Privacy Policy — PeopleHQ

Effective date: July 24, 2026

Last updated: July 24, 2026

1. Who we are

PeopleHQ is a cloud-based HR and payroll management system developed and operated by Multitech Solutions, located in Kolkata, India. We provide this service to businesses (“Organisations”) to manage their employees, attendance, leave, and payroll.

For the purposes of India’s Digital Personal Data Protection Act, 2023 (DPDP Act), Multitech Solutions acts as the Data Fiduciary for data collected directly from Users of PeopleHQ. Each Organisation using PeopleHQ acts as the Data Fiduciary (as employer) for the personal data of its own employees stored within the platform. Multitech Solutions acts as a Data Processor for employee data processed on the Organisation’s behalf.

Note on Employees vs Users: Many individuals whose data is stored in PeopleHQ (“Employees”) do not themselves log into the platform — their records are managed by their employer’s authorised administrators and managers (“Users”). Where an Employee also has their own login (for self-service features), they are both an Employee and a User.

2. What personal data we collect

From Users (people who log into PeopleHQ):

  • Name and email address (from Microsoft, Google, or email/password registration)
  • Login activity and session data
  • Actions performed within the app (recorded in audit logs)

From Employees (all employees recorded by an Organisation, whether or not they have their own login):

  • Name, employee code, department, designation, date of birth, gender, phone number, email address, work location
  • Permanent Account Number (PAN), bank account number, and IFSC code — collected specifically for salary payment and statutory compliance (see Section 2A below)
  • Attendance records, including timestamps, and — only where an Organisation has enabled this specific feature — GPS location and a photograph captured at the moment of a mobile attendance punch
  • Compensation, payslip, and payroll records
  • Leave and regularization request records
  • Documents uploaded to an Employee’s record by their Organisation (e.g. ID proof, offer letters)
  • If an Organisation connects a third-party biometric attendance device: the timestamp of each attendance scan and the device’s own internal user reference number. PeopleHQ does not receive, store, or process fingerprint images or biometric templates themselves — these remain on the physical device and are never transmitted to us.

Automatically collected:

  • IP address and browser/device type (for security)
  • Usage logs (pages visited, actions taken)

2A. PAN, bank account, and financial data — special notice

We collect PAN, bank account number, and IFSC code for Employees specifically to enable salary disbursement and to support the Organisation’s statutory obligations (including provident fund, employee state insurance, professional tax, and income tax withholding). This data is:

  • Encrypted at rest using AES-256 encryption
  • Never displayed in full within the application interface — only a masked version (e.g. last 4 digits) is ever shown on screen
  • Accessible in full only through a single, audit-logged process used exclusively to generate bank payment files
  • Every instance of this data being decrypted is recorded in our audit log, including who accessed it and when

Processing this data is necessary for the Organisation to fulfil its obligations as an employer under Indian law. Where an Employee has their own PeopleHQ account, they will be asked to accept this Privacy Policy on first login. Organisations are responsible for providing appropriate notice to Employees who do not have individual accounts, consistent with their own obligations as employer and Data Fiduciary.

3. Why we collect this data and our lawful basis

DataPurposeLawful basis
User name and emailAccount creation and identificationLegitimate purpose (contract)
Login and session dataSecurity and authenticationLegitimate purpose
Audit logsAccountability and data integrityLegitimate purpose
Employee personal detailsCore HR functionalityLegitimate purpose of the Organisation as employer
PAN, bank account, IFSCSalary payment and statutory complianceLegal obligation / legitimate use for employment purposes
Attendance GPS and photo (where enabled)Verifying attendance authenticityLegitimate purpose of the Organisation as employer

4. How long we keep your data

  • Active account data:Retained for the duration of your Organisation’s subscription plus 90 days after account closure
  • Payroll and statutory records: Retained for the duration of employment plus any minimum period required under applicable Indian labour and tax laws
  • Audit logs: Retained for 2 years from the date of the logged action
  • Attendance photographs (where the Organisation has enabled this feature): Retained for the duration of employment. A defined automatic deletion schedule for this specific data is under active development; this policy will be updated once that schedule is implemented.
  • Uploaded documents: Retained until deleted by the Organisation or until account closure
  • Deleted user data: Name snapshots in activity logs retained for audit integrity; login credentials and personal identifiers deleted within 30 days of account deletion

5. Who we share your data with

We do not sell your personal data to any third party.

We share data only with the following service providers who process it on our behalf:

ProviderPurposeLocation
SupabaseDatabase and file storage hostingMumbai, India (AWS ap-south-1)
VercelApplication hosting and deliveryGlobal CDN
Microsoft / GoogleOAuth authenticationGlobal

Note on statutory bodies: PeopleHQ does not currently transmit data directly to government bodies (such as EPFO, ESIC, or the Income Tax Department) on an Organisation’s behalf. Organisations remain responsible for their own statutory filings using reports generated within PeopleHQ.

Note on cross-border transfers: Some of our service providers may process data outside India. We take reasonable contractual measures to ensure adequate protection of your data. As India’s approved country list under DPDP is pending publication, we will review and update our data transfer practices accordingly.

6. Your rights as a Data Principal

Under India’s DPDP Act 2023, you have the following rights:

Right to access: You may request a summary of personal data we hold about you.

Right to correction:Users may update their own profile information directly in the app. For corrections to Employee records, contact your Organisation’s administrator, who is responsible for maintaining accurate Employee data.

Right to erasure: You may request deletion of your personal data. We will process erasure requests within 30 days, subject to legal retention requirements (e.g. audit logs, statutory payroll records).

Right to grievance redressal: You may raise a complaint with our Data Protection Officer (details below).

Right to nominate: You may nominate another individual to exercise these rights on your behalf in the event of death or incapacity.

To exercise any of these rights, contact us at: info@multitechsolutions.co.in

7. Data security

We implement the following security measures:

  • All data transmitted over HTTPS (TLS encryption)
  • Passwords hashed using bcrypt (industry standard)
  • PAN, bank account, and IFSC details encrypted at rest using AES-256
  • Role-based access controls, with financial and payroll data restricted to administrators only
  • Comprehensive audit logging of all sensitive data access and changes
  • Tenant isolation — each Organisation’s data is strictly separated at both the application and database level

Despite these measures, no system is completely secure. In the event of a personal data breach, we will notify affected parties and the Data Protection Board of India as required by law.

8. Cookies

PeopleHQ uses session cookies for authentication only. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

9. Children’s data

PeopleHQ is a business tool intended for use in a professional employment context. We do not knowingly collect data from individuals under the legal minimum working age under applicable Indian law.

10. Contact and grievance redressal

Data Protection Officer / Grievance Officer:

Multitech Solutions, Kolkata, India

Email: info@multitechsolutions.co.in

Response time: Within 48 hours for acknowledgment, 30 days for resolution.

You also have the right to lodge a complaint with India’s Data Protection Board once it is constituted.

11. Changes to this policy

We will notify all Organisation administrators by email when this policy is updated in a material way. Continued use of PeopleHQ after notification constitutes acceptance of the updated policy.