Privacy Policy

Effective Date: 01 July 2026

Last Updated: July 1, 2026

Alfa Marine Electronics (“Company,” “we,” “our,” or “us”) respects the privacy of its employees and other authorized users. This Privacy Policy explains how we collect, use, store, protect, and disclose information when users access or use the OneHRIS mobile application (“Application”).

The Application is designed primarily for employees and authorized personnel of Alfa Marine Electronics to perform employment-related and business-related activities, including attendance management, leave applications, expense claims, lead management, task management, and viewing salary slips.

By using the Application, you acknowledge that your information will be handled as described in this Privacy Policy and in accordance with applicable laws, employment policies, and Company procedures.

1. Information We Collect

Depending on the features used and the permissions granted, we may collect the following categories of information.

1.1 Personal and Employment Information

We may collect or process information associated with your employment profile, including:

  1. Full name
  2. Employee number or employee ID
  3. Email address
  4. Designation
  5. Company or business unit
  6. Profile photograph
  7. User account and login information

Most of this information may already exist in the Company’s human resource management or enterprise resource planning system and may be displayed or processed through the Application.

1.2 Attendance Information

When you use the attendance or check-in and check-out features, we may collect:

  1. Check-in and check-out date and time
  2. Attendance status
  3. Shift or working schedule
  4. Device information associated with the attendance entry
  5. Geographic location, where location-based attendance is enabled

Location information is collected only when required for an attendance feature and when the appropriate device permission has been granted.

1.3 Leave Application Information

When you create or manage a leave application, we may collect:

  1. Leave type
  2. Leave period and selected dates
  3. Half-day information
  4. Reason for leave
  5. Leave balance and allocation information
  6. Approval status and workflow history

Leave information may contain private or sensitive details. Users should only provide information necessary for processing the leave request.

1.4 Expense Claim Information

When you create or manage an expense claim, we may collect:

  1. Expense type and category
  2. Expense date
  3. Claimed and approved amounts
  4. Description and business purpose
  5. Approval status and workflow history
  6. Payment or reimbursement status

1.5 Lead and Business Contact Information

When you create or manage a lead, we may collect information about customers, prospective customers, or other business contacts, including:

  1. Individual or organization name
  2. Contact person’s name
  3. Business email address and phone number
  4. Address, region, or territory
  5. Lead source
  6. Business requirements and interests
  7. Communication notes
  8. Follow-up details
  9. Lead status and assignment information

Users must only enter business contact information that they are authorized to process for legitimate Company purposes.

1.6 Task Information

When you create, update, assign, or complete tasks, we may collect:

  1. Task title and description
  2. Assigned employees, teams, or departments
  3. Start date, due date, and completion date
  4. Priority and status
  5. Comments, instructions, and progress updates
  6. Attachments and supporting documents
  7. Activity and modification history

1.7 Salary and Payroll Information

The Application may allow employees to securely view salary slips and related payroll information, including:

  1. Employee name and payroll period
  2. Basic salary and allowances
  3. Deductions
  4. Net salary
  5. Other payroll-related information included in the salary slip

Salary and payroll information is confidential and is made available only to the relevant employee and authorized Company personnel.

1.8 Device and Technical Information

We may automatically collect limited technical information needed to operate, secure, and improve the Application, including:

  1. Device type and model
  2. Operating system and application version
  3. Device identifiers
  4. IP address
  5. Language and regional settings
  6. Login timestamps
  7. Application activity and diagnostic logs
  8. Error, crash, and performance information
  9. Security and authentication records

1.9 Notifications

With your permission, the Application may send notifications relating to:

  1. Attendance
  2. Leave applications
  3. Expense claims
  4. Assigned or overdue tasks
  5. Lead follow-ups
  6. Approval requests
  7. Salary slip availability
  8. Important Company announcements

You can manage notification permissions through your mobile device settings, although disabling notifications may prevent you from receiving important work-related alerts.

2. How We Use Information

We use the information collected through the Application to:

  1. Verify and manage user accounts
  2. Authenticate employees and authorized users
  3. Record and manage employee attendance
  4. Process leave applications and approvals
  5. Process expense claims and reimbursements
  6. Create and manage leads and business opportunities
  7. Create, assign, update, monitor, and complete tasks
  8. Provide employees with access to salary slips
  9. Maintain employment and business records
  10. Support HR, payroll, finance, sales, and operational processes
  11. Communicate notifications, reminders, and approval updates
  12. Prevent unauthorized access, fraud, and misuse
  13. Investigate technical problems and security incidents
  14. Improve the reliability, security, and performance of the Application
  15. Comply with employment, tax, accounting, regulatory, and legal requirements
  16. Enforce Company policies and protect the rights and interests of the Company, its employees, customers, and business partners

We process information only for legitimate employment, administrative, operational, security, compliance, and business purposes, or with consent where consent is required by applicable law.

3. Application Permissions

Depending on the features enabled, the Application may request the following permissions:

Location

Location permission may be used to verify where an employee checks in or checks out. Location data will only be collected when the relevant attendance feature is used or when location-based attendance is required by Company policy.

Notifications

Notification permission may be used to send work-related reminders, approval updates, task assignments, attendance alerts, and other Company communications.

The Application will only use permissions for the purposes explained at the time the permission is requested.

4. How We Share Information

We do not sell or rent personal information.

Information may be accessed or shared only when reasonably necessary with:

  1. Authorized HR, payroll, finance, sales, management, and administrative personnel
  2. Your reporting manager or relevant approvers
  3. Other employees involved in assigned tasks, leads, projects, or approval workflows
  4. The Company’s subsidiaries, branches, or affiliated organizations, where applicable
  5. Technology, hosting, cloud, notification, authentication, maintenance, and support providers
  6. Professional advisers, auditors, or consultants where necessary
  7. Government authorities, regulators, courts, or law-enforcement agencies when required by law
  8. Other parties when necessary to protect the security, rights, property, or lawful interests of the Company or another person

Third-party service providers are permitted to process information only for authorized purposes and are expected to apply appropriate confidentiality and security protections.

5. Third-Party Services

The Application may use third-party services for functions such as:

  1. Cloud hosting and data storage
  2. Application authentication
  3. Push notifications
  4. Error and crash reporting
  5. Application performance monitoring
  6. Maps or location verification
  7. Email and communication services
  8. Enterprise resource planning and human resource management integrations

These providers may process limited technical or personal information according to their own privacy policies and their agreements with the Company.

Third-party providers currently used:

[LIST RELEVANT PROVIDERS, SUCH AS FIREBASE, GOOGLE MAPS, MICROSOFT AZURE, AWS, ERPNEXT HOSTING PROVIDER, OR WRITE “NOT APPLICABLE”]

6. Data Storage and International Transfers

Information may be stored:

  1. On the Company’s internal servers;
  2. Within the Company’s ERP, HRMS, payroll, or business systems; or
  3. On servers operated by approved cloud or technology providers.

Depending on the location of the Company and its service providers, information may be processed or stored in a country other than the country where the user is located. Where required, we take reasonable measures to ensure that international transfers are subject to appropriate legal, contractual, and security safeguards.

7. Data Security

We use reasonable administrative, organizational, and technical measures to protect information against unauthorized access, alteration, disclosure, loss, destruction, or misuse.

These measures may include:

  1. User authentication and access controls
  2. Role-based permissions
  3. Secure network communication and encryption
  4. Password and session-management controls
  5. Server and database security measures
  6. Audit logs and activity monitoring
  7. Regular backups
  8. Software updates and security reviews
  9. Restricted access to payroll and other confidential information
  10. Confidentiality obligations for authorized personnel

However, no electronic system, mobile application, or method of data transmission can be guaranteed to be completely secure. Users are responsible for keeping their login credentials confidential and for protecting their devices against unauthorized access.

Users should immediately notify the Company if they believe that their account, password, device, or personal information has been compromised.

8. Data Retention

We retain information for as long as reasonably necessary to:

  1. Provide and operate the Application;
  2. Maintain employment, attendance, payroll, financial, sales, and operational records;
  3. Complete approvals, claims, investigations, audits, or legal proceedings;
  4. Comply with tax, accounting, employment, regulatory, and legal obligations;
  5. Enforce Company policies and agreements; and
  6. Protect the Company’s legal and business interests.

Retention periods may vary depending on the type of record, applicable law, Company policy, and legitimate business requirements.

When information is no longer required, it may be deleted, anonymized, securely archived, or otherwise handled according to the Company’s data-retention procedures.

9. Employee and User Rights

Subject to applicable laws and Company policies, users may have the right to:

  1. Request access to their personal information
  2. Request correction of inaccurate or incomplete information
  3. Request deletion of certain information where legally permitted
  4. Request restriction of certain processing
  5. Object to certain processing activities
  6. Withdraw consent where processing is based on consent
  7. Request information about how their data is being used
  8. Submit a complaint regarding the handling of their information

Some information may not be deleted while the user remains employed or where the Company must retain it for payroll, attendance, financial, tax, legal, security, audit, or regulatory purposes.

To exercise an applicable right, contact the Company using the information provided in the “Contact Us” section below.

10. Account Access and Deletion

The Application is intended for employees and other authorized users. User accounts may be created, managed, suspended, or disabled by the Company.

When employment or authorization ends:

  1. Access to the Application may be disabled;
  2. Business and employment records may remain within the Company’s systems;
  3. Records will be retained or deleted according to applicable laws and Company retention policies.

Where account deletion is available or legally required, users may submit a request using the contact information below. Deleting an application account does not necessarily require the deletion of employment, payroll, accounting, attendance, financial, legal, or other records that the Company is required or permitted to retain.

11. User Responsibilities

Users must:

  1. Keep their login credentials secure
  2. Not share their accounts with another person
  3. Provide accurate and relevant information
  4. Only upload documents they are authorized to provide
  5. Avoid including unnecessary sensitive information in descriptions or attachments
  6. Protect customer, employee, and business information accessed through the Application
  7. Comply with Company policies regarding acceptable use, confidentiality, information security, attendance, expenses, leads, and task management
  8. Immediately report unauthorized access, security concerns, or suspected misuse

12. Children’s Privacy

The Application is intended for employees and authorized business users and is not designed for children.

We do not knowingly collect personal information directly from children through the Application. If we become aware that information has been collected from a child without appropriate authorization, we will take reasonable steps to delete or otherwise appropriately handle that information.

13. Automated Decision-Making

The Application may automatically calculate, display, classify, or route information, such as attendance status, leave balances, expense approval workflows, task status, reminders, or notifications.

Unless otherwise disclosed, the Application is not intended to make final employment decisions solely through automated processing without appropriate review by authorized Company personnel.

14. Links and External Services

The Application may contain links to external websites, documents, systems, or services. We are not responsible for the privacy or security practices of third-party websites or services that are not controlled by the Company.

Users should review the privacy policies of those third parties before providing information to them.

15. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  1. Changes to the Application or its features
  2. Changes to the information we collect or process
  3. Changes to Company procedures
  4. Changes to third-party services
  5. Legal or regulatory requirements
  6. Security or operational improvements

The updated Privacy Policy will be published on this webpage or made available through the Application. The “Last Updated” date at the top of this policy will indicate when the latest changes were made.

Where required, we may also notify users of material changes through the Application, email, or another appropriate method.

16. Contact Us

For questions, concerns, privacy requests, account-deletion requests, or complaints relating to this Privacy Policy or the Application, please contact:

Company: Alfa Marine Electronics

Application Name: OneHRIS

Privacy/HR Contact: +923234855011

Email: zia@pukattechnology.com

Address: Karachi, Plot No. SA-5 (ST-8), Sector 6G, Mehran Town Korangi Industrial Area

Website: https://alfamarine.com

We will review and respond to privacy-related requests in accordance with applicable laws and Company procedures.