MyHRMS — Privacy Policy

Last updated: 20 August 2026

MyHRMS ("the App") is a workforce-management application provided by MyHRMS ("we", "us") to its employees and authorised staff. This policy explains what data the App collects, why, and how it is protected. The App is intended for internal organisational use only.

Who this applies to

The App is used by employees of the organisation that deploys it. Your employer is the data controller; we process data on their behalf to provide attendance, leave, and HR functionality.

Data we collect

  • Account & identity: name, work email, phone number, employee ID, role.
  • Precise & approximate location: collected during attendance punch in/out and, while you are checked in, in the background — to count the work travel you can claim as reimbursement, to keep your recorded hours accurate if you leave your work site mid-shift, and to give you your own record of both in the app. Background collection occurs during an active work session and, if you raise an emergency SOS alert, until that alert is closed. It requires your permission and can be switched off at any time.
  • Camera / photos: a photo captured at attendance punch for verification.
  • Face data (biometric): a facial image captured at punch is compared against your enrolled reference image to confirm identity. Face images are treated as sensitive biometric data. Enrolment requires your consent. See Face data (biometric) below for full detail of collection, use, sharing, storage, retention and deletion.
  • Device identifiers: a device fingerprint used to bind attendance to your approved device and prevent fraud.
  • Attendance & HR records: punch times, work sessions, leave requests, and related HR data you submit.
  • Travel distance: kilometres derived on our servers from your recorded shift positions, and any mileage claim you submit. The app never sends a distance figure; you can see the day-by-day legs behind every number.
  • Emergency alerts & safety check-ins: SOS alerts you raise, your position while an alert is open, and a copy of your emergency contact, so responders can reach you when you work alone.
  • Motion & activity sensors (iOS): used on your device to refine location readings so your travel distance is not under-counted.

Face data (biometric)

This section describes, in full, what face data the App collects and everything we do with it. Face data is treated as sensitive biometric information and is handled separately from all other data in this policy.

What face data we collect

The App collects facial photographs only — ordinary images captured by your device camera, taken by you: one reference photo when you enrol, after you give explicit consent on the enrolment screen, and one attendance photo each time you check in or check out.

We do not create, derive or store a faceprint, face template, face embedding, face geometry map or any other mathematical representation of your face. We do not enrol you in any face database or face collection, and we do not use face data to identify you anywhere outside your own attendance records.

While a capture screen is open, the App runs a check on your device to confirm a live person is in frame (for example, asking you to blink). That check runs entirely on your device, is used only to decide when to take the photo, and its data is discarded immediately — it is never transmitted or stored.

How face data is used

Solely to verify that the person recording an attendance punch is the employee the punch is recorded against. Your attendance photo is compared with your enrolled reference photo and the comparison produces a similarity score and a pass/fail result, which are stored against that attendance record. Face data is never used for advertising or marketing, is never sold, is never used to track you across other apps or websites, and is never used for any purpose other than the attendance verification described here.

Sharing and third parties

Face data is not sold, rented or shared with any third party for that third party's own purposes, and is never disclosed to advertisers, data brokers or analytics providers.

One third-party service provider processes face images strictly on our instructions: Amazon Web Services (AWS). Images are stored in Amazon S3 and the face comparison is performed by Amazon Rekognition, using stateless comparison operations that return only a similarity score. No face collection, face template or face identifier is created or retained in Amazon Rekognition. AWS acts as our processor and may not use the images for its own purposes.

Within your organisation, your enrolled reference photo can be viewed only by your employer's authorised HR and administrator users, and every such view is recorded in an access log. Data belonging to one organisation is never visible to another.

Where face data is stored

All face images are stored in a private, access-controlled Amazon S3 bucket hosted in the AWS Asia Pacific (Mumbai), India region. The bucket blocks all public access; images are never served from a public URL. When an authorised user views an image, the App issues a single-use link that expires within 5 minutes. All transmission uses TLS/HTTPS encryption, and images are encrypted at rest in Amazon S3.

How long face data is retained

  • Attendance photos (each punch): 90 days. They are then deleted automatically by a scheduled daily job. An employer may configure a longer period where its own legal or payroll-record obligations require it; the period in force is available from your HR team.
  • Enrolled reference photo: kept only while you are enrolled. It is deleted when you withdraw consent, when your employer revokes the enrolment, or when your employment record is closed — and in all of those cases no later than 30 days after that event. There is no indefinite retention of face data.

When an image is deleted, the image file itself is destroyed. The attendance record it belonged to keeps only its date, time and verification result, which contain no biometric data.

Deleting your face data, and withdrawing consent

Face capture happens only with your explicit consent, given on the enrolment screen before any photo is taken, and you may withdraw that consent at any time. To withdraw consent and have your enrolled face image deleted, contact your HR administrator or email us at ankitlathwal19198@gmail.com. The image is deleted within 30 days of the request, and normally the same day it is processed. You do not have to give a reason.

Because attendance verification depends on a reference image, you will not be able to record attendance in the app after deleting it unless you enrol again. Withdrawing consent has no effect on your pay, your leave, or any other part of your employment record.

Why we collect it

Solely to operate the App's core functions: paying you for the travel and hours you actually worked (mileage claims, timesheets you can dispute), lone-worker safety (emergency alerts and check-ins), attendance capture and verification, work-site geofencing, fraud prevention (device + face + location checks), and leave and HR management. We do not use your data for advertising and do not sell it.

How it is stored and shared

Data is transmitted over encrypted HTTPS connections to servers operated for your organisation, and photos/biometric images are stored in a private, access-controlled cloud storage bucket. Access is restricted to authorised HR/administrator roles within your organisation. We do not share your data with third parties for their own purposes.

Data retention

Attendance and HR records are retained for the period required by your organisation's policy and applicable law.

Attendance photos are deleted 90 days after capture by a scheduled daily job. Your enrolled face reference photo is deleted when you withdraw consent, when the enrolment is revoked, or when your employment record is closed — in every case within 30 days. Face data is never retained indefinitely. Full detail is in Face data (biometric).

Security

All network traffic uses TLS/HTTPS. Passwords are hashed. Biometric images reside in private storage with role-gated, audited access.

Your rights

You may request access to, correction of, or deletion of your personal data, and withdraw biometric consent, by contacting your HR administrator or emailing ankitlathwal19198@gmail.com. Withdrawing biometric consent may limit attendance features that rely on face verification.

Contact