Skip to content
Chefotech HRMS

Privacy Policy

What personal data the platform handles, why, and the rights people have over it.

Last updated · Chefotech Technologies Private Limited

The two roles, and why the difference matters

This platform holds personal data in two quite different capacities, and almost every question about privacy depends on which one is in play.

  • Employee data belongs to our customers. When an employer uses this platform to manage their staff, the employer decides what data to collect and why. In data protection language the employer is the controller and we are the processor. We act on their instructions, and we do not decide what happens to that data.
  • Account and marketing data is ours. When someone signs up, contacts sales, or browses the marketing site, we decide how that data is used. For that data we are the controller, and this policy is the full description of what we do.

If you are an employee and want to see, correct or delete data your employer holds about you in this platform, your employer is the right place to ask — they control it. We will help them respond, and if you contact us directly we will refer you to them and tell them you asked.

Data we handle as processor, for our customers

The categories depend on what each customer chooses to configure, but typically include:

  • Identity and contact details — name, employee code, work and personal email, telephone number, address.
  • Employment details — job title, department, location, manager, joining date, employment type, salary structure.
  • Attendance data — clock-in and clock-out times, the device or method used, computed working hours, and the resulting attendance status.
  • Biometric identifiers where a customer connects a biometric device. The platform stores the device's user identifier and the punch events it reports. It does not store fingerprint or facial templates — those remain on the device.
  • Leave and absence records, including reasons where the customer's policy asks for them.
  • Payroll data — earnings, deductions, statutory contributions and payslips.
  • Documents that the customer or employee uploads.

We do not use any of this data for our own purposes. We do not sell it, we do not share it for advertising, and we do not use it to train models.

Data we handle as controller

For people who deal with us directly rather than through an employer:

  • Account data — the name, work email and organisation of people who register, and the security data needed to authenticate them.
  • Billing data — plan, invoices and payment status. Card details are handled by our payment processor and do not reach our servers.
  • Support data — the content of messages you send us and our replies.
  • Product telemetry — which features are used and errors encountered, so we can find and fix problems. This is tied to an account, not to an individual employee's records.
  • Marketing site analytics, only where you consent to non-essential cookies.

Why we are allowed to process it

As processor, our lawful basis is our customer's instruction; the customer is responsible for having a basis of their own — usually the performance of the employment contract, compliance with a legal obligation such as payroll and statutory filings, or their legitimate interests.

As controller, we rely on: performance of a contract (running your account); legitimate interests (keeping the service secure, improving it, and telling existing customers about relevant changes); legal obligation (tax and accounting records); and consent (non-essential cookies and marketing email, which you can withdraw at any time).

Who else sees the data

We use a small number of sub-processors to run the service — hosting, image delivery, email delivery, and error monitoring. Each is bound by a written contract with data protection terms. The current list is published on the Sub-processors page, and we give notice before adding a new one.

We disclose data to law enforcement or a regulator only where legally compelled. Where we are lawfully able to, we will tell the affected customer first so that they can challenge it.

We do not sell personal data to anyone, in any capacity.

Where the data is held

Customer Data is hosted in the region selected for the customer's account. Where data is transferred out of its region — for example to a support engineer in another country — we rely on the transfer mechanisms described in the Data Processing Addendum.

How long it is kept

As processor, we keep Customer Data for as long as the customer's account is active, and delete it after termination on the timeline in the Terms: read-only for 30 days, deleted from live systems within a further 60, and cycled out of backups after that.

As controller, we keep account and billing records for as long as is required for tax and accounting purposes, and support correspondence for three years.

Audit logs are deliberately kept for longer and cannot be edited or selectively deleted, because an audit trail that can be trimmed is not an audit trail.

Security

Data is encrypted in transit and at rest. Access to production systems is restricted, individually authenticated and logged. Each tenant's data is isolated at the database query layer, not merely by a filter in application code — a request without a tenant context fails rather than returning everything.

The Security page describes our practices in more detail.

No system is immune. If a breach affects personal data, we will notify affected customers without undue delay and give them what they need to meet their own notification obligations.

Your rights

Depending on where you live, you may have the right to access a copy of your data, to have it corrected, to have it deleted, to restrict or object to processing, to receive it in a portable format, and to withdraw consent.

For data we control, write to privacy@chefotech.com and we will respond within 30 days. For data your employer controls, contact your employer.

If you are not satisfied with our response you may complain to your local data protection authority. In India, you may also contact our Grievance Officer, [GRIEVANCE OFFICER NAME], at grievance@chefotech.com, who will respond within the statutory period.

Children

The platform is a workplace tool and is not intended for anyone under 18. We do not knowingly collect data from children. If a customer uses the platform to manage lawfully employed young people, that data is Customer Data and the customer is responsible for the additional protections that apply.

Changes and contact

We will post any change here and, if it is significant, notify account administrators by email.

Data Protection Officer: [DATA PROTECTION OFFICER NAME] — privacy@chefotech.com

Chefotech Technologies Private Limited, [REGISTERED OFFICE ADDRESS LINE 1], [ADDRESS LINE 2], [CITY], [STATE] [POSTCODE], India