Utso Privacy Policy
Effective Date: October 2, 2026 Last Updated: October 2, 2026
This Privacy Policy explains how InfoDigita Technologies (“Utso”, “we”, “us”, “our”) collects, uses, stores, and protects personal data in connection with the Utso platform (utso.net, utso.app, and associated services, together the “Service”).
1. Who this covers
| Who you are | Example | How your data reaches us |
|---|---|---|
| Account holder or employee | You work for a company that uses Utso for HR, attendance, leave, tasks or payroll | Your employer creates your record. You can update parts of it yourself |
| Job applicant | You applied for a role through a company’s Utso careers page | You submitted it through a public application form |
| Business contact | You are a contact or customer of a company that uses Utso’s CRM | The company entered your details, or you messaged it on WhatsApp, Facebook Messenger or an email address it connected to its CRM |
| Website visitor | You browse utso.net | Your browser and our analytics tools |
Our role. For employee, payroll, attendance, task and CRM data entered by a customer company, the customer is the data controller and Utso is the data processor, acting on the customer’s instructions. For account, login and billing data, Utso is the controller. If your employer entered your data, send requests about it to your employer first.
Contact: [email protected]. Data Protection Officer: we have not appointed one. Send privacy matters to [email protected].
2. What we collect
2.1 Identity and contact details
| Data | Required? | Notes |
|---|---|---|
| Email address | Required | Your login |
| First name | Required | |
| Last name | Optional | |
| Phone number | Optional for employees. Required for the administrator who signs up a new company | Stored encrypted |
| National ID | Optional | Stored encrypted |
| Date of birth | Optional | Stored encrypted |
| Gender | Optional in self-service. Required when an administrator creates your record | |
| Present and permanent address | Optional | Stored encrypted |
| Profile photo | Optional | |
| Country, language | Optional |
2.2 Employment information
Your employer records job title, department, branch, team, manager, employment dates, attendance, leave requests and balances, shifts, tasks, projects, timesheets and performance reviews.
2.3 Payroll and financial information
If your employer uses Utso Payroll we store TIN, bank name, account number, branch and routing number, mobile banking number and provider, salary and compensation figures, increments, and a snapshot of each payroll run. Payslip PDFs are generated and stored. These fields are encrypted at rest. For billing, we also store the company’s legal name, address, billing email and tax ID, encrypted.
2.4 Attendance devices
If your employer uses biometric attendance hardware, we store the ID the device assigns you, the employee ID entered on the device, the name held on the device, and your punch times. We do not receive or store fingerprint or face templates. Matching happens on your employer’s own hardware.
2.5 Files and content
Profile photos, leave supporting documents, task attachments, notice attachments, CVs and cover letters. Content you write: task comments, time-entry notes, leave reasons, attendance edit reasons, CRM notes, interview notes and job-application answers.
2.6 Health-related information
We have no dedicated health field. If your employer’s leave policy asks for supporting documents for sick leave, the document you upload (for example a medical certificate) is stored. The free-text reason on a leave request may contain health details if you choose to write them.
2.7 Technical data
- Push token. If you use the mobile app and allow notifications, the token issued by Google Firebase is stored. It is deleted when your account or record is removed.
- Failed sign-ins. We record the email entered, your IP address and browser user-agent, to block brute-force attacks.
- Successful sign-ins. We record only your user ID, company ID and time. We do not log your IP address or user-agent.
- Feedback. If you send in-app feedback, your browser user-agent is included.
2.8 CRM channel messages (business contacts)
If you message a company that uses Utso’s CRM on a channel it has connected, we store your message on that company’s behalf.
| Channel | What is stored | How it reaches us |
|---|---|---|
| Your number, display name, message text, media, delivery and read status | The company connects its own WhatsApp Business account. Meta relays the message to us | |
| Facebook Messenger | Your Page-scoped ID, message text, media links | The company connects its own Facebook Page. Meta relays the message to us |
| Your address and display name, subject, body, attachments | The company forwards or BCCs your email to an address we issue. Cloudflare receives it first and relays it to us |
We do not import WhatsApp history from before the company connected the channel, and we do not read anyone’s mailbox. The company you messaged is the controller of this content and must tell you that the channel is recorded in its CRM.
2.9 Cookies and website analytics
In the Utso apps we use first-party cookies only: auth.token (keeps you signed in, 7 days), refresh.token (renews your session, 7 days) and a language preference. There are no advertising cookies and no analytics tools in the apps.
On the marketing website utso.net we use Google Tag Manager and Google Analytics to understand aggregate visits. These collect your IP address, device and browser details, and pages visited, and Google receives that data. You can block these with your browser settings or a browser extension.
Our web pages load fonts from Google’s font service, so Google receives your IP address and browser user-agent. The form that re-sends an expired invitation link loads Cloudflare Turnstile to check you are a person.
3. What we do not collect
- No location data. No GPS, no geofencing, no IP-based location.
- No fingerprint or face templates.
- No advertising, no sale of personal data.
- No SMS. One-time codes go by email or your authenticator app.
- No payment card data. We have no payment gateway. Invoices are paid by bank transfer.
- No AI processing of your content.
- We never ask for race, ethnicity, religion, politics, sexual orientation, union membership, marital status or blood group.
4. Why we use it
We use personal data to provide the Service (accounts and your employer’s HR, attendance, leave, task and project records), to pay people (payroll, payslips, bank files), for security (sign-in, one-time codes, audit logs), to send email and push notifications that concern you, to keep records the law requires, and to give support. Where the law requires a legal basis, we (or the customer, as controller) rely on performing the contract, legal obligations such as payroll and tax records, legitimate interests such as security and fraud prevention, and consent where it is required. For health-related documents the basis is the employer’s legal obligations in employment law.
5. Who we share it with
We do not sell personal data and we do not share it for advertising. These companies receive personal data to run the Service.
| Recipient | What they receive | Why |
|---|---|---|
| Google (Firebase Cloud Messaging) | Your push token and notification text. Payroll notifications include your net pay and pay period. CRM notifications include contact and deal names and values | Mobile notifications |
| Amazon Web Services (SES, United States) | All outbound email, including one-time codes, invitations and payslip PDFs with net pay | Sending email |
| Hetzner Online (Finland storage, compute) | Uploaded files, and the servers and databases that hold your data | Hosting and file storage |
| Cloudflare | Every request to our websites and API, including IP address and browser user-agent | DNS, certificates, traffic proxy, Turnstile human check, email routing for CRM |
| Let’s Encrypt | Our domain names | Certificates |
| Google (Fonts, Tag Manager, Analytics) | IP address, browser data, pages visited on utso.net | Fonts and website analytics |
| Meta Platforms | If a customer connects WhatsApp or Messenger: message content, media, the customer’s number or Page ID | Meta operates the channel |
| Your employer’s own mail server | CRM email only, if your employer set up outgoing mail | Sending email for them |
We may also disclose data when the law requires it or to defend legal claims.
6. Where your data is
| What | Where |
|---|---|
| Databases and servers | Singapore |
| Uploaded files | Helsinki, Finland |
| Outbound email in transit | United States |
| Web and API traffic | Cloudflare’s network, near wherever you are |
| WhatsApp and Messenger messages in transit | Meta’s global network, before they reach our servers |
Your data is therefore processed in several countries, including outside Bangladesh.
7. How long we keep it
| Data | Kept for |
|---|---|
| Account and employment records | Until you or your employer delete them. Then anonymised as in section 8 |
| Payroll and tax records | Your name, bank details and TIN stay attached for 5 years after deletion, then are erased. Salary, deduction and payment figures are kept permanently. Payroll audit entries are redacted 12 years after deletion. |
| Sign-in and audit logs, activity feed | 90 days |
| Attendance device logs | 400 days |
| Database backups | 7 days locally. An offsite copy is kept up to 90 days |
| Job applicant data | Until a company administrator erases the application, or you ask the company or us to |
| CRM channel messages | Message text 24 months after last activity. Attachments 12 months. Raw incoming payload 7 days. Unlinked or spam conversations 90 days. A company administrator can change these within set limits |
8. Deleting your data, and what that does not reach
In the app: Settings, Security, Delete my account. You confirm your password. Your whole Utso account is closed, across every company you belong to.
- Your account is disabled immediately and you are signed out everywhere.
- It is deleted after 30 days. To cancel, sign in again before that date and choose to cancel. We email you the date and any cancellation.
- Each company’s administrators are emailed your name, email, company and the deletion date so the employer can settle final pay.
- On the deletion date you are removed from every company and your personal fields are erased.
Without signing in: use our account deletion page or email [email protected].
What you should know:
- We anonymise records in place rather than remove rows. Your name, email, phone, ID number, addresses, birth date and photo are destroyed. The empty record stays.
- Backups keep your data after deletion: 7 days locally, up to 90 days offsite. We cannot edit a backup.
- Some activity-log entries may keep a display name where two people share a name and we could not safely tell them apart.
- Some task change-history snapshots may keep personal data beyond the assignee name.
- Some payroll bonus-run audit entries are not covered by the per-person erasure.
- Job applicants have no self-service delete. A company administrator can erase a candidate, but the erasure is partial. To have your application erased, ask the company or email [email protected].
- In the performance module, your name is replaced with “Deleted Employee” but goals, feedback, review answers and notes stay, and names typed inside them are not removed.
- CRM channel messages can be hard-deleted per contact by a company administrator, including attachment files. Backups are the same exception as item 2.
9. How we protect it
- Passwords are hashed with bcrypt and are never recoverable.
- Optional two-factor sign-in with an authenticator app. One-time codes expire after 5 minutes.
- Traffic between you and us is encrypted with TLS.
- National ID, phone, addresses, date of birth, payroll financial fields, company billing details and two-factor secrets are encrypted at rest.
- Uploaded files are private and served through short-lived signed links.
- Each customer’s operational data is in its own database.
- The API gateway limits request rates and restricts cross-origin access.
- The mobile app pins our TLS certificate.
No system is completely secure. If a security incident affects personal data we will tell affected customers without undue delay so they can meet their own duties. We hold no security certifications.
10. Your rights
You may have rights to access, correct, delete, restrict or object to processing of your data, and to receive a copy.
- Delete: in the app, as in section 8.
- Correct: update most of your profile in the app.
- Access and copy: Settings, Security, Download my data gives you one JSON file. You can download it up to twice a minute and 10 times an hour. It includes your account details across all your companies, plus, for the company you are signed in to, your employee record, attendance, leave, time entries, comments, matched job applications and (if your employer uses Payroll) payslips, salary and bank details. It does not include uploaded files, performance reviews, goals, projects, CRM, budget or notification data, or interview and offer records.
- Object or restrict: email [email protected].
We answer rights requests within one month. You can complain to your local data protection authority.
11. Children
Utso is a workplace product and is not for anyone under 18. We do not knowingly process the data of children, except for an employer’s own apprentice or intern records.
12. Changes and governing law
We may update this policy. We will tell you by email or in the product at least 15 days before material changes take effect. The “Last Updated” date shows the latest revision. This policy is governed by the laws of Bangladesh, and the courts of Dhaka have jurisdiction.
13. Contact
Privacy: [email protected]. General support: [email protected]. Phone: +88 01304-220-033. Hours: Saturday to Thursday, 10:00 AM to 7:00 PM (BST).
See also: Terms of Service, Account & Data Deletion, Billing, Cancellation & Refund Policy.
