This policy explains what data passes through Diwan, who is responsible for it, where it is stored, who can see it, how long it is kept, and how to exercise your rights. If anything is unclear, contact us at [email protected].
1. Who we are and what this policy covers
Diwan HR ("Diwan", "we", "us") is a human resources, payroll and attendance system for companies in Syria, a service operated by Najdat Talmsani Audeh. It runs as a web application (PWA), as an Android app and as an iPhone app, and is offered in two ways:
- Diwan Cloud: hosted by us, with a dedicated address for each company (
company-name.diwanhr.com). - On-premises edition: the company installs Diwan on its own server, and we provide support.
This policy applies to customer companies, their employees who use Diwan, candidates who apply to vacancies through Diwan, and visitors to diwanhr.com.
2. Who is responsible for the data
| Data | Responsible party (controller) | Diwan's role |
|---|---|---|
| Employee and candidate data entered by, or collected for, the company (profile, payroll, attendance, leave, requests, etc.) | The customer company (the employer) | Processor: we store it and run the system on it solely on the company's behalf, under its instructions and settings |
| Data about the customer company as our client (contract, invoices, payments, contacts, support tickets) | Diwan | Controller |
| Marketing website visitors and contact messages | Diwan | Controller |
In other words: if you are an employee, your employer decides what is kept about you and who can see it, and it is your first point of contact for any request about your data (Section 10). We do not use any company's employee data for any other purpose, we do not sell it, and we do not use it for advertising.
3. What data we process
3.1 Employee data entered by the company
Depending on the fields the company fills in, this may include:
- Identification and contact: name in two languages, employee number, photo, email and mobile number, address, dependants.
- Identity (sensitive group): national ID number, passport number, social insurance number, date of birth, mother's name and place of birth.
- Employment: branch, department, job title and manager, hire date and contract, work schedule, custody items, documents and their expiry dates.
- Payroll (sensitive group): base salary and pay components, the wage registered with social insurance, tax status, advances and instalments, payslips and payroll runs, final settlement.
- Payment (sensitive group): bank account number or IBAN, or Sham Cash wallet number.
- Health (sensitive group): health notes, disability, sick-leave reports and attachments.
- Actions: requests and approvals, leave and balances, disciplinary actions, end of service, issued letters.
- Change history: who changed what, when and why (without the values of sensitive fields).
3.2 Attendance data
- Punches: clock-in and clock-out times and their source (phone, kiosk, QR code, biometric device, manual entry by HR, or correction).
- Location: only at the moment of a punch from a phone, and only if you consent (Section 4).
- Selfie photo: only if the company enables it and you take one when punching.
- Review flags: for example "outside the allowed location", "mock location" or "device clock changed". Flags never reject a punch; they bring it to HR for review.
- Biometric devices: Diwan receives only the employee's device number, the punch time and the user name stored on the device. Fingerprint templates and face images never leave the device and are never stored by us: we instruct the device not to send them, and if it does, they are discarded without being stored.
3.3 Account and sign-in data
- Email address or mobile number for sign-in codes, and your password (stored only as a one-way hash that no one, including us, can read).
- Open sessions and the device or browser type (shown on the "My sessions" screen so you can review and end them), and the sign-in method.
- Your preferences: language, numerals, dark mode and notifications.
3.4 Job candidates
If you apply to a company's vacancy through Diwan: your name, contact details, city, CV, answers to the application form, and the hiring team's evaluations and application stages. The company that opened the vacancy is responsible for this data.
3.5 Hala (the AI assistant)
Hala works only if the company adds an API key for an AI service on its own account (for example Gemini, OpenAI or Anthropic). When you ask Hala a question:
- Not sent to the provider: any employee name, number, amount, salary or date from the data, or any ID, account or health information. These are replaced with references (such as "P1" or "N3") before sending, and the actual values are inserted into the answer on our side afterwards. Long digit sequences, email addresses and phone numbers you type in your question are also removed.
- Sent to the provider: the text of your question after this cleaning, tool results in reference form, and the last few messages of the conversation in the same form. Neither the company's name nor your name is sent.
- Hala can only see what you can see on your own screens, and cannot change anything unless you confirm it yourself.
- Your conversations are yours alone: neither the system administrator nor the Diwan team can read them. Their text is encrypted in the database and deleted after the period the company sets (Section 9).
- Use of the provider is subject to that provider's terms, on the company's account. Diwan has no account with the provider for this purpose.
3.6 Customer company data
Company name and address, contacts, contract and plan, invoices, payments and proofs of payment, and support tickets and their attachments.
3.7 Marketing website visitors
diwanhr.com contains no tracking tools, analytics, advertising or third-party libraries. The contact form only opens your own email application and sends nothing to a server. If you write to us, we keep your message and address in order to reply.
4. Location and photos at punch time
- Location is recorded only at the moment of a punch. There is no background or continuous tracking. The mobile apps do not request background location permission at all.
- Before your first punch with location, we ask for your consent, explaining that only your location at the moment of the punch is recorded. If you decline, the punch is recorded without a location (it is not rejected), and is flagged "no location" for HR if the company requires a location.
- You can revoke location permission for the app or the browser at any time from your phone's settings; no location will then be recorded.
- The apps obtain location from the phone itself, without Google services, and detect mock locations so the punch can be flagged for review.
- Selfies are compressed to about 50 KB and deleted from the device as soon as they reach the server.
- Who can see this evidence (coordinates and photo): you, and HR by default, or as configured in your company's roles. Every time someone other than the employee opens an employee's selfie, it is recorded in the access log.
- Retention: coordinates and photos are deleted after 90 days by default; the company may extend this or keep them indefinitely. When they are deleted, the punch itself remains, with its flags and calculated distance.
5. Where data is stored
- Diwan Cloud: on a server at Hetzner in Helsinki, Finland, with encrypted backups on separate Hetzner storage in Germany. This means the data is stored outside Syria, within the European Union.
- On-premises edition: on the company's own server, with its backups kept by the company. Diwan keeps no copy of its data or of its backups.
- On your device: the browser or app stores some items so that it can work offline: punches not yet sent (encrypted), your user and employee identifiers, name and employee number, and your preferences. When you sign out, unsent punches stay on the device until you sign in again (or are deleted if you choose so).
6. Encryption and security
- In transit: all connections use HTTPS.
- Sensitive fields are encrypted in the database with AES-256-GCM: national ID, passport number, social insurance number, health notes and disability, bank account and wallet numbers, the company's Hala API key, and the text of Hala conversations. Files containing salaries, account numbers or disciplinary matters (such as payroll output files and receipts, disciplinary letters, clearance certificates and job offers) are also encrypted in storage.
- Amounts and salaries are not encrypted field by field because they are needed for calculation; they are protected by permissions and by company isolation (below).
- Company isolation: each company is isolated from all others at the database level itself, not only in application code.
- Passwords are stored with Argon2id as a one-way hash. After several consecutive failed attempts, the account is locked for a period.
- Second factor: any user holding a permission over payroll, sensitive data or access management must complete an additional verification code in the session before using those permissions. (An employee viewing their own data does not need it.)
- Backups are encrypted on the server itself before they leave it (AES-256), so the storage provider cannot read their contents. Every month, a restore of the latest backup is tested automatically to confirm it is sound.
- Mobile apps: the session token is kept in the system's encrypted storage (Android Keystore on Android; the Keychain on iPhone, for that device only), and the apps contain no keys or secrets.
- On-premises edition: encryption keys are held only by the company, on a recovery sheet printed at installation. Diwan keeps no copy, so we cannot recover them if they are lost.
- Technical logs use an allow-list: only identifiers and statuses are written. No salary, ID number, health information, location, email address, phone number or message text.
No system is 100% secure, but these measures are built into the system itself and are covered by automated tests.
7. Who can see the data
7.1 Within the company
The company decides who sees what, through roles and permissions (employee, line manager, HR, finance, executive management, system administrator and others, all adjustable by the company):
- Employees see their own data and the company's general structure (only the name, job title, department and photo of colleagues).
- Managers see their team according to their permissions.
- Payroll has a separate gate: no one sees it without a separate activation, at a visibility level chosen by the company (totals only, anonymised, or full).
- Sensitive data (identity, bank, health) requires separate permissions. HR sees health information by default, and the company can remove this.
- Every access to another employee's sensitive data, or to a payslip or payroll run, is recorded in the access log.
7.2 The Diwan team (Diwan Cloud)
- We do not access your company's data without its permission. The company grants an "access grant" from its settings, with a role it chooses, for at most 30 days, and can revoke it at any moment. There is no other way in.
- During such access, the team member sees a fixed banner stating they are in as the Diwan team, the company receives a notification, and the company can see every grant and every session on its "Diwan team access" screen. Every change we make is recorded under our name in the company's audit log.
- Even with a grant, we cannot use Hala on the company's account, grant permissions, or read anyone's notifications.
- Support tickets: we read only the text and images the company sends. The screen warns against including salaries, ID numbers or health information. Ticket attachments are encrypted in storage.
- Aggregated account-health signals: without a grant, we see only counts, dates and statuses (such as the number of active employees, the last sign-in by any user, whether the last payroll run was closed), with no names, amounts or employee identifiers, to help the company with onboarding and follow-up. The company can see the same figures on the "What Diwan sees about you" page in its Diwan support section.
7.3 On-premises edition
The Diwan team has no access. Support takes place through a diagnostic file sent by the system administrator, a time-limited support user, or a secure connection opened by the customer for up to 24 hours, all of which are logged. The "health heartbeat" (technical information about the installation, with no information about any employee, user or amount) is off until the system administrator enables it, and the administrator can see exactly what is sent.
8. Third parties through which data passes
We use the following parties only to operate the service:
| Party | Purpose | What passes |
|---|---|---|
| Hetzner (Helsinki, Finland) | The Diwan Cloud server | All Diwan Cloud data (stored there) |
| Hetzner Storage Box (Germany) | Backups | Copies encrypted before leaving the server, which it cannot read |
| Zoho (Zoho Mail, later ZeptoMail, in Zoho's EU data centres) | Sign-in codes and notifications by email | Recipient address and message text (no salaries or sensitive information) |
| An intermediary WhatsApp platform (the channel is currently off, and is enabled only once a platform is chosen) | Sign-in codes and notifications on WhatsApp | Mobile number and message text (no salaries or sensitive information) |
| Browser push services (Google, Apple, Mozilla or Microsoft, depending on your browser) | Device notifications, if you allow them | An encrypted notification containing only a short sentence and a link |
| Apple Push Notification service (APNs) | iPhone app notifications on Diwan Cloud, if you allow them | A fixed sentence ("You have a new notification in Diwan"), the unread count and the page link, without the notification text |
| The AI provider chosen by the company | Hala, if the company enables it with its own key | The cleaned question (Section 3.5) |
| Cloudflare | Hosting the diwanhr.com marketing website | Ordinary page requests |
We do not sell data to anyone, and we do not share it for advertising.
9. Retention
General rule: company data is kept for as long as the company is our customer, because employee and payroll records are legal and financial records. For some data types, the company can set a deletion period in its settings.
| Data | Period |
|---|---|
| Employee profile, contracts, requests, leave and attendance | Indefinitely by default |
| Closed payroll runs and everything they used, the audit log and the access log | Indefinitely, and never deleted, even by a setting |
| Punch coordinates, selfies and kiosk photos | 90 days by default; the company may extend this or keep them indefinitely |
| Text of Hala conversations | 90 days by default; the company may choose between 7 days and 10 years |
| Candidates with no open application | Indefinitely by default; the company may set a period. Candidates may ask the company to erase their data (Section 10) |
| Exported report files (Excel or PDF) | 30 days by default (the company may choose 1 to 365) |
| Unconfirmed employee import files | 7 days by default (up to 30) |
| Uploaded files never attached to anything | 24 hours |
| Backups (Diwan Cloud) | One backup every night; we keep the last 7 daily, 4 weekly and 12 monthly backups, so the oldest is about one year old |
| Technical logs | A limited period: they rotate automatically and older entries are overwritten |
When a company leaves Diwan: its account is suspended and its data remains stored. We provide a copy of its data on request (Excel for employees and closed payroll runs). Full deletion takes place only upon the company's written request, 30 days after the request. After deletion, the data remains in the encrypted backups until it rotates out (about one year at most), and is used only to restore the system after a failure.
10. Your rights and how to exercise them
If you are an employee or a candidate
Since your employer is responsible for your data, your requests go to your employer (HR or the system administrator):
- Access: you can view most of your data yourself in Diwan ("My Diwan"): your profile, payslips, leave balance, attendance and requests.
- Correction: ask HR; for attendance there is a correction request inside Diwan.
- Erasure or restriction: subject to your employer's policy and the law. Some data cannot be deleted because it is a legal or financial record (such as closed payroll runs). Candidates may request erasure; the company then erases the name, contact details, CV, answers and evaluation comments, and only anonymous statistical figures remain.
- Location: revoke the permission from your phone's settings at any time (Section 4).
- Notifications: choose your channels in your preferences.
- Sessions: view and end them from "My sessions".
If you cannot reach your employer, or it does not respond, contact us at [email protected] and we will forward your request to it. We cannot change or delete an employee's data without the company's decision.
If you are a customer company or a website visitor
Contact us directly at [email protected] to access, correct or request deletion of your data held by us, within the limits of what we must retain by law (such as invoices).
11. Emails and notifications
- Emails are sent in your company's name from
[email protected], and contain the company's logo and the Diwan logo as images embedded in the message. No images are loaded from outside, and there is no email-open or link tracking. - Emails, WhatsApp messages and lock-screen notifications never contain a salary, ID number, health information, leave type or reason. Sensitive notifications (such as disciplinary matters or resignations) use a generic sentence: "Something new is waiting for you in Diwan". Details are shown only after you sign in to Diwan.
- Mobile app notifications do not contain the notification text: Android says "You have new notifications in Diwan", and iPhone says "You have a new notification in Diwan" with the count.
- If your company has set a reply-to address, some emails (such as messages to candidates) carry a reply-to header pointing to the company's email.
12. Cookies and on-device storage
- In the Diwan application: we use strictly necessary cookies only, for the sign-in session. There are no advertising, analytics or tracking cookies. The session cookie is bound to your company's exact address and cannot be read by any script.
- Session length: 30 days for ordinary employees, 12 hours for managers, HR and any wider role, and 30 days in the mobile apps.
- Local storage: display preferences (language, dark mode, etc.) and unsent punches (Section 5).
- On the marketing website: no cookies. If you press the dark-mode button, your choice is saved in your browser.
13. Mobile apps (Android and iPhone)
Both apps open your company's own Diwan. They contain no Google or Firebase libraries and no analytics, advertising or tracking tools, and they do not write logs containing location or session tokens. Screenshots are allowed.
13.1 Android
| Permission | Purpose |
|---|---|
| Internet and network state | Connecting to Diwan, and knowing when there is a connection to send punches |
| Location (precise and approximate) | At the moment of a punch only, after your consent. No background location |
| Camera | Selfie and QR code scanning, only when you press the button |
| Notifications | The "You have new notifications" alert |
| Run after device restart | To reschedule background sending of unsent punches |
13.2 iPhone
| Permission | Purpose |
|---|---|
| Location "While Using the App" only | At the moment of a punch only, after your consent. No "Always" permission and no background location. If you chose "Approximate location", full accuracy is requested for that punch only |
| Camera | Selfie and QR code scanning, only when you press the button |
| Notifications | The "You have a new notification in Diwan" alert with the count, without the notification text (Section 8) |
| Background refresh | Sending unsent punches when the connection returns, and updating the notification count |
The session token and the key for stored punches are kept in the iPhone Keychain for that device only: they are not synced to iCloud or included in backups, and do not move to a new device.
14. Security incidents
If a security incident affects a company's data, we will notify the company as soon as possible after we become aware of it, explaining what happened and what we have done, and the company will decide how to inform its employees in accordance with the law.
15. Changes to this policy
If we make a material change, we will notify customer companies 30 days before it takes effect and update the date above.
16. Contact
For any privacy question: [email protected]
Diwan HR, a service operated by Najdat Talmsani Audeh · Damascus, Syria