Legal
How Worklay collects, uses, safeguards, and lets you control your personal data across our web and mobile apps.
Worklay (“we”, “our”, or “us”) operates a multi-tenant HR, project, and team management platform for Indian SMBs at worklay.app and via our companion mobile app (together, the “Platform”). This Privacy Policy explains what data we collect, why we collect it, how it is protected, and what rights you have. By using the Platform you agree to this policy. If you register on behalf of an organisation, you represent that you have authority to bind that organisation.
Quick summary
When you use the Platform to manage work, we store the content you create:
Where your organisation uses the Asset Inventory module, we store company asset records (asset code, brand, model, serial number, cost, vendor, warranty, condition) and an assignment history linking each asset to the employee it is currently or was previously issued to, including assignment/return dates and acknowledgement status.
Files you upload (task attachments, HR documents, generated payslips and compliance filings) are stored in a private Cloudflare R2 bucket. Files are never publicly accessible; access is granted only via time-limited (15-minute) presigned URLs. We validate MIME type and enforce a 10 MB per-file limit.
Subscription payments are processed exclusively by Razorpay. We store only the Razorpay customer ID, subscription ID, and plan identifier — never raw card numbers, CVVs, or bank details entered at checkout.
Our HR Core and Payroll modules let your organisation record data that is especially sensitive under Indian law. We store this data solely to enable your organisation to run payroll and meet its own statutory obligations, at the direction of your organisation (which acts as the Data Fiduciary for its employees' data under the DPDP Act, 2023):
How we protect this data
Important: Worklay generates statutory filing exports (PF ECR, ESI/PT returns, Form 16/24Q) as downloadable files only. We do not transmit data directly to any government portal or e-filing system — your organisation remains responsible for reviewing, uploading, and filing these documents with the appropriate authorities. See also Section 6 of our Terms of Service.
We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes.
Worklay uses a shared-database, tenant-isolated architecture. Every data record is tagged with an organizationId and all database queries are automatically scoped to your organisation. Employees of Organisation A cannot access data belonging to Organisation B. Isolation is enforced at both the application layer (TenantGuard) and the database query layer (Mongoose tenant plugin).
Platform administrators (Worklay staff) may access organisation data only when required to resolve a support ticket or investigate a security incident, and only after internal authorisation. Such access is logged.
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| MongoDB Atlas | Primary database | All structured data | AWS Mumbai (ap-south-1) |
| Cloudflare R2 | File & attachment storage | Uploaded files, generated payslips & compliance filings | India region |
| AWS SES | Transactional email & broadcast messaging | Recipient email, name | ap-south-1 |
| Razorpay | Payment processing | Billing contact, plan | India |
| Firebase Cloud Messaging (Google) | Mobile push notifications | Device push token | Global (Google infrastructure) |
| Vercel | Frontend hosting / CDN | HTTP request metadata | Global CDN |
| Redis Cloud | Caching & job queues | Session data, job payloads | India region |
All sub-processors are bound by data processing agreements consistent with the DPDP Act 2023.
A note on WhatsApp broadcasts: Worklay does not integrate with any WhatsApp Business API and does not transmit message content through WhatsApp/Meta servers. When an App Admin sends a broadcast “via WhatsApp”, the Platform only generates a pre-filled wa.me deep link; the admin's own device and WhatsApp account is used to review and send the message manually. WhatsApp is therefore not a Worklay sub-processor.
You own your data. You can export your organisation's content at any time:
deletedAt timestamp and excluded from normal queries; they are permanently purged 90 days after deletion.Under the Digital Personal Data Protection Act, 2023 and applicable Indian law, you have the following rights:
To exercise any right, email privacy@worklay.app with the subject line “Data Rights Request”. We will respond within 30 days. If your query concerns HR, payroll, or statutory data, your first point of contact is your own organisation's HR/Payroll admin (the Data Fiduciary), who may loop in Worklay as needed.
We use first-party cookies solely for authentication:
access_token — HttpOnly, Secure, SameSite=Lax; expires in 15 minutes.refresh_token — HttpOnly, Secure, SameSite=Lax; expires in 7 days; rotated on every use._auth / _role — readable indicator cookies for middleware routing; contain no sensitive data.We do not use third-party tracking cookies, advertising pixels, or analytics SDKs that share data with external parties. Disabling cookies will prevent login.
Worklay uses WebSocket connections (Socket.io) to deliver real-time notifications — task updates, comments, leave approvals, and system alerts. When you use the Platform:
On the mobile app, we additionally use Firebase Cloud Messaging to deliver push notifications (task assignments, approvals, shift-end reminders) to your device even when the app is closed. This requires registering a device push token with our backend; you can disable notifications at any time from your device's notification settings.
The Worklay mobile app (Android/iOS) may request the following device permissions. All are optional and can be revoked at any time from your device settings; declining a permission only disables the related feature.
The Platform is intended for business use by individuals 18 years of age or older. We do not knowingly collect personal data from minors. If we become aware that a minor has registered, we will delete the account promptly.
We may update this policy from time to time. Material changes will be notified via email and an in-app notification at least 14 days before taking effect. Continued use of the Platform after the effective date constitutes acceptance of the revised policy. The current version is always available at worklay.app/privacy-policy.
In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, our Grievance Officer details are:
Role: Worklay Grievance Officer
Email: grievance@worklay.app
Privacy inquiries: privacy@worklay.app
Response time: Within 30 days of receipt
© 2026 Worklay. All rights reserved.