DOREP · by Montrai Labs

Privacy Policy

Version 2026-07-01 · Effective 1 July 2026
DOREP is a business-to-business business-management (ERP) platform covering accounting, invoicing, stock and purchasing, HR and payroll, client management and field sales. Employees ("Employees") and management staff ("Management") use DOREP on behalf of the business that employs them (the "Employer" / "Company"). This policy explains what data the DOREP application and website collect, how it is used, and the rights you have — including how to delete your account.

1. Who we are

DOREP is operated by Montrai Labs ("we", "us"). For most data described here, your Employer is the data controller (they decide why your data is processed) and we act as a data processor providing the software. For account, billing and security data we act as controller. Contact: privacy@dorep.app.

2. Information we collect

CategoryExamplesWhy
Account & identityName, username, phone number, email, password (hashed), role, employer/company, profile photoCreate and secure your account; operate the service
Location dataGPS coordinates during check-in and while sharing location during working hours; visit/order locationsVerify field visits, show reps on the management map, plan routes. Collected only while you are checked in / sharing.
Facial / biometric dataA selfie captured at sign-up and at check-in, processed for face-presence verificationConfirm the right person is checking in and reduce fraud. Face detection runs on your device where possible.
Business recordsClients/pharmacies, visits, orders, returns, samples, expenses, payments, plans, tasks, messagesDeliver the core CRM/ERP functionality your Employer uses
KYC documents (Management sign-up)Company registration/incorporation documents, IDsVerify a legitimate business before activating an account
Device & technicalDevice push token, app version, platform, IP address, diagnostic logsDeliver notifications, security, and troubleshooting

3. How we use your information

We do not sell your personal data, and we do not use it for advertising.

4. Location tracking — important

DOREP collects precise location only while you are checked in / actively sharing location, to let your Employer's management see field activity in real time. You control check-in/out from the app, and you may deny or revoke the location permission in your device settings at any time (some features will then not work). Location is not collected in the background when you are checked out.

5. Biometric / facial data

The check-in and sign-up selfie is used to confirm a live person is present ("face detection"). Where the platform supports it, this processing happens on your device. Selfies associated with an account are deleted when the account is deleted (see §9). By using facial check-in you consent to this processing; if you do not consent, contact your Employer for an alternative.

6. Legal bases for processing

7. Sharing & disclosure

Your data is visible to your Employer's authorised Management and administrators, and to us as the software provider. We use a limited set of sub-processors to run the service (secure hosting, map tiles, and push-notification delivery by Apple and Google). We may disclose data if required by law. We do not share your personal data with third parties for their own purposes.

8. Data retention

We keep business records for as long as your Employer's account is active and as required by law. Raw GPS location history is retained for a limited operational period and then pruned. When an account is deleted, personal identifiers are removed as described below.

9. Your rights & deleting your account

You can request deletion of your account directly in the app — open More → Account → Delete my account. Because DOREP is an employer-managed workforce tool, a deletion request from an Employee is reviewed by their Management, and a request from Management is reviewed by the platform administrator, before it is finalised. Once approved, your personal identifiers (name, phone, email, photo, address, login) and your check-in selfies are removed/anonymised and your sign-in credentials and device tokens are deleted. Business transaction records created for your Employer may be retained in anonymised form where the Employer or the law requires it.

You may also request access to, correction of, or a copy of your data by emailing privacy@dorep.app or contacting your Employer.

10. Security

Passwords are stored hashed, traffic is encrypted in transit (HTTPS/TLS), access is role-restricted, and we keep encrypted backups. No system is perfectly secure, but we take reasonable measures to protect your data.

11. Children

DOREP is a workplace tool and is not directed to, or intended for, anyone under 18. We do not knowingly collect data from children.

12. International use

DOREP is operated primarily for use in Iraq. By using the service you understand your data is processed on servers used to deliver the platform.

13. Changes to this policy

We may update this policy; we will change the version and effective date above and, for material changes, ask you to re-accept in the app.

14. Contact

Questions or requests: privacy@dorep.app. You may also reach us via the contact page.