Privacy Policy

Version 2026.07.28 · Effective 2026-07-28 · Last updated 2026-07-28

Faciro ("we", "us") provides workforce software for small and medium businesses, with a focus on Mauritius SMEs. You can manage leave, optionally connect a compatible attendance clock, track working hours, absences and overtime, and prepare a payroll summary. Faciro does not store biometric fingerprint or face templates. This policy explains how we process personal data when you use faciro.com and related services.

We aim to process personal data in line with the Mauritius Data Protection Act 2017 (DPA 2017) and, where relevant, other applicable privacy laws. This policy is for information only, is not legal advice, and has not been reviewed by counsel for your specific situation. You should obtain independent legal advice where needed.

Who is responsible for your data?

  • Your employer (the company workspace) is the data controller for employee identity and HR fields they collect, leave, balances, approvals, attendance punches shown in Faciro, working hours, absences, overtime, work-from-home records, and payroll-preparation fields (including optional salary helper amounts).
  • Faciro acts as a data processorfor that workspace data, on the employer's instructions. See our Data Processing Addendum.
  • For Faciro account administration, billing, support, website marketing leads, and platform security data, Faciro is the data controller.

Mauritius organisations that process staff personal data may also need to register with the Data Protection Office. Employers remain responsible for their own DPA duties and must inform employees that their data is processed in Faciro. See the Employee Privacy Notice for a plain-language summary employees can read.

Data we collect

  • Identity and contact: name, email, phone number; optional national ID / NIC number and date of birth when collected by the employer or entered in a staff profile
  • Account: password (stored hashed), role, company association
  • Leave records: dates, type, status, reasons, manager notes, balances
  • Attendance punches: clock-in/out times and device person IDs when your employer connects Hikvision / Hik-Connect or imports a CSV (no biometric templates)
  • Work-from-home declarations and related manager approvals when enabled
  • Derived workforce figures: working hours, absences, overtime, and payroll-preparation summaries built from attendance and leave day rows
  • Payroll-helper fields (optional Mauritius sheet helper): amounts such as basic salary, transport, advances, and related period settings — used to prepare information for payroll teams, not to issue payslips
  • Sick leave attachments you upload (may include health-related information — see below)
  • Marketing leads: name, contact details, and message content when you request a quotation or demo on the public website
  • Technical: session cookie, CSRF cookie, server and security logs; optional Google Analytics when configured and you consent (see Cookie Policy)

Special / sensitive data

Sick-leave notes or medical attachments can be health-related personal data under DPA 2017. We process them only to provide leave features requested by the employer, with role-based access (typically employee, their manager, and company admin). Employers should only ask for what they need and should set internal rules for medical documents.

Why we process data

  • To provide leave request, approval, balance, and history services
  • To show attendance, working hours, absences, overtime, and related day status (including work-from-home where enabled)
  • To prepare payroll summary / Mauritius payroll-helper information for HR, admin, or accountants (Faciro does not process payroll or issue payslips)
  • To send notifications (email) about leave and related workflows
  • To respond to quotation and demo enquiries
  • To maintain security and prevent fraud
  • To comply with legal obligations

Legal basis (DPA 2017)

Depending on the processing, we rely on:

  • Performance of a contract (providing the Faciro service to the workspace)
  • Legitimate interests of employers in managing workforce leave, attendance-derived hours, and payroll-preparation summaries (balanced against staff rights)
  • Consent where required (for example creating a Faciro account, or optional analytics cookies)
  • Legal obligations where applicable

Subprocessors and transfers

Faciro uses cloud providers that may process data outside Mauritius. The current production list is published on our Subprocessors page (including database hosting, application hosting, transactional email, and file storage for attachments when enabled). Optional analytics is described there as well.

When personal data is transferred outside Mauritius, we use providers with appropriate security measures and contractual safeguards, and we describe these transfers in our Data Protection Office filings where required. Controllers should assess transfer risk for their own compliance file.

Retention

How long we keep categories of data is summarised in our Data Retention Summary. In short: workspace operational data is retained while the employer keeps an active workspace (and for a reasonable period after closure for backup/security, or earlier on a written deletion request subject to legal holds); account and billing records as needed for contract, tax, and disputes; password reset tokens expire after a short period; logs are kept for a limited security window.

Your rights

Under DPA 2017 (and other laws that may apply), individuals may have rights to access, correct, erase, or object to certain processing of their personal data, subject to legal exceptions.

Employees should contact their employer (the controller) first for leave, attendance, and HR records in the workspace. You may also contact Faciro at info@faciro.com. You may lodge a complaint with the Mauritius Data Protection Office where applicable.

Security

We use encryption in transit (HTTPS), hashed passwords, access controls, CSRF protection for authenticated browser requests, and company-scoped data isolation. No system is perfectly secure; report concerns or suspected breaches to info@faciro.com.

Personal data breaches

If Faciro becomes aware of a personal data breach affecting workspace data we process for a customer, we will notify that customer without undue delay so they can meet their own notification duties. Platform security and privacy requests: info@faciro.com.

Customers must inform employees

Workspace admins must tell staff that leave, attendance, hours, and related records may be processed in Faciro, and must point them to appropriate notices (including the Employee Privacy Notice) as part of their own controller obligations.

Cookies

See our Cookie Policy.

Contact

General: info@faciro.com

Privacy requests: info@faciro.com

Data Protection Office (Mauritius): dataprotection.govmu.org