Important Relationship Clarification (SaaS & HRMS Business Model)
To establish absolute legal clarity regarding workforce data governance under global privacy frameworks (including GDPR, CCPA/CPRA, and India's DPDP Act):
Employer / Client as Data Controller
Your employer / organization acts as the primary Data Controller for all employee master records, employment contracts, attendance logs, leave balances, compensation structures, and payroll information managed on dissolveX HRMS.
dissolveX as Data Processor
Dissolvex Technologies acts as a Data Processor providing enterprise cloud software infrastructure to automate HR workflows, attendance geo-tagging, salary disbursement calculations, and employee self-service strictly under employer instructions.
Information We Collect
In operating an end-to-end Enterprise HRMS and Workforce Management suite, dissolveX processes the following categories of information:
2.1 Information You Provide Directly
-
Employer Account Information: Corporate entity name, registered office address, designated HR administrator names, official email addresses, billing contacts, and payment authorization details.
-
Integration Credentials & API Keys: Encrypted tokens, OAuth credentials, and API connection keys provided to link third-party enterprise tools (e.g., Google OAuth, WhatsApp Meta Cloud API, biometric attendance devices, banking gateways).
2.2 HRMS & Workforce Data (Processed on Employer's Behalf)
-
Employee Identity & Profiles: Full employee names, unique employee IDs, official and personal email addresses, phone numbers, job titles, department hierarchy, emergency contact details, and dates of joining.
-
Attendance, Geo-Fencing & Shift Rosters: Clock-in/out timestamps, shift schedules, overtime calculations, geo-fenced punch coordinates (captured strictly at the moment of check-in/out without continuous background GPS tracking), and biometric verification hashes.
-
Leave & Time-Off Records: Leave quota balances, applied time-off requests, manager approvals, holiday calendars, and optional medical fitness certificates submitted for sick leave.
-
Payroll, Tax & Compensation Records: CTC breakup, salary structures, payslips, bank account numbers, IFSC codes, PAN, PF/ESI registration numbers, and investment tax declarations.
-
Performance, OKRs & Help Desk: Performance appraisal scores, manager feedback, goal/OKR tracking metrics, asset allocation receipts, and internal HR grievance tickets.
2.3 Automated Usage & Security Telemetry
-
System Telemetry & Access Logs: IP addresses, browser types, device fingerprints, login timestamps, and biometric scanner handshake logs to prevent unauthorized access and verify workplace punch integrity.
How We Use Your Information
We use the collected workforce information strictly to execute, manage, and optimize automated HR and enterprise operations:
Geo-Attendance & Shift Management
To validate geo-fenced clock-ins, monitor shift rosters, calculate overtime hours, and record real-time attendance logs.
Automated Payroll & Tax Engine
To compute monthly salary disbursements, generate encrypted PDF payslips, and calculate statutory tax and PF/ESI deductions.
Leave Tracking & Approvals
To process employee time-off applications, trigger automated multi-level manager approvals, and maintain accurate leave quotas.
Drasti AI & WhatsApp HR Desk
To answer employee HR policy queries, provide instant leave balance lookups, and dispatch shift reminders via WhatsApp securely.
System Security & Immutable Audit Ledgers
To detect brute-force login attempts, maintain tamper-evident audit trails of HR administrative actions, and ensure 99.9% uptime reliability.
Google API Services User Data Policy (Google OAuth)
Our HRMS platform includes optional enterprise integrations allowing administrators to connect Google Workspace accounts via OAuth (such as Google Calendar for interview/shift synchronization and Gmail for automated onboarding digests):
-
Limited Use Compliance: Dissolvex Technologies Private Limited's use and transfer of information received from Google APIs to any other app will adhere strictly to the Google API Services User Data Policy, including the Limited Use requirements.
-
Zero AI Model Training: We do not use Google user data or employee email payloads to train, tune, or improve artificial intelligence or machine learning models.
-
No Data Selling or Advertising: We never sell, rent, or share Google user data with third-party advertising networks or data brokers. Google data is accessed strictly to execute authorized HR automations (e.g., dispatching payslips via corporate Gmail).
Data Sharing & Third-Party Sub-processors
We do not sell or monetize employee or organizational data. We only share information with certified third-party sub-processors essential to executing HRMS services:
| Sub-processor | HRMS Functionality Scope | Data Elements Processed | Compliance Verification |
|---|---|---|---|
|
Meta Platforms, Inc.
WhatsApp Cloud API
|
Employee attendance punches, shift alerts, and leave notifications via WhatsApp | Notification payloads, employee mobile numbers | Encrypted Transit |
|
AI Providers
OpenAI, L.L.C. & Ollama
|
Drasti AI HR policy search, document summarization & helpdesk queries | Workflow text prompts (Zero public model training) | Zero Retention API |
|
Cloud Infrastructure
MongoDB Atlas, AWS
|
Encrypted employee master database hosting & file storage | Multi-tenant HRMS databases & document vaults | SOC-2 & ISO 27001 |
|
Payment Gateways
Razorpay / Stripe
|
HRMS SaaS subscription billing & tokenized payment settlements | Employer billing metadata, invoice IDs | PCI-DSS Level 1 |
Data Security & HRMS Protection Standards
To safeguard sensitive workforce records, dissolveX enforces end-to-end administrative, technical, and physical security standards:
TLS 1.3 & AES-256
All data in transit is encrypted via TLS 1.3. Databases and document attachments are encrypted at rest with AES-256.
Biometric Hash Safeguards
Facial and fingerprint check-in devices convert punches into one-way cryptographic hashes. Raw biometric photos are never stored.
Multi-Tenant DB Isolation
Strict logical database segregation prevents cross-tenant data bleed across different employer workspaces.
Payroll & Tax Encryption
Salary structures, PAN, and bank accounts are protected with field-level encryption and role-based access tokens.
Immutable Audit Logs
Every administrative view, export, or edit of employee PII is stamped in a tamper-proof audit trail with timestamp and IP.
Role-Based Access (RBAC)
Granular permission tiers (Super Admin, HR Manager, Manager, Employee) ensure zero unauthorized profile visibility.
Your Rights & Choice
Under global privacy regulations (including GDPR, CCPA, and DPDP Act), employers and individual employees possess essential statutory rights:
Access & Rectify
Employees can review and request corrections to inaccurate personal profiles or attendance punches via HR admins or ESS.
Data Portability & Export
Employers can export structured machine-readable backups (JSON/CSV) of employee records and payroll ledgers at any time.
Right to Erasure (30-Day Purge)
Upon workspace decommissioning, all employee master records and uploaded documents are permanently purged within 30 days.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect enhancements to our HRMS platform, new statutory compliance standards, or security upgrades. When updates are published, we will revise the “Last Updated” date at the top of this document and notify registered HR administrators through in-app notices or official email broadcasts.
Contact Us
If you have questions, inquiries, or grievance requests regarding our HRMS privacy architecture or data security standards, please contact our Data Protection Team at inquire@dissolvex.in.