Privacy Policy

Effective: January 1, 2025 · Last updated: July 9, 2026

This Privacy Policy describes how Aayatti Systems Private Limited (“Aayatti”) collects, uses, stores, and protects information obtained through our enterprise HRMS platform. This policy applies to all enterprise clients, authorized administrators, and end-users accessing the platform under an enterprise account.

1. Information We Collect

Aayatti collects information necessary to provide workforce management services to enterprise clients. This includes: (a) Organizational data provided by the enterprise administrator during onboarding, including company registration details, authorized signatory information, and billing details; (b) Employee data uploaded by the enterprise, including names, employee IDs, department assignments, designation history, and bank account details for payroll processing; (c) Attendance and location data collected through our mobile and desktop applications, including GPS coordinates, network identifiers (office WiFi SSIDs), and device attestation tokens for anti-spoofing verification; (d) Where the employer has enabled it, supplemental attendance data: a background location trail for field-role employees recorded only between punch-in and punch-out during shift hours, desktop application-usage records (application name and active/idle state) from the desktop companion during work hours, and premises entry/exit events from biometric access devices; (e) Usage data generated during platform interactions, including login timestamps, action logs, and error reports submitted to our monitoring infrastructure.

2. How We Use Your Information

All data collected by Aayatti is used exclusively to provide and improve our services. Organizational and employee data is used to process payroll calculations, generate compliance filings, and produce statutory reports as required under Indian labor law. Attendance and location data is used to verify clock-in events and detect location spoofing attempts. For field-role employees whose employer enables the location trail, location is additionally recorded between punch-in and punch-out (never outside working hours or for non-field roles) — only after the employee grants explicit one-time in-app consent (declining keeps the feature off and does not prevent punching), no more often than once every five minutes or 50 meters of movement, with recording stopping automatically at punch-out or shift end — and shown to the employer’s HR team alongside that day’s punches; employees see an in-app notice and indicator whenever trail recording is active. Desktop application-usage records and premises entry/exit events, where enabled by the employer, are supporting information for manual attendance review only — they are never used to alter attendance automatically and are not used for any other purpose. Supplemental location-trail data is retained for 3 years (aligned with statutory attendance-register retention) and then permanently deleted. Usage data is used to monitor platform health, diagnose issues, and improve product features. This data is aggregated and anonymized where possible before analysis.

3. Data Storage and Tenant Isolation

Each enterprise client on the Aayatti platform is provisioned with a fully isolated tenant database. Your organization’s data is logically and physically segregated from all other enterprise tenants. Aayatti maintains this zero cross-pollination architecture as a non-negotiable infrastructure requirement. All data at rest is encrypted using AES-256-GCM. All data in transit is encrypted using TLS 1.3. Encryption keys are rotated on a scheduled basis and are unique to each tenant environment.

4. Third-Party Services

Aayatti integrates with third-party services to deliver specific functionality: Apple App Attest and Google Play Integrity APIs are used to verify the authenticity of mobile device attestation tokens — these services do not receive employee personal data; Sentry is used for real-time error monitoring and error reports are sanitized to remove personally identifiable information before transmission; payment processing for subscription billing is handled by a PCI-DSS-compliant payment processor and Aayatti does not store card numbers or banking credentials. We do not sell, rent, or share your personal data with any third party for commercial or marketing purposes under any circumstances.

5. Your Rights and Data Access

Enterprise administrators retain full control over their organization’s data within the Aayatti platform. Administrators may export complete data sets, modify employee records, and request permanent deletion of their organization’s data at any time through the administration console. Upon contract termination, Aayatti will provide a complete data export in machine-readable format within 14 business days. Following the export period, all data will be permanently and irreversibly deleted from our systems within 30 calendar days.

6. Contact and Updates

For questions or requests related to this Privacy Policy, contact our Data Protection Officer at privacy@aayatti.com. For enterprise-level Data Processing Agreements (DPAs), contact legal@aayatti.com. This policy is reviewed on a quarterly basis. Material changes will be communicated to all enterprise account holders via email at least 30 days before they take effect. Continued use of the platform following notice of a material change constitutes acceptance of the updated policy.