eco
Grapeit
Legal

Privacy Policy

Effective Date: September 2026 | Last Updated: September 2026

1. Introduction

Grapeit ("We," "Us," "Our") operates a payroll and human resources management platform. This Privacy Policy explains how we collect, use, process, and protect personal data when you use our Service.

Our Commitment: We comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) and treat your data with the highest standards of security and confidentiality.

2. Who We Are & Our Role

Data Controller & Processor Relationship

  • You (the organization) are the Data Controller—you decide what personal data to collect and how it's used
  • We (Grapeit) are the Data Processor—we process data on your instructions to deliver the Service

This Privacy Policy covers our processing practices as a Data Processor. You are responsible for obtaining consent from employees and individuals whose data you input into Grapeit.

3. Types of Personal Data We Process

3.1 Employee Data (Collected by You)

When you input employee information into Grapeit, we process:

  • Identity: Name, employee ID, date of birth, gender, marital status
  • Contact: Email address, phone number, physical address
  • Financial: Bank account details, salary, bonuses, allowances, deductions, tax information
  • Employment: Job title, department, reporting manager, employment dates, contract type
  • Attendance: Clock-in/out times, leave requests, leave balance, shift information
  • Compliance: PAN, Aadhaar number (if collected for payroll processing), ESI details, PF details
  • Health/Sensitive: Medical leave records, disability status, dependents information

3.2 Organization Data (Collected by Us)

When you create an account or use the Service, we collect:

  • Account: Organization name, industry, size, registered address, GST/MSME details
  • Contact: Email, phone number, business contact person
  • Usage: Features used, API calls, report generation, login frequency, session duration
  • Device: IP address, browser type, operating system, approximate location (country/city level)
  • Support: Support tickets, feedback, communication records

3.3 Data You Choose to Provide

  • Customizations, preferences, settings within the Service
  • Documents you upload (e.g., policies, templates, forms)
  • Voluntary feedback, survey responses, or feature requests

4. Legal Basis for Processing Personal Data

4.1 Employee Data

We process Employee Data (salary, identity, bank details) based on:

  • Your Consent: You have collected lawful consent from employees to process their data
  • Contractual Necessity: Processing is necessary to fulfill your payroll obligations and employment contracts
  • Legal Obligation: Compliance with tax law, labor laws (Minimum Wages Act, PF Act, ESI Act, Gratuity Act, Income Tax Act)
  • Legitimate Interest: Payroll accuracy, fraud detection, security monitoring

4.2 Organization Data

We process on the basis of:

  • Contractual Necessity: Required to deliver the Service
  • Legitimate Interest: Service improvement, security, compliance, analytics

4.3 Sensitive Personal Data

Data like Aadhaar, PAN, bank account details, health information, or biometric data (if you integrate attendance devices) is processed only with explicit consent for payroll/compliance purposes.

5. How We Use Personal Data

5.1 Service Delivery

  • Process payroll and calculate deductions (PF, ESI, income tax, professional tax)
  • Generate salary slips, payment advices, and statutory registers
  • Manage employee records, attendance, leave, and benefits
  • Enable you to run compliance reports (Form 12A, DSC, ECR, etc.)
  • Process reimbursements and expense claims
  • Generate analytics dashboards for HR and payroll insights

5.2 Security & Fraud Prevention

  • Detect and prevent unauthorized access or misuse
  • Monitor for suspicious activity (multiple failed logins, unusual data exports)
  • Investigate security incidents
  • Protect against data breaches and cyberattacks

5.3 Legal Compliance

  • Respond to regulatory requests (Income Tax Department, Labor Commissioner, RBI, NRLM audits)
  • Maintain records for statutory compliance
  • Fulfill legal obligations under applicable laws
  • Support audit trails for tax authorities

5.4 Service Improvement

  • Analyze aggregated, anonymized usage patterns (e.g., most-used features, error rates)
  • Develop new features and improve existing ones
  • Conduct research on payroll best practices (without identifying individuals)
  • Create benchmarking reports for HR metrics

5.5 Communication

  • Send transactional emails (password reset, invoice, account updates)
  • Notify you of system maintenance, outages, or security alerts
  • Respond to your support requests
  • Provide educational content on payroll compliance and HR best practices

5.6 What We Do NOT Do

  • We do NOT sell, rent, lease, or trade employee data
  • We do NOT use employee data for marketing or advertising
  • We do NOT share employee data with third-party marketers or data brokers
  • We do NOT use data to profile individuals for decisions that significantly affect them (automated decision-making)

6. Who We Share Data With

6.1 Service Providers & Sub-Processors

We engage third parties who process data on our behalf:

  • Cloud Hosting: Infrastructure, backup, disaster recovery (all data encrypted)
  • Payment Gateway: Process subscription payments (billing data only, no employee data)
  • Email Service: Send transactional emails (email addresses, transaction data)
  • SMS Provider: Optional SMS notifications (phone numbers, notification content)
  • Analytics: Usage analytics, feature adoption (anonymized, aggregated data only)
  • Support Tools: Manage support tickets (support request content only)
  • Compliance Partners: Statutory filing support (form data as specified in your agreement)

All sub-processors are contractually bound to:

  • Process data only as instructed by us
  • Implement security standards equivalent to ours
  • Not disclose data to unauthorized parties
  • Delete or return data upon termination

6.2 Legal & Regulatory Disclosure

We may disclose personal data if required by law:

  • Court orders, search warrants, or judicial decrees
  • Regulatory requests from Income Tax Department, Labor Commissioner, RBI, or other authorities
  • Enforcement of our Terms of Service or protection of legal rights

We will attempt to notify you before disclosing data unless legally prohibited.

6.3 Business Transfers

If Grapeit is acquired, merged, or sold, personal data may be transferred as part of the transaction. We will provide 30 days' notice and allow you to opt out.

6.4 No Unauthorized Sharing

We do NOT share data with:

  • Third-party marketers, advertisers, or data brokers
  • Competitors or external analytics vendors
  • Any party without your explicit consent (except as legally required)

7. Data Retention

7.1 Active Account

While you use Grapeit, we retain all Customer Data (employee records, payroll history, reports) to deliver the Service.

7.2 After Account Termination

  • Employee Data: 90 days (allows export and backup retrieval)
  • Backup Copies: 30 days after deletion (disaster recovery only)
  • Legal/Tax Data: 7 years (compliance with IT Act, labor law, tax law)
  • Audit Logs: 2 years or as required by law (security, compliance verification)
  • Account Data: 5 years (tax and accounting requirements)

7.3 Your Rights

  • You may request data deletion at any time via dpo@grapeit.in
  • We will delete non-legally-required data within 30 days
  • Legally-required data (tax records) is retained per statutory obligations
  • You may export your data at any time for portability

8. Data Protection & Security

8.1 Technical Measures

  • Encryption at Rest: AES-256 encryption for all stored data
  • Encryption in Transit: TLS 1.2+ for all data transmitted over the internet
  • Access Control: Role-based access control (RBAC); employees access only what they need
  • Audit Logging: All data access and modifications are logged and monitored
  • Firewalls & Intrusion Detection: Network perimeter protection and real-time threat monitoring
  • Multi-factor Authentication (MFA): Optional MFA available for account security
  • Regular Security Updates: Timely patching of vulnerabilities and software updates

8.2 Organizational Measures

  • Data Protection Training: Our team receives annual DPDP Act and data security training
  • Access Restrictions: Only authorized personnel access Customer Data; access is logged
  • Confidentiality Agreements: All team members sign confidentiality agreements
  • Third-Party Audits: Annual security assessments and penetration testing
  • Incident Response Plan: Documented procedures for breach detection and response
  • Backup & Disaster Recovery: Daily automated backups stored in geographically distinct locations

8.3 Your Responsibility

You are responsible for:

  • Keeping your account credentials (username, password) confidential
  • Enabling multi-factor authentication if available
  • Monitoring for unauthorized access and notifying us immediately
  • Ensuring employees consent to data collection before inputting their data
  • Compliance with data collection and processing laws in your jurisdiction

8.4 What We Cannot Guarantee

  • No system is 100% secure; cyber threats are constantly evolving
  • We cannot guarantee protection against advanced, targeted attacks
  • We are not liable for breaches resulting from your actions (weak passwords, compromised credentials)

9. Data Breach Notification

9.1 Our Obligations

If we discover a personal data breach that poses a risk to individuals, we will:

  • Notify you within 72 hours of discovery (as required by DPDP Act)
  • Provide details of nature of breach, likely consequences, measures taken, and our contact information

9.2 Your Obligations

As Data Controller, you must:

  • Notify affected individuals without undue delay (if required by law)
  • File a complaint with the Data Protection Board if individuals' rights are violated
  • Document the breach and our response
  • Assess the risk to individuals and report to authorities if required

9.3 Cooperation

We will cooperate with your breach investigation, provide forensic details, and support your notifications to individuals and regulators.

10. Data Subject Rights (Under DPDP Act)

If you are an employee whose data is processed by Grapeit, you have the following rights:

10.1 Right to Access

  • You may request confirmation of whether your personal data is being processed
  • You may request a copy of your data in a structured, commonly used format
  • Request contact: Your organization's HR or dpo@grapeit.in
  • Response time: Within 30 days of request

10.2 Right to Correction

  • You may request correction of inaccurate or incomplete data
  • Example: Incorrect salary figure, wrong address
  • We will update data and notify you of changes

10.3 Right to Erasure

  • You may request deletion of your data (subject to legal retention obligations)
  • We cannot erase data required for tax compliance, legal holds, or ongoing employment
  • Non-compliance data will be deleted within 30 days

10.4 Right to Data Portability

  • You may request your data in a structured, machine-readable format (CSV, Excel, JSON)
  • Useful for switching payroll systems or transferring to another organization
  • We will provide data within 30 days of request

10.5 Right to Grievance Redressal

If you believe your data rights are violated, you may:

  1. Submit a grievance to your organization
  2. Contact our Data Protection Officer at dpo@grapeit.in
  3. File a complaint with the Digital Personal Data Protection Board (established under DPDP Act)

11. International Data Transfers

11.1 Data Localization

All personal data is stored and processed within India (data centers in ap-south-1 region). We do not transfer employee data outside India without explicit consent, as required by DPDP Act and Reserve Bank guidelines.

11.2 Exception: International Customers

If your organization is based outside India but uses Grapeit, or if you have EU customers:

  • We comply with GDPR for EU data subjects
  • We do not transfer EU personal data outside the EU without appropriate safeguards
  • Specific Data Processing Agreements apply

12. Cookies & Tracking

12.1 What Are Cookies?

Cookies are small text files stored on your device to remember preferences and track usage.

12.2 Cookies We Use

  • Session: Keep you logged in, remember preferences (until session ends)
  • Authentication: Verify your identity securely (30 days)
  • Analytics: Understand how users interact with features (1 year)
  • Preference: Remember your language, theme, display settings (1 year)

12.3 Disabling Cookies

You can disable cookies in your browser settings. However, some features of Grapeit may not work correctly without cookies.

12.4 Third-Party Cookies

We do not allow third-party advertisers or data brokers to place tracking cookies on Grapeit.

13. Changes to This Privacy Policy

13.1 Updates

We may update this Privacy Policy to reflect:

  • Changes in data protection laws (e.g., new regulations)
  • Changes in our business practices (new data uses, new partners)
  • Improved clarity or accuracy

13.2 Notification

  • We will post updated versions on our website
  • Material changes will be communicated via email to your registered organization contact
  • Continued use of the Service after updates indicates your acceptance

14. Data Protection Officer (DPO) & Contact

14.1 Privacy Inquiries

For questions about this Privacy Policy, data subject requests, or concerns:

14.2 Response Time

We aim to respond to all inquiries within 10 business days. Complex requests may take up to 30 days.

15. Compliance with Applicable Laws

This Privacy Policy complies with:

  • Digital Personal Data Protection Act, 2023 (primary framework)
  • Information Technology Act, 2000 (data security standards)
  • Reserve Bank of India Guidelines (data localization for banking data)
  • Income Tax Act, 1961 (tax data retention requirements)
  • Employment Laws (labor data protection)
  • GDPR (where applicable to EU data subjects)

16. Your Consent

By using Grapeit, you:

  • Acknowledge that you have read and understood this Privacy Policy
  • Consent to our processing of personal data as described
  • Confirm that you have obtained consent from employees before inputting their data
  • Agree to our Data Processing Agreement

By accessing or using Grapeit, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

Last updated: September 2026 | Version: 1.0