1. Scope of this Policy
This Policy applies to information collected through the SERA HR mobile application for iOS and Android, the SERA HR web portal at serahr.in (and its sub-domains), our public marketing website, and any related APIs, edge functions, notification services, and support channels. It does not apply to third-party services that your employer connects to SERA HR (for example, their bank, payroll provider, or messaging tools) — those services have their own privacy policies.
2. Controller & contact
The entity responsible for this Platform is:
Legal name: [[LEGAL_ENTITY_NAME]]
Registered office: [[REGISTERED_OFFICE_ADDRESS]]
Corporate identification number (CIN): [[CIN_NUMBER]]
Grievance officer: [[GRIEVANCE_OFFICER_NAME]]
Email: privacy@serahr.in
Phone: [[GRIEVANCE_OFFICER_PHONE]]
Under section 8 of the DPDP Act we have appointed a Grievance Officer who is your first point of contact for any data-related complaint. The Grievance Officer will acknowledge every complaint within seventy-two (72) hours and endeavour to resolve it within thirty (30) days.
3. Information we collect
We collect the following categories of information:
3.1 Identity & contact information
- Full name, employee identifier, email address, phone number.
- Employer / organisation name and organisation code.
- Designation, department, reporting manager, team leader, join date.
3.2 Authentication information
- Hashed password (never stored in plain text).
- One-time verification codes and their expiry timestamps.
- Session tokens issued by our authentication provider.
- The fact that biometric app-lock is enabled or disabled.
3.3 Attendance & activity information
- Punch-in and punch-out timestamps, working hours, and computed status (present, late, half-day, on leave, early punch-out).
- A selfie captured at punch-in and punch-out (see § 8).
- Approximate geo-coordinates and, where available, reverse-geocoded address (see § 7).
- QR-code or Wi-Fi network identifier used to validate the punch, where the employer has enabled those options.
3.4 Employment & payroll information
- Salary structure, day rate, bank details (masked account number, IFSC) and PAN, where entered by you or your employer.
- Leave balance, leave requests, and approval history.
- Payroll runs, payslips, deductions, and taxes.
- Performance reviews, targets, and feedback where the module is enabled by your employer.
- Documents uploaded to your profile (see § 10).
3.5 Organisation & subscription information
- Organisation legal name, address, GSTIN (optional), and the plan tier.
- Invoices, payment references from Razorpay, and payment method type (Card, UPI, Net-Banking).
- Support tickets and their history.
3.6 Device & log information
- Device model, operating-system version, application version, and diagnostic identifiers necessary for delivering push notifications.
- IP address, approximate city, browser type (for the web portal), and access timestamps recorded in server logs.
- Crash reports and non-personal analytics events (see § 6 and § 11).
4. How we use information
We use the information described above to:
- Provide the core HR features (attendance, leave, payroll, notifications, reports, recruitment).
- Authenticate you and enforce role-based access control.
- Detect fraud and abuse — including duplicated punches, spoofed locations, and unauthorised account access.
- Bill your employer for the subscription and generate GST-compliant invoices.
- Send transactional communications (email, SMS, push) about your requests, approvals, payroll, and account.
- Comply with legal obligations, respond to lawful government requests, and enforce our Terms & Conditions.
- Improve the Platform — measuring feature adoption, diagnosing crashes, and understanding aggregated usage.
We do not sell your personal information. We do not use it for third-party behavioural advertising. We do not use it to train machine-learning models that could be repurposed outside your employer's instance.
5. Legal basis for processing
Depending on the applicable law, we rely on the following legal bases:
- DPDP Act (India): processing is grounded in your consent at signup and, for the majority of employer-side activities, in "certain legitimate uses" under section 7 (employment records, performance of a contract).
- GDPR (EU / UK): where GDPR applies, we rely on Article 6(1)(b) (contract), 6(1)(c) (legal obligation), 6(1)(f) (legitimate interest — securing the Platform), and 6(1)(a) (explicit consent) for optional processing such as marketing communications.
- Sensitive categories: biometric-adjacent data (selfies used for face verification) is processed under Article 9(2)(b) GDPR — employment obligations — and section 7 DPDP.
6. Cookies & analytics (web portal)
The web portal uses a minimal set of cookies:
- Strictly necessary: authentication cookies set by Supabase to keep you signed in. These cannot be disabled without breaking the service.
- Functional: preferences such as your last-selected month on the Attendance page.
- Analytics: aggregated, non-personal usage counts. If we enable analytics that use cookies (for example, Plausible or Google Analytics 4), we will surface a cookie banner allowing you to opt in or reject.
The mobile application does not use cookies but stores an authentication token and app-preference values in the operating system's secure storage.
7. Location data
We collect the device's approximate location onlywhen you attempt to punch in or punch out and only if your employer has enabled the location-verification option. The reading is used to (a) confirm that you are within the office geo-fence configured by your employer, and (b) record the address on the attendance row so HR can audit anomalies. We do not track location in the background and the application does not request the "Always allow" permission on iOS or ACCESS_BACKGROUND_LOCATION on Android.
8. Camera & face verification
At punch-in and punch-out we open the front camera to capture a selfie. The selfie is uploaded to a private storage bucket in our Supabase project and is retrievable only by (a) you, (b) your employer's HR or admin users with the appropriate permission, and (c) our support staff acting under a signed data-processing agreement. We use on-device face detection to check that a human face is present in the frame; we do not use the selfie for face-recognition-based identification, and we do not build a face-embedding template. The camera is not accessed at any other point in the application.
9. Push notifications
Push notifications are delivered via Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM). We send notifications for events initiated inside your organisation: approvals, punch-out reminders, payslip availability, and support replies. You can disable notifications from your device settings; the Platform will still function but you will need to check the app manually for updates.
10. File uploads
The Platform allows uploads of profile photos, employee ID documents, payslip PDFs, and other HR documents. Uploads are stored in Supabase Storage. Private buckets require a signed URL for access; public buckets (such as profile photos) are accessible via a direct URL but cannot be listed. Files are scanned for size limits and MIME type; executables and archive types are rejected.
11. Third-party services
We rely on the following processors. Each has been vetted for its own security posture and is bound by a data-processing agreement:
- Supabase Inc. — hosted authentication, PostgreSQL database, storage buckets, edge functions. Region: [[SUPABASE_REGION]].
- Razorpay Software Pvt. Ltd. — subscription payments, invoicing, and GST-compliant transaction records. Card numbers and CVV are handled directly by Razorpay and never touch our servers.
- Google LLC / Firebase — push notification delivery (FCM) for Android and diagnostic services.
- Apple Inc. — push notification delivery (APNs) for iOS.
- Gmail SMTP — outbound transactional email (welcome mail, OTP delivery, invoice attachments).
- Vercel Inc. — web-portal hosting.
12. International data transfers
Where feasible we keep your data on Supabase infrastructure in [[SUPABASE_REGION]]. Certain processors (Firebase, Apple, Vercel) operate global networks and may process metadata outside India. We rely on Standard Contractual Clauses (GDPR) and the DPDP Act's permitted-country framework for such transfers. We do not transfer personal data to jurisdictions that the Central Government has notified as restricted.
13. Security safeguards
We use technical and organisational safeguards commensurate with the sensitivity of the data:
- TLS 1.2+ for all traffic between the app / portal and our servers.
- Row-Level Security (RLS) on every business table so an authenticated user can only read data belonging to their own organisation.
- Encryption-at-rest on the Postgres database and all storage buckets.
- Hashed passwords using industry-standard KDFs (Supabase Auth's bcrypt-based implementation).
- Optional biometric app-lock and device credential fallback.
- Least-privilege service accounts, rotated secrets, and audit logs on privileged operations.
- Regular vulnerability scanning and dependency updates.
No system is impenetrable. In the event of a personal-data breach that is likely to cause significant harm, we will notify the Data Protection Board of India and affected principals within the timelines prescribed by the DPDP Act.
14. Data retention
We retain personal data for the following periods:
- Attendance records: for the duration of your employment plus seven (7) years, as required by Indian payroll and tax law.
- Payslips and payroll runs: seven (7) years.
- Punch-in/out selfies: ninety (90) days after the corresponding attendance day, then automatically purged.
- Support tickets: three (3) years after closure.
- OTP verifications: twenty-four (24) hours.
- Cancelled organisation accounts: ninety (90) days grace, then permanent deletion of the workspace and all personal data (see § 16).
Where a longer retention period is required by law (for example, contested payroll disputes or ongoing legal proceedings) we retain only the specific records necessary for that purpose.
15. Your rights
Subject to applicable law, you have the following rights:
- Access: obtain a copy of the personal data we hold about you.
- Correction: request that inaccurate or incomplete data be corrected.
- Erasure: request deletion of your data, subject to statutory retention requirements.
- Nominate: nominate another individual to exercise your rights in the event of death or incapacity (DPDP Act § 14).
- Grievance: raise a complaint with our Grievance Officer (see § 2). You may also approach the Data Protection Board of India.
- Portability (GDPR): receive your data in a structured, machine-readable format.
- Withdraw consent: where processing is based on consent, withdraw it at any time by contacting privacy@serahr.in.
Because much of your data is entered by your employer, some rights (particularly correction and erasure) may need to be exercised through your employer's HR admin. We will assist your employer in responding to such requests.
16. Account deletion
You may request deletion of your personal SERA HR account at any time by writing to privacy@serahr.in or through the in-app "Delete my account" option under Profile → Help & Support. On confirmation:
- Your login credentials and app-preference data are deleted within seven (7) days.
- Attendance, payroll, and other records required by your employer for legal or statutory purposes are transferred to your employer's control and are no longer linked to your login (they remain with the employer as the Data Fiduciary).
- Selfies and profile photos are purged.
Organisation-wide deletion (closing a workspace) can be initiated by the primary organisation administrator from Settings → Danger zone or by writing to us. A ninety (90) day grace period applies before irreversible deletion, during which the workspace can be reactivated.
17. Children's privacy
SERA HR is a workplace product intended for use by employed adults. We do not knowingly collect personal data of children under the age of eighteen (18). If a child's data has been submitted to the Platform in error, please contact us and we will delete it promptly.
18. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make a material change, we will (a) update the "Effective" date at the top, (b) send a notice by email or in-app banner, and (c) where required by law, seek fresh consent. Continued use of the Platform after a change constitutes acceptance of the revised Policy.
19. Contact us
Questions, complaints, or requests to exercise your rights should be addressed to: