Privacy Policy
Effective Date: September 2026 | Last Updated: September 2026
1. Introduction
Grapeit ("We," "Us," "Our") operates a payroll and human resources management platform. This Privacy Policy explains how we collect, use, process, and protect personal data when you use our Service.
Our Commitment: We comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) and treat your data with the highest standards of security and confidentiality.
2. Who We Are & Our Role
Data Controller & Processor Relationship
- You (the organization) are the Data Controller—you decide what personal data to collect and how it's used
- We (Grapeit) are the Data Processor—we process data on your instructions to deliver the Service
This Privacy Policy covers our processing practices as a Data Processor. You are responsible for obtaining consent from employees and individuals whose data you input into Grapeit.
3. Types of Personal Data We Process
3.1 Employee Data (Collected by You)
When you input employee information into Grapeit, we process:
- Identity: Name, employee ID, date of birth, gender, marital status
- Contact: Email address, phone number, physical address
- Financial: Bank account details, salary, bonuses, allowances, deductions, tax information
- Employment: Job title, department, reporting manager, employment dates, contract type
- Attendance: Clock-in/out times, leave requests, leave balance, shift information
- Compliance: PAN, Aadhaar number (if collected for payroll processing), ESI details, PF details
- Health/Sensitive: Medical leave records, disability status, dependents information
3.2 Organization Data (Collected by Us)
When you create an account or use the Service, we collect:
- Account: Organization name, industry, size, registered address, GST/MSME details
- Contact: Email, phone number, business contact person
- Usage: Features used, API calls, report generation, login frequency, session duration
- Device: IP address, browser type, operating system, approximate location (country/city level)
- Support: Support tickets, feedback, communication records
3.3 Data You Choose to Provide
- Customizations, preferences, settings within the Service
- Documents you upload (e.g., policies, templates, forms)
- Voluntary feedback, survey responses, or feature requests
4. Legal Basis for Processing Personal Data
4.1 Employee Data
We process Employee Data (salary, identity, bank details) based on:
- Your Consent: You have collected lawful consent from employees to process their data
- Contractual Necessity: Processing is necessary to fulfill your payroll obligations and employment contracts
- Legal Obligation: Compliance with tax law, labor laws (Minimum Wages Act, PF Act, ESI Act, Gratuity Act, Income Tax Act)
- Legitimate Interest: Payroll accuracy, fraud detection, security monitoring
4.2 Organization Data
We process on the basis of:
- Contractual Necessity: Required to deliver the Service
- Legitimate Interest: Service improvement, security, compliance, analytics
4.3 Sensitive Personal Data
Data like Aadhaar, PAN, bank account details, health information, or biometric data (if you integrate attendance devices) is processed only with explicit consent for payroll/compliance purposes.
5. How We Use Personal Data
5.1 Service Delivery
- Process payroll and calculate deductions (PF, ESI, income tax, professional tax)
- Generate salary slips, payment advices, and statutory registers
- Manage employee records, attendance, leave, and benefits
- Enable you to run compliance reports (Form 12A, DSC, ECR, etc.)
- Process reimbursements and expense claims
- Generate analytics dashboards for HR and payroll insights
5.2 Security & Fraud Prevention
- Detect and prevent unauthorized access or misuse
- Monitor for suspicious activity (multiple failed logins, unusual data exports)
- Investigate security incidents
- Protect against data breaches and cyberattacks
5.3 Legal Compliance
- Respond to regulatory requests (Income Tax Department, Labor Commissioner, RBI, NRLM audits)
- Maintain records for statutory compliance
- Fulfill legal obligations under applicable laws
- Support audit trails for tax authorities
5.4 Service Improvement
- Analyze aggregated, anonymized usage patterns (e.g., most-used features, error rates)
- Develop new features and improve existing ones
- Conduct research on payroll best practices (without identifying individuals)
- Create benchmarking reports for HR metrics
5.5 Communication
- Send transactional emails (password reset, invoice, account updates)
- Notify you of system maintenance, outages, or security alerts
- Respond to your support requests
- Provide educational content on payroll compliance and HR best practices
5.6 What We Do NOT Do
- We do NOT sell, rent, lease, or trade employee data
- We do NOT use employee data for marketing or advertising
- We do NOT share employee data with third-party marketers or data brokers
- We do NOT use data to profile individuals for decisions that significantly affect them (automated decision-making)
6. Who We Share Data With
6.1 Service Providers & Sub-Processors
We engage third parties who process data on our behalf:
- Cloud Hosting: Infrastructure, backup, disaster recovery (all data encrypted)
- Payment Gateway: Process subscription payments (billing data only, no employee data)
- Email Service: Send transactional emails (email addresses, transaction data)
- SMS Provider: Optional SMS notifications (phone numbers, notification content)
- Analytics: Usage analytics, feature adoption (anonymized, aggregated data only)
- Support Tools: Manage support tickets (support request content only)
- Compliance Partners: Statutory filing support (form data as specified in your agreement)
All sub-processors are contractually bound to:
- Process data only as instructed by us
- Implement security standards equivalent to ours
- Not disclose data to unauthorized parties
- Delete or return data upon termination
6.2 Legal & Regulatory Disclosure
We may disclose personal data if required by law:
- Court orders, search warrants, or judicial decrees
- Regulatory requests from Income Tax Department, Labor Commissioner, RBI, or other authorities
- Enforcement of our Terms of Service or protection of legal rights
We will attempt to notify you before disclosing data unless legally prohibited.
6.3 Business Transfers
If Grapeit is acquired, merged, or sold, personal data may be transferred as part of the transaction. We will provide 30 days' notice and allow you to opt out.
6.4 No Unauthorized Sharing
We do NOT share data with:
- Third-party marketers, advertisers, or data brokers
- Competitors or external analytics vendors
- Any party without your explicit consent (except as legally required)
7. Data Retention
7.1 Active Account
While you use Grapeit, we retain all Customer Data (employee records, payroll history, reports) to deliver the Service.
7.2 After Account Termination
- Employee Data: 90 days (allows export and backup retrieval)
- Backup Copies: 30 days after deletion (disaster recovery only)
- Legal/Tax Data: 7 years (compliance with IT Act, labor law, tax law)
- Audit Logs: 2 years or as required by law (security, compliance verification)
- Account Data: 5 years (tax and accounting requirements)
7.3 Your Rights
- You may request data deletion at any time via dpo@grapeit.in
- We will delete non-legally-required data within 30 days
- Legally-required data (tax records) is retained per statutory obligations
- You may export your data at any time for portability
8. Data Protection & Security
8.1 Technical Measures
- Encryption at Rest: AES-256 encryption for all stored data
- Encryption in Transit: TLS 1.2+ for all data transmitted over the internet
- Access Control: Role-based access control (RBAC); employees access only what they need
- Audit Logging: All data access and modifications are logged and monitored
- Firewalls & Intrusion Detection: Network perimeter protection and real-time threat monitoring
- Multi-factor Authentication (MFA): Optional MFA available for account security
- Regular Security Updates: Timely patching of vulnerabilities and software updates
8.2 Organizational Measures
- Data Protection Training: Our team receives annual DPDP Act and data security training
- Access Restrictions: Only authorized personnel access Customer Data; access is logged
- Confidentiality Agreements: All team members sign confidentiality agreements
- Third-Party Audits: Annual security assessments and penetration testing
- Incident Response Plan: Documented procedures for breach detection and response
- Backup & Disaster Recovery: Daily automated backups stored in geographically distinct locations
8.3 Your Responsibility
You are responsible for:
- Keeping your account credentials (username, password) confidential
- Enabling multi-factor authentication if available
- Monitoring for unauthorized access and notifying us immediately
- Ensuring employees consent to data collection before inputting their data
- Compliance with data collection and processing laws in your jurisdiction
8.4 What We Cannot Guarantee
- No system is 100% secure; cyber threats are constantly evolving
- We cannot guarantee protection against advanced, targeted attacks
- We are not liable for breaches resulting from your actions (weak passwords, compromised credentials)
9. Data Breach Notification
9.1 Our Obligations
If we discover a personal data breach that poses a risk to individuals, we will:
- Notify you within 72 hours of discovery (as required by DPDP Act)
- Provide details of nature of breach, likely consequences, measures taken, and our contact information
9.2 Your Obligations
As Data Controller, you must:
- Notify affected individuals without undue delay (if required by law)
- File a complaint with the Data Protection Board if individuals' rights are violated
- Document the breach and our response
- Assess the risk to individuals and report to authorities if required
9.3 Cooperation
We will cooperate with your breach investigation, provide forensic details, and support your notifications to individuals and regulators.
10. Data Subject Rights (Under DPDP Act)
If you are an employee whose data is processed by Grapeit, you have the following rights:
10.1 Right to Access
- You may request confirmation of whether your personal data is being processed
- You may request a copy of your data in a structured, commonly used format
- Request contact: Your organization's HR or dpo@grapeit.in
- Response time: Within 30 days of request
10.2 Right to Correction
- You may request correction of inaccurate or incomplete data
- Example: Incorrect salary figure, wrong address
- We will update data and notify you of changes
10.3 Right to Erasure
- You may request deletion of your data (subject to legal retention obligations)
- We cannot erase data required for tax compliance, legal holds, or ongoing employment
- Non-compliance data will be deleted within 30 days
10.4 Right to Data Portability
- You may request your data in a structured, machine-readable format (CSV, Excel, JSON)
- Useful for switching payroll systems or transferring to another organization
- We will provide data within 30 days of request
10.5 Right to Grievance Redressal
If you believe your data rights are violated, you may:
- Submit a grievance to your organization
- Contact our Data Protection Officer at dpo@grapeit.in
- File a complaint with the Digital Personal Data Protection Board (established under DPDP Act)
11. International Data Transfers
11.1 Data Localization
All personal data is stored and processed within India (data centers in ap-south-1 region). We do not transfer employee data outside India without explicit consent, as required by DPDP Act and Reserve Bank guidelines.
11.2 Exception: International Customers
If your organization is based outside India but uses Grapeit, or if you have EU customers:
- We comply with GDPR for EU data subjects
- We do not transfer EU personal data outside the EU without appropriate safeguards
- Specific Data Processing Agreements apply
12. Cookies & Tracking
12.1 What Are Cookies?
Cookies are small text files stored on your device to remember preferences and track usage.
12.2 Cookies We Use
- Session: Keep you logged in, remember preferences (until session ends)
- Authentication: Verify your identity securely (30 days)
- Analytics: Understand how users interact with features (1 year)
- Preference: Remember your language, theme, display settings (1 year)
12.3 Disabling Cookies
You can disable cookies in your browser settings. However, some features of Grapeit may not work correctly without cookies.
12.4 Third-Party Cookies
We do not allow third-party advertisers or data brokers to place tracking cookies on Grapeit.
13. Changes to This Privacy Policy
13.1 Updates
We may update this Privacy Policy to reflect:
- Changes in data protection laws (e.g., new regulations)
- Changes in our business practices (new data uses, new partners)
- Improved clarity or accuracy
13.2 Notification
- We will post updated versions on our website
- Material changes will be communicated via email to your registered organization contact
- Continued use of the Service after updates indicates your acceptance
14. Data Protection Officer (DPO) & Contact
14.1 Privacy Inquiries
For questions about this Privacy Policy, data subject requests, or concerns:
- Email: dpo@grapeit.in
- Email: privacy@grapeit.in
- Phone: +91-98765-43210
- Mailing Address: Grapeit, Maharashtra, India
14.2 Response Time
We aim to respond to all inquiries within 10 business days. Complex requests may take up to 30 days.
15. Compliance with Applicable Laws
This Privacy Policy complies with:
- Digital Personal Data Protection Act, 2023 (primary framework)
- Information Technology Act, 2000 (data security standards)
- Reserve Bank of India Guidelines (data localization for banking data)
- Income Tax Act, 1961 (tax data retention requirements)
- Employment Laws (labor data protection)
- GDPR (where applicable to EU data subjects)
16. Your Consent
By using Grapeit, you:
- Acknowledge that you have read and understood this Privacy Policy
- Consent to our processing of personal data as described
- Confirm that you have obtained consent from employees before inputting their data
- Agree to our Data Processing Agreement
By accessing or using Grapeit, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
Last updated: September 2026 | Version: 1.0