1. Scope
This Policy explains how personal and workforce information is handled when owners, managers, and employees use DigiBillMate HRM. The employing or subscribing business generally decides why employee information is collected and how it is used. Employees should also review notices and policies issued by their employer.
2. Information Collected
- Account information: name, employee ID, mobile number, email, role, status, and authentication information.
- Employment information: address, department, designation, joining date, identity-verification details, emergency contacts, and document-verification confirmation where entered by the business.
- Attendance information: check-in and check-out times, break sessions, working hours, overtime, attendance status, leave, holidays, approvals, rejection reasons, and audit history.
- Verification information: location data when permission is granted, office-location comparison, QR verification, verification level and score, device identifier, device name, operating system, browser information, timestamps, and network-related technical data.
- Usage and support information: settings, actions performed, errors, and information supplied when requesting support.
3. How Information Is Used
Information is used to authenticate users, register authorized devices, record and verify attendance, manage employees and leave, calculate work and break durations, prepare reports, maintain audit trails, prevent misuse, troubleshoot problems, secure the service, and support lawful business operations.
4. No Sale or Commercial Exploitation of Customer Data
DigiBillMate HRM does not sell, rent, trade, broker, or license customer or employee personal information to third parties for monetary gain, advertising, profiling, or unrelated marketing. Customer data is not a commercial product. It is processed only to provide, secure, maintain, support, or lawfully operate the HRM service, to follow the subscribing business's authorized instructions, or when disclosure is legally required.
Access by hosting, database, authentication, security, or application-delivery providers is limited to processing needed to operate the service and does not give those providers permission to independently sell or use customer data for their own advertising.
5. Data Minimization and Confidential Information
DigiBillMate HRM is designed to collect only information reasonably required for employee administration, attendance, leave, verification, reporting, security, and audit purposes. The service does not intentionally request or store readable account passwords or PINs, payment-card details, bank credentials, or unrelated private information.
Some information required for HR operations, including identity-proof numbers, addresses, emergency contacts, location verification, and employment records, may be confidential personal information. Such information is stored only when the business or user provides it for an available HRM function and is subject to access controls. Users must not enter medical records, financial credentials, passwords, full payment-card data, private documents, or other highly sensitive information into remarks, reasons, addresses, or other free-text fields unless the field expressly requests it and the business has a lawful need to collect it.
6. Location and Device Permissions
Location is requested only for features that require attendance or workplace verification. Denying permission may cause an attendance event to fail or require manager review. Device information helps bind employee access to an authorized device and detect improper use. Users can manage browser permissions through their device settings, subject to their employer’s attendance policy.
7. Saved Login Information
If a user enables saved login information, compatible browsers may store credentials using their own credential-management feature. DigiBillMate HRM stores account references needed to request those credentials but does not intentionally store the readable password or PIN in application storage. Users should enable this only on a private, secured device and can remove saved credentials through the login screen or browser password settings.
8. Limited Disclosure and Service Providers
Information may be available only to authorized owners, managers, administrators, employees, and technical service providers according to their roles and operational need. Information may also be disclosed when required by a valid legal obligation, to investigate fraud or security threats, to protect users or the service, or as part of a lawful business transfer subject to appropriate confidentiality and data-protection obligations. These limited disclosures are not a sale of customer data.
9. Data Retention
Information is retained for as long as needed to provide the service, meet the business’s employment and recordkeeping needs, maintain security and audit history, resolve disputes, and comply with applicable law. Retention periods may differ by organization and record type. The business administrator should request deletion or export according to its legal obligations and service arrangement.
10. Security and Data-Incident Protection
Administrative, technical, and access controls are used to reduce the risk of unauthorized access, disclosure, alteration, loss, or misuse. These safeguards include authenticated access, role restrictions, shop-level data separation, secure connections, and audit records. Access is intended to be limited to authorized operational purposes.
No internet, cloud, browser, or device-based system can truthfully guarantee that a data incident will never occur. If a confirmed security incident affects protected customer data, reasonable containment, investigation, remediation, and legally required notification steps will be taken. The subscribing business and every user must also protect credentials and devices, remove access promptly when authorization ends, configure roles correctly, and report suspected unauthorized access without delay.
11. User Choices and Rights
Depending on applicable law, users may have rights to request access, correction, deletion, restriction, or a copy of personal information. Employees should normally submit requests to their owner, manager, or employer because that business controls their workforce records. Some information may need to be retained for legal, security, payroll, or audit purposes.
12. Children
The service is intended for authorized business users and is not directed to children. Businesses must ensure that any workforce use involving a minor is lawful and supported by all required notices and permissions.
13. International Processing
Hosting or technical providers may process information in locations different from the user’s location. The subscribing business is responsible for confirming that its use and transfer of employee information complies with applicable requirements.
14. Policy Updates
This Policy may be updated when the product, processing practices, or legal requirements change. The effective date will be revised when an updated version is published.
15. Questions and Requests
Employees should contact their owner, manager, or employer for privacy questions or requests concerning workforce records. Business administrators may use the official DigiBillMate support channel supplied with their service arrangement.