Legal

Privacy Policy

How Worklay collects, uses, safeguards, and lets you control your personal data across our web and mobile apps.

Effective July 31, 2026Last updated July 31, 2026Aligned with the DPDP Act, 2023 (India)
Table of contents
  1. 1. Information We Collect
  2. 2. Sensitive Personal Data (Aadhaar, PAN & Financial Info)
  3. 3. How We Use Your Information
  4. 4. Multi-Tenancy & Data Isolation
  5. 5. Third-Party Sub-Processors
  6. 6. Data Portability & Export
  7. 7. Data Retention
  8. 8. Security Measures
  9. 9. Your Rights (DPDP Act 2023)
  10. 10. Cookies & Session Management
  11. 11. Real-Time Features & Push Notifications
  12. 12. Mobile App Permissions
  13. 13. Children's Privacy
  14. 14. Changes to This Policy
  15. 15. Grievance Officer & Contact

Worklay (“we”, “our”, or “us”) operates a multi-tenant HR, project, and team management platform for Indian SMBs at worklay.app and via our companion mobile app (together, the “Platform”). This Privacy Policy explains what data we collect, why we collect it, how it is protected, and what rights you have. By using the Platform you agree to this policy. If you register on behalf of an organisation, you represent that you have authority to bind that organisation.

Quick summary

  • We collect only what is necessary to operate the Platform.
  • We never sell or share your data for advertising.
  • Your organisation's data is strictly isolated from other tenants.
  • All data is stored on servers located in India (AWS Mumbai region).
  • Government IDs (Aadhaar, PAN) and bank details are treated as sensitive personal data with restricted access.
  • You can export or delete your data at any time.

1Information We Collect

1.1 Account & Organisation Data

  • Organisation name, registered address, GST/company details, contact email, mobile, and logo.
  • Org-admin name, work email, and mobile provided during onboarding.
  • Statutory registration identifiers configured by your organisation for compliance purposes — PAN, TAN, GSTIN, PF establishment code, ESIC establishment code, and state-wise Professional Tax registration numbers (see Section 2).

1.2 Employee & HR Profile Data

  • First and last name, work email, mobile number, designation, employee code.
  • Date of birth, gender, marital status, reporting manager, department, employment type/status, and dates (entered by the org admin or HR for personnel records).
  • Profile avatar, if uploaded (via web or the mobile app's camera/gallery).
  • Emergency contact name, relationship, and phone number, where provided by the employee or HR.
  • Government-issued identifiers and financial identifiers — see Section 2 for how these are treated.
  • Supporting HR documents uploaded by employees or admins: PAN card, Aadhaar card, bank proof, resume, offer letter, and relieving letter.
  • Employees may view their own HR profile and submit change requests, which are routed to an admin for approval; the original and requested values are both retained for audit purposes.

1.3 Work & Collaboration Content

When you use the Platform to manage work, we store the content you create:

  • Tasks & Projects — titles, descriptions, priorities, due dates, status changes, and custom fields.
  • Comments & Mentions — text content, @-mentioned user IDs, and timestamps.
  • Time Logs — logged hours, notes, and the task or project they are associated with.
  • Documents — file names, folder structure, and upload metadata.
  • Activity Feed — an audit trail of create, update, and delete actions (actor, entity, diff, timestamp).

1.4 Attendance & Leave Records

  • Leave requests — type, dates, reason, and approval status.
  • Leave balances per type per employee.
  • Attendance check-in/check-out events, if enabled by your org admin, including timestamp, IP address, and — where the employee grants browser/device location permission — GPS latitude, longitude, and resolved address at the moment of check-in/check-out.
  • Automatic shift-end check-out: if an employee forgets to check out, the Platform records a system-generated check-out at the configured shift end time and sends a nudge notification beforehand. This is purely schedule-based and does not use location data.

1.5 Asset Inventory Records

Where your organisation uses the Asset Inventory module, we store company asset records (asset code, brand, model, serial number, cost, vendor, warranty, condition) and an assignment history linking each asset to the employee it is currently or was previously issued to, including assignment/return dates and acknowledgement status.

1.6 Authentication & Security Data

  • Email address and bcrypt-hashed password (never stored in plain text).
  • Optional TOTP 2FA secrets (Enterprise plan), stored encrypted at rest.
  • JWT refresh token hashes and session metadata.

1.7 Files & Attachments

Files you upload (task attachments, HR documents, generated payslips and compliance filings) are stored in a private Cloudflare R2 bucket. Files are never publicly accessible; access is granted only via time-limited (15-minute) presigned URLs. We validate MIME type and enforce a 10 MB per-file limit.

1.8 Automatically Collected Data

  • IP address, browser type, OS, referring URL, and page-visit timestamps (stored in audit logs).
  • WebSocket connection events (connect, disconnect, room membership) for real-time features.
  • API request logs used for rate limiting and security monitoring.

1.9 Payment Information

Subscription payments are processed exclusively by Razorpay. We store only the Razorpay customer ID, subscription ID, and plan identifier — never raw card numbers, CVVs, or bank details entered at checkout.

2Sensitive Personal Data (Aadhaar, PAN & Financial Info)

Our HR Core and Payroll modules let your organisation record data that is especially sensitive under Indian law. We store this data solely to enable your organisation to run payroll and meet its own statutory obligations, at the direction of your organisation (which acts as the Data Fiduciary for its employees' data under the DPDP Act, 2023):

  • Government identifiers — PAN, Aadhaar number, UAN, PF number, and ESIC number recorded on an employee's HR profile.
  • Bank account details — account number, IFSC, account holder name, bank name and branch, used to disburse salary.
  • Compensation history — historised CTC, basic pay, HRA, and allowance structures.
  • Payslips — per-employee earnings, statutory deductions (PF, ESI, professional tax, TDS), employer contributions, net pay, and a bank-account snapshot captured at the time each payslip is generated (so historical payslips remain accurate even if bank details are later updated).
  • Bank payment files — a consolidated file of employee bank details generated per payroll run so your organisation can upload it to its own bank's portal for salary disbursal.
  • Statutory compliance filings — downloadable exports such as PF ECR, ESI returns, Professional Tax returns, Form 16, and Form 24Q, which necessarily embed employee PAN and TDS figures.

How we protect this data

  • Access is restricted by role-based permissions to authorised HR and Payroll personnel within your organisation only; other employees cannot view a colleague's sensitive fields.
  • Data is stored in our tenant-isolated database, which is encrypted at rest by our database provider (MongoDB Atlas) and encrypted in transit (TLS 1.2+).
  • All access to sensitive HR and payroll records is logged in the audit trail (actor, action, timestamp).
  • We do not use Aadhaar or PAN numbers for any purpose other than the HR/payroll recordkeeping your organisation configures, and we do not publish, display, or share them outside your organisation's Workspace.

Important: Worklay generates statutory filing exports (PF ECR, ESI/PT returns, Form 16/24Q) as downloadable files only. We do not transmit data directly to any government portal or e-filing system — your organisation remains responsible for reviewing, uploading, and filing these documents with the appropriate authorities. See also Section 6 of our Terms of Service.

3How We Use Your Information

  • Provide, operate, and improve Platform features — task management, HR & payroll, time tracking, leave management, asset inventory, reporting, real-time collaboration, etc.
  • Process payroll runs and generate statutory compliance filings/exports at your organisation's direction.
  • Send transactional emails — welcome, password reset, task assignment, leave approval, subscription alerts — via AWS SES.
  • Deliver admin-initiated broadcast announcements to your organisation's contacts by email, and by generating a pre-filled WhatsApp message link that your admin sends manually from their own WhatsApp account (see Section 5).
  • Push real-time in-app and mobile push notifications when relevant events occur (task assigned, comment added, leave approved, shift-end check-out reminder, etc.).
  • Process payments and manage subscription lifecycle via Razorpay.
  • Maintain audit logs for compliance, security, and dispute resolution purposes.
  • Enforce subscription plan limits (employee count, project count, storage quota).
  • Detect, investigate, and prevent fraud, abuse, or security incidents.
  • Meet applicable legal obligations under Indian law (IT Act 2000, DPDP Act 2023).

We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes.

4Multi-Tenancy & Data Isolation

Worklay uses a shared-database, tenant-isolated architecture. Every data record is tagged with an organizationId and all database queries are automatically scoped to your organisation. Employees of Organisation A cannot access data belonging to Organisation B. Isolation is enforced at both the application layer (TenantGuard) and the database query layer (Mongoose tenant plugin).

Platform administrators (Worklay staff) may access organisation data only when required to resolve a support ticket or investigate a security incident, and only after internal authorisation. Such access is logged.

5Third-Party Sub-Processors

ProviderPurposeData SharedLocation
MongoDB AtlasPrimary databaseAll structured dataAWS Mumbai (ap-south-1)
Cloudflare R2File & attachment storageUploaded files, generated payslips & compliance filingsIndia region
AWS SESTransactional email & broadcast messagingRecipient email, nameap-south-1
RazorpayPayment processingBilling contact, planIndia
Firebase Cloud Messaging (Google)Mobile push notificationsDevice push tokenGlobal (Google infrastructure)
VercelFrontend hosting / CDNHTTP request metadataGlobal CDN
Redis CloudCaching & job queuesSession data, job payloadsIndia region

All sub-processors are bound by data processing agreements consistent with the DPDP Act 2023.

A note on WhatsApp broadcasts: Worklay does not integrate with any WhatsApp Business API and does not transmit message content through WhatsApp/Meta servers. When an App Admin sends a broadcast “via WhatsApp”, the Platform only generates a pre-filled wa.me deep link; the admin's own device and WhatsApp account is used to review and send the message manually. WhatsApp is therefore not a Worklay sub-processor.

6Data Portability & Export

You own your data. You can export your organisation's content at any time:

  • Self-service exports — Report pages offer CSV/Excel export for tasks, time logs, leave records, attendance, and payroll/compliance filings offer direct PDF/file downloads.
  • Full data export — Email privacy@worklay.app to request a full JSON export of your organisation's data. We will deliver it within 14 business days.
  • Before cancellation — You may request an export before your account is closed. See the Termination section in our Terms of Service.

7Data Retention

  • Active organisation data is retained for as long as the account is active.
  • Soft-deleted records (tasks, projects, employees, etc.) are marked with a deletedAt timestamp and excluded from normal queries; they are permanently purged 90 days after deletion.
  • Audit logs (activity feed, access logs) are retained for 2 years.
  • Payroll and statutory compliance records (payslips, bank payment files, filing exports) are retained for the period required by applicable Indian labour, tax, and payroll regulations, which may exceed the retention period of other Workspace data, even after account closure.
  • After subscription cancellation with no renewal, account data is retained for 60 days to allow export, then permanently deleted (subject to the statutory retention above).
  • You may request immediate deletion by contacting privacy@worklay.app.

8Security Measures

  • Passwords hashed with bcrypt (cost factor 12); never stored in plain text.
  • All data in transit protected by TLS 1.2+ (HTTPS and WSS).
  • JWT access tokens expire in 15 minutes; refresh tokens (7-day) are rotated on every use and stored as bcrypt hashes.
  • HTTP security headers enforced via Helmet.js — HSTS, X-Frame-Options, X-Content-Type-Options, and XSS-Protection.
  • API rate limiting: 100 requests / minute globally; 5 requests / 15 minutes on authentication endpoints.
  • File uploads validated for MIME type and size (10 MB per file). Files stored in a private bucket; never served without a time-limited presigned URL.
  • Sensitive HR and payroll fields (Aadhaar, PAN, bank details, compensation) are visible only to roles granted HR/Payroll permissions within your organisation.
  • Optional TOTP 2FA available for Enterprise plan users.
  • Razorpay webhook payloads verified with HMAC-SHA256 signatures.

9Your Rights (DPDP Act 2023)

Under the Digital Personal Data Protection Act, 2023 and applicable Indian law, you have the following rights:

  • Access — Request a copy of personal data we hold about you.
  • Correction — Request correction of inaccurate or incomplete data.
  • Erasure — Request deletion of your personal data (subject to legal retention requirements, including statutory payroll/tax retention described in Section 7).
  • Portability — Receive your data in a structured, machine-readable format.
  • Grievance Redressal — Lodge a complaint with our Grievance Officer (see Section 15).
  • Nomination — Nominate a person to exercise rights on your behalf in the event of your death or incapacity.
  • Withdraw consent — Where processing relies on consent (e.g. optional profile photo, device push notifications), you may withdraw it at any time via account/device settings without affecting past processing.

To exercise any right, email privacy@worklay.app with the subject line “Data Rights Request”. We will respond within 30 days. If your query concerns HR, payroll, or statutory data, your first point of contact is your own organisation's HR/Payroll admin (the Data Fiduciary), who may loop in Worklay as needed.

10Cookies & Session Management

We use first-party cookies solely for authentication:

  • access_token — HttpOnly, Secure, SameSite=Lax; expires in 15 minutes.
  • refresh_token — HttpOnly, Secure, SameSite=Lax; expires in 7 days; rotated on every use.
  • _auth / _role — readable indicator cookies for middleware routing; contain no sensitive data.

We do not use third-party tracking cookies, advertising pixels, or analytics SDKs that share data with external parties. Disabling cookies will prevent login.

11Real-Time Features & Push Notifications

Worklay uses WebSocket connections (Socket.io) to deliver real-time notifications — task updates, comments, leave approvals, and system alerts. When you use the Platform:

  • Your browser establishes a persistent WebSocket connection, authenticated by your JWT token.
  • You are placed in organisation-scoped and user-scoped rooms; events are pushed only to the relevant rooms.
  • Connection events (connect, disconnect) are logged for security purposes.
  • WebSocket traffic is encrypted with TLS (WSS).

On the mobile app, we additionally use Firebase Cloud Messaging to deliver push notifications (task assignments, approvals, shift-end reminders) to your device even when the app is closed. This requires registering a device push token with our backend; you can disable notifications at any time from your device's notification settings.

12Mobile App Permissions

The Worklay mobile app (Android/iOS) may request the following device permissions. All are optional and can be revoked at any time from your device settings; declining a permission only disables the related feature.

  • Camera / Photo Library — to capture or select a profile picture.
  • Notifications — to receive push notifications via Firebase Cloud Messaging.
  • Location — requested only if your organisation enables location-tagged attendance check-in/check-out; the app captures your coordinates at the moment of check-in/check-out only, not continuously in the background.

13Children's Privacy

The Platform is intended for business use by individuals 18 years of age or older. We do not knowingly collect personal data from minors. If we become aware that a minor has registered, we will delete the account promptly.

14Changes to This Policy

We may update this policy from time to time. Material changes will be notified via email and an in-app notification at least 14 days before taking effect. Continued use of the Platform after the effective date constitutes acceptance of the revised policy. The current version is always available at worklay.app/privacy-policy.

15Grievance Officer & Contact

In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, our Grievance Officer details are:

Role: Worklay Grievance Officer

Email: grievance@worklay.app

Privacy inquiries: privacy@worklay.app

Response time: Within 30 days of receipt

© 2026 Worklay. All rights reserved.