Legal
Privacy Policy
Effective date: January 1, 2026 · Last updated: March 1, 2026
1. Overview
Zentra is an HR management platform operated by Pentabay Softwares. This policy explains what personal data we collect through Zentra, why we collect it, and the rights you have over it. It is written to align with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and India's Digital Personal Data Protection Act, 2023 (DPDPA).
2. Information We Collect
Depending on your role in an organization using Zentra, we process:
- Identity and contact details - name, email, phone, department, designation
- Employment records - attendance, leave history, performance and onboarding data
- Payroll data - salary structure, bank details, tax identifiers, generated payslips
- Documents you upload - identification, visas, work permits, certifications
- System data - login timestamps, device/session metadata, audit and access logs
3. How We Use Your Information
Personal data is used strictly to operate the HR functions your organization has enabled, including:
- Running payroll and generating statutory filings and payslips
- Tracking attendance, leave balances, and approvals
- Sending expiry reminders for uploaded documents (visas, certifications)
- Powering Zentra Copilot responses scoped to your own account and organization
- Maintaining audit and access logs required for security and compliance
We do not sell personal data, and we do not use employee data to train third-party AI models.
4. Data Retention
Data is retained for as long as your organization's account is active, plus any additional period required by statutory record-keeping obligations in your country (e.g. payroll and tax records). Organizations can configure shorter retention windows for non-statutory data through their data retention policy settings.
5. Your Rights
Depending on your jurisdiction, you have the right to access, correct, export, or request deletion of your personal data. Zentra supports this directly:
- Self-serve data export from your employee portal
- Self-serve deletion requests, routed to your organization's HR admin for action
- A consent record for any optional data processing, viewable at any time
6. Security Measures
All sensitive fields are encrypted at rest with AES-256-GCM, access is governed by role-based permissions, and every action is written to an append-only audit log. A full breakdown is available on our Security & Trust page.
7. Third-Party Processors
We use a limited set of infrastructure processors to operate Zentra - including cloud hosting (OVHcloud, data residing in the BHS Canada region), authentication (AWS Cognito), and transactional email delivery. Each is bound by a data processing agreement and only receives the minimum data required to perform its function.
8. Children's Privacy
Zentra is a workplace product not directed at children, and we do not knowingly collect data from individuals under the age of 18.
9. Changes to This Policy
We'll update the "last updated" date above whenever this policy changes, and will notify organization admins directly of any material change.
10. Contact
Questions about this policy or a data request can be sent to your organization's HR admin, or directly to corporate@pentabay.com.