Privacy Policy

Effective August 20, 2026

1. Introduction

This Privacy Policy explains how SoraCore β€” an HR, payroll and accounting platform operated by SAGBRAIN GLOBAL PTE. LTD. β€” collects, uses, stores, and protects information when your Organization uses the platform to manage its workforce and finances. It applies to all users (Admin, HR, Employee, Accountant, Viewer, and CA Officer roles) and to organizations operating one or more legal entities across different countries.

The SoraCore service is provided by SAGBRAIN GLOBAL PTE. LTD. (UEN 202611585N), a company incorporated in Singapore, for customers in every market.

For most personal data in SoraCore, your Organization (your employer) is the data controller / data fiduciary and decides how the data is used; SoraCore acts as a data processor on its behalf. Where you interact with us directly β€” for example when signing your Organization up for a subscription β€” SAGBRAIN GLOBAL PTE. LTD. is the controller for that limited account and billing information.

2. Information We Collect

SoraCore collects the following categories of information, entered by your Organization or generated through your use of the platform:

  • Account & profile data: name, email, employee ID, position, department, phone, address, date of birth, national identification number, and profile photo.
  • Attendance data: check-in/check-out timestamps, break durations, and GPS location captured at the moment of check-in and check-out.
  • Leave & work data: leave applications and balances, daily and overtime work reports, attendance correction requests, and manager/team hierarchy assignments.
  • Financial data (where applicable): payroll records, payslip details, invoices, expenses, and finance/accounting entries handled by Accountant and CA Officer roles.
  • Communications: notices, in-app notifications, and feedback submissions you create, including any attachments you upload.
  • Account activity: login sessions, security/presence-check acknowledgements, and preference settings such as language and theme.
  • Billing & subscription data: company details, the administrator's contact information, the selected plan, and payment metadata. Card payments are handled by our payment provider β€” SoraCore does not store full card numbers on its own servers.
  • AI assistant content: if your Organization enables the AI knowledge assistant, the documents it uploads and the questions users ask are processed by a third-party AI provider to generate answers (see "Data Sharing" below).

Special / sensitive categories. Some data carries heightened legal protection and additional safeguards: biometric and real-time geolocation data used for attendance, and national identification numbers such as the Singapore NRIC/FIN where your Organization records them for HR, payroll or tax purposes. These are collected only where your Organization has established a lawful basis, are restricted by role, and are covered by the storage encryption described in Section 4.

3. How We Use Your Information

Information collected in SoraCore is used to:

  • Record and calculate attendance, leave balances, overtime, and payroll on your Organization's behalf.
  • Route approvals (e.g. leave, corrections, financial documents) to the appropriate HR, Admin, or CA Officer users.
  • Send you notifications, reminders, and notices relevant to your role and account.
  • Generate reports, dashboards, and exports (Excel/PDF) for your Organization's management and record-keeping.
  • Maintain the security of your account and the platform, including detecting unauthorized access.

We do not use your data for advertising, and we do not sell personal information to third parties.

Processing is carried out on behalf of your Organization and typically relies on lawful bases including performance of the employment relationship, your Organization's legitimate interests in running its business, and compliance with legal obligations (payroll, tax, and labor-law record-keeping). Where a feature involves biometric, geolocation, or other sensitive data, your Organization β€” as controller β€” is responsible for establishing and recording the lawful basis, including obtaining and evidencing any consent its local law requires, before enabling that feature. SoraCore does not obtain that consent from employees on your Organization's behalf.

4. How Your Data Is Stored & Protected

Where it is stored. Your Organization's data is held in a managed PostgreSQL database on Amazon Web Services (Amazon RDS), hosted in the Tokyo, Japan region (ap-northeast-1). It is stored and processed there regardless of the country in which your Organization operates, and regardless of the fact that Sagbrain Global Pte. Ltd. is incorporated in Singapore. If we introduce additional hosting regions in future, we will update this policy and notify Organization Admins before the change takes effect.

Encryption at rest. Storage encryption is enabled on the database instance, so the underlying volumes, automated backups and snapshots are written in encrypted form. Someone obtaining the raw storage cannot read your data from it.

Encryption in transit. Traffic between your browser and SoraCore travels over HTTPS. The connection between the application and the database is also encrypted, and the database's certificate is verified rather than merely accepted β€” encryption without that check would prevent eavesdropping but not an attacker impersonating the database.

Separation between organizations. Organizations share one database and are separated logically: every record carries the identity of the organization it belongs to, and every query is filtered by the organization of the signed-in user. We describe this as logical separation rather than a dedicated database per customer, because that is what it is.

Access controls. Permissions are role-based, so a user sees only what their role allows. Sign-in issues a short-lived access token alongside a refresh token, so a captured token is useful only briefly. Passwords are stored as one-way bcrypt hashes and are never recoverable β€” SoraCore staff cannot read your password, and neither can we return it to you if it is lost.

What we do not currently do. We do not maintain field-level access logs recording each time a national identifier is viewed, and we do not encrypt individual database columns separately from the storage-level encryption described above. Both are on our roadmap; we would rather state the position plainly than imply protections that are not in place. Where a data breach occurs, we follow the notification duties set out in Section 7.

5. Data Sharing, Subprocessors & International Transfers

Your data is only shared within your own Organization's account, visible to users according to their role. SoraCore does not sell or share your personal data with third parties for marketing purposes. We use a limited set of service providers ("subprocessors") strictly to operate the platform:

  • Cloud hosting for the database and application servers.
  • Email delivery via your Organization's configured provider (SMTP settings managed by your Admin).
  • Mapping / reverse geocoding to turn attendance check-in coordinates into a readable place name.
  • Payment processing for subscription billing (card data is handled by the payment provider, not stored by SoraCore).
  • AI provider β€” where the AI assistant is enabled, uploaded documents and user questions are sent to a third-party large-language-model provider solely to generate answers; this content is not used to train public models on your behalf.

International transfers. SoraCore is operated by Sagbrain Global Pte. Ltd., a company incorporated in Singapore, but the infrastructure holding your data is located in Japan. Data belonging to Organizations outside Japan β€” including Organizations in Singapore β€” is therefore transferred to and processed in Japan. As a Singapore organization transferring personal data abroad we are subject to the transfer-limitation requirement of the PDPA, and the processing carried out in Japan is additionally subject to Japan's Act on the Protection of Personal Information (APPI). Where a subprocessor processes data outside Japan, the recipient is bound by contract to a standard of protection comparable to that required under the PDPA. Where the law of your own country imposes additional conditions on transferring employee data abroad, your Organization, as controller, is responsible for satisfying them before entering that data into SoraCore.

6. Your Rights

Depending on your role, your location, and your Organization's policies, you can:

  • View and update your own profile information directly from your account settings.
  • Request a correction to attendance or report records through the built-in correction workflow.
  • Ask your Organization's HR or Admin team what data is held about you, or to correct or remove data, subject to record-keeping and legal obligations (e.g. payroll history required for tax or labor law).
  • Where the law provides, request access to a copy of your data, correction or erasure, restriction of or objection to certain processing, data portability, and withdrawal of consent β€” without being disadvantaged for exercising these rights.

Because SoraCore is a workforce tool used on behalf of your Organization, requests to access, correct, or delete your data should first be directed to your Organization's HR or Admin team (the controller for your employment records); we will support them in responding. As our service is provided from Singapore, you may also contact the Personal Data Protection Commission (PDPC) of Singapore. If you are located elsewhere, you may in addition have the right to complain to your own national data-protection authority.

7. Singapore Privacy Information (PDPA)

SoraCore is provided from Singapore by SAGBRAIN GLOBAL PTE. LTD., and our processing is governed by Singapore's Personal Data Protection Act (PDPA), regulated by the Personal Data Protection Commission (PDPC).

  • We observe the PDPA obligations that apply to us: purpose limitation, notification, access & correction, accuracy, protection, retention limitation, transfer limitation, and accountability.
  • NRIC/FIN is stored only where your Organization lawfully requires it for HR, payroll or tax purposes. It is never used for authentication β€” not for logins, passwords, or document access β€” and is access-restricted.
  • We notify the PDPC of a notifiable data breach within 3 calendar days of assessing it as notifiable, and affected individuals as soon as practicable.
  • We have appointed a Data Protection Officer whose contact details appear in Section 12.

If your Organization operates outside Singapore, its own national data-protection, employment and payroll laws will usually continue to apply to it as controller β€” including any local rules on consent, employee notice, data localisation, or cross-border transfer. Your Organization is responsible for meeting those obligations. We will support reasonable requests needed for it to do so; contact us at support@soracore.net.

8. Bangladesh Privacy Information

SoraCore is sold into Bangladesh by SAGBRAIN GLOBAL PTE. LTD. from Singapore. Bangladesh's Personal Data Protection Act, 2026 applies to organisations outside the country that handle the personal data of people in Bangladesh, so it reaches us as well as your Organization. We set out our position plainly rather than leaving it to be inferred:

  • Roles. Your Organization is the data fiduciary / controller for its employees' records and decides what is collected and why. SoraCore acts as its processor, handling that data only on its instructions and to run the service.
  • Where the data is. In Japan (Tokyo, ap-northeast-1), as described in Sections 4 and 5. We do not currently keep a copy inside Bangladesh. If a localisation requirement applies to a particular category of your data, your Organization should raise it with us before entering that data into SoraCore so we can tell you whether we are able to meet it.
  • Cross-border transfer. Entering data into SoraCore transfers it to Japan. Your Organization, as fiduciary, is responsible for having a lawful basis for that transfer and for giving its employees the notice Bangladeshi law requires; we will provide whatever information about our processing it needs in order to do so.
  • Sensitive categories. Payroll, bank details, national identifiers and attendance location receive the handling described in Section 4. Geolocation and presence monitoring are additionally governed by the consent and notice records described in Section 3.
  • Statutory record-keeping. Bangladeshi law obliges your Organization, as employer, to keep certain records β€” wage and attendance registers under the Bangladesh Labour Act, 2006, and tax withholding and payment records under the Income Tax Act, 2023 and the NBR rules made under it. That is why the retention described in Section 9 keeps payroll, attendance and leave history after an employee leaves, rather than deleting it on request. Deciding which records those are, and for how long, is your Organization's responsibility as fiduciary; SoraCore stores and produces them on its instructions. Compliance with these Acts rests on how your Organization pays and rosters its people β€” the software records those decisions, it does not make them.
  • Complaints. Raise these with your Organization's HR or Admin team first, as fiduciary. You may also contact us directly, and you retain any right to complain to the competent Bangladeshi authority.

Enforcement provisions under the 2026 Act are being phased in, and guidance on several points β€” including the exact scope of any localisation requirement β€” is still developing. We keep this section under review and will update it as the position becomes settled rather than claiming a certainty that does not yet exist.

9. Data Retention

Employment-related data (attendance, leave, payroll, reports) is retained for as long as your account remains active and for a period afterward as required for payroll, tax, and labor-law record-keeping β€” including the employee and wage records that Singapore's Employment Act requires an employer to keep, and any longer period your Organization's own local law imposes. When an employee's account is deactivated, historical records are retained by the Organization rather than deleted outright, so reports, payslips, and audit trails remain accurate; national identifiers are securely deleted once the legal purpose for holding them ends.

10. Cookies & Similar Technologies

SoraCore uses your browser's local storage (not third-party tracking cookies) to keep you signed in and to remember preferences such as language and theme. See our Cookie Policy for full details.

11. Children’s Privacy

SoraCore is a workforce management platform intended for use by employees of a registered Organization and is not directed at, or intended for use by, children.

12. Data Protection Officer & Contact

As required by the PDPA, we have appointed a Data Protection Officer (DPO). You can reach the DPO and our privacy team at support@soracore.net.

For employment-record requests, please also contact your Organization's HR or Admin team, who act as the controller. Our registered office is: SAGBRAIN GLOBAL PTE. LTD. (UEN 202611585N), 100D Pasir Panjang Road #05-03, MEISSA, Singapore 118520.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. Material changes will be communicated to Organization Admins, and the "Effective" date at the top of this page will be updated accordingly.