Privacy Policy
This policy describes how AuraX HRM collects, uses, and protects personal and workplace data across the web dashboard and mobile application.
1. Scope and who this applies to
This Privacy Policy applies to all users of the AuraX HRM platform — employees, HR managers, and company administrators — who access the service through the web dashboard or the mobile application.
AuraX HRM is a Human Resource Management platform deployed for and operated by your employer (referred to as “the Company”). The Company is the data controller for its employees’ data. AuraX HRM acts as the data processor, handling data on behalf of the Company in accordance with this policy.
By using AuraX HRM, you acknowledge that the Company has engaged AuraX HRM to process your data for the purposes described below.
2. Data we collect
2.1 Identity and profile data
- Full name, employee ID, and job title
- Department and reporting manager
- Contact details: work email address and phone number
- Date of joining and employment status
- Profile photo (if provided)
- Salary and compensation details
2.2 Attendance data
- Check-in and check-out timestamps (date and time)
- GPS coordinates (latitude and longitude) captured at the time of each punch
- Selfie photographs taken during punch-in and punch-out via the mobile app
- Total hours logged per day and monthly aggregates
- Attendance status: present, absent, half-day, on leave, or public holiday
- Regularisation requests and supporting notes
2.3 Leave data
- Leave type, start and end dates, and half-day designations (morning/evening)
- Leave request status and reviewer notes
- Annual leave balances per leave type
- Compensatory leave credits and the associated work dates that generated them
2.4 Payroll data
- Monthly payslip records including earnings, deductions, and net pay
- Payroll head configuration (component names and values)
- Loan repayment EMI amounts deducted from payslips
2.5 Loan and financial data
- Loan application details: amount, EMI count, repayment start month, and applicant notes
- Loan approval or rejection status and reviewer notes
- Full EMI repayment schedule
2.6 Tour expense data
- Tour dates, customer names, and team members associated with a tour
- Advance amounts requested and approved
- Daily expense entries (date, description, amount) submitted during the tour
- Settlement status, balance owed, and reviewer notes
2.7 Documents
- Uploaded employee documents such as employment contracts, government-issued ID proofs, certificates, and other records
- Document titles, upload dates, and expiry dates where applicable
2.8 Communication data
- Company notices posted by HR and company administrators, including any attached files
- Company policy documents (PDFs) uploaded and made available to employees
2.9 Technical and usage data
- Authentication tokens (JSON Web Tokens) used to maintain login sessions
- Device type and operating system version (mobile app)
- API request logs for security and debugging purposes
3. How we use your data
Data collected by AuraX HRM is used exclusively for the following purposes:
- Authenticating users and maintaining secure login sessions
- Recording and verifying daily attendance, including location and identity verification via GPS and selfie
- Processing leave requests, tracking balances, and managing HR approvals
- Generating accurate monthly payslips that incorporate real attendance data, leave taken, and loan repayments
- Managing employee loan applications, approval workflows, and automated EMI deductions in payroll
- Processing tour expense advances and settlement claims
- Maintaining an employee document repository with expiry tracking
- Distributing company notices and policy documents to relevant employees
- Providing HR and company administrators with workforce analytics, attendance reports, and leave summaries
- Audit logging to support compliance and dispute resolution
We do not use your data for marketing, advertising, or any purpose outside of operating the HR management functions described above.
4. Who can access your data
4.1 You (employee)
You can view your own attendance records, leave history and balances, payslips, loan schedule, tour expenses, and uploaded documents. You cannot view another employee’s data.
4.2 HR managers
HR managers within your company can access attendance records, leave requests, loan applications, compensatory leave claims, and employee profile details for all employees in the company. They cannot access data belonging to employees of other companies on the platform.
4.3 Company administrators
Company administrators have the same access as HR managers and can additionally manage payroll structures, approve tour expense settlements, configure attendance settings, and manage leave policies.
4.4 AuraX HRM
AuraX HRM staff may access data only when required to provide technical support, investigate a reported issue, or fulfil a legal obligation. All such access is logged.
4.5 Third-party service providers
Attendance selfie photographs and company policy documents are stored using Google Cloud Storage (GCS). Google processes this data solely to provide the storage service and is bound by its own data processing agreement. No other third parties have access to your personal data.
5. Data storage and security
All structured data (profiles, attendance records, payroll, leaves, loans) is stored in a MongoDB database hosted on a secured server with access restricted by firewall rules and credential-based authentication.
File uploads — including attendance selfie photographs, company policy PDFs, and notice attachments — are stored in Google Cloud Storage (GCS) with access controlled via signed URLs.
The following security measures are in place:
- All communication between clients and the server is encrypted over HTTPS/TLS
- Authentication uses short-lived JSON Web Tokens (JWT); tokens are stored in secure storage on mobile and in httpOnly cookies on web
- Database access is restricted to the application backend; no direct public database connections are permitted
- GPS coordinates and selfie photos are transmitted only over encrypted connections and stored with access controls
No system is completely immune to security risks. In the event of a data breach that affects your personal data, your employer and AuraX HRM will notify affected users in accordance with applicable law.
6. Retention periods
Data is retained for as long as your employment record is active on the platform and for a reasonable period thereafter to support payroll audits, legal compliance, and dispute resolution. The Company, as data controller, is responsible for setting and enforcing data retention policies for its employees.
- Attendance records and payslips: retained for the duration of employment and a minimum of 3 years after the last payslip generation
- Selfie photographs from attendance punches: retained as part of the attendance record for the same period
- Leave records and loan schedules: retained for the duration of the associated financial or HR record
- Authentication logs: retained for up to 12 months for security purposes
Upon termination of the Company’s account with AuraX HRM, all data associated with that company can be exported and will be deleted from our systems within 90 days, unless a legal hold applies.
7. Your rights
Depending on applicable law, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you
- Correction: request that inaccurate or incomplete data be corrected
- Deletion: request deletion of your data, subject to legal and contractual retention requirements
- Portability: request your data in a structured, machine-readable format
- Objection: object to processing that is not strictly necessary for the employment relationship
Because AuraX HRM operates as a processor on behalf of your employer, requests to exercise these rights should first be directed to your HR department or company administrator. AuraX HRM will assist the Company in fulfilling such requests promptly.
8. Mobile app permissions
The AuraX HRM mobile application requests the following device permissions:
- Camera — required to capture the attendance selfie during punch-in and punch-out. Photos are not stored on the device after upload.
- Location (GPS) — required to record your GPS coordinates at the time of each attendance punch. Location is only accessed when you actively initiate a punch; the app does not track your location in the background.
- Storage (read/write) — required on some Android versions to temporarily process the selfie image before upload.
- Internet access — required to communicate with the AuraX HRM backend.
You may revoke camera or location permissions from your device settings at any time, but doing so will prevent the attendance punch functionality from working correctly.
9. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify users via the Notice Board in the application.
Continued use of AuraX HRM after changes are posted constitutes acceptance of the updated policy.
10. Contact
If you have questions about this Privacy Policy, or wish to exercise any of the rights described in Section 7, please contact your HR department in the first instance.
For platform-level data concerns, you may also write to the AuraX HRM team via the contact details provided by your company administrator.