Privacy Policy
Otjetu HR is HR and payroll software sold to employers. Most of the personal information in the system is about your employer's staff, and it was put there by your employer — not by us. We hold it on their behalf, we do not sell it, and we do not use it to advertise to anyone.
1. Who we are
Otjetu HR is operated by Octovia Nexus (“Otjetu”, “we”, “us”), registration number [registration number], of Windhoek, Namibia.
You can reach us at [email protected] for any question about this policy or about personal information we hold.
2. Whose data this is, and who decides what happens to it
This distinction determines who you should approach about your information, so it is worth being precise:
| Whose information | Who decides how it is used | Our role |
|---|---|---|
| Employee records — the staff of a business that uses Otjetu HR | The employer. They chose to use Otjetu, they decide what to enter, and they decide who on their team may see it. | We store and process it on the employer's instructions. We do not decide what goes in, and we do not use it for our own purposes. |
| Account holders — the person who signs a business up, and billing contacts | Us. We need this to provide and bill for the service. | We decide how it is used, within this policy. |
| Website visitors — anyone browsing otjetu-hr.com | Us. | We collect very little — see section 7. |
If you use Otjetu HR because your employer gave you a login, your employer controls your record. To correct your details, ask a question about why something is held, or request deletion, speak to your employer's HR or payroll contact first. We cannot change or release an employer's records on an employee's instruction alone — doing so would let anyone alter someone else's employment file. Where we can help, we will, through your employer.
3. What information we hold
Information employers enter about their staff
The employer chooses what to complete. The system can hold:
- Identity and contact — name, date of birth, gender, nationality, national ID or passport number, address, phone, email, photo.
- Employment — job title, department, work location, manager, start date, employment type, working days per week, employment status and its history, termination date and reason.
- Pay and financial — salary or hourly rate, allowances, deductions, overtime, expense claims, loans, bonuses, payslips, and bank account details used to pay wages.
- Tax and statutory — tax reference number, Social Security (SSC) number, work permit details and expiry.
- Leave and attendance — leave balances, requests and approvals, timesheets, clock-in records.
- Documents — anything the employer uploads to an employee's file, such as contracts, certificates or letters.
Two fields deserve specific mention because they are more sensitive than the rest:
- Racial designation and disability status. Otjetu collects these because Namibian employers with 25 or more staff must report on workforce composition under the Affirmative Action (Employment) Act 29 of 1998. They are used to produce that statutory return and the related workforce reports — nothing else. They are optional fields; an employer who does not need them can leave them blank.
We do not collect health records, biometric data, or criminal history as structured fields. If an employer uploads such material as a document, it sits in their file store under their control and their responsibility.
Information about account holders
- Name, work email address and password (stored only as a secure hash — we never see or store your actual password).
- Company name, industry, staff-count range, and the plan chosen.
- Business registration and tax identifiers, if entered in company settings.
- Two-factor authentication settings, if enabled.
- Billing records — invoices, amounts, payment status. We do not store card details; billing is by bank transfer, so no card is ever held.
Information collected automatically
- Audit log — the application records who changed what and when (for example a salary change), because employers need that accountability trail. This is visible to the employer, not used by us for anything else.
- Security and operational logs — IP address and timestamps on sign-in attempts and errors, used to detect abuse and diagnose faults.
- We run no advertising trackers and no third-party analytics. There is no Google Analytics, no advertising pixel and no behavioural profiling on this service.
4. Why we hold it
| Purpose | What this covers |
|---|---|
| Providing the service | Running payroll, calculating PAYE and Social Security, tracking leave, producing payslips, letters and reports — the things the employer signed up for. |
| Meeting Namibian legal duties | Employers must keep employment records under the Labour Act 11 of 2007, deduct and report PAYE under the Income Tax Act, contribute under the Social Security Act 34 of 1994, and report workforce composition under the Affirmative Action Act. The system exists largely to help them do this. |
| Account administration | Signing you in, verifying your email, sending service notices, issuing invoices and payment reminders. |
| Security and abuse prevention | Detecting unusual sign-in activity, blocking automated signup abuse, and keeping tenants isolated from one another. |
| Support | Investigating a fault or question you raise with us. |
| Improving the product | Understanding which features are used and where errors occur, using operational data. We do not mine employee records for this. |
We never sell personal information, and we do not share it with advertisers or data brokers.
5. Where your data is stored
Otjetu HR runs on managed cloud infrastructure provided by established commercial hosting and network providers, in secure data centres operated to recognised international security standards.
Like almost all cloud software, that infrastructure and the networks carrying your traffic may be located outside Namibia. We select providers that operate under strong data-protection regimes and bind each of them, by contract, to protect your information and to use it only to provide their service to us.
If your organisation is subject to a requirement that data must remain within Namibia, please raise this with us at [email protected] before signing up so we can tell you whether we can meet it.
6. Who else can see it
We use a small number of service providers to run Otjetu HR. Each may handle personal information only as needed to perform their function, and may not use it for their own purposes:
| Type of provider | What they do |
|---|---|
| Cloud hosting | Runs the servers and database that store your data. |
| Network & security | DNS, TLS encryption, and protection against attacks and abusive traffic. |
| Email delivery | Delivers the emails the platform sends — payslip notifications, invites, invoices, password resets. Sees the recipient address and the message content. |
| Accounting integration (optional) | Only active if an employer connects Xero themselves, and only payroll journal totals are sent — not individual employee records. |
We will name the specific providers we use on request — email [email protected]. Customers with procurement or audit requirements normally ask for this, and we are happy to provide it.
Beyond these, we disclose personal information only where we are legally required to — for example under a court order or a lawful demand from a Namibian authority. If that happens and we are permitted to tell the affected employer, we will.
7. Cookies
Otjetu HR uses only the cookies it needs to sign you in and keep the session secure. There are no advertising, marketing or analytics cookies, which is why you are not asked to accept a cookie banner.
| Cookie | Purpose | Notes |
|---|---|---|
access_token | Keeps you signed in. | Not readable by scripts; sent only over HTTPS. |
refresh_token | Renews your session so you are not signed out mid-task. | Not readable by scripts; sent only over HTTPS. |
csrf_access_token | Protects against forged requests from other websites. | Readable by the app by design — that is how the protection works. Contains no personal information. |
Clearing these cookies signs you out. The application cannot function without them.
8. How we protect it
- Separation between businesses. Each business's data is isolated at the database level, so one customer's queries cannot reach another's records even if the application were tricked into trying.
- Encryption in transit. All traffic uses HTTPS. The site is served over HTTPS only, and browsers are instructed to refuse insecure connections.
- Password protection. Passwords are stored as one-way hashes. We cannot read them, and nor can anyone who obtained the database.
- Optional two-factor authentication for account holders.
- Role-based access. Employers control which of their staff can see payroll, personal details or reports.
- Audit trail. Changes to records are logged with who made them and when.
- Restricted internal access. Only personnel who need it to operate or support the service can reach production systems.
No system is perfectly secure. If a breach affects your data and creates a real risk to the people involved, we will notify the affected employer without undue delay, describe what happened, and tell you what we are doing about it.
9. How long we keep it
- While the account is active, we keep data for as long as the employer needs it. Employment records commonly must be kept for years after someone leaves — that is the employer's call, and their legal duty.
- If an account closes, the employer may ask us to delete their workspace. Deletion removes the business and its employee records permanently and cannot be undone. Ask us before you close if you need an export first.
- Backups may retain copies for a limited period after deletion before being overwritten in the ordinary cycle.
- Invoices and payment records are kept as long as tax and company law requires, even after an account closes.
10. Your rights
Whoever you are, you can ask us to:
- Tell you what we hold about you and why.
- Correct anything inaccurate.
- Delete information, where we are not required to keep it.
- Provide a copy of it in a usable format.
- Stop sending non-essential email. Service messages such as payslip notifications and invoices cannot be switched off while an account is active, because they are part of the service.
Write to [email protected]. We aim to respond within 30 days. We may need to verify who you are first — we are not going to hand over an employment record to someone who cannot show it is theirs.
As noted in section 2, if the request concerns an employee record, we will normally direct you to your employer, who controls it. We will assist them in responding.
11. The legal position in Namibia
We would rather be straight with you than imply protections that do not exist.
As at the date of this policy, Namibia has no comprehensive data protection statute in force. A Data Protection Bill has been in draft since 2022 but has not been enacted. The protections that do apply are:
- Article 13 of the Namibian Constitution, which protects privacy against unreasonable interference.
- The Electronic Transactions Act 4 of 2019, which governs electronic dealings and requires you to have opted in before receiving unsolicited commercial messages.
- Sector duties of confidentiality, including those attaching to employment and tax records.
We have written this policy, and built the platform, to the standard the draft Bill and comparable laws elsewhere would require — rather than to the minimum currently enforceable. If Namibia enacts a data protection law, we will update this policy and our practices to comply.
12. Changes to this policy
If we change this policy in a way that materially affects how we handle personal information, we will notify account holders by email or in the application before it takes effect. The date at the top always shows the current version.
13. Contact us
Questions, requests or complaints about privacy:
- Email: [email protected]
- Post: Octovia Nexus, Windhoek, Namibia
If you are not satisfied with our response, you may pursue the matter through the Namibian courts under Article 13 of the Constitution, or through any supervisory authority established once data protection legislation comes into force.