Privacy Policy
Last Updated: August 18, 2026
NexHR ("we", "us", or "our") is committed to protecting the privacy of our subscribers (Employers) and their staff (Employees). This Privacy Policy explains how we collect, use, process, and protect personal data across our Website, Employer Web Portal, Employer App, and Employee Mobile Application (collectively, the "Platform").
1. Information We Collect
A. Employer/Company Information
To register and administer a workspace, we collect:
- Company registration details (Company Name, CIN Number, GST Number).
- Administrator profile information (Full Name, Designation, Work Email, Phone Number, Password).
- Billing and transaction history (processed securely via PCI-DSS compliant third-party payment gateways).
B. Employee Information
At the direction and invitation of the Employer, we process:
- Basic profile info (Full Name, Employee Code, Date of Joining, Designation, Salary Structures).
- Contact info (Work Email, Mobile Phone Number).
- Bank details for salary payouts (Bank Account Number, Branch Name, IFSC Code).
C. Account/Authentication Information
- OTP logs and login metadata to secure access.
- Session tokens managed through cache caches (such as Redis) to track active devices.
D. Device & IP Information
- Device specifications (Device ID, OS type, model name, device name) to facilitate secure device binding and prevent unauthorized account usage.
- Network details (IP Address, access times, log records).
E. Attendance & Geofencing Information
- Geofence coordinates configured by the Employer to set punch boundaries.
- Punch-in/Punch-out time stamps.
F. Camera & Location Information
- Camera Access: Used solely to capture optional profile photos or validation images during punch actions as requested by the Employer's configurations.
- Location Access: Processed exclusively to assert geofenced check-in boundaries.
2. Important Location Processing Wording
NexHR does NOT perform continuous, live, or background tracking of employee locations.
Your location data is only processed at the precise moment you execute an attendance action (e.g., clicking "Clock In / Punch-In" or "Clock Out / Punch-Out") to verify that the check-in occurs within the employer-configured Geofence. Once the location boundary check is complete and the punch event is recorded, location processing ceases. Location configuration is also accessed by administrators when setting up physical company branch boundaries on maps.
3. How Data is Used
We process data to provide and improve the Platform services, including:
- Facilitating secure login verification via OTP.
- Displaying real-time attendance status on the Employer Dashboard.
- Assisting the Employer with automated calculations of payroll parameters.
- Protecting platform security through device binding verification.
- Sending transactional push notifications or SMS alerts regarding shift edits.
4. Data Sharing
We do not sell, rent, or lease your data to third parties. We share data only with trusted infrastructure providers required to operate our service:
- Cloud Infrastructure (AWS): For secure database storage (PostgreSQL) and media asset hosting (S3 Buckets).
- Caching & Sessions (Redis): To store temporary OTP tokens and active session variables.
- SMS Gateways: To dispatch authentication OTPs to user mobile phones.
- Legal Compliance: We may disclose information if required to do so by law or in response to valid requests by public authorities.
5. Data Security
We implement professional-grade administrative, technical, and physical security measures to safeguard data:
- Industry-standard encryption for data in transit (TLS) and data at rest.
- Cryptographic hashing (Bcrypt) for all stored passwords.
- Restricted access logs limiting database queries to authorized personnel.
6. Data Retention
We retain personal data only as long as:
- The Employer maintains an active subscription to the Platform.
- Historically required to compile employment, tax, and attendance records as mandated by applicable labor and tax laws.
- Session and OTP caches are auto-expunged (Redis entries for OTPs expire within 5 minutes; refresh tokens expire within 7 days).
7. Account & Data Deletion
- Employers can request full company workspace deletion by contacting us. Upon confirmation, all workspace databases, employees, branches, and logs are expunged from production systems.
- Employees who wish to delete their access account can request deletion through the app or website. Please note that account deletion removes access credentials; historical employment logs (such as attendance metrics) are owned by the Employer and will remain archived in the company records as legally required.
8. Cookies & Web Analytics
We use standard essential cookies on our website and portals to maintain active logins and session settings. We may use privacy-compliant web analytics tools to measure site traffic and optimize usability.
9. Children/Minors
Our Platform is designed exclusively for workplace enterprise services and is not directed to individuals under the age of 18. We do not knowingly collect information from children.
10. Policy Updates
We may modify this Privacy Policy from time to time. The updated document will be posted on this page with an adjusted "Last Updated" date.
11. Contact Information
For privacy queries or to exercise your data rights, please contact:
- Email: support@nexhr.in
- Address: NexHR Technologies Private Limited, New Delhi, India.