Privacy Policy
Last updated: 22 July 2026
Shivay Digital Crowd Media Tech (“we”) operates Shivay Workspace. This policy explains what personal data the platform handles, why, and what rights people have. It is written with India's Digital Personal Data Protection Act, 2023 in mind.
1. Our role
Each subscribing organisation is the Data Fiduciary for its employees' data and decides what to collect. We act as a Data Processor, handling that data only to run the Service on the organisation's instructions. Employees with questions about their own records should contact their employer's HR first.
2. Data we process
- Identity & contact: name, work email, phone, address, date of birth, photo.
- Employment: employee code, department, designation, manager, joining date, salary structure, leave balances.
- Statutory identifiers: PAN, Aadhaar number, UAN and bank details, where the employer chooses to record them.
- Attendance: GPS coordinates at check-in/out, distance from office, optional selfie, IP address, device and browser, battery and network type, timestamps.
- Work activity: tasks, projects, daily reports, expense claims, documents, chat messages, complaints.
- Technical logs: access and audit logs kept for security.
3. Purpose
Data is used solely to provide the Service: verifying attendance, calculating salary and deductions, managing leave and approvals, assigning work, generating reports, and securing accounts. We do not sell personal data, do not use it for advertising, and do not use it to train third-party AI models.
4. Location and camera
Location and camera are used only at the moment of an attendance action, and only after the browser prompts for permission. We do not track location in the background. If permission is denied, check-in may be unavailable as configured by the employer.
5. Storage and security
- Data is stored on servers located in India.
- Each organisation has a separate database — data is never mixed between customers.
- All traffic is encrypted in transit (HTTPS/TLS). Passwords are stored as bcrypt hashes and are never readable by us.
- Database connection secrets are encrypted at rest (AES-256-GCM).
- Access is role-based; administrative actions are recorded in an audit log.
6. Retention
- Records are retained while the organisation's subscription is active.
- Automated backups are retained for 45 days, then deleted.
- After termination, the workspace may be permanently deleted 30 days after the final data export.
- Employers may need to keep payroll and attendance records longer to meet statutory obligations.
7. Sharing
We share data only with infrastructure providers necessary to run the Service (hosting, email delivery), and where required by law. All such providers are bound by confidentiality obligations.
8. Your rights
Individuals may request access to, correction of, or deletion of their personal data, and may withdraw consent where processing is consent-based. Requests should go to the employer (Data Fiduciary); we will assist them in fulfilling such requests. Grievances may also be sent to us at omkar.dmimpact@gmail.comand will be acknowledged within 7 days.
9. Breach notification
In the event of a personal data breach, we will notify affected organisations without undue delay and cooperate with any reporting required to the Data Protection Board of India.
10. Children
The Service is not intended for anyone under 18.
11. Changes
Material changes to this policy will be notified in the application or by email at least 14 days in advance.
12. Contact
Grievance Officer: omkar.dmimpact@gmail.com
Note: this document is a good-faith template and not legal advice. Have it reviewed by a qualified lawyer, especially before handling Aadhaar data at scale.