Home  /  Privacy policy

Privacy policy

How Quintechs Information Technology processes personal data within our Dynamics 365 HR and Payroll application. Effective date: 13 November 2025.

This Privacy Policy describes how Quintechs Information Technology (“we”, “us” or “our”) processes personal data within our specialised HR and payroll application (the “Application”), built on Microsoft Dynamics 365 Finance and Operations.

It applies to data processing activities related to our clients (employers) and their respective employees (data subjects) in the Middle East and Arab Gulf (GCC) region. We commit to handling all data in compliance with relevant local data protection legislation.

1. Our role in data processing

Due to the nature of our Application as a specialised business system, Quintechs Information Technology operates primarily as a data processor.

  • Data controller (your client): the organisation that purchases and uses the Application to manage its workforce. The data controller determines the purposes and means of processing personal data.
  • Data processor (our company): Quintechs Information Technology. We process personal data strictly on behalf of, and according to the documented instructions of, the data controller, as defined in our service agreements.
  • Data subject: the individual employee, applicant or contractor whose personal data is processed within the Application.

2. Personal data processed within the Application

The Application processes highly sensitive and comprehensive personal data necessary for all aspects of employee management and compensation in the GCC. This includes, but is not limited to:

  • Identification and contact data: full name, National ID / Iqama number, passport details, date of birth, nationality, religion, residential address, phone number and email address.
  • Employment and contract data: job title, department, grade / level, employee contract details, hire date, termination date and end-of-service data.
  • Financial and payroll data: salary, allowances, deductions, bank account details (IBAN), social insurance and security (GOSI / social security) details, and loans management data.
  • Time and attendance data: leave and tickets management records, overtime, absence and late management data.
  • Sensitive personal data: employee medical insurance details, health records (for sick leave and insurance), and details of dependants and family members (for benefits and visa processing).

3. Purpose and legal basis for processing

We process personal data exclusively to provide and maintain the functions of the Application. The data controller is responsible for establishing the legal basis for processing, which generally relies on:

  • Performance of an employment contract: processing data necessary to pay the employee, manage benefits and fulfil contractual terms.
  • Compliance with legal obligations: processing required to meet mandatory governmental and labour regulations in the GCC (for example GOSI submissions, residency requirements and labour law adherence).
  • Legitimate interest: processing necessary to ensure the security, integrity and operational health of the Dynamics 365 platform and our service delivery.
  • Consent: processing based on the employee’s specific, voluntary consent (for example for certain Employee Self-Service requests).

4. Data storage, security and Dynamics 365

  • Platform: our Application is built on the security framework of Microsoft Dynamics 365 Finance and Operations.
  • Data location: data is stored in Microsoft Azure data centres. The specific location of data residency (which may be a regional GCC cloud centre) is determined by our client (the data controller) during deployment. We support our clients in meeting all applicable local data residency and localisation requirements.
  • Security measures: we implement and maintain appropriate technical and organisational security measures, including role-based access controls within D365, data encryption and monitoring, to protect against unauthorised access, disclosure, alteration or destruction. We enforce strict access protocols for our support personnel, granting access only on a need-to-know basis for support and maintenance activities.

5. Data transfer, sharing and integrations

  • Internal access: personal data is accessed only by Quintechs Information Technology’s authorised technical and support staff, to perform essential services (including monitoring, bug fixes, support and enhancements) under strict confidentiality agreements.
  • Third-party sharing (controller instruction): we facilitate data sharing with external entities — such as local banks for salary transfers, government authorities for compliance, and insurance providers — only as instructed and authorised by the data controller through the Application’s integration features (REST APIs or business events).
  • Cross-border transfers: transfers of personal data across borders (outside the data controller’s jurisdiction) are managed in compliance with the relevant GCC data protection laws. This may require specific contractual safeguards, regulatory approvals or reliance on an adequacy mechanism to ensure the data retains a high level of protection.

6. Data subject rights and contact

As a data processor, Quintechs Information Technology is committed to supporting our clients in upholding the rights of data subjects (employees). These rights typically include the right of access, rectification (correction) and erasure (deletion), subject to legal retention limits for payroll data.

To exercise these rights, the data subject must direct their request to their employer (the data controller). The data controller will then officially instruct Quintechs Information Technology to take the necessary action within the Application, provided such action does not violate local labour or tax laws that mandate record keeping.

7. Data retention

Personal data is retained within the Application for the period required by the data controller, in accordance with the mandatory data retention periods stipulated by the local labour and statutory laws of the GCC countries where they operate. We will delete or anonymise the data upon formal instruction from the data controller once those legal periods expire.

8. Changes to this privacy policy

We may update this Privacy Policy periodically to reflect changes in our service offerings or in response to new regulatory developments in the GCC region. We will post the revised policy on this website and update the effective date at the top.

9. Contact information

If you have any questions or concerns about this Privacy Policy or our role as a data processor, please contact our data protection and compliance team: