MAKE UAE PAPERLESS

Every customisation inside your package is configured free of cost.

See the policy

SECURITY & COMPLIANCE

Your HR data is the most sensitive data you hold

Salaries, passports, medical records, disciplinary files. eHRMS treats HR data the way a bank treats account data — UAE-resident, encrypted, permission-scoped and audited.

  • UAE data residency
  • TLS 1.3 / AES-256
  • 51 permissions
  • UAE PDPL

THE CONTROLS

How your HR data is actually protected

Data residency

Hosted on UAE and GCC-approved cloud nodes with data kept in country. On-premise available where policy requires it.

Encryption

TLS 1.3 in transit, AES-256 at rest, with multi-factor authentication on sensitive roles.

Access control

51 discrete permissions in named roles, scoped per entity. Salary visibility is controlled separately from the rest of the profile.

Audit log

Tamper-evident activity logging with long-term retention — every action attributable.

UAE PDPL

Lawful-processing controls, consent logs, data-subject request handling and configurable retention.

Backups & continuity

Daily backups with tested restore, and 99.7% uptime.

SEPARATION OF DUTIES

Because HR data leaks internally more than externally

Most HR data incidents are not sophisticated attacks. They are a spreadsheet emailed to the wrong person, or somebody who could see every salary in the company because access was all-or-nothing.

  • Payroll, HR and finance functions held in separate permission sets
  • Salary visibility granted independently of profile access
  • Per-entity data scoping in multi-company groups
  • Super Admin and tenant administration reserved to the platform operator
  • Every view and change recorded against a named user
  • Approval chains with SLAs, so sign-off is evidenced rather than assumed

Security questionnaires and procurement due-diligence packs are something we complete regularly — ask and we will work through yours. Report a suspected vulnerability to info@globosoft.ae.

FAQ

Security questions

On UAE and GCC-approved cloud nodes, with data kept in country. On-premise deployment is available for organisations whose internal policy or regulator requires it.

The platform is built for compliance with the UAE Personal Data Protection Law: lawful processing controls, consent logging, data-subject request handling and configurable retention. Compliance is a shared responsibility — the platform provides the controls, and your configuration and policies determine how they are used.

Through 51 discrete permissions grouped by module, bundled into named roles. Users hold one or more roles per company in a multi-entity setup, and data is scoped per entity. The salary tab is permission-controlled separately, so line managers can see their team without seeing pay.

TLS 1.3 in transit and AES-256 at rest, with multi-factor authentication available on sensitive roles.

Yes — a tamper-evident activity log recording every action with long-term retention. It is what you produce when an inspector or internal auditor asks who changed what, and when.

It is yours. Exportable in standard formats at any time, with no exit ransom clauses.

Send us your security questionnaire

We complete procurement due-diligence packs regularly. Send yours over and we will work through it properly — or bring your security lead to the demo.

Prefer to talk? Call +971 4 874 1144 or email info@globosoft.ae