Legal

    Privacy Policy

    Effective 7 June 2026 · Last updated 7 June 2026

    1.Who we are

    Axiotta Technologies Private Limited (“Axiotta”, “we”, “us”) operates the Axiotta HRMS platform (the “Service”), a human-resources management system for Indian small and medium businesses. Our registered office is at Mumbai, Maharashtra, India (CIN: [CIN to be added]; GSTIN: [GSTIN to be added]).

    This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and the choices and rights you have. It applies to this website, the Axiotta HRMS web application (including the employee self-service portal), and any related services we provide.

    2.The two roles we play

    Under India's Digital Personal Data Protection Act, 2023 (“DPDP Act”), Axiotta plays two different roles depending on whose data is being processed:

    • As a Data Fiduciary, we determine the purpose and means of processing personal data we collect directly — from website visitors, and from HR administrators who sign up to create a customer workspace.
    • As a Data Processor, we process personal data about employees, candidates and other individuals on behalf of customer organisations (each a “Customer”). In this role, the Customer is the Data Fiduciary and determines the purpose of processing; we only process the data on the Customer's documented instructions, including the configuration choices the Customer makes in the Service.

    If you are an employee of an organisation that uses Axiotta HRMS, your employer is the Data Fiduciary for your data. Please address requests to exercise your rights to your employer first; we will cooperate with them as required.

    3.What personal data we collect

    3.1 From website visitors

    When you visit this website, we collect minimal technical information (IP address, user agent, referring page, pages viewed). We do not use third-party advertising or behavioural tracking.

    3.2 From customer administrators (as Data Fiduciary)

    When you create an Axiotta workspace, we collect your name, work email, phone number, a hashed password, your organisation's name, your role at the organisation, and optionally your organisation's GSTIN and address. We send a verification email to confirm the address.

    3.3 From customer organisations about their employees (as Data Processor)

    When a Customer uses Axiotta HRMS, the Customer uploads or causes us to process personal data about their employees, candidates and contractors. The categories typically include:

    • Identification & contact — name, employee code, work email, personal email, phone number, date of birth, gender, marital status, blood group, residential and permanent address, emergency contact details.
    • Employment — designation, department, manager, date of joining, employment type, shift group, location.
    • Statutory identifiers— Permanent Account Number (PAN), Aadhaar number, Universal Account Number (UAN), Provident Fund number, Employees' State Insurance number. These are stored encrypted (AES-256) and are decrypted only when a feature specifically requires them.
    • Financial — bank account number, IFSC code, branch name, CTC, payslip line items (basic, HRA, allowances, PF, ESI, PT, TDS, net salary). Bank details are stored encrypted.
    • Attendance & biometric — punch-in / punch-out timestamps, device identifier, employee code, derived attendance status. We do not store fingerprint templates or facial biometric templates.Templates remain on the Customer's biometric device; we receive only the resulting timestamp + employee code log entries.
    • Leave & absence — leave applications, balances, approvals.
    • Documents — identity documents (Aadhaar, PAN, address proof), educational and employment certificates, resumes, offer letters, police clearance certificates, and similar artefacts uploaded by the Customer or by employees through the self-service portal.
    • Application / recruitment — candidate profile, stage, interview notes.

    The exact data processed depends on which modules the Customer enables. Customers may choose to leave any optional field blank.

    4.How we use personal data

    We use personal data for the following purposes:

    • Service delivery — providing the HRMS functionality the Customer has subscribed to, including attendance processing, payroll calculations (PF, ESI, Professional Tax, TDS), leave management, document storage, recruitment workflows and analytics.
    • Account management — creating accounts, authenticating users, sending transactional emails (welcome, password reset, email verification, payslip delivery, late-arrival and similar notifications).
    • Customer support— responding to support queries and troubleshooting reported issues. In the course of support, our staff may need to view Customer Data; we do this only on the Customer's instructions or to resolve the reported issue.
    • Security & abuse prevention — detecting and preventing fraud, brute-force attacks, abuse of the Service, and unauthorised access; rate-limiting login attempts.
    • Service improvement — understanding aggregate, anonymised usage patterns to improve the Service. We do not use Customer Data for advertising or training third-party AI models.
    • Legal compliance— complying with applicable Indian laws including the DPDP Act, the Information Technology Act 2000, the Income-tax Act 1961, the Employees' Provident Funds and Miscellaneous Provisions Act 1952 and the Employees' State Insurance Act 1948.

    6.How long we keep personal data

    We retain personal data for the period necessary to provide the Service and to meet our legal obligations:

    • Active Customer accounts— for as long as the Customer's subscription is active.
    • After Customer termination — Customer Data is retained for up to thirty (30) days after termination to allow the Customer to export it, then deleted from primary systems. Backups containing deleted data are overwritten in the ordinary backup rotation within ninety (90) days.
    • Statutory payroll records — payroll registers, attendance registers, wage slips and similar documents are retained as long as the underlying Indian labour and tax law requires (typically up to seven (7) years from the end of the relevant financial year), even after Customer termination, unless the Customer assumes custody by exporting them.
    • Inactive workspaces — workspaces with no activity for twelve (12) consecutive months will be flagged for deletion after a 30-day notice to the Customer.
    • Server and security logs — retained up to one hundred and eighty (180) days.

    7.Who we share data with

    We do not sell personal data. We share personal data only with the following categories of recipients and only as needed:

    7.1 Subprocessors

    We use the following subprocessors to operate the Service. Each is bound by a written agreement to process personal data only on our instructions and to maintain appropriate security:

    SubprocessorPurposeRegion
    Amazon Web Services (AWS S3)Encrypted document storageap-south-1 (Mumbai)
    Managed PostgreSQL providerPrimary application databaseap-south-1 (Mumbai)
    Vercel Inc.Application hosting & CDNEdge globally; India for traffic from India
    ResendTransactional email (welcome, password reset, payslip delivery, notifications)United States

    The transactional-email subprocessor receives only the metadata necessary to deliver the message (recipient address, subject, message body). We will provide thirty (30) days' notice through this page before adding or replacing a subprocessor in a way that materially changes the categories of personal data shared.

    7.2 Statutory authorities

    We may disclose personal data to government authorities, courts and regulators where required by Indian law, in response to a valid legal order, or where necessary to protect the rights, property or safety of any person. Where legally permitted, we will notify the affected Customer before responding to a legal request that targets their data.

    7.3 Corporate transactions

    If Axiotta is involved in a merger, acquisition or sale of assets, personal data may be transferred to the successor entity subject to the protections of this Policy. We will notify Customers in advance of any change in ownership that materially affects how their data is processed.

    8.Where data is stored

    All Customer Data (the primary application database and document storage) is stored in the AWS Mumbai region (ap-south-1) inside India. We do not transfer Customer Data outside India for storage.

    Limited transactional email metadata (recipient address, subject line, message body of automated emails) transits our email subprocessor, which operates infrastructure in the United States. This transfer is necessary for sending the email and is the minimum required to deliver the message. We use a provider that offers industry-standard contractual safeguards.

    9.How we protect personal data

    We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the data we process:

    • Encryption in transit — all traffic to the Service is served over TLS 1.2+.
    • Encryption at rest — Customer Data and document storage is encrypted at rest. Bank account details, Aadhaar, PAN and other statutory identifiers are additionally encrypted at the application layer with AES-256-GCM using keys held outside the database.
    • Passwords — user passwords are hashed with bcrypt (cost 10) and never stored in plaintext.
    • Access control — role-based access; principle of least privilege; multi-factor authentication for our administrative access.
    • Document access — uploaded documents are stored with non-guessable object keys and served via time-limited signed URLs.
    • Rate limiting & abuse prevention — on authentication and other sensitive endpoints.
    • Backups — encrypted database backups with a defined rotation.
    • Breach notification — in the event of a personal-data breach that is likely to affect you, we will notify the Data Protection Board of India and the affected Customer (and, through them, affected individuals) without undue delay and as required by the DPDP Act.

    10.Your rights

    Subject to the conditions of the DPDP Act, you have the following rights in respect of personal data we hold about you:

    • Right to information — to know what personal data of yours we process and the identities of the data fiduciaries / processors involved.
    • Right to correction and erasure — to ask us to correct inaccurate data, complete incomplete data, update outdated data or erase data that is no longer required.
    • Right to withdraw consent — where we rely on consent.
    • Right to grievance redressal — to escalate complaints to our Grievance Officer.
    • Right to nominate — to nominate another individual to exercise rights on your behalf in the event of death or incapacity.

    If you are an employee, contractor or candidate of a Customer organisation, please contact your employer first to exercise these rights — your employer is the Data Fiduciary for your data and we act on their instructions. We will support them in responding to your request within the statutory timelines.

    If you are a customer administrator or website visitor, contact us at hrms@axiotta.com.

    11.Cookies and similar technologies

    We use a small number of strictly-necessary cookies and similar local-storage entries:

    • Authentication session — to keep you signed in.
    • CSRF token — to protect against cross-site request forgery.
    • Theme preference — to remember whether you chose light or dark mode.

    We do not use third-party advertising cookies, behavioural-tracking pixels or cross-site analytics that identify individual visitors.

    12.Children

    The Service is not directed at children under eighteen (18) years of age and we do not knowingly process personal data of children. If you believe we have inadvertently collected such data, please contact our Grievance Officer and we will delete it.

    13.Changes to this Privacy Policy

    We may update this Privacy Policy from time to time. For any change that materially affects how we process your personal data (for example, new purposes or new subprocessor categories), we will provide at least thirty (30) days' advance notice by updating this page and, where appropriate, by emailing the Customer's primary contact. The “Last updated” date at the top of this page reflects when the policy was last changed.

    14.Grievance Officer

    In accordance with the DPDP Act and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, our Grievance Officer is:

    Name: [Grievance Officer name]

    Email: hrms@axiotta.com

    Postal address: Axiotta Technologies Private Limited, Mumbai, Maharashtra, India

    The Grievance Officer will acknowledge your complaint within forty-eight (48) hours and provide a substantive response within thirty (30) days.

    15.Contact us

    For any question about this Policy or our data practices, write to us at hrms@axiotta.com.