At **MyWorkara**, we respect the privacy of our corporate customers ("Employers") and their workforce ("Employees"). This Privacy Policy details how we collect, use, process, and secure the personal details, attendance records, geolocations, and payroll parameters uploaded to our platform.
1. Information We Collect
We collect details necessary to provision and administer an HRMS system:
- Account Information: First name, last name, corporate email address, password, mobile number, and company metadata (state, city, industry).
- Employee Directory Data: Full names, job titles, roles, emails, and phone numbers of teammates added by the administrator.
- Attendance Records: Time and date logs of punch-ins and punch-outs. If geofenced check-in is activated, the system accesses precise GPS geolocation coordinates.
- Financial Metrics: Salary, PF/ESI parameters, and tax brackets for automated payroll calculations.
MyWorkara ESS mobile app (Android). The employee self-service app collects the following, and only while you are using the relevant feature:
- Camera (selfie at check-in): When an Employee checks in or out, the app opens the front camera to capture a single photograph, used solely to verify that the attendance entry belongs to that Employee. The photo is uploaded to private storage that only the Employee and their Employer's HR administrators can access. The camera is never used in the background, and no video or audio is recorded.
- Precise location (GPS): At check-in and check-out the app reads the device's current coordinates to record where attendance was marked and, where the Employer has configured office locations, to determine whether the Employee is on site. Location is read only at that moment — never continuously and never in the background.
- Account & device storage: A sign-in session token is stored on the device so the Employee stays logged in.
Attendance photographs and coordinates are visible to the Employee who created them and to authorised HR administrators and managers within that Employer's workspace. They are never sold, never shared with advertisers, and never used to build profiles or track Employees outside working check-ins. Employees may decline the camera and location permissions; attendance can still be recorded without them, with the corresponding detail omitted.
2. How We Use Information
All customer data is used solely to provide and support the HRMS platform:
- Calculating monthly payroll, PF, ESI, and salary breakdowns.
- Verifying check-in coordinates against corporate geofence areas.
- Inviting employees via WhatsApp or SMS triggers.
- Generating real-time attendance dashboards and workforce insights.
4. DPDP Act 2023 Compliance
We comply with the **Digital Personal Data Protection (DPDP) Act, 2023** of India. As a service provider, MyWorkara acts as a Data Processor, whereas the Employer behaves as the Data Fiduciary.
Employers are responsible for obtaining explicit, unambiguous consent from their Employees before uploading their personal details or recording their geolocations. We support data fiduciary mandates by offering tools to export, modify, or erase data upon administrative request.
5. Security Practices
We take physical, technical, and organizational measures to safeguard your information:
- All data transport between users and our servers uses secure HTTPS/TLS encryption.
- Passwords are securely hashed using bcrypt in Supabase Auth.
- Database rows are secured using Row-Level Security (RLS) policies, preventing unauthorized read/writes between separate customer workspaces.
6. Retention & Deletion
We retain personal information for as long as your workspace account is active or needed to compile tax/payroll registers. If you terminate your account, you can request full erasure of your company’s database records by sending a request from your workspace settings panel.
7. Contact & Support
If you have any questions or data concerns under the DPDP Act, please email our grievance officer at hello@myworkara.com. We will respond within 48 hours.
