Privacy Policy & Data Protection
Last updated: September 24, 2026 • Version 2.4 • Applicable to all HRMS tenants & applications
Welcome to HRMS ("we", "us", "our"). We are committed to maintaining the highest standard of data privacy, security, and statutory compliance for all our corporate customers ("Subscribers"), their employees ("Workers"), contractors, and job candidates.
This Privacy Policy applies to the HRMS cloud application platform, mobile applications (iOS and Android), API connectors, biometric hardware integrations, and related marketing websites. By accessing or using HRMS, you acknowledge that you have read and understood this Privacy Policy.
To ensure total regulatory clarity under data protection frameworks (including EU GDPR Article 28 and India DPDP Act 2023):
-
Employer / Tenant as Data Controller: Your organization (the employer subscribing to HRMS) acts as the Data Controller. Your company determines which employees are added, what attendance policies apply, how salary components are calculated, and how long records are maintained.
-
HRMS as Data Processor: HRMS operates strictly as a Data Processor. We process employee personal data exclusively under the written instructions of your organization, as defined in our Master Subscription Agreement (MSA) and Data Processing Addendum (DPA).
Individual employees seeking to modify, access, or delete their employment records should direct their request to their employer’s HR Administrator.
Depending on the specific HRMS modules enabled by your employer, we collect and process the following categories of data:
| Data Category | Data Fields Collected | Primary Purpose |
|---|---|---|
| Subscriber Account Data | Company name, admin name, billing address, work email, phone number, VAT/GST registration numbers. | Account setup, billing, customer support, and system alerts. |
| Workforce Personal Profiles | Full name, employee ID, job title, department, manager hierarchy, DOB, emergency contacts, government identifiers (PAN, SSN, Aadhaar where legally mandated). | Employee directory, organization chart, statutory compliance, and identification. |
| Attendance & Location Data | Clock-in/out timestamps, IP whitelisting logs, geofenced GPS coordinates (mobile punch), shift allocations, overtime hours. | Time tracking, shift roster enforcement, overtime calculation, and attendance regularization. |
| Biometric Hardware Logs | Non-reversible mathematical biometric hash tokens generated by hardware terminals (facial/fingerprint hash IDs). | Biometric turnstile and attendance terminal synchronization. |
| Payroll & Financial Data | Salary structure, bank account numbers, IFSC/IBAN codes, tax declarations, Form 16, loan/advance ledgers, payslips. | Automated monthly salary calculation, bank payout advice generation, and tax compliance. |
| Recruitment & ATS Records | Candidate resumes, interview feedback scores, background check statuses, compensation proposals. | Applicant tracking, interview scheduling, and digital offer letter generation. |
We process collected data exclusively for valid business and operational reasons, including:
Core Platform Operations
Executing attendance algorithms, computing leave balances, generating automated salary sheets, and rendering interactive dashboards.
HR AI Assistant (Copilot)
Processing query prompts in real-time. Prompts sent to HRMS AI Copilot are processed ephemerally and are NEVER used to train public LLM models.
Security & Audit Trail
Maintaining immutable audit logs for role-based actions, preventing fraudulent clock-in attempts, and protecting system integrity.
Transactional Communications
Sending OTP logins, payslip generation emails, leave request manager notifications, and critical platform security advisories.
Zero Raw Biometric Image Guarantee
HRMS does NOT store raw fingerprint images or high-resolution facial images on our servers. Biometric attendance hardware devices connected to HRMS convert biometric scans locally into non-reversible mathematical hash strings (templates).
These mathematical hashes cannot be reverse-engineered to reconstruct physical biometric features. Employers utilizing biometric features are required under their DPA to obtain necessary employee consent under local legislation.
Geolocation Tracking Rules: GPS location coordinates captured via the HRMS mobile app are transmitted only at the precise instant of a clock-in or clock-out event when Geofenced Attendance is enabled. HRMS does NOT perform background continuous tracking of employees during non-working hours.
We do NOT sell, rent, or trade personal data to third-party advertisers. We share data only with vetted infrastructure sub-processors necessary to run the HRMS service:
| Sub-Processor | Service Function | Data Location | Security Certifications |
|---|---|---|---|
| Amazon Web Services (AWS) | Primary Cloud Infrastructure, Encrypted Storage & Database Hosting | US, EU, India Datacenters | ISO 27001, SOC 1/2/3, PCI-DSS |
| Twilio & AWS SES | Transactional SMS, WhatsApp Alerts & Email Delivery | Global Edge Network | SOC 2, GDPR Compliant |
| Stripe / Razorpay | Subscription Payment Gateway & Billing Processing | US / India | PCI-DSS Level 1 Compliant |
HRMS implements enterprise-grade technical and organizational security controls to safeguard data integrity:
AES-256 Encryption
All database tables, files, and backups encrypted at rest.
TLS 1.3 Transport
High-grade HSTS SSL encryption for all web and mobile traffic.
RBAC & MFA
Granular role permissions with compulsory Multi-Factor Authentication.
Active Accounts: We retain customer workforce records for as long as the organization maintains an active HRMS subscription.
Post-Termination Export Window: Upon cancellation or contract expiration, Subscribers have a 30-day grace period to export all employee records, attendance logs, and payslip PDFs via standard CSV, Excel, or JSON formats.
Cryptographic Deletion: Following the 30-day window, HRMS executes automated cryptographic deletion routines, purging tenant data from active databases within 60 days, and clearing off-site encrypted backups within 90 days.
Under global regulations (including GDPR, CCPA, and DPDP Act), workers have fundamental data rights:
- Right to Access & Portability: Employees can view and download their payslips, leave records, and profile details via the Employee Self-Service (ESS) app.
- Right to Rectification: Employees can submit profile updates or attendance regularization requests to their HR manager for approval.
- Right to Erasure / Forgotten: Requests for account deletion must be submitted directly to the employer's HR Administrator (Data Controller).
HRMS provides multi-region data hosting options (US, EU, and India). For enterprise tenants subject to cross-border transfer restrictions, transfers are executed under standard EU Standard Contractual Clauses (SCCs) and regional data residency constraints.
We use essential session cookies strictly necessary to maintain authenticated login sessions, CSRF token validation, and security preferences. Analytical telemetry is anonymized and used solely to optimize application page load speeds.
If you have questions regarding this Privacy Policy, wish to report a security vulnerability, or seek assistance with a privacy inquiry, please contact our Data Protection Officer:
HRMS Data Protection Office
Email: dpo@yourhrms.com | Legal & Compliance Team
Address: 123 Business Avenue, Suite 500, Tech City