At Zenith360 HR we take privacy seriously — it’s the foundation of the trust HR teams place in us. This policy is written to be readable, not legalistic. If anything is unclear, please email us at privacy@zenith360-hr.com and we’ll clarify or fix it.
1. Who we are
Zenith360 HR (“Zenith360”, “we”, “our”, “us”) is a multi-tenant human-resources platform operated by ADB Consulting LLP, an Indian limited-liability partnership with its registered office in India. You can reach us at hello@zenith360-hr.com.
This policy explains what personal data Zenith360 collects, why we collect it, how we use and share it, how long we keep it, and the rights you have. It applies to the Zenith360 web portal at https://zenith360-hr.com, the Zenith360 HR mobile applications (Android and iOS), and every Zenith360 API.
2. Who is the data controller?
Zenith360 acts as the data controller only for the personal data we collect about our direct customers (the people who sign up for a Zenith360 subscription — administrators, HR agency owners, group administrators).
For all other personal data processed inside Zenith360 — employees of our customers, candidates, clients, project team members — Zenith360 acts as a data processor. Your employer / HR agency is the data controller and decides what data is entered, retained, deleted, and how long we retain it. If you have questions about your own personnel record, please contact your employer’s HR team first.
3. Categories of personal data we collect
Depending on how you use Zenith360, we may process the following categories of personal data:
- Identity & contact: name, employee code, email, phone, address, date of birth.
- Employment: designation, department, joining date, reporting manager, salary structure, PF / ESIC / PAN, bank account (for payroll).
- Authentication: hashed password, session tokens, IP address, browser / device fingerprint.
- Attendance & location: geo-coordinates when you check in / out, coarse-address reverse-geocoded via OpenStreetMap, working-hours computations.
- Biometric (selfie): baseline enrollment photograph and every live check-in photo; an AI-generated match score for each check-in.
- Trip & vehicle: GPS waypoints during an active trip, mode of travel, vehicle number, computed distance, anomaly flags, per-km fuel amount.
- Documents: ID proofs, offer / appointment letters, payslips, timesheets, reimbursement receipts you upload.
- Communications: in-app messages, kudos, feedback, survey responses, support tickets.
- Device & push: mobile OS version, device model, Firebase Cloud Messaging token, app locale.
- Financial (agency / group billing): subscription tier, seat count, Razorpay payment token (Razorpay stores the actual card / UPI data — we do not).
4. Why we collect it (purposes & legal bases)
- Contract performance — providing the HR workflows your employer has subscribed to (attendance, payroll, leaves, reimbursements, KPIs, ATS, LMS).
- Legitimate interest — fraud prevention (face-match, anomaly detection on trips, audit logs).
- Legal obligation — statutory compliance (PF, ESIC, PT, TDS, labour-law audits, retention of payroll records).
- Consent — camera + background-location permissions on the mobile app, marketing communications (which you can opt out of anytime).
5. Who we share it with
We do not sell your personal data. We share it only with:
- Your employer (the data controller) and their authorised administrators.
- Approved sub-processors listed below:
- MongoDB Atlas (database hosting — India region).
- Emergent Object Storage (uploads: selfies, receipts, offer letters).
- Emergent LLM Key (server-side calls to Anthropic Claude, OpenAI, Google Gemini for AI features).
- Razorpay (payment processing for agency / group subscriptions).
- Firebase Cloud Messaging (push notification delivery only — no message content is retained).
- OpenStreetMap Nominatim (reverse-geocoding of check-in coordinates to a human-readable address).
- Statutory / government authorities where legally required (e.g. PF / ESIC audits, court orders).
6. How long we retain data
- Active employee record — for the duration of employment plus 7 years (statutory payroll retention).
- Check-in selfies (live) — 90 days rolling window unless flagged for HR review.
- Baseline selfie — for the duration of employment; deleted within 30 days of separation.
- GPS trip waypoints — 12 months.
- Audit logs — 3 years (fraud-investigation retention).
- Subscription / billing data — 7 years (India tax retention).
Your employer may configure shorter retention windows in their tenant settings. Where they do, the shorter window wins.
7. Your rights
Subject to applicable law (DPDP Act 2023 in India, GDPR in the EEA, and equivalent laws elsewhere), you have the right to:
- Ask for a copy of the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion (see /delete-account).
- Object to processing based on legitimate interest.
- Withdraw consent for camera / location / marketing anytime from your device settings.
- Lodge a complaint with your local data-protection authority.
To exercise any of these rights, email privacy@zenith360-hr.com. We respond within 30 days.
8. Security
All data is encrypted in transit (TLS 1.2+). Passwords are hashed with bcrypt. Access to production infrastructure is limited to a small on-call team using single-sign-on with hardware-key 2FA. We keep audit logs of every admin action for 3 years. In the unlikely event of a personal-data breach we will notify affected users and the appropriate regulator within 72 hours of confirming it.
9. Children
Zenith360 is a workplace product. It is not intended for anyone under 18, and we do not knowingly collect data from children.
10. Changes to this policy
If we make a material change to this policy, we will notify direct customers by email at least 14 days before the change takes effect. The date at the top of this page is the last time this policy was updated.
Zenith360 HR is a product of ADB Consulting LLP · Registered in India · Contact: hello@zenith360-hr.com