Privacy Policy
This policy explains how Hyluminix Infosystems Private Limited (“we”, “us”) handles personal data when a business (“the tenant”, “your employer”) uses the Hyluminix HRMS service, including its Android companion app “HRMS Attendance”. It covers the people who administer a tenant account and the employees whose records a tenant keeps in the service.
Who is responsible. For an employee's HR data, the employer (the tenant) is the data controller and decides what is collected and why. Hyluminix Infosystems Private Limited is the data processor that stores and processes that data only to provide the service to that tenant. For the account data of the person who signs a tenant up, we are the controller.
1. What we collect
- Account and administrator identity: the administrator's name, work email address, an optional phone number, a hashed password, and the company/tenant name and workspace address.
- Employee records: the details a tenant enters for its staff — name, contact details, employment details such as department, designation and joining date, and payroll-related components needed to produce payslips and statutory reports.
- Attendance and leave: attendance punches and timestamps, shift assignments, leave balances and leave requests.
- Optional GPS location at a punch: when a tenant switches on GPS attendance, the device location is captured at the moment of a punch so the punch can be tied to a place. This is a single position per punch, not a continuous record.
- Optional field/trip tracking location (background location): when a tenant switches on field tracking and an employee starts a tracking session for their shift, the app collects the device's position repeatedly — including while the app is in the background or the screen is off — so the employee's route for that shift can be recorded. It runs only while a session the employee started is active, and it stops when the session ends, when the employee ends it, and when the shift auto-closes at the end of the day. This is disclosed in the app and requires the device location permission to be granted, including the “Allow all the time” option on Android 10+.
- Optional face recognition (biometric data): when a tenant switches on the face-attendance service, the image captured at check-in is sent to our servers, where it is processed into a face template and compared to the employee's enrolled template to confirm attendance. This is biometric data and is processed only with the employee's explicit consent. Face detection on the device itself uses Google's on-device ML Kit and does not send anything to Google.
- Push notification token: when you sign in on a phone, a notification token issued by Google Firebase Cloud Messaging is stored against the account so the app can deliver attendance reminders and alerts. The token identifies the app installation, not the person; it is removed when the account or tenant is deleted.
- Device and technical logs: IP address, browser/app user agent, request timestamps, app version and the device/session identifiers the tracking feature uses, kept to secure the service and diagnose faults.
2. Why we process it and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Provide the HRMS: records, attendance, leave, payroll and reports | Performance of the contract with the tenant |
| Secure the service, prevent abuse and support users | Our legitimate interest in running a safe service |
| GPS location at the moment of a punch | Consent, given through the app, which can be withdrawn |
| Field/trip tracking location while a tracking session is active (background location) | Consent, given through the app and the Android location permission, which can be withdrawn |
| Face recognition attendance (biometric template + match score) | Explicit consent, given through the app, which can be withdrawn |
| Statutory payroll, tax and attendance records | Compliance with a legal obligation |
3. Face recognition and biometric consent
Face recognition is an optional add-on. It is only active for a tenant that has bought and enabled it, and for an employee who has given explicit consent. The consent can be revoked at any time; once revoked, face attendance stops for that employee and the enrolment template is deleted as described in the deletion sections below. Biometric data is never used to identify a person outside the attendance purpose and is never sold.
4. How long we keep it (retention)
We keep personal data only for as long as the table below says. When a period ends, the data is deleted. An employee's employer (the tenant) controls the HR records, so the employer decides how long it keeps them for its own purposes; the platform does not keep them for longer than that. Deletion can also be requested at any time — see the Delete Account page.
| Data | Retention period | What happens at the end |
|---|---|---|
| Administrator and account data — name, work email, optional phone, hashed password, company name and workspace address, and the push-notification token of each device you sign in from | Kept while the tenant subscription is active. Deleted when the tenant is deleted: the tenant database (all of the above plus all employee data) is dropped. | On deletion the tenant database is destroyed and its database credentials are removed. A tombstone (tenant name, slug, contact email, status, deletion date) is kept in the platform control database so the deletion can be audited and cannot be replayed; it holds no credentials and no employee data. |
| Employee records and documents — profile, contact and employment details, uploaded documents and attachments | Kept while the tenant subscription is active. The tenant (the employer, which controls this data) decides how long it keeps them for its own HR purposes. | Deleted with the tenant database when the tenant is deleted. An employer can ask us to erase an individual record earlier. |
| Attendance, shift, leave and payroll records (including payslips, statutory reports and the records needed to produce them) | Kept while the tenant subscription is active, and afterwards only for the period the employer is required to keep them by statutory payroll, tax or attendance law. The employer sets that period; we do not extend it. | Deleted at the end of the tenant's required period or when the tenant is deleted, whichever comes first. An employer can request export or earlier erasure of what it is not required to keep. |
| GPS punch locations — the device position captured at the moment of an attendance punch | Maximum 90 days. | Deleted after 90 days, or immediately on request or when the account/tenant is deleted. |
| Field tracking positions — the position stream recorded while an employee has a tracking session running (background tracking) | Maximum 90 days. | The position stream expires after 90 days. The daily travel summary that belongs to the tenant's own attendance record for that employee is kept with the tenant's records (see above) and is deleted with them. |
| Face-recognition data — the biometric consent record, the face template (embedding) and the encrypted enrolment source image | The enrolment image is kept for a maximum of 90 days from capture, and is deleted immediately when consent is withdrawn or the account/tenant is deleted. Consent records are kept as evidence of the consent you gave. | On withdrawal or deletion the stored image and template are erased and the template is marked superseded, so face attendance stops. The consent ledger entry (and a template row with no image, kept only as proof that erasure happened) is deleted with the tenant database. |
| Task and project module content — form responses, activity logs, import logs and completion GPS coordinates | Form responses: 730 days. Activity and import logs: 365 days. Completion GPS coordinates: 90 days. | Each is deleted when its period is reached (completion GPS is cleared from the record and the audit row is kept); all of it is deleted with the tenant database. |
| Technical and application logs — IP address, user agent, request timestamps and errors | 14 days, on a rotating daily log. | Deleted automatically when the 14-day log file rotates out. |
| Commercial records — the order recorded against a subscription (plan, cycle, user count, amount, currency) | Kept while the tenant is active and afterwards for as long as tax and accounting law requires. | Deleted at the end of that period. No card or bank details are stored by the service: payment is handled by the payment provider. |
5. Cookies and similar technologies
The website sets only the cookies needed to serve the pages and process the forms you submit. They are listed here in full:
| Cookie | Purpose | Lifetime |
|---|---|---|
| hrms_session | Strictly necessary. Identifies your browser session so forms work and, after you sign in, so you stay signed in. | 120 minutes (a new cookie is issued on the next request after it expires). |
| XSRF-TOKEN | Strictly necessary. Carries the cross-site request forgery token that protects every form on this site from being submitted by another website. | Same as the session cookie. |
We set no advertising, analytics or profiling cookies, and we run no third-party analytics on this site, so no cookie-consent choice is required: the two cookies above are strictly necessary to serve the pages and process the forms you submit. Our public pages request webfonts, an icon font and a JavaScript library from third-party content delivery services (Google Fonts, Material Design Icons, the Google-hosted jQuery library), which receive your IP address as part of serving that content.
The browser part of the service stores no cookie of its own for tracking: the two cookies above are the only ones it sets. The Android app does not use cookies to track you; when you sign in it stores a session token on the device, as described in the app's own disclosures.
6. Who we share it with
We do not sell personal data. We share it only with the sub-processors needed to run the service, and with authorities where the law requires it.
- Hyluminix Communication Gateway — transactional email (signup, password, notifications)
- Google Firebase (Cloud Firestore + Cloud Messaging) — storage of field-tracking position data and delivery of app push notifications
- Google Maps Platform — map display and address lookup for coordinates inside the mobile app
- Cashfree Payments — subscription payment processing, when a paid plan is purchased
Each sub-processor is bound to process data only on our instructions and to keep it confidential.
7. Security and tenant isolation
- Each tenant has its own isolated database, so one tenant's data is never mixed with another tenant's.
- Data is encrypted in transit between the app/browser and the service. Biometric enrolment images are stored encrypted at rest.
- Access is restricted to authorised users, and administrator accounts are protected by authentication.
8. Your rights and how to raise a grievance
Subject to applicable law, you can ask to access the personal data held about you, to correct it, to erase it, and to withdraw consent for GPS location, field tracking, or face recognition. An employee's HR records are controlled by the employer, so requests about those records are normally made through the employer's HR administrator; we help the employer respond. To exercise a right, email privacy@hyluminix.com.
Grievance Officer & Data Protection Officer
Prabeer Kochar
Email: privacy@hyluminix.com
Address: A-12, E-8 Extension, Near Shweta Mandir, Gulmohar, Venkatesh Nagar, Bhopal, Madhya Pradesh 462010, India
A privacy or data-protection complaint or grievance can be sent to this contact.
We acknowledge a grievance within
2 business days and answer it within
30 days.
The general privacy mailbox stays open for access, correction and erasure requests: privacy@hyluminix.com. If you are not satisfied with the answer you receive from the officer above, you can escalate: If you are not satisfied with the answer you receive, mark your email “Escalation” and send it to the general privacy mailbox; you may also complain to the Data Protection Board of India.
9. Children's data
This is a workplace service. We do not knowingly collect personal data from children. If you believe a child's data has reached the service, contact us and we will delete it.
10. Who is responsible, and under which law
The service is operated by Hyluminix Infosystems Private Limited (A-12, E-8 Extension, Near Shweta Mandir, Gulmohar, Venkatesh Nagar, Bhopal, Madhya Pradesh 462010, India). For your employer's employee records, your employer (the tenant) is the data fiduciary and we process the data on its instructions; for the account you sign in with, we are the data fiduciary for the limited purpose of running the service.
We follow the following Indian law in how this data is handled:
- Information Technology Act, 2000
- IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
- Digital Personal Data Protection Act, 2023 (principles applied)
These pages are governed by the laws of India, with jurisdiction at Madhya Pradesh, India.
11. Changes to this policy
We may update this policy to reflect changes in the service or the law. The effective date at the top shows the current version, and material changes will be communicated to tenant administrators.
12. Contact
Privacy questions and data requests: privacy@hyluminix.com. General support: info@hyluminix.com, Mon–Sat, 10:00–18:00 IST, excluding public holidays — we reply within 1 business day. Full support hours and response times are on the Contact & Support page. Phone: +91 92430 77840.