DATA PRIVACY & DPDP COMPLIANCEv1.0Effective: March 2026

JOY PeopleHR — Privacy Policy

Comprehensive privacy disclosures detailing how JOY PeopleHR collects, processes, stores, and safeguards personal and employee workforce data in accordance with Indian data protection laws and zero-trust standards.

Legal & Compliance Hub

Key Governance Highlights (Enterprise Overview)

✓
Strict tenant-isolated data processing with PostgreSQL Row-Level Security (RLS)
✓
Edge biometric mathematical vector hashing — raw fingerprints/facial images are never uploaded
✓
Privacy-preserving mobile geofencing active strictly during employee check-in/out timestamps
✓
Zero commercial sale of employee personal data to third-party data brokers
✓
15-day post-termination data export window prior to irreversible cryptographic purge
§ 01

1. Introduction

Joy Corporate Solutions Private Limited ("JOY", "we", "us", "our") operates JOY PeopleHR, an HR management and payroll platform available through our website, web application and mobile applications.

This Privacy Policy explains how JOY collects, uses, stores, protects and otherwise processes personal information in connection with JOY PeopleHR.

JOY is committed to handling personal information responsibly and in accordance with applicable Indian law.

This Policy should be read together with the JOY PeopleHR Terms and Conditions and, where applicable, the JOY PeopleHR Data Processing Agreement.

§ 02

2. Who This Policy Applies To

This Policy applies to:

organizations using JOY PeopleHR;

HR administrators;

managers;

employees using the mobile or web application;

authorized users;

visitors to joypeoplehr.com;

individuals who communicate with JOY.

§ 03

3. Customer-Controlled Employee Data

JOY PeopleHR is an HRMS used by organizations to manage their workforce.

In relation to employee information uploaded or generated by a Customer, the Customer generally determines the purposes for which the information is collected and used, such as employment administration, attendance, payroll, leave, HR management and statutory compliance.

JOY processes that information to provide the Service to the Customer.

Accordingly, the Customer is responsible for ensuring that it has the necessary legal basis, authority, notices, permissions and consents required for processing employee information.

The specific responsibilities of JOY and the Customer are further described in the Data Processing Agreement.

§ 04

4. Information We May Process

Depending on the Customer's configuration and the features used, JOY PeopleHR may process:

Identity and employee information

Name

Employee ID/code

Date of birth

Gender where configured

Contact details

Address

Department

Designation

Reporting structure

Employment information

Identification and KYC information

Aadhaar-related information

PAN information

Passport information

Driving licence information

Other identity documents submitted by the Customer

Payroll information

Salary

CTC

Allowances

Deductions

Bank account information

Tax-related information

PF/EPF information

ESIC information

Professional Tax information

Payslip information

Attendance information

Check-in and check-out records

Attendance history

Shift information

Working hours

Late/early departure information

Attendance regularization records

Location information

Where GPS attendance is enabled, the mobile application may process location information associated with attendance check-in and check-out.

JOY PeopleHR is designed so that location processing for attendance occurs in connection with the relevant attendance event rather than as continuous employee location surveillance.

Documents

The Service may store:

identity documents;

employment documents;

offer/appointment documents;

employee-submitted documents;

payroll documents;

other HR records.

Technical information

JOY may process:

IP address;

device information;

browser information;

operating system;

application version;

log information;

authentication information;

security events;

crash/error information.

Communication information

JOY may process information necessary for:

email;

SMS;

WhatsApp;

push notifications;

customer support;

account communications.

§ 05

5. Purposes of Processing

Personal information may be processed to:

provide JOY PeopleHR;

create and manage accounts;

authenticate users;

manage employee records;

process attendance;

process payroll;

generate payslips;

support statutory payroll calculations;

manage leave;

manage employee documents;

facilitate onboarding and offboarding;

support employee communication;

provide notifications;

provide customer support;

maintain security;

detect misuse or unauthorized access;

troubleshoot technical issues;

improve the Service;

perform analytics;

create aggregated or anonymized benchmarks;

process payments;

comply with applicable law;

enforce contractual rights;

protect JOY and its users.

§ 06

6. Payment Information

Payments may be processed through Razorpay or other authorized payment providers.

JOY may receive transaction-related information necessary to confirm payment, reconcile invoices and manage subscriptions.

JOY does not intend to store complete card credentials where payment processing is handled by the payment provider.

Payment providers may process information under their own privacy policies and terms.

§ 07

7. Cookies and Similar Technologies

The JOY PeopleHR website and applications may use cookies, local storage, SDKs or similar technologies for:

authentication;

session management;

security;

preferences;

analytics;

performance;

service functionality.

Where required by law, appropriate notices or controls will be provided.

§ 08

8. Sharing of Personal Information

JOY may disclose or provide access to personal information to:

the Customer;

authorized Customer administrators;

authorized employees/managers;

service providers;

cloud infrastructure providers;

payment providers;

SMS providers;

email providers;

WhatsApp providers;

push-notification providers;

mapping/location providers;

security providers;

professional advisors;

governmental authorities where legally required.

JOY does not sell employee personal information as a commercial product.

§ 09

9. Third-Party Service Providers

JOY may use third-party service providers to operate the platform.

These may include providers for:

cloud hosting;

payment processing;

SMS;

email;

WhatsApp;

push notifications;

maps;

analytics;

security;

authentication.

JOY expects such providers to process information only as necessary to provide their services and subject to appropriate contractual or technical safeguards.

§ 10

10. Data Hosting

JOY PeopleHR is currently undergoing infrastructure development and testing using Supabase infrastructure, including infrastructure located in the Mumbai region.

JOY currently intends to migrate the platform infrastructure to Amazon Web Services (AWS) in the future.

Infrastructure arrangements may therefore change.

JOY will update its privacy and data-processing documentation where required by applicable law or where material changes occur.

§ 11

11. International Data Transfers

JOY PeopleHR is currently intended primarily for organizations operating in India.

JOY does not currently intend to transfer Customer Data internationally as part of the standard service model.

As JOY expands internationally or changes its infrastructure/service providers, applicable international-transfer requirements and contractual safeguards will be addressed.

§ 12

12. Data Security

JOY uses reasonable technical and organizational safeguards intended to protect personal information.

Depending on the system component, security measures may include:

role-based access control;

authentication;

access restrictions;

tenant isolation;

encryption/security controls;

signed access mechanisms;

logging;

monitoring;

backup mechanisms;

security reviews;

controlled administrative access.

No electronic system can guarantee absolute security.

§ 13

13. Data Retention

JOY retains personal information only for as long as reasonably necessary for the relevant purpose, contractual requirements, security, legal obligations and legitimate business needs.

For Customer accounts that are cancelled or terminated, JOY's standard process provides a 15-day period for data export/recovery before eligible Customer Data may be permanently deleted.

Certain information may be retained longer where required by law, taxation, accounting, security, dispute resolution or other legitimate requirements.

§ 14

14. Data Deletion

Customers may request deletion of eligible Customer Data subject to:

contractual obligations;

legal requirements;

legitimate retention requirements;

security and fraud-prevention requirements;

dispute or legal-hold requirements.

Permanent deletion may affect the ability to restore or recover information.

§ 15

15. Employee Requests

Where employee information is controlled by a Customer organization, employees should generally direct requests concerning their employment data to their employer/organization.

JOY may assist the Customer in responding to valid requests where JOY is processing the information on the Customer's behalf.

Where JOY independently determines the purpose of processing particular information, individuals may contact JOY directly using the contact details provided in this Policy.

§ 16

16. Children's Data

JOY PeopleHR is designed for employment and workforce-management purposes and is not intended for children.

Customers must not create employee accounts for children except where lawful and appropriate for a genuine employment relationship and where all applicable legal requirements are satisfied.

§ 17

17. Business Analytics and Product Improvement

JOY may use aggregated, anonymized or de-identified information to:

understand product usage;

improve performance;

identify product trends;

benchmark workforce-management patterns;

improve product functionality;

develop new features.

JOY will take reasonable measures to prevent such analytics from being used to identify individual employees where the information has been properly anonymized or de-identified.

§ 18

18. Marketing Communications

JOY may communicate with customers regarding:

account activity;

billing;

service changes;

security;

product updates;

support;

relevant marketing where permitted.

Customers may opt out of non-essential marketing communications where applicable.

§ 19

19. Data Breach and Security Incidents

If JOY becomes aware of a security incident involving personal information, JOY will assess the incident and take reasonable steps to contain, investigate and remediate it.

Where required by applicable law, JOY will make required notifications.

Where JOY is processing Customer Data on behalf of a Customer, JOY will cooperate with the Customer in accordance with the applicable Data Processing Agreement.

§ 20

20. Changes to this Privacy Policy

JOY may update this Privacy Policy from time to time.

Material changes may be communicated through the website, application, email or other appropriate means.

The updated Policy will state its effective date.

§ 21

21. Contact

Joy Corporate Solutions Private Limited No.16, Krishna Complex, Avinashi - Coimbatore Road, Thennampalayam, Arasur, Coimbatore, Tamil Nadu 641407, India.

General Contact: contact@joypeoplehr.com | Support & Policies: support@joypeoplehr.com | Phone: +91 99443 99088 | Website: joypeoplehr.com

Joy Corporate Solutions Private Limited

Registered Operating Entity for JOY PeopleHR

Registered Corporate Office:

No.16, Krishna Complex, Avinashi - Coimbatore Road, Thennampalayam, Arasur, Coimbatore, Tamil Nadu 641407, India.

Jurisdiction: Coimbatore, Tamil Nadu, India

General Inquiries & Contact:✉ contact@joypeoplehr.com
Support, Policies & Helpdesk:✉ support@joypeoplehr.com
Direct Phone / Helpline:+91 99443 99088