Privacy policy
Effective 10 September 2026 · Nusayla
This policy explains what personal data Nusayla collects when you use Orlabia Tech, why we collect it, who we share it with, and how you get it deleted.
1. Who we are
Nusayla (TODO — trade licence no.), Gulshan-2, is the data controller for personal data processed through Orlabia Tech. Contact us at mail.nusayla@gmail.com.
2. What we collect
- Account data — name, email address, mobile number, company name, and a password hash held by our authentication provider. We never store your password.
- Billing data — orders, invoices, transaction references and the payment rail used. Card and wallet credentials are handled by the payment provider and never reach our servers.
- Service data — the content you put into the services you buy: employee records and attendance in Employee Management, social order links in the SMM panel, message threads in Chat, and API request metadata in the developer platform.
- Technical data — IP address, browser user agent, request timestamps and error logs, kept for security and abuse prevention.
- Analytics data — see clause 6.
3. Why we process it
To provide and bill for the services you asked for (performance of a contract), to keep accounts secure and detect abuse (legitimate interest), to meet accounting and tax obligations (legal obligation), and to measure our advertising (consent, clause 6).
4. Who we share it with
Only the processors we need to run the service: our authentication provider, hosting and database provider, email and SMS delivery providers, payment providers, our live-chat provider, and — where you use Employee Management, Chat or the SMM panel — the platform on the other side of the integration you connected. We do not sell personal data and we do not share it for anyone else’s advertising.
5. Employee Management data
Where you use Employee Management, your organisation is the controller of your employees’ records and we are your processor. Biometric check-in uses a device passkey: the fingerprint never leaves the employee’s phone, and what we store is a public key and a counter. You are responsible for telling your employees what you collect and for having a lawful basis to do so.
6. Cookies and analytics
We use strictly necessary cookies to keep you signed in. Where enabled, we also use Google Analytics 4 and the Meta pixel to measure which ads bring signups and purchases. These set their own cookies and receive the page you visited and, on signup or purchase, that the event happened and its value. You can block them with your browser or ad blocker; the service works without them.
7. How long we keep it
Account and service data for as long as your account is open. When you delete your account we schedule the personal data for erasure and hold it for at most 30 days so a mistaken deletion can be reversed and any open payment dispute can be settled. Invoices and transaction records are kept for the period our tax law requires, even after erasure.
8. Your rights
You may ask for a copy of your data, correct it, have it erased, or object to processing based on legitimate interest. Email mail.nusayla@gmail.com and we will answer within 30 days. Account deletion is also available from Dashboard → Settings.
9. Security
Traffic is served over TLS. Passwords are hashed, API keys are stored only as a SHA-256 digest, and third-party access tokens are encrypted at rest. Access to production data is limited to staff who need it and every administrative action is written to an audit log.
10. Changes
We will update the effective date above when this policy changes and, for material changes, tell account holders by email before they take effect.
Questions about this document? Email mail.nusayla@gmail.com or see our contact page.