Legal

Privacy Policy

Effective date: January 1, 2026 · Last updated: March 1, 2026

1. Overview

Zentra is an HR management platform operated by Pentabay Softwares. This policy explains what personal data we collect through Zentra, why we collect it, and the rights you have over it. It is written to align with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and India's Digital Personal Data Protection Act, 2023 (DPDPA).

2. Information We Collect

Depending on your role in an organization using Zentra, we process:

  • Identity and contact details - name, email, phone, department, designation
  • Employment records - attendance, leave history, performance and onboarding data
  • Payroll data - salary structure, bank details, tax identifiers, generated payslips
  • Documents you upload - identification, visas, work permits, certifications
  • System data - login timestamps, device/session metadata, audit and access logs

3. How We Use Your Information

Personal data is used strictly to operate the HR functions your organization has enabled, including:

  • Running payroll and generating statutory filings and payslips
  • Tracking attendance, leave balances, and approvals
  • Sending expiry reminders for uploaded documents (visas, certifications)
  • Powering Zentra Copilot responses scoped to your own account and organization
  • Maintaining audit and access logs required for security and compliance

We do not sell personal data, and we do not use employee data to train third-party AI models.

4. Data Retention

Data is retained for as long as your organization's account is active, plus any additional period required by statutory record-keeping obligations in your country (e.g. payroll and tax records). Organizations can configure shorter retention windows for non-statutory data through their data retention policy settings.

5. Your Rights

Depending on your jurisdiction, you have the right to access, correct, export, or request deletion of your personal data. Zentra supports this directly:

  • Self-serve data export from your employee portal
  • Self-serve deletion requests, routed to your organization's HR admin for action
  • A consent record for any optional data processing, viewable at any time

6. Security Measures

All sensitive fields are encrypted at rest with AES-256-GCM, access is governed by role-based permissions, and every action is written to an append-only audit log. A full breakdown is available on our Security & Trust page.

7. Third-Party Processors

We use a limited set of infrastructure processors to operate Zentra - including cloud hosting (OVHcloud, data residing in the BHS Canada region), authentication (AWS Cognito), and transactional email delivery. Each is bound by a data processing agreement and only receives the minimum data required to perform its function.

8. Children's Privacy

Zentra is a workplace product not directed at children, and we do not knowingly collect data from individuals under the age of 18.

9. Changes to This Policy

We'll update the "last updated" date above whenever this policy changes, and will notify organization admins directly of any material change.

10. Contact

Questions about this policy or a data request can be sent to your organization's HR admin, or directly to corporate@pentabay.com.