EasyHRA PRIVACY POLICY Human Resource Management System (HRMS) Effective Date: 15/06/2026 | Last Updated: 15/06/2026 | Version: 1.0 Applicable Law: Digital Personal Data Protection Act, 2023 | IT Act, 2000 | SPDI Rules, 2011
IMPORTANT NOTICE TO EMPLOYEES AND USERS This Privacy Policy governs how EasyHRA Adhyat Solutions Private Limited, a company incorporated in India under the Companies Act, 2013, CIN: U74920KA2019PTC124929, registered at Sy No. 78, TTB Compound, Kithaganur Main Road, Parvathinagar, Medahalli, Bengaluru, Karnataka 560049 collects, uses, stores, and protects your personal data, including biometric information. By accessing or using EasyHRA, you confirm that you have read, understood, and agreed to this Privacy Policy. If you do not agree, do not access or use the Service.
1. Definitions The following terms shall have the meanings assigned to them: • "EasyHRA" / "Company" / "We" / "Us": Adhyat Solutions Private Limited, a company incorporated in India, its successors, and permitted assigns. • "Data Principal": The individual (employee, user, or visitor) to whom the personal data relates — as defined under the DPDP Act, 2023. • "Data Fiduciary": The entity that determines the purpose and means of processing personal data. EasyHRA acts as a Data Fiduciary when you register directly, and as a Data Processor when processing on behalf of your employer. • "Personal Data": Any data about an individual who is identifiable by or in relation to such data. • "Sensitive Personal Data / Biometric Data": Facial images, face descriptors/vectors, fingerprint records, or other biometric identifiers used for attendance authentication. • "Subscribing Organisation": An employer or business that has purchased a subscription to the EasyHRA Service for their employees. • "Service": EasyHRA's website, mobile application (Android and iOS), software platform, APIs, and related HR management solutions. • "DPDP Act": The Digital Personal Data Protection Act, 2023, and rules and regulations made thereunder.
2. Scope and Applicability This Privacy Policy applies to: • All employees, contractors, HR administrators, and authorised users of Subscribing Organisations that use EasyHRA. • Visitors to our website www.easyhra.com. • Users of our mobile applications on Android and iOS devices. • Any person whose personal data is provided to us by a Subscribing Organisation for HR, payroll, or attendance management purposes.
This Policy does NOT apply to third-party hardware devices (e.g., biometric attendance terminals) or their manufacturers. We encourage you to review their privacy policies separately.
3. Identity of the Data Fiduciary For the purposes of the DPDP Act, 2023: • EasyHRA as Data Fiduciary: When you visit our website, register for a trial, or interact with us directly. • EasyHRA as Data Processor: When we process employee data on behalf of a Subscribing Organisation (who is the Data Fiduciary in such cases). In this role, we act only on the documented instructions of the Subscribing Organisation.
Contact details of the Data Fiduciary / Data Protection Contact: • Company Name: Adhyat Solutions Private Limited • CIN: U74920KA2019PTC124929 • Registered Address: Sy No. 78, TTB Compound, Kithaganur Main Road, Parvathinagar, Medahalli, Bengaluru, Karnataka 560049 • Email: privacy@easyhra.com • Phone: +91-98441 55550 • Grievance Officer: Shankar K, Head of Information and Security
4. Personal Data We Collect 4.1 Information You or Your Employer Provides • Account and identity data: Full name, employee ID, email address, mobile number, designation, department, date of joining, reporting manager, date of birth. • Authentication data: Username, password (stored as a one-way cryptographic hash — never in plaintext), device PIN. • Profile information: Profile photograph (non-biometric), address, emergency contacts. • Payroll and financial data: Bank account details, salary structure, PF/ESI details, professional tax, income tax declarations, investment proofs, and reimbursement claims. • Leave and attendance: Leave applications, work-from-home requests, attendance regularisation requests. • Exit and separation data: Full and Final settlement information, relieving documentation, notice period details.
4.2 Biometric and Sensitive Personal Data Notice Regarding Biometric Data Collection EasyHRA collects and processes biometric data ONLY where your Subscribing Organisation has enabled facial recognition attendance and ONLY after obtaining your explicit, informed, and freely given written or electronic consent. You have the right to refuse consent, in which case an alternate attendance method (PIN, OTP, or manual HR marking) shall be offered. Biometric data is NEVER collected without consent.
Where consent is obtained, we collect: • Facial images: Captured at the time of enrolment and during each check-in/check-out event. • Face descriptors (vectors/embeddings): Mathematical representations derived from facial images. These descriptors cannot be used to reconstruct or reverse-engineer the original image.
Biometric data is treated as Sensitive Personal Data under the SPDI Rules, 2011, and Sensitive Data under the DPDP Act, 2023. It is processed exclusively for attendance verification and fraud prevention (e.g., buddy-punching detection).
4.3 Data Collected Automatically • Attendance logs: Date, time, punch type (check-in/check-out), shift, and verification method. • Location data: GPS coordinates at the time of check-in/check-out, only if enabled by your Subscribing Organisation and only after disclosure to you. You may disable location access in your device settings; this may limit functionality. • Device information: Device model, operating system version, unique device identifier (UDID/IMEI), IP address, app version. • Usage data: Features accessed, session duration, error logs, crash reports, and click-stream data — collected in anonymised or pseudonymised form where possible. • Cookies and tracking technologies: Used on our website for session management, performance analytics, and user preference storage. See Section 11 for details.
5. Purposes of Processing We process your personal data only for the following specific, lawful, and disclosed purposes: • Account creation, authentication, and access management. • Attendance recording, verification, shift management, and regularisation. • Leave management and work-from-home administration. • Payroll generation, payslip distribution, and statutory deductions (PF, ESI, Professional Tax, TDS). • Income tax estimation and TDS computation based on salary structure and investment declarations. • Full and Final settlement processing upon employment termination. • Detection and prevention of fraud, buddy-punching, and unauthorised access. • Customer support, grievance redressal, and user communications. • Service improvement, feature development, and internal analytics (using anonymised data). • Compliance with applicable Indian laws including labour laws, tax laws, and data protection laws.
We do NOT process your personal data for advertising, marketing profiling, sale to third parties, or any purpose not listed above without your prior explicit consent.
6. Legal Basis for Processing We process your personal data on the following lawful bases under the DPDP Act, 2023: • Consent (Section 6, DPDP Act): For biometric data and any processing beyond employment necessity. Consent is obtained through a clear, specific, and informed consent mechanism before processing commences. You may withdraw consent at any time by writing to privacy@easyhra.com. • Legitimate Use for Employment: For processing personal data necessary to fulfil obligations arising from your employment relationship with your employer. • Legal Obligation: For processing required to comply with Indian laws including the Payment of Wages Act, Provident Funds Act, Income Tax Act, Professional Tax Act, and applicable labour laws.
Your Right to Withdraw Consent You may withdraw consent for biometric attendance at any time. Withdrawal will result in your Subscribing Organisation being notified and an alternate attendance method being activated. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. It does not affect processing required under legal obligation.
7. How We Share Your Information We do NOT sell, rent, or trade your personal data. We share your data only as described below: • With your Subscribing Organisation: Attendance records, leave status, payroll data, and HR information are shared with your employer's authorised HR administrators as part of the Service's core function. • With trusted Data Processors: We engage third-party service providers for cloud hosting (servers located in India), email/SMS delivery, payment processing, and crash analytics. All such providers are bound by Data Processing Agreements (DPAs) that prohibit use of your data for any purpose other than service delivery. • For legal compliance: We may disclose personal data if required by a court order, government authority, or applicable Indian law. We will, where legally permissible, notify the affected user or Subscribing Organisation before such disclosure. • Business transfer: In the event of a merger, acquisition, or asset sale involving EasyHRA, your data may be transferred to the successor entity. You will be notified at least 30 days in advance of such a transfer and may request deletion of your data subject to legal retention obligations.
We expressly confirm: Biometric data (facial images and face descriptors) is NEVER shared with any third party for marketing, advertising, profiling, or any purpose unrelated to attendance verification for your Subscribing Organisation.
8. Data Retention We retain personal data only for as long as necessary to fulfil the stated purpose and comply with applicable Indian laws:
Data Category Retention Period Legal Basis for Retention Account and profile data Employment period + 3 years Statutory compliance, audit requirements Attendance and payroll records 7 years from date of record Payment of Wages Act; Income Tax Act; PF Act Biometric data (facial images) 90 days after employment termination OR consent withdrawal DPDP Act, 2023; SPDI Rules, 2011 Biometric face descriptors (vectors) Active employment only; deleted within 30 days of termination Data minimisation principle — DPDP Act Usage logs and analytics 12 months (identifiable); then anonymised IT Act; security audit requirements Legal dispute records Until final resolution + 3 years Limitation Act, 1963
Upon expiry of the applicable retention period, data is securely deleted using irreversible cryptographic erasure or physical destruction of storage media, as applicable.
9. Data Security We implement the following technical and organisational measures to protect your data: • Encryption of data in transit using TLS 1.2 or higher. • Encryption of data at rest using AES-256 encryption. • Biometric face descriptors are stored as one-way encrypted vectors — they cannot be reverse-engineered to reconstruct a facial image. • Role-based access controls (RBAC) ensuring only authorised personnel access personal data. • Multi-factor authentication (MFA) for all administrator accounts. • Regular security reviews, vulnerability assessments, and penetration testing. • Data centres and cloud infrastructure aligned to ISO 27001 security standards. • Employee confidentiality agreements and mandatory data protection training. • Audit logs for all access to sensitive data.
In the event of a personal data breach that is likely to result in risk to the rights and freedoms of Data Principals, we will notify the Data Protection Board of India and affected Data Principals/Subscribing Organisations as required under the DPDP Act, 2023, within the prescribed timelines.
10. Your Rights as a Data Principal Under the DPDP Act, 2023, you have the following rights: • Right to Access (Section 11): Obtain a summary of personal data we process about you and the processing activities. • Right to Correction and Erasure (Section 12): Request correction of inaccurate or incomplete data, and erasure of data that is no longer required for the stated purpose. • Right to Withdraw Consent (Section 6): Withdraw previously given consent at any time. Withdrawal does not affect the lawfulness of prior processing. • Right to Grievance Redressal (Section 13): Lodge a complaint with our Grievance Officer (see Section 14). • Right to Nominate (Section 14, DPDP Act): Nominate another individual to exercise your data rights in the event of your death or incapacity. • Right to approach the Data Protection Board: If dissatisfied with our response, you may approach the Data Protection Board of India as constituted under the DPDP Act, 2023.
To exercise any of the above rights, submit a written request to [PRIVACY CONTACT EMAIL] with the subject line: "Data Principal Rights Request — [Your Name] — [Employee ID]". We shall respond within 72 hours of acknowledgment and resolve within 30 days.
11. Children's Privacy EasyHRA is designed exclusively for use by employees and HR professionals who are 18 years of age or older. We do not knowingly collect personal data from individuals below the age of 18. If we discover that data of a person below 18 has been provided without verifiable parental or guardian consent, we will delete it promptly. Where processing of data of a person below 18 is undertaken, it shall be conducted strictly in accordance with Section 9 of the DPDP Act, 2023.
12. Cookies and Tracking Technologies Our website uses the following types of cookies: • Strictly Necessary Cookies: Required for authentication, session management, and core security. These cannot be disabled. • Performance Cookies: Help us understand how visitors use the website (e.g., pages visited, time spent). Data is aggregated and anonymised. • Functionality Cookies: Remember your preferences such as language, time zone, and login session.
You may control or disable non-essential cookies through your browser settings. Disabling certain cookies may affect website functionality. Our mobile application does not use third-party advertising cookies.
13. Data Storage and International Transfers All personal data collected from Indian users is primarily stored on servers located within India, in compliance with applicable data localisation requirements.
Where we engage international service providers for limited ancillary functions (such as crash reporting or email delivery), any transfer of data outside India is made only to countries that are not restricted under the DPDP Act and only with appropriate contractual safeguards, including Data Processing Agreements that impose obligations equivalent to those under Indian law.
Biometric data is stored exclusively on servers located within the territory of India and is never transferred outside India.
14. Grievance Redressal If you have any concern, complaint, or query regarding the processing of your personal data, you may contact our Grievance Officer:
Grievance Officer Name Shankar K Designation Grievance Officer / Data Protection Officer Email privacy@easyhra.com Phone +91-98441 55550 Address Sy No. 78, TTB Compound, Kithaganur Main Road, Parvathinagar, Medahalli, Bengaluru, Karnataka 560049 Response Timeline Acknowledgment within 48 hours; Resolution within 30 days
If you are not satisfied with our response, you may approach the Data Protection Board of India as constituted under the DPDP Act, 2023, at the address/portal notified by the Central Government.
15. Changes to This Privacy Policy We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service features. We will: • Post the revised policy on our website (www.easyhra.com) at least 30 days before the changes take effect. • Notify all registered users via in-app notification and email to the registered email address. • For material changes involving biometric data or sensitive personal data, obtain fresh consent before continuing processing.
Continued use of the Service after the effective date of a revised policy constitutes acceptance of the revised policy. The "Last Updated" date at the top of this document indicates when the most recent changes took effect.
16. Governing Law and Jurisdiction This Privacy Policy is governed by and construed in accordance with the laws of India, including but not limited to the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, the Information Technology (SPDI) Rules, 2011, and other applicable Indian laws.
Any dispute arising out of or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts located in Bengaluru, Karnataka, India. 17. Contact Us For any questions, requests, or feedback about this Privacy Policy, please contact: • Company: Adhyat Solutions Private Limited • Email: privacy@easyhra.com • Phone: +91-98441 55550 • Address: Sy No. 78, TTB Compound, Kithaganur Main Road, Parvathinagar, Medahalli, Bengaluru, Karnataka 560049 • Website: www.easyhra.com
Declaration This Privacy Policy has been prepared in accordance with the Digital Personal Data Protection Act, 2023; the Information Technology Act, 2000; the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011; and all other applicable laws of India. EasyHRA is committed to protecting the privacy, dignity, and data rights of every Data Principal. This document constitutes a legally binding notice and agreement between EasyHRA and its users.