00 AM to 7:00 PM (BST)
