Trust & legal

Privacy Policy

Version 1.0 · Effective 25 September 2026 · DPDP Act 2023 aligned · Applies to the AdviHR Service.

1. Who we are

AdviHR (“AdviHR”, “we”, “us”) provides a multi-tenant human-resources management system delivered as software-as-a-service (the “Service”). When an employer subscribes to the Service (the “Customer”), the Customer is the data fiduciary / controller of the personal data it processes through AdviHR, and AdviHR acts as a data processor on the Customer's behalf.

Our Data Protection Officer and Grievance Officer can be reached at privacy@advihr.com and grievance@advihr.com. We acknowledge data-principal grievances within 7 calendar days and endeavour to resolve them within 30 days.

2. What information we collect

  • Account data — name, work email, password hash, role, the company you belong to, and (optionally) your authenticator-app secret if you enable two-factor authentication.
  • HR records — employment details, payroll data (CTC, deductions, PF/ESIC/PT/TDS), attendance, leave balances, expense claims, performance, and documents uploaded by you or your employer.
  • Consent records — each consent decision you or your employer records against the Service (purpose, our notice version at the time, decision, timestamp, and the source IP where applicable), kept in an append-only log.
  • Technical metadata — IP address, browser user-agent, and audit logs of security-sensitive actions (sign-in, role changes, payroll runs, billing events).
  • Billing data — handled by Razorpay; AdviHR stores only Razorpay subscription identifiers and never sees your full card or UPI details.

3. Roles & lawful basis

We process personal data on the following grounds:

  • Consent — collected through in-product consent records for the purposes listed in the notice you or your employer accepted (for example terms acceptance at sign-up, payroll processing, background verification, performance analytics, and optional marketing messages — all opt-in).
  • Contract performance — to deliver and operate the Service the Customer subscribed to.
  • Legal obligation — Indian statutory requirements (PF, ESIC, PT, TDS filings), tax law, and records retention.
  • Legitimate interest — to prevent fraud, abuse, and unauthorised access; and to keep the Service secure.

An employer that uses AdviHR to process its employees' data remains responsible for ensuring a lawful basis for that processing (typically the employment relationship plus its own notices and consent collection). AdviHR provides the consent-register tooling so the employer can record when consent was obtained from each person.

4. Where data is stored & cross-border transfer

Production data is stored in cloud-hosted, encrypted PostgreSQL databases in secure data centres (region available on request). Document uploads are stored in restricted-access object storage with encryption at rest. If data is processed by infrastructure located outside India, we rely on contractual safeguards and the transfer mechanisms permitted under the DPDP Act and inform you of such transfers in this Policy. We never share customer data with advertising networks.

5. Who we share with

  • Sub-processors — our infrastructure / cloud-hosting provider (database and object storage), Razorpay (billing/payment processing), and the SMTP provider that delivers transactional emails. Each is bound by a data-processing agreement and processes data only for the listed purpose.
  • Authorities — only when compelled by valid legal process under applicable law.
  • We do not sell personal data, ever. If we change the list of sub-processors you may be processing through, we will update this page and notify the registered admin.

6. How long we keep it

For active tenants, data is kept for as long as the subscription is active. After cancellation:

  • Operational data is retained for 90 days to allow restoration or export on customer request.
  • Statutory records (payroll, tax, PF, ESIC) are retained for the period mandated by Indian law (typically up to 8 years).
  • Consent records and audit logs are retained for 3 years (consent proof follows the statutory period for the underlying record).

7. Your rights

Under the DPDP Act and this Policy, a data principal may:

  • Access a copy of their data (employees can use the in-app “My data” export, or ask HR).
  • Correct inaccurate data.
  • Erase data no longer needed, subject to statutory retention.
  • Withdraw consent for processing based on consent; where processing rests on another lawful basis (e.g. statutory filings), we will explain why it continues.
  • Lodge a grievance with our Grievance Officer (acknowledged within 7 calendar days), and thereafter with the Data Protection Board of India.

Ask your employer's HR admin first — they control most of your data. If your employer does not respond within 30 days, or for complaints about AdviHR's own processing, write to privacy@advihr.com and we will act as a backstop.

8. Security

  • Tenant isolation at the database row level (PostgreSQL RLS).
  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • JWT-based authentication, with optional TOTP two-factor authentication and Google Workspace / SAML SSO.
  • Audit logging of all security-sensitive actions, per-tenant rate limiting, and account lockout after repeated failed logins.
  • Annual independent security assessment, aligned with ISO 27001-style controls.

9. Data-breaches

If we detect a personal-data breach that affects you or your employees, we will notify the registered admin without delay, and (where required) the Data Protection Board of India and the affected data principals, with the details of the breach and the measures taken to contain it.

10. Website analytics & cookies

AdviHR sets only essential cookies to operate the Service securely and keep you signed in. We do not use advertising, marketing, or cross-site tracking cookies, and the marketing side of the site can be browsed without creating an account.

CookiePurposeTypeLifetime
advihr_accessSigned-in session token (HttpOnly, not readable by scripts)Essential30 minutes
advihr_refreshRotates the session token when it expires (HttpOnly)Essential14 days
advihr_csrfSecurity nonce checked against form requests to prevent CSRF attacksEssential30 minutes
advihr_consentRemembers the choice you make in our cookie bannerEssential12 months

We also keep small local site preferences (in your browser's in-site storage, not as cookies) such as the demo data source toggle. None of these track you across the site or across other websites. You can clear any of the above at any time from your browser settings; clearing the session cookies will sign you out.

11. Children

The Service is not directed at children. If you believe a child's data has been provided to us, contact the Grievance Officer and we will take reasonable steps to delete it.

12. Changes to this Policy

If we materially change this Policy, we will notify the registered admin of each tenant by email at least 30 days in advance and ask for re-consent in-product where the change affects a ground of processing. Continued use after the effective date constitutes acceptance of the updated Policy, subject to any re-consent you give.

13. Contact & grievance redress

Data Protection Officer / Grievance Officer: grievance@advihr.com (acknowledgement within 7 calendar days, resolution target 30 days). The officer will also escalate to the Data Protection Board of India where the DPDP Act requires.

See also: Terms of Service and Security.