Privacy Policy

Last updated: July 2026 · Effective from: July 2026

1. Who We Are

Payroll-IND ("we", "our", "us") is an Indian payroll and HR software platform operated under the domain Payroll-IND.com. We are a Data Fiduciary as defined under the Digital Personal Data Protection Act, 2023 ("DPDP Act").

Contact: support@Payroll-IND.com

2. Scope

This policy applies to all personal data processed through the Payroll-IND platform — including data about the employer (organisation admin), HR users, and employees whose payroll records are managed on the platform.

By creating an account and using Payroll-IND, you (the employer/organisation) act as a Data Fiduciary for your employees' data, and Payroll-IND acts as a Data Processor on your behalf. You are responsible for obtaining consent from your employees to process their data using this platform.

3. Data We Collect

3.1 Organisation / Employer Data

  • Organisation name, registered address, state
  • PAN of organisation (encrypted at rest using AES-256)
  • TAN of organisation (encrypted at rest using AES-256)
  • Admin email address and phone number
  • Organisation logo

3.2 Employee Personal Data

  • Full name, date of birth, email address, phone number
  • Designation, department, employment type, date of joining
  • Employee code, work location, work state
  • Photograph

3.3 Sensitive Personal Data (encrypted at rest)

  • PAN number — required for TDS computation and Form 16 generation
  • Aadhaar number — required for EPF/UAN linking (stored masked; only last 4 digits displayed in UI)
  • Bank account number and IFSC code — required to generate the salary bank transfer file
  • UAN (Universal Account Number) — required for EPF ECR filing
  • ESIC number — required for ESIC challan filing
  • PRAN (Permanent Retirement Account Number) — required for NPS contributions
  • Gross salary and salary components — required for payroll computation
  • Income Tax declarations (Form 12BB) and investment proof documents

3.4 Biometric / Attendance Data

  • Attendance logs from biometric devices (punch-in/out timestamps, device ID)
  • We do not store raw biometric templates (fingerprints, iris scans). Only attendance timestamps are stored.

3.5 Usage Data

  • IP address and user-agent string (stored in audit logs)
  • Login timestamps and session activity

4. Why We Collect This Data (Purpose Limitation)

DataPurposeLegal Basis
PANTDS computation, Form 16, Form 24QIncome Tax Act 1961
Aadhaar / UANEPF ECR filing, EPFO linkageEmployees' Provident Funds Act 1952
ESIC numberESIC challan filingESI Act 1948
Bank accountSalary bank transfer file generationEmployer-employee agreement
Salary dataPayroll computation, payslip generationEmployer-employee agreement
Biometric timestampsAttendance tracking for LOP computationEmployer-employee agreement
Investment proofsTDS reduction via Section 80C/80D declarationsIncome Tax Act 1961
IP / audit logsSecurity, fraud prevention, complianceIT Act 2000, IT Rules 2011

5. How We Store and Protect Your Data

  • Encryption at rest: PAN, Aadhaar, bank account numbers, and organisation tax identifiers are encrypted using AES-256-GCM before being stored in the database.
  • Encryption in transit: All data is transmitted over HTTPS (TLS 1.2 or higher).
  • Data residency: All data is stored on servers located in India (Mumbai/ap-south-1 region). No data is transferred outside India.
  • Access control: Role-based access ensures each user can only access data relevant to their role. An accountant cannot see salary amounts unless explicitly granted permission.
  • Audit logs: All data access, modifications, and payroll runs are logged with timestamp, user ID, and IP address.
  • Two-factor authentication: Owner and HR Admin accounts are required to set up TOTP-based 2FA.
  • Backups: Daily encrypted database backups are retained for 30 days.

6. Who We Share Your Data With

We do not sell, rent, or trade personal data. We share data only in the following circumstances:

  • Government portals (indirect): Compliance files (EPF ECR, ESIC Excel, Form 24Q) are downloaded by the employer and uploaded directly to EPFO/ESICNet/TRACES. We do not transmit data to these portals on your behalf.
  • Email/SMS/WhatsApp providers: Transactional messages (payslips, OTPs, set-password links) are sent via third-party providers. Only the email address, phone number, and the specific message content are shared.
  • Cloud infrastructure: Our hosting provider (AWS, India region) processes data as a sub-processor. AWS is bound by data processing agreements consistent with Indian data protection requirements.
  • Legal requirement: We may disclose data if required by a valid court order, statutory authority, or law enforcement request under Indian law.

7. Data Retention

Data TypeRetention PeriodReason
Payroll records, payslips8 years from the date of the payroll runIncome Tax Act 1961 (books of accounts)
EPF/ESIC records8 yearsEPF Act, ESI Act
Form 16 / Form 24Q8 yearsIncome Tax Act 1961
Audit logs5 yearsIT Rules 2011
Active employee dataFor the duration of employment + 3 yearsLabour law requirements
Inactive employee data3 years after last payroll runStatutory compliance
Account data (after deletion)Deleted within 30 days of request, subject to legal holdsDPDP Act 2023

8. Your Rights (Data Principal Rights under DPDP Act 2023)

As a Data Principal (employee or employer using this platform), you have the following rights:

  • Right to access: Request a summary of personal data held about you.
  • Right to correction: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your personal data (subject to statutory retention obligations — payroll records must be retained for 8 years under the Income Tax Act).
  • Right to grievance redressal: Lodge a complaint with our Grievance Officer (details below).
  • Right to nominate: Nominate a person to exercise your rights in the event of your death or incapacity.

To exercise any of these rights, submit a request via our Data Request form or email privacy@Payroll-IND.com. We will respond within 30 days.

9. Cookies

Payroll-IND uses only essential session-related tokens (JWT access tokens stored in memory, refresh tokens). We do not use advertising cookies, analytics trackers, or third-party tracking pixels.

10. Children's Data

Payroll-IND is a B2B platform intended for use by organisations and their employees. We do not knowingly collect data from individuals under 18 years of age.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify organisation admins via email and display a notice on the dashboard. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the platform after the effective date constitutes acceptance.

12. Grievance Officer

In accordance with the Information Technology Act, 2000 and IT (Amendment) Act, 2008, and the DPDP Act, 2023, the details of the Grievance Officer are:

Name: [Grievance Officer Name — update before launch]

Designation: Grievance Officer, Payroll-IND

Email: grievance@Payroll-IND.com

Address: [Registered address — update before launch]

Response time: Within 30 days of receipt of complaint

13. Governing Law

This Privacy Policy is governed by the laws of India, including the Information Technology Act, 2000, the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023. Any disputes shall be subject to the exclusive jurisdiction of courts in India.