
This Policy explains how Stabee collects, uses, shares, and protects Personal Data, whether you are a visitor to our website, a Customer subscribed to the Platform, or an employee of a company that uses Stabee, and what rights you have over your data.
Last updated: 11 October 2026
1. Who we are and the scope of this Policy
In this Policy, “Stabee” or “we” refers to the operator of the Stabee platform.
This Policy applies to the Stabee website; to the “Platform,” meaning Stabee’s cloud HR management service, including the web-based company portal (company.stabee.co) and the employee and manager mobile apps; and to our related communications and support services. It does not apply to external websites and services that we may link to, each of which has its own policy.
This Policy forms an integral part of the Terms of Service.
2. Definitions
- “Customer”: the company or organization that subscribes to the Platform to manage its employees’ affairs.
- “User”: any person to whom the Customer grants an account on the Platform, such as the Account Administrator, HR managers, managers, and employees.
- “Account Administrator”: the Customer’s User who has permission to manage its account and subscription.
- “Customer Data”: everything the Customer or its Users enter into or upload to the Platform, including employee and job applicant data.
- “Personal Data”: any data that identifies a natural person or makes it possible to identify them, directly or indirectly.
- “Processing”: any operation performed on Personal Data, such as collecting, recording, storing, using, disclosing, or deleting it.
3. Our role in processing data
- Customer Data, including employee and job applicant data: the Customer is its controller, as it decides what data to enter and for what purpose, and we are its processor: we process it on the Customer’s behalf, in accordance with its instructions, and solely for the purpose of providing the service.
- Website visitor data, and the Customer’s account, communication, and billing data: we are the controller of this data and process it in accordance with this Policy.
- If you are an employee of one of our Customers, your employer is responsible for your data on the Platform and for informing you of the purposes for which it is used, so please direct your questions and requests about it to your employer first.
4. Data we collect from website visitors
- When you fill in the “Contact us” form or request a demo: your name, email address, company name, phone number and its country (if you enter them), the text of your message, and the page from which the request was sent.
- To show prices in your country’s currency, we infer your country from your browser’s language or from the approximate location of your internet connection, without determining your precise location.
- Technical data that accompanies every request, such as IP address, browser type, and request time, which we use to protect the website and its forms from abuse and attacks.
- Aggregated visit statistics that we obtain from Cloudflare Web Analytics, a privacy-friendly service: it does not use cookies, does not track visitors across websites, and shows us only aggregate figures, such as the number of visits, the most viewed pages, and traffic sources.
5. Customer account and subscription data
- When a company account is created: the company’s name and country; the Account Administrator’s name, email address, and phone number; and the password.
- A record of acceptance of the Terms of Service and the Privacy Policy: the time of acceptance, the version of the Terms, the IP address, the browser type, and the country we inferred, so that we can verify that it matches the company country selected.
- Subscription and billing data: the Plan, billing cycle, invoices, payments, and refunds.
- Payment data: payment is made by Visa or Mastercard card, or via Apple Pay, on the secure payment page of the payment provider Paymob, not on Stabee, so we never see the full card number or its security code. To renew the subscription, we keep a reference token issued by Paymob, stored in encrypted form, together with the card type, its last four digits, and its expiry date.
- Correspondence you exchange with us by email or through support channels.
Some of this data is required to create the account and provide the service, which cannot be provided without it.
6. Customer Data within the Platform
The Customer and its Users enter or upload this data as the Customer decides and depending on the modules it uses. It may include:
- Identity and contact data: name, photo, date of birth, gender, nationality, marital status, national ID or residence permit number, visa number, phone numbers, email address, and address.
- Employment data: employee number, branch, department, direct manager, hire date, employment status, terms of employment, and academic qualifications.
- Financial data: salary, allowances, and deductions; payroll runs and payslips; and bank account number (IBAN).
- Attendance data: check-in and check-out times, the device’s location when attendance is recorded and its distance from the branch, IP address, and a selfie if the attendance mode chosen by the Customer requires one.
- Requests and approvals: leave, short leave, salary advances, and other requests, with their attachments and approval stages.
- Documents: copies of IDs, contracts, letters, and other files the Customer uploads.
- Family member data and emergency contacts.
- Health data, such as chronic conditions, if the Customer chooses to record it; this is sensitive data.
- Recruitment data: job openings, applicants’ data and CVs, their candidacy stages, and notes about them.
- Announcements and messages that the Customer publishes to its employees within the Platform.
7. Usage and device data
- Sign-in and session logs: sign-in time, IP address, browser or device type, and failed sign-in attempts.
- Audit log: records of significant actions, such as changes to data and permissions and approvals of requests and payroll, showing who performed them, when, and from which IP address.
- Notification data: your device’s notification token, its operating system type, and the app language, to deliver notifications to the two mobile apps.
8. Mobile app permissions
- Location: the app reads your device’s location when you open the attendance screen to show you the map and your distance from the branch, and sends it to us only when you check in or check out. The app does not track your location in the background.
- Camera: to take the attendance photo when the Customer requires it. We do not use this photo for facial recognition or any biometric processing.
- Files: to attach documents that you choose yourself to your requests.
- Notifications: to inform you of updates on your requests, your attendance, and your company’s announcements.
You can revoke any permission in your device settings; note, however, that revoking the location or camera permission may prevent you from recording attendance in the app if the Customer requires them.
9. How we use data
- Providing and operating the Platform in accordance with the Customer’s settings and instructions, including calculating attendance, leave, and payroll and preparing reports. The Platform automatically applies the rules that the Customer configures, such as calculating lateness and leave balances, and the Customer remains the decision-maker on matters concerning its employees.
- Creating accounts, verifying Users’ identities when they sign in, and protecting the Platform against fraud, abuse, and intrusion.
- Managing subscriptions and billing, collecting fees, and meeting accounting and tax obligations.
- Responding to your inquiries and demo requests, and providing technical support.
- Sending service messages, such as verification codes, security alerts, subscription and billing notices, and notices of changes to this Policy or to the Terms of Service.
- Improving the Platform using aggregated statistics that do not identify anyone.
- Complying with laws, court orders, and lawful requests from competent authorities, and protecting our rights and those of our Users.
We do not sell or rent Personal Data, and we do not use Customer Data for advertising or marketing or to build profiles of the Customer’s employees. We send you marketing messages only with your consent or where the law permits it, and you can stop them at any time.
10. Legal bases for processing
We process the data for which we are the controller on one or more of the following bases, depending on the applicable law:
- Performance of the contract with the Customer, or taking steps at its request before entering into a contract.
- Compliance with a legal obligation, such as retaining invoices and accounting records.
- A legitimate interest that does not override your rights, such as protecting the Platform from abuse and improving our services.
- Your consent, where the law requires it, which you may withdraw at any time without affecting the lawfulness of processing carried out before the withdrawal.
As for Customer Data, the Customer, as its controller, determines the legal basis for processing it and is responsible for ensuring that such a basis exists, including by obtaining its employees’ consent where the law requires it, particularly for sensitive data.
11. Cookies and browser storage
- Cookies are small text files that a browser stores; data saved in the local storage of a browser or an app is similar.
- Our website does not set its own cookies, and the analytics service we use does not rely on them. Our network provider, Cloudflare, may set a necessary technical cookie when needed to distinguish harmful automated traffic.
- In the company portal and the mobile apps, we use only the storage that is necessary for the Platform to work: a secure cookie that keeps and renews your sign-in session, the current User’s basic data for display, interface preferences such as language, and sign-in tokens in the device’s secure storage.
- We do not use advertising cookies or tracking tools, and the analytics service does not run inside the company portal.
- You can delete or block cookies in your browser settings, but blocking the necessary ones will prevent you from signing in to the Platform.
12. Who we share data with
We disclose Personal Data only in the following cases, and only to the extent necessary:
- Within the Customer’s account: the Customer’s Users can see data according to the roles and permissions that the Customer sets.
- The service providers we use to operate the Platform, listed in the next section, under contractual obligations to protect the data and not to use it for any purpose other than the one specified.
- Government and judicial authorities, where the law requires us to or a binding legal order is issued, in which case we notify the Customer of the request where the law permits.
- The entity to which the Platform is transferred in the event of a merger, acquisition, or transfer of business, provided that the data remains protected in accordance with this Policy, and with notice to Customers.
- Any other party, with your consent or at the Customer’s request.
13. Service providers (subprocessors)
We currently use the following providers, each with a specific role:
- Hetzner Online: hosting of servers, databases, and files in data centers within the European Union (Germany and Finland).
- Cloudflare: protecting the website and the Platform against attacks, encrypting connections and speeding up their delivery over its global network, and aggregated website traffic statistics.
- Paymob: processing card and Apple Pay payments and storing cards for subscription renewal; it receives the transaction amount and the Account Administrator’s name, email address, and phone number.
- Google Firebase Cloud Messaging: delivering notifications to the two mobile apps; it receives the device’s notification token and the text of the notification.
- Google Maps, and the address service of the device’s operating system: displaying the map and the city name within the two mobile apps.
- Anthropic (Claude): powering the “Smart Assistant” and automated analyses within the Platform, such as employee behavior analysis, request analysis, and matching candidates to jobs. It receives the User’s question, aggregated indicators about the record being analyzed, and the candidate’s CV when matching is requested, but not ID numbers, contact details, or bank details. Anthropic does not use this data to train its models.
- Email: we send Platform emails from our own mail server, without using an external email provider.
We update this list whenever it changes, and we notify Customers of any material change to it. The list does not include services that the Customer connects to the Platform using its own key, as the Customer contracts with them directly.
14. Where data is stored and cross-border transfers
- Platform data is stored on servers in data centers within the European Union, which is usually outside the Customer’s country. Connections pass through Cloudflare’s global network, and some of the service providers listed above may process data in other countries owing to the nature of their services.
- We protect transferred data with safeguards that include contractual obligations with service providers to protect the data and keep it confidential, encryption of connections in transit, access controls, and encryption of the most sensitive fields in the database. Our hosting provider is also subject to the EU General Data Protection Regulation (GDPR).
- The Customer, as the controller of its employees’ data, is responsible for verifying that transferring that data outside its country is permitted under that country’s law, and for meeting any requirements that the law may impose, such as notifying employees or obtaining their consent, assessing the risks of the transfer, or obtaining authorization from the competent authority, as the case may be.
- If the Customer is subject to sector-specific regulations that require data to be hosted within its country, it must verify that the Platform is suitable for this before subscribing.
15. Data protection
We apply technical and organizational measures appropriate to the nature and sensitivity of the data, including:
- Isolating each company’s data from that of other companies, so that one company’s Users cannot access another company’s data.
- Role-based permissions set by the Customer. By default, access to ID numbers, visa numbers, and health data is limited to the Account Administrator and the HR manager, unless the Customer grants this permission to other roles.
- Encryption of all connections to the Platform using the TLS protocol.
- Storing passwords using the Argon2id hashing algorithm, so that they are never stored in readable form.
- Encryption of ID numbers, visa numbers, health data, bank account numbers, and payment card tokens within the database.
- Storing uploaded files in a private space that is not publicly accessible, and downloading them through temporary links after verifying the requester’s permission.
- Limiting repeated failed sign-in attempts, and requiring two-step verification for Stabee team accounts.
- An audit log that records sensitive actions and who performed them.
- Daily backups of databases and files.
However, no system connected to the internet is entirely free of risk; we therefore recommend that Users choose strong passwords and not share them, and that Customers immediately deactivate the account of anyone who leaves the organization.
16. Stabee team access to Customer Data
- Our team accesses Customer Data only to the extent necessary to provide support, to operate and protect the Platform, or to comply with a legal obligation.
- Access to a Customer’s account for support purposes is limited to authorized team members, for no more than 30 minutes per session, with the reason for access recorded and the User whose account was accessed notified.
- During these sessions, the support team cannot change the subscription, payment details, or passwords, or export payroll data, and every change made during a session is recorded in the audit log under the team member’s name.
17. Data retention and deletion
We retain data for as long as it is needed for the purpose for which it was collected, or for as long as the law requires us to retain it, and then delete it. The following periods apply:
- Customer Data: for the duration of the subscription, and the Customer may edit or delete it within the Platform at any time. Deleting an employee record archives it and allows it to be restored; if the Customer wishes to permanently erase a specific person’s data before the account is closed, we will help it do so when it contacts us.
- After the trial period or subscription ends without renewal: the account is suspended and its data remains stored, so that the Customer can resume its subscription or request a copy of its data.
- When the account is closed, at the Customer’s request or under the Terms of Service: we notify the Account Administrator, User access stops, and a 30-day period begins, unless otherwise agreed, during which the data remains stored and a copy of it can be requested; all of the Customer’s data and files are then permanently deleted from our systems.
- Invoices and payment records: retained for 10 years from the date the account is deleted, for accounting and legal purposes, and then deleted automatically. They contain the company’s data, not its employees’ data.
- Audit log: each entry is retained for 3 years from the date it is recorded and then deleted automatically, and it remains until then even if the account is deleted.
- Sign-in attempt logs and expired sessions: deleted after 90 days, as are in-Platform notifications 90 days after they are sent.
- Job applicants’ CVs: deleted automatically 24 months after they are uploaded.
- Uploaded files not linked to any record: deleted automatically after 7 days.
- Sign-up requests whose email address has not been verified: deleted after 7 days. After verification, we keep the record of acceptance of the Terms for as long as the account exists.
- “Contact us” form messages: we keep them for as long as they are needed to follow up on your request, and we delete them whenever you ask us to.
- Backups: replaced automatically in their regular cycle, so that deleted data disappears from them within a limited period.
After an account is deleted, we keep a brief record proving that it existed and when it ended, such as the company name and the dates on which the account was created and deleted.
18. Your rights
Depending on the law that applies to you, your rights may include:
- The right to know how your data is collected and used and the legal basis for doing so, which this Policy explains.
- The right to access your data and obtain a copy of it.
- The right to correct your inaccurate or incomplete data, and to update it.
- The right to have your data deleted when it is no longer needed or when the consent on which it is based is withdrawn, unless the law requires us to retain it.
- The right to data portability, by receiving your data in a structured, commonly used, and machine-readable format.
- The right to object to processing or to request its restriction in the cases provided for by law.
- The right to withdraw your consent at any time, where consent is the basis for processing.
- The right to lodge a complaint with the data protection authority in your country.
19. How to exercise your rights
- Visitors and Customers: email us at [email protected]. We will ask for what is needed to verify your identity before acting on the request, and we will respond within 30 days of receiving the complete request, unless the applicable law sets a shorter period.
- Employees and job applicants: please direct your requests to your employer, as the controller of your data. If we receive your request directly, we will refer it to your employer and help it fulfill the request.
- The Customer can fulfill many of these requests itself: editing records, and exporting employee and attendance data, payslips, and reports in CSV format. It may also ask us for a complete copy of its data and files in a compressed file; we send the download link to the Account Administrator, and it remains valid for 7 days.
- We fulfill these requests free of charge, and we may refuse or limit a request if it is repeated without justification, affects the rights of others, or conflicts with a legal obligation, in which case we will explain the reason to you.
20. Applicable data protection laws
We comply with the personal data protection laws that apply to processing in the countries where we serve our Customers, including:
- Kingdom of Saudi Arabia: the Personal Data Protection Law (PDPL) issued by Royal Decree No. M/19 dated 9/2/1443 AH, as amended, and its regulations.
- United Arab Emirates: Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.
- Sultanate of Oman: the Personal Data Protection Law promulgated by Royal Decree No. 6/2022, as amended, and its Executive Regulations.
- State of Qatar: Law No. 13 of 2016 on the Protection of Personal Data Privacy.
- Kingdom of Bahrain: Law No. 30 of 2018 promulgating the Personal Data Protection Law.
- State of Kuwait: the Data Privacy Protection Regulation issued by the Communication and Information Technology Regulatory Authority under Resolution No. 26 of 2024.
- Arab Republic of Egypt: the Personal Data Protection Law promulgated by Law No. 151 of 2020, and its Executive Regulations.
Rights, deadlines, and exemptions vary from one law to another, and each processing operation is governed by the law that applies to it.
21. Data breach notification
- If we become aware of a security breach affecting Customer Data, we will notify the Customer without undue delay and provide it with the information available to us to help it meet its obligations to the competent authorities and the affected individuals.
- If the breach affects data for which we are the controller, we will notify the competent authorities and the affected individuals as required by the applicable law.
22. Children
The Platform is a service intended for businesses and is not directed at anyone under 18 years of age, and we do not knowingly collect children’s data directly from them. The Customer may enter data about its employees’ family members, including children, for HR purposes, in which case it is responsible for the legal basis for doing so and for limiting the data to what is necessary. If you become aware that a child has provided us with their data directly, please contact us so that we can delete it.
23. Changes to this Policy
- We may update this Policy to keep pace with the development of the Platform or changes in the law, and we publish the updated version on this page with the date of the last update.
- If a change is material, we will notify Customers’ Account Administrators by email or within the Platform a reasonable time before it takes effect.
24. Contact us
For any question about this page, email us at [email protected] or reach us through our contact page.






