Privacy Policy
Last updated: June 11, 2026 • Version 2.0
Compliant with the Digital Personal Data Protection Act, 2023 (DPDP Act) and Digital Personal Data Protection Rules, 2025
1. Introduction
VYNTRA ("we," "our," or "us") is committed to safeguarding the privacy of our users in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025 (DPDP Rules) notified by the Ministry of Electronics and Information Technology (MeitY) on November 13, 2025.
This Privacy Policy is a standalone notice presented independently of any other information. It provides a fair account of the details necessary for you to give specific and informed consent for the processing of your personal data, as required under Rule 3 of the DPDP Rules, 2025.
By accessing or using our Platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please discontinue use of the Platform immediately.
2. Definitions
- "Data Principal" — The individual to whom the personal data relates (Section 2(j) DPDP Act). In our context: employees, administrators, and other users.
- "Data Fiduciary" — The entity that determines the purpose and means of processing personal data (Section 2(i) DPDP Act). For our Platform, the Data Fiduciary is the organization (tenant) using VYNTRA.
- "Data Processor" — Any person who processes personal data on behalf of the Data Fiduciary (Section 2(k) DPDP Act). VYNTRA acts as a Data Processor.
- "Significant Data Fiduciary (SDF)" — A Data Fiduciary meeting criteria under Section 5 of the DPDP Act (volume of data, impact on Data Principals, sensitive data, or key infrastructure).
- "Consent Manager" — A Data Fiduciary registered with the Data Protection Board that acts as a single point of contact for Data Principals to give, manage, review, and withdraw consent (Rule 4).
- "Personal Data Breach" — Any unauthorized access, disclosure, alteration, or destruction of personal data.
- "Processing" — Any operation on personal data including collection, recording, organization, storage, adaptation, retrieval, use, disclosure, alignment, combination, restriction, erasure, or destruction (Section 2(t)).
3. Roles and Responsibilities
VYNTRA operates as a Data Processor on behalf of its tenant organizations (the Data Fiduciaries). The tenant organization determines what employee data is collected and why. VYNTRA processes that data solely for the purposes specified by the tenant and in accordance with this Privacy Policy and the DPDP Rules.
If you are an employee whose data is processed through VYNTRA, your employer (the tenant) is the Data Fiduciary responsible for the lawful basis of processing. You may direct data-related requests to your employer's administrator or to us directly as outlined in Section 10.
Important: Under Section 8(1) of the DPDP Act, compliance responsibility rests with the Data Fiduciary even where processing is carried out by a Data Processor. VYNTRA, as Data Processor, processes data only under valid contracts with Data Fiduciaries.
4. Information We Collect (Itemized Description — Rule 3)
In accordance with Rule 3(b)(i) of the DPDP Rules, 2025, we provide an itemized description of the personal data we collect:
4.1 Identity and Contact Information
- Full name, email address, phone number
- Employee ID, designation, department
- Profile photograph
4.2 Employment Information
- Joining date, employment status, reporting manager
- Salary information, bank account details (encrypted)
- PAN number, Aadhaar number (encrypted)
4.3 Attendance and Location Data
- GPS coordinates at check-in and check-out
- Live GPS tracking data (only when explicitly enabled by the employer and consented to by the employee)
- Attendance selfie photographs
- IP address and device information
4.4 Financial and Statutory Data
- Payroll data including earnings, deductions (PF, ESIC, PT, TDS)
- Reimbursement claims with receipt images
- Sales records and incentive calculations
4.5 Technical and Usage Data
- Browser type, operating system, device identifiers
- Log files, access timestamps, feature usage patterns
- Cookie data and similar tracking technologies
5. Purpose of Processing (Rule 3(b)(ii))
In accordance with Rule 3(b)(ii) of the DPDP Rules, 2025, we provide a specific description of the goods/services and uses enabled by processing:
- Workforce Management: Managing employee records, attendance, leave, and organizational hierarchy through the HRMS platform.
- Payroll Processing: Calculating and disbursing salaries, statutory deductions (PF, ESIC, PT, TDS), and reimbursements via the payroll module.
- Attendance Verification: Verifying employee presence through GPS-based check-in/out and photo capture via the attendance module.
- Field Force Tracking: Real-time GPS tracking of field employees (only with explicit consent) for operational efficiency via the live tracking module.
- Compliance: Fulfilling legal and regulatory obligations under Indian labor laws, tax laws, and statutory requirements.
- Platform Improvement: Analyzing usage patterns to improve our services (using anonymized/aggregated data where possible).
- Communication: Sending service-related notifications, alerts, and administrative communications.
We do not process your personal data for any purpose incompatible with the above without obtaining your fresh consent.
6. Legal Basis and Consent
Under the DPDP Act and Rules, we process personal data on the following bases:
- Consent (Section 6): We obtain your explicit, informed, and freely given consent before processing sensitive personal data. Consent must be: (1) Free — not bundled or coerced; (2) Specific — for a defined purpose; (3) Informed — supported by this clear notice; (4) Unconditional; (5) Unambiguous — indicated by clear affirmative action. No pre-ticked boxes or implied consent.
- Legitimate Use (Section 7): Certain processing is permitted without consent for: employment purposes, medical emergencies, public health, legal proceedings, state functions, and other notified purposes.
- Employer Direction: As a Data Processor, we process data as directed by the tenant organization (Data Fiduciary) for legitimate business purposes.
Withdrawal of Consent: You have the right to withdraw your consent at any time. Withdrawal must be as easy as giving consent (Rule 3(c)(i)). Withdrawal does not affect the lawfulness of processing before withdrawal. However, withdrawing certain consents may limit your ability to use specific features.
7. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data. We may share your data only in the following circumstances:
- Within the Organization: Your data is accessible to authorized personnel within your organization based on role-based access permissions.
- Service Providers (Data Processors): We share data with trusted third-party service providers under valid contracts (Section 8(2) DPDP Act) that require equivalent security safeguards (Rule 6(f)).
- Legal Obligations: We may disclose data when required by law, court order, or governmental authority.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, with notice to affected users.
8. Data Security (Rule 6 — Reasonable Security Safeguards)
In accordance with Rule 6 of the DPDP Rules, 2025, we implement the following minimum security safeguards to prevent personal data breaches:
- (a) Encryption & Masking: Personal data is secured through encryption (AES-256-GCM), obfuscation, masking, or virtual tokens mapped to personal data — both at rest and in transit (TLS 1.2+).
- (b) Access Controls: Strict role-based access control (RBAC) restricts access to computer resources to authorized personnel only.
- (c) Monitoring & Logging: Visibility on accessing of personal data through appropriate logs, monitoring, and review for enabling detection of unauthorized access, investigation, and remediation.
- (d) Backup & Recovery: Reasonable measures for continued processing in the event of data compromise, including regular encrypted backups and disaster recovery plans.
- (e) One-Year Log Retention: Access and activity logs are retained for a minimum period of one year to enable detection of unauthorized access and investigation (Rule 6(e)).
- (f) Data Processor Contracts: Contracts with Data Processors require equivalent security safeguards (Section 8(2) DPDP Act, Rule 6(f)).
- (g) Technical & Organizational Measures: Appropriate technical and organizational measures including employee training, security policies, and incident response procedures.
9. Data Breach Notification (Rule 7)
In the event of a personal data breach, VYNTRA will comply with Rule 7 of the DPDP Rules, 2025:
- Notification to Data Principals: Without delay, through user account or registered communication mode, we will intimate: (a) description of the breach (nature, extent, timing); (b) likely consequences; (c) mitigation measures implemented; (d) safety measures you may take; (e) contact information for follow-up queries.
- Notification to Data Protection Board: Without delay, a description of the breach. Within 72 hours (or longer period allowed by the Board), a detailed report including: (i) updated breach information; (ii) events, circumstances, and reasons leading to breach; (iii) mitigation measures; (iv) findings regarding who caused the breach; (v) remedial measures to prevent recurrence; (vi) report on intimations given to affected Data Principals.
10. Data Retention and Erasure (Rule 8)
In accordance with Rule 8 of the DPDP Rules, 2025:
- Retention: Personal data is retained only for the period necessary to serve the specified purpose. Once the purpose is served, data is erased unless retention is required by law.
- Advance Notice Before Erasure: We will provide at least 48 hours' advance notice to the Data Principal before erasing personal data (Rule 8).
- Specific Retention Periods:
| Data Category | Retention Period |
|---|---|
| Employee Records | Duration of employment + 8 years (labor law requirement) |
| Payroll & Tax Records | Minimum 8 years (Income Tax Act, 1961) |
| Attendance Data | 3 years from creation |
| Live GPS Tracking Data | 90 days (auto-purged) |
| Consent Records | Duration of processing + 5 years after withdrawal |
| Access & Activity Logs | 1 year minimum (Rule 6(e)) |
| Account Data (on deletion request) | Erased within 30 days (except legal retention) |
11. Your Rights Under the DPDP Act (Rule 14)
As a Data Principal, you have the following rights under Sections 11-14 of the DPDP Act, as operationalized by Rule 14 of the DPDP Rules, 2025:
11.1 Right to Access (Section 11)
You have the right to obtain a summary of your personal data being processed, the processing activities, and the identities of all Data Processors and other Data Fiduciaries with whom your data has been shared.
11.2 Right to Correction and Erasure (Section 12)
You have the right to request correction of inaccurate or misleading personal data and completion of incomplete personal data. You may also request erasure of personal data that is no longer necessary for the purpose for which it was collected.
11.3 Right to Grievance Redressal (Section 13)
You have the right to readily available means of registering grievances. Under Rule 14, grievances must be resolved within 90 days. We provide a grievance redressal mechanism accessible from your dashboard.
11.4 Right to Nominate (Section 14)
You have the right to nominate any other individual who shall, in the event of your death or incapacity, exercise your rights under the Act.
11.5 Right to Withdraw Consent
You may withdraw your consent at any time through your profile settings. Withdrawal must be as easy as giving consent (Rule 3(c)(i)). Upon withdrawal, we will cease processing and erase your data unless retention is required by law.
11.6 How to Exercise Your Rights
- Submitting a request through the Data Subject Request feature in your dashboard
- Emailing us at privacy@vyntra.in
- Contacting your organization's HR administrator
We will acknowledge your request within 48 hours and resolve it within 90 days as required by Rule 14 of the DPDP Rules, 2025.
12. Cross-Border Data Transfers (Rule 15)
Under Section 16 of the DPDP Act and Rule 15 of the DPDP Rules, 2025, your personal data may be transferred outside India only to countries not restricted by the Central Government. The Government may notify specific countries or territories to which transfers are restricted.
We ensure that any cross-border transfer complies with applicable Indian law and that the receiving entity provides adequate data protection. We monitor Government notifications regarding restricted jurisdictions.
13. Children's Data (Rules 10, 11, 12)
Our Platform is not intended for individuals below 18 years of age. We do not knowingly collect personal data from children. Processing of children's personal data requires verifiable consent from a parent or lawful guardian (Rule 10). Similar protections apply to persons with disabilities who have lawful guardians (Rule 11).
14. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Enable essential platform functionality (authentication, session management)
- Remember your preferences and settings
- Analyze usage patterns to improve our services
You can manage your cookie preferences through our cookie consent banner. Non-essential cookies are only placed with your explicit consent.
15. Data Protection Officer (Rule 9) — Appointment Pending
Under Rule 9 of the DPDP Rules, 2025, a Data Protection Officer (DPO) must be appointed and their contact information published on the website/app. A DPO has not yet been formally appointed. Until a DPO is appointed, all data protection queries are managed by the VYNTRA support team via the contact below. A DPO will be appointed as the organization scales and as required by the DPDP Rules.
Data Protection Officer
Email: dpo@vyntra.in
Grievance Officer: grievance@vyntra.in
Data Subject Requests: dsr@vyntra.in
Response time: Within 48 hours of receipt. Grievances resolved within 90 days (Rule 14).
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India or file an appeal with the Appellate Tribunal (Rule 22).
16. Significant Data Fiduciary Obligations (Rule 13)
If VYNTRA or a tenant organization is designated as a Significant Data Fiduciary (SDF) under Section 5 of the DPDP Act, additional obligations under Rule 13 apply, including:
- Appointment of a Data Protection Officer (DPO) who is based in India
- Conducting Data Protection Impact Assessments (DPIAs) periodically
- Annual audits of data processing activities by an independent auditor
- Due diligence to verify that algorithmic software does not pose a risk to the rights of Data Principals
- Compliance with any additional requirements notified by the Central Government
17. Exemptions (Section 17, Rule 16, Rule 22)
Certain processing is exempt from some or all provisions of the DPDP Act under Section 17:
- Processing by State instrumentalities for sovereignty, security, public order (Section 17(1))
- Processing for research, archiving, or statistical purposes (Section 17(2)(b), Rule 16)
- Processing for journalistic purposes in public interest (Section 17(2)(a))
- Processing for legal proceedings and judicial functions (Section 17(2))
- Startups and small businesses may be exempted by Government notification under Section 17(4) (no notification issued as of June 2026)
Important: Even under exemptions, Section 8(1) (compliance responsibility) and Section 8(5) (valid processor contracts) survive. Security safeguards are maintained regardless of exemption status.
18. Consent Withdrawal and Erasure (Rule 3(c)(i), Rule 8)
You may withdraw your consent at any time. Withdrawal must be as easy as giving consent — if consent was given with a single click, withdrawing it requires no more effort (Rule 3(c)(i)).
Upon withdrawal, we will cease processing and erase your personal data. We will provide at least 48 hours' advance notice before erasure (Rule 8). Erasure may be delayed where retention is required by law (e.g., tax records, labor law compliance).
19. Changes to This Policy
We may update this Privacy Policy from time to time. Any material changes will be notified to you through the Platform or via email at least 30 days before taking effect. The "Last updated" date at the top of this page indicates when the policy was last revised. Continued use of the Platform after changes constitutes acceptance of the updated policy.
20. Contact Us (Rule 3(c), Rule 9)
In accordance with Rule 3(c) and Rule 9 of the DPDP Rules, 2025, we provide the following communication links:
VYNTRA
Email: vyntrahrms-support@swedana.in
Note: A Data Protection Officer (DPO) has not yet been formally appointed. This email is managed by the VYNTRA support team who handles all data protection queries. A DPO will be appointed as required under Rule 9 of the DPDP Rules, 2025.
This Privacy Policy is available in English. If you require it in any of the 22 languages specified in the Eighth Schedule of the Constitution of India, please contact us and we will make it available.