Effective August 20, 2026
This Privacy Policy explains how SoraCore β an HR, payroll and accounting platform operated by SAGBRAIN GLOBAL PTE. LTD. β collects, uses, stores, and protects information when your Organization uses the platform to manage its workforce and finances. It applies to all users (Admin, HR, Employee, Accountant, Viewer, and CA Officer roles) and to organizations operating one or more legal entities across different countries.
The SoraCore service is provided by SAGBRAIN GLOBAL PTE. LTD. (UEN 202611585N), a company incorporated in Singapore, for customers in every market.
For most personal data in SoraCore, your Organization (your employer) is the data controller / data fiduciary and decides how the data is used; SoraCore acts as a data processor on its behalf. Where you interact with us directly β for example when signing your Organization up for a subscription β SAGBRAIN GLOBAL PTE. LTD. is the controller for that limited account and billing information.
SoraCore collects the following categories of information, entered by your Organization or generated through your use of the platform:
Special / sensitive categories. Some data carries heightened legal protection and additional safeguards: biometric and real-time geolocation data used for attendance, and national identification numbers such as the Singapore NRIC/FIN where your Organization records them for HR, payroll or tax purposes. These are collected only where your Organization has established a lawful basis, are restricted by role, and are covered by the storage encryption described in Section 4.
Information collected in SoraCore is used to:
We do not use your data for advertising, and we do not sell personal information to third parties.
Processing is carried out on behalf of your Organization and typically relies on lawful bases including performance of the employment relationship, your Organization's legitimate interests in running its business, and compliance with legal obligations (payroll, tax, and labor-law record-keeping). Where a feature involves biometric, geolocation, or other sensitive data, your Organization β as controller β is responsible for establishing and recording the lawful basis, including obtaining and evidencing any consent its local law requires, before enabling that feature. SoraCore does not obtain that consent from employees on your Organization's behalf.
Where it is stored. Your Organization's data is held in a managed PostgreSQL database on Amazon Web Services (Amazon RDS), hosted in the Tokyo, Japan region (ap-northeast-1). It is stored and processed there regardless of the country in which your Organization operates, and regardless of the fact that Sagbrain Global Pte. Ltd. is incorporated in Singapore. If we introduce additional hosting regions in future, we will update this policy and notify Organization Admins before the change takes effect.
Encryption at rest. Storage encryption is enabled on the database instance, so the underlying volumes, automated backups and snapshots are written in encrypted form. Someone obtaining the raw storage cannot read your data from it.
Encryption in transit. Traffic between your browser and SoraCore travels over HTTPS. The connection between the application and the database is also encrypted, and the database's certificate is verified rather than merely accepted β encryption without that check would prevent eavesdropping but not an attacker impersonating the database.
Separation between organizations. Organizations share one database and are separated logically: every record carries the identity of the organization it belongs to, and every query is filtered by the organization of the signed-in user. We describe this as logical separation rather than a dedicated database per customer, because that is what it is.
Access controls. Permissions are role-based, so a user sees only what their role allows. Sign-in issues a short-lived access token alongside a refresh token, so a captured token is useful only briefly. Passwords are stored as one-way bcrypt hashes and are never recoverable β SoraCore staff cannot read your password, and neither can we return it to you if it is lost.
What we do not currently do. We do not maintain field-level access logs recording each time a national identifier is viewed, and we do not encrypt individual database columns separately from the storage-level encryption described above. Both are on our roadmap; we would rather state the position plainly than imply protections that are not in place. Where a data breach occurs, we follow the notification duties set out in Section 7.
Your data is only shared within your own Organization's account, visible to users according to their role. SoraCore does not sell or share your personal data with third parties for marketing purposes. We use a limited set of service providers ("subprocessors") strictly to operate the platform:
International transfers. SoraCore is operated by Sagbrain Global Pte. Ltd., a company incorporated in Singapore, but the infrastructure holding your data is located in Japan. Data belonging to Organizations outside Japan β including Organizations in Singapore β is therefore transferred to and processed in Japan. As a Singapore organization transferring personal data abroad we are subject to the transfer-limitation requirement of the PDPA, and the processing carried out in Japan is additionally subject to Japan's Act on the Protection of Personal Information (APPI). Where a subprocessor processes data outside Japan, the recipient is bound by contract to a standard of protection comparable to that required under the PDPA. Where the law of your own country imposes additional conditions on transferring employee data abroad, your Organization, as controller, is responsible for satisfying them before entering that data into SoraCore.
Depending on your role, your location, and your Organization's policies, you can:
Because SoraCore is a workforce tool used on behalf of your Organization, requests to access, correct, or delete your data should first be directed to your Organization's HR or Admin team (the controller for your employment records); we will support them in responding. As our service is provided from Singapore, you may also contact the Personal Data Protection Commission (PDPC) of Singapore. If you are located elsewhere, you may in addition have the right to complain to your own national data-protection authority.
SoraCore is provided from Singapore by SAGBRAIN GLOBAL PTE. LTD., and our processing is governed by Singapore's Personal Data Protection Act (PDPA), regulated by the Personal Data Protection Commission (PDPC).
If your Organization operates outside Singapore, its own national data-protection, employment and payroll laws will usually continue to apply to it as controller β including any local rules on consent, employee notice, data localisation, or cross-border transfer. Your Organization is responsible for meeting those obligations. We will support reasonable requests needed for it to do so; contact us at support@soracore.net.
SoraCore is sold into Bangladesh by SAGBRAIN GLOBAL PTE. LTD. from Singapore. Bangladesh's Personal Data Protection Act, 2026 applies to organisations outside the country that handle the personal data of people in Bangladesh, so it reaches us as well as your Organization. We set out our position plainly rather than leaving it to be inferred:
ap-northeast-1), as described in Sections 4 and 5. We do not currently keep a copy inside Bangladesh. If a localisation requirement applies to a particular category of your data, your Organization should raise it with us before entering that data into SoraCore so we can tell you whether we are able to meet it.Enforcement provisions under the 2026 Act are being phased in, and guidance on several points β including the exact scope of any localisation requirement β is still developing. We keep this section under review and will update it as the position becomes settled rather than claiming a certainty that does not yet exist.
Employment-related data (attendance, leave, payroll, reports) is retained for as long as your account remains active and for a period afterward as required for payroll, tax, and labor-law record-keeping β including the employee and wage records that Singapore's Employment Act requires an employer to keep, and any longer period your Organization's own local law imposes. When an employee's account is deactivated, historical records are retained by the Organization rather than deleted outright, so reports, payslips, and audit trails remain accurate; national identifiers are securely deleted once the legal purpose for holding them ends.
SoraCore uses your browser's local storage (not third-party tracking cookies) to keep you signed in and to remember preferences such as language and theme. See our Cookie Policy for full details.
SoraCore is a workforce management platform intended for use by employees of a registered Organization and is not directed at, or intended for use by, children.
As required by the PDPA, we have appointed a Data Protection Officer (DPO). You can reach the DPO and our privacy team at support@soracore.net.
For employment-record requests, please also contact your Organization's HR or Admin team, who act as the controller. Our registered office is: SAGBRAIN GLOBAL PTE. LTD. (UEN 202611585N), 100D Pasir Panjang Road #05-03, MEISSA, Singapore 118520.
We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. Material changes will be communicated to Organization Admins, and the "Effective" date at the top of this page will be updated accordingly.