Privacy & Data Security Policy
Last updated: June 15, 2026
1. Information Collected & Encryption Protocols
WorkforceOS is a modular HRMS platform that processes human resources, compliance, and payroll records on behalf of your employer (the subscribing Organization). We collect and store:
- Employee Profiles & Identifiers: Legal names, corporate emails, emergency contact logs, PAN numbers, and Aadhaar numbers.
- Encrypted Bank & Financial Data: Employee bank accounts, IFC codes, and salary details are strictly subjected to hardware-accelerated AES-256-GCM field-level encryption before being committed to our PostgreSQL database, securing them against unauthorized read access.
- Shift Attendance Logs: GPS coordinates and client IP addresses captured during Office (WFO) or Remote (WFH) shift check-ins to prevent time spoofing, alongside logs of individual break durations.
- Performance & Task History: Task assignments, lifecycle state transitions, quality ratings, peer reviews, and qualitative HR evaluations.
2. Processing Scope & Access Control
Data processing is strictly confined to the operations of the subscribing organization. We utilize your data to calculate monthly payrolls (incorporating LOP absent rules and Indian statutory calculations), verify leave double-approval structures, track OKR progress, and log audit entries.
All views and endpoints are guarded by a robust Role-Based Access Control (RBAC) middleware layer, ensuring that sensitive data such as salary slips, audit logs, and employee profiles are accessible only to authorized Org Admins or HR Managers.
3. Immutable Auditing & Zero Data Sharing
WorkforceOS does not share, lease, or sell organization databases or individual attendance histories to third-party data analytics or advertising companies.
Every data creation, modification, or deletion is recorded in our immutable Audit Log, documenting the actor ID, timestamp, before/after values, and IP address. This log cannot be deactivated or cleared by organization administrators, guaranteeing compliance and data traceability.
4. Retention & Deletion Rights
Organization databases are isolated. Deletion requests for specific employee profiles, credentials, or audit tracks must be directed to your organization administrator. Upon license expiration or termination, all isolated database instances are soft-deleted immediately and permanently wiped from our server backups within 30 days.
