EmployDB by DAXTOP — Privacy Policy
Last updated: September 14, 2026
This policy explains what personal data EmployDB processes, why it processes it, who can see it, and the controls you have. It is written to be read — if anything is unclear, ask us at the address at the bottom and we will answer in plain language.
Who we are
EmployDB (employdb.com) is an HR management platform and verified employment network operated by DAXTOP. Accounts are shared across DAXTOP services (daxtop.com, daxtop.app, employdb.com).
Data we process
- Account data — name, email address, and authentication data for your DAXTOP account.
- Employment records — factual employment data issued by employers: dates, positions, promotions, training, certifications, awards, and employment status.
- Private HR records — data your employer manages about you (e.g. salary history, contracts, leave). These are visible to your employer's authorized HR staff and to you, and are never shared through the verification network.
- Audit and access logs — records of who created, changed, or viewed data.
How data enters EmployDB
When a DAXTOP product owner explicitly enables HR management, EmployDB receives the minimum necessary data about the users registered under that specific product (name, email, and team role). No other data from other products or users is shared. The owner can revoke this at any time, which stops all further syncing.
Employee control
- You can always see every record about yourself, including private HR records.
- Recruiters can access your verified profile only after your explicit, scoped approval, which expires automatically and is revocable at any time.
- You can see a log of everyone who viewed your profile.
- You can dispute inaccurate records; disputes and their resolutions are permanently recorded.
- You can export your complete record at any time.
What we never store
The platform does not accept subjective opinions about people. Only structured, factual, evidence-backed employment events can be recorded.
The AI assistant
A company’s HR staff can ask the built-in assistant questions about that company’s own records. Answering a question means sending the relevant records to the AI provider the company’s chosen model runs on. That is a transfer to a third party, and these are its limits.
- It happens only when somebody asks a question. There is no background processing of employment records, no training on your data, and nothing is sent when the assistant is not in use.
- It carries only what the person asking could already read. The assistant inherits their role and never widens it. HR staff cannot open a private record anywhere in EmployDB, so an HR staff member’s question is answered without those records being assembled at all.
- Private HR records are opt-in for each question. Salary, warnings, evaluations and medical accommodations are included only when an owner or HR admin asks about one named person and explicitly asks for them. They are never sent for a question about the company as a whole, and the answer states whether they were sent.
- Nothing an employee shared through the network is sent. The assistant operates inside one company’s own records. It is not connected to the verification network, to talent search, or to any other company’s data.
- The assistant cannot write. It can prepare a draft entry for a person to review and submit. Its answers are not stored and never become part of an employment record.
Security
Data is stored on Google Cloud (Firebase) with role-based access enforced server-side, encrypted in transit and at rest. Sessions use HttpOnly, Secure, SameSite=strict cookies; all state-changing requests require CSRF tokens, which are held in memory rather than stored. Signing in to your account is not by itself enough to store a payment method, issue an integration key or export your record: those ask you to confirm your password again.
Cookies and sessions
EmployDB uses only the cookies required to operate the service. When you sign in we set a session cookie, a companion cookie that identifies this browser's session so that you can review and sign out your sessions from your profile, and — after you confirm your password for a sensitive change — a short-lived confirmation cookie. All of them are HttpOnly, Secure and SameSite=strict, and they are deleted when you sign out or when your session expires. A session cookie lasts one day and is renewed while you keep using EmployDB, for at most thirty days, after which you are asked for your password again. We also set a random device cookie, kept for a year, that lets us recognise a browser you have signed in from before, so that we can email you when your account is signed in to from a browser we have not seen; it identifies the browser to us only, is stored on our side only as a hash, is kept when you sign out — which is what makes the recognition work — and is not used for tracking or advertising. Our staff sign-in sets its own equivalents, including its own device cookie, which are separate from yours. We do not use advertising cookies and we do not sell personal data to anyone, for any purpose.
For each browser signed in to your account we keep the browser and device type, the site you signed in from, when you signed in, and a truncated network address — never the full address and never your browser's full identification string. It is shown only to you, so you can recognise your own sessions and end any of them, and it is deleted when that session ends and never later than the session's own lifetime. A session is bound to the kind of browser that opened it: if the same session is presented by a different one, we end it rather than trust it.
Data retention
Verified employment records are retained for the benefit of the employee, including after the issuing company leaves the platform — that permanence is the point of verified history. Private HR records are retained while the employing company's account is active. Audit logs are append-only and retained for the life of the related records.
Your rights
You can access every record about yourself directly in your account, export your complete history at any time, dispute inaccurate records, and request correction or deletion of your account data under applicable privacy law. Requests are handled by the DAXTOP privacy team.
Contact
Privacy requests: [email protected]
