Trust & legal
Version 1.0 · Effective 25 September 2026 · DPDP Act 2023 aligned · Applies to the AdviHR Service.
AdviHR (“AdviHR”, “we”, “us”) provides a multi-tenant human-resources management system delivered as software-as-a-service (the “Service”). When an employer subscribes to the Service (the “Customer”), the Customer is the data fiduciary / controller of the personal data it processes through AdviHR, and AdviHR acts as a data processor on the Customer's behalf.
Our Data Protection Officer and Grievance Officer can be reached at privacy@advihr.com and grievance@advihr.com. We acknowledge data-principal grievances within 7 calendar days and endeavour to resolve them within 30 days.
We process personal data on the following grounds:
An employer that uses AdviHR to process its employees' data remains responsible for ensuring a lawful basis for that processing (typically the employment relationship plus its own notices and consent collection). AdviHR provides the consent-register tooling so the employer can record when consent was obtained from each person.
Production data is stored in cloud-hosted, encrypted PostgreSQL databases in secure data centres (region available on request). Document uploads are stored in restricted-access object storage with encryption at rest. If data is processed by infrastructure located outside India, we rely on contractual safeguards and the transfer mechanisms permitted under the DPDP Act and inform you of such transfers in this Policy. We never share customer data with advertising networks.
For active tenants, data is kept for as long as the subscription is active. After cancellation:
Under the DPDP Act and this Policy, a data principal may:
Ask your employer's HR admin first — they control most of your data. If your employer does not respond within 30 days, or for complaints about AdviHR's own processing, write to privacy@advihr.com and we will act as a backstop.
If we detect a personal-data breach that affects you or your employees, we will notify the registered admin without delay, and (where required) the Data Protection Board of India and the affected data principals, with the details of the breach and the measures taken to contain it.
| Cookie | Purpose | Type | Lifetime |
|---|---|---|---|
| advihr_access | Signed-in session token (HttpOnly, not readable by scripts) | Essential | 30 minutes |
| advihr_refresh | Rotates the session token when it expires (HttpOnly) | Essential | 14 days |
| advihr_csrf | Security nonce checked against form requests to prevent CSRF attacks | Essential | 30 minutes |
| advihr_consent | Remembers the choice you make in our cookie banner | Essential | 12 months |
We also keep small local site preferences (in your browser's in-site storage, not as cookies) such as the demo data source toggle. None of these track you across the site or across other websites. You can clear any of the above at any time from your browser settings; clearing the session cookies will sign you out.
The Service is not directed at children. If you believe a child's data has been provided to us, contact the Grievance Officer and we will take reasonable steps to delete it.
If we materially change this Policy, we will notify the registered admin of each tenant by email at least 30 days in advance and ask for re-consent in-product where the change affects a ground of processing. Continued use after the effective date constitutes acceptance of the updated Policy, subject to any re-consent you give.
Data Protection Officer / Grievance Officer: grievance@advihr.com (acknowledgement within 7 calendar days, resolution target 30 days). The officer will also escalate to the Data Protection Board of India where the DPDP Act requires.
See also: Terms of Service and Security.