Privacy Policy

FlowHR Technologies Pvt. Ltd.

AES-256GDPRISO 27001
Last Updated: 27 July 2026  ·  Effective: 1 August 2026
01

Overview & Scope

FlowHR ("we", "our", or "us") is a biometric Human Resource Management SaaS platform operated by FlowHR Technologies Pvt. Ltd. This Privacy Policy ("Policy") governs how we collect, use, store, share, and protect information about individuals who interact with our platform, website (flowhr.com), APIs, and related services (collectively, the "Services").

This Policy applies to: (a) HR administrators and company representatives who purchase and configure FlowHR for their organisation; (b) employees and contractors whose data is processed through the platform by their employer; (c) visitors and prospective customers who browse our website or request a demo. If you are an employee whose data is processed by your employer through FlowHR, your primary relationship regarding that data is with your employer — FlowHR acts as a data processor on their behalf.

By accessing or using our Services, you acknowledge that you have read and understood this Policy. If you do not agree with any part of this Policy, please discontinue use of our Services immediately.

02

Data We Collect

We collect information in three principal ways: (i) information you provide directly; (ii) information generated automatically through your use of our Services; and (iii) information we receive from your employer or third-party integrations.

Account & Identity Data — When you register, we collect your full name, business email address, job title, organisation name, phone number, and account credentials (password stored as a salted bcrypt hash). We never store passwords in plain text.

Employee HR Data — Employers upload or sync employee records into FlowHR including: employee ID, department, designation, joining date, compensation details, leave balances, performance ratings, emergency contacts, and government-issued identification numbers (e.g., Aadhaar, PAN, National Insurance). This data is provided by and belongs to the employer.

Attendance & Device Data — Our attendance terminals capture timestamps, device serial numbers, terminal location identifiers, and, where biometric hardware is deployed, raw biometric templates. We also log access events (login/logout times, IP addresses, user agents) for security audit purposes.

Communication & Support Data — If you contact us via email, chat, or support tickets, we retain that correspondence to resolve your issue and improve our Services.

Usage Analytics — We automatically collect page-view events, feature interaction logs, session duration, and performance metrics using privacy-respecting analytics. This data is aggregated and does not directly identify individual end-users.

03

Biometric Data Handling

FlowHR integrates with third-party biometric attendance hardware (fingerprint scanners, facial recognition terminals, iris scanners) manufactured and configured by your employer. We treat biometric data as a special category requiring the highest level of protection.

What constitutes biometric data under our policy: fingerprint minutiae templates, facial geometry feature vectors, and iris pattern codes. We do NOT store raw biometric images — only mathematical templates derived from the biometric scan, which cannot be reverse-engineered to reconstruct the original biometric sample.

Storage & Encryption — Biometric templates are stored in an isolated, encrypted database partition using AES-256 encryption at rest. Templates are additionally encrypted with a hardware security module (HSM)-managed key unique to each organisation. Template data is never co-mingled across organisations.

Purpose Limitation — Biometric templates are used exclusively for attendance verification. They are never shared with third parties for marketing, profiling, or any purpose other than confirming that the person presenting their biometric matches the enrolled template on record for the claimed employee ID.

Enrolment Consent — It is the responsibility of the employing organisation (data controller) to obtain explicit written consent from each employee before enrolment. FlowHR's onboarding checklist includes a mandatory consent acknowledgement step, and our DPA with each customer contractually requires this.

Deletion — When an employee is offboarded or when your organisation terminates its FlowHR subscription, all biometric templates for that employee/organisation are permanently and irreversibly deleted from our systems within 72 hours, with a certificate of deletion provided on request.

04

Employee Data & Controller Relationships

For employee personal data (attendance records, payroll data, leave histories, performance reviews), your employer is the data controller and FlowHR is the data processor. This means your employer determines the purpose and means of processing; FlowHR merely executes those instructions on their behalf.

Data Processing Agreement (DPA) — All organisations using FlowHR must execute our standard DPA (available at flowhr.com/legal/dpa) before processing employee data. The DPA incorporates Standard Contractual Clauses (SCCs) for cross-border transfers where applicable.

Access Controls — Employee data is logically segmented by organisation tenant. Our multi-tenant architecture ensures strict isolation: no organisation's data can be accessed by another. Role-based access controls within each organisation limit which HR administrators can view sensitive records such as payroll, medical, or disciplinary information.

Sensitive Categories — FlowHR allows employers to optionally store health-related data (e.g., sick leave reasons, medical certificates). This data is treated as a sensitive special category under GDPR Article 9 and requires explicit consent or a legal basis under domestic employment law. We recommend employers use FlowHR's consent management module for such data.

05

How We Use Your Data

Service Delivery — To provide the core features of FlowHR including attendance tracking, payroll calculation, leave management, performance appraisals, recruitment workflows, and HR analytics dashboards.

Security & Fraud Prevention — To detect and prevent unauthorised access, detect anomalous login patterns, enforce session limits, and maintain security audit logs required for compliance frameworks such as ISO 27001.

Product Improvement — Aggregated, anonymised usage data helps us understand which features are most valuable, identify bottlenecks in user workflows, and prioritise our development roadmap. We do not use individual employee data for product improvement without employer permission.

Communications — To send service notifications (e.g., maintenance windows, security alerts), product update announcements, and, where you have opted in, marketing communications about FlowHR features and events. You may unsubscribe from marketing emails at any time via the link in each email.

Legal Compliance — To comply with applicable laws and regulations, respond to lawful requests from government authorities, enforce our Terms of Service, and protect our legal rights.

We do NOT sell your personal data. We do NOT use employee data to train AI models without explicit consent. We do NOT engage in behavioural advertising using employee or HR data.

06

Third-Party Integrations

FlowHR integrates with a curated set of third-party service providers to deliver our Services. Each sub-processor has been evaluated for privacy and security compliance and is bound by data processing agreements.

Cloud Infrastructure — We host our platform on Amazon Web Services (AWS) in the ap-south-1 (Mumbai) region, with disaster-recovery failover to ap-southeast-1 (Singapore). AWS infrastructure is ISO 27001, SOC 2 Type II, and PCI-DSS certified.

Payment Processing — Subscription billing is handled by Razorpay and Stripe. FlowHR does not store credit card numbers or payment credentials. Transactions are processed using PCI-DSS Level 1 compliant payment gateways.

Email & Notifications — We use Amazon SES for transactional emails and Firebase Cloud Messaging for push notifications. These providers only receive the data necessary to deliver the specific message (recipient address/token, message content).

Analytics — We use a self-hosted instance of Plausible Analytics for website traffic analytics. Plausible is cookieless and GDPR-compliant. No personal data is shared with any advertising or social media platform for analytics purposes.

Payroll Integrations — Where employers connect FlowHR to payroll providers (e.g., GreytHR, Keka, Zoho Payroll), data is transmitted over encrypted API connections. Employers are responsible for reviewing the privacy terms of any third-party payroll software they connect.

A full and current list of our sub-processors is published at flowhr.com/legal/sub-processors and is updated within 15 days of any addition or removal.

07

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes outlined in this Policy, to comply with legal obligations, resolve disputes, and enforce our agreements.

Active Accounts — Employee HR records and attendance data are retained for the duration of the employment relationship plus a post-termination period determined by your employer's data retention policy (minimum recommended: 7 years to comply with Indian labour laws and potential statutory disputes).

Biometric Templates — Deleted within 72 hours of employee offboarding or subscription termination (see Section 03).

Security Logs — Access logs and audit trails are retained for 12 months online and 24 months in cold archival storage, after which they are permanently deleted.

Backup Data — Encrypted backups are retained for 30 days. When primary data is deleted, backup copies are expunged during the next scheduled backup rotation cycle, which runs daily.

Inactive Accounts — If your organisation's subscription lapses and no renewal or data export request is made within 90 days, we will issue a 30-day notice before permanently deleting all associated data. A final data export in machine-readable format (JSON/CSV) will be made available upon request during this window.

Anonymised, aggregated statistical data that cannot be used to identify individuals is exempt from retention limits and may be kept indefinitely for benchmarking and research purposes.

08

Your Rights as a Data Subject

Depending on your jurisdiction, you may have the following rights with respect to your personal data. FlowHR supports the exercise of these rights through self-service tools in the platform and via our Data Protection Officer (DPO).

Right of Access (Art. 15 GDPR) — You may request a complete copy of the personal data we hold about you, free of charge, in a portable format. Responses are provided within 30 days.

Right to Rectification (Art. 16 GDPR) — If your personal data is inaccurate or incomplete, you may request correction. HR administrators can update most employee records directly in the platform; other corrections can be requested via dpo@flowhr.com.

Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR) — You may request deletion of your personal data where the processing is no longer necessary, consent has been withdrawn, or processing is unlawful. Note that where your employer has a legal obligation to retain certain records (e.g., tax filings), erasure may not be possible until the statutory period expires.

Right to Restriction of Processing (Art. 18 GDPR) — You may request that we restrict processing of your data (e.g., while a rectification request is pending).

Right to Data Portability (Art. 20 GDPR) — You may receive your personal data in a structured, commonly used, machine-readable format (JSON/CSV) for transfer to another controller.

Right to Object (Art. 21 GDPR) — You may object to processing based on legitimate interests or for direct marketing. If you object to marketing, we will cease immediately.

To exercise any of these rights, email dpo@flowhr.com with the subject line "Data Subject Request — [Right Type]". We will respond within 30 calendar days. If you are an employee, some requests must be directed to your employer as the data controller.

09

GDPR & International Compliance

FlowHR is committed to compliance with the EU General Data Protection Regulation (GDPR), the UK GDPR, India's Digital Personal Data Protection Act 2023 (DPDPA), and other applicable data protection laws.

Legal Bases for Processing (GDPR Art. 6) — We rely on the following legal bases: (a) Contract — processing necessary to perform our service agreement; (b) Legitimate Interests — security monitoring, fraud prevention, and service improvement; (c) Legal Obligation — retaining records as required by law; (d) Consent — marketing communications and optional special-category data processing.

Cross-Border Data Transfers — For customers in the EU/EEA, personal data is stored in-region where possible. Where transfers occur to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) as the transfer mechanism. Our DPA includes the latest SCCs approved by the European Commission.

Data Protection Impact Assessments (DPIAs) — We conduct DPIAs for all new features that involve systematic processing of sensitive or biometric data. Results inform our engineering decisions and are available to enterprise customers upon request under NDA.

Under India's DPDPA, we act as a Data Fiduciary in respect of data provided by our direct customers, and as a Data Processor in respect of employee data processed on behalf of employer-customers. We maintain the notices and consent records required under the Act.

10

Security Measures

FlowHR employs a defence-in-depth security architecture to protect personal and biometric data against unauthorised access, disclosure, alteration, and destruction.

Encryption — All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Database backups are encrypted with separate key material. Biometric templates use an additional HSM-managed encryption layer.

Access Control — Access to production systems is restricted to authorised personnel via multi-factor authentication (MFA) and hardware security keys. Privileged access is time-limited and logged. We follow the principle of least privilege throughout our infrastructure.

Penetration Testing — We conduct annual third-party penetration tests and quarterly internal vulnerability assessments. Critical and high-severity findings are remediated within 14 and 30 days respectively. We operate a responsible disclosure programme at flowhr.com/security.

Incident Response — We maintain a documented incident response plan. In the event of a data breach affecting your personal data, we will notify affected organisations within 72 hours of becoming aware, in compliance with GDPR Article 33 and applicable national laws.

Employee Training — All FlowHR staff complete mandatory privacy and security awareness training at onboarding and annually thereafter. Personnel with access to personal data sign confidentiality agreements.

ISO 27001 Certification — Our information security management system (ISMS) is certified to ISO/IEC 27001:2022. Our current certificate is available on our Security page.

11

Cookies & Tracking

Our website (flowhr.com) uses a minimal set of cookies to enable core functionality and understand how visitors use our site.

Strictly Necessary Cookies — Session cookies required for authentication and CSRF protection. These cannot be disabled without breaking core functionality. Duration: session (deleted on browser close).

Preference Cookies — Store your chosen language and display preferences (e.g., dark mode). Duration: 1 year.

Analytics Cookies — We use our self-hosted Plausible Analytics instance, which does NOT set cookies and does NOT collect personally identifiable information. It tracks only aggregated, anonymous page-view data.

We do NOT use advertising cookies, third-party tracking pixels, or social media retargeting technologies. We do NOT share cookie data with advertising platforms.

Cookie Consent — A cookie consent banner is presented to EU/EEA visitors on first visit. You may withdraw consent or change your preferences at any time via the "Cookie Settings" link in our website footer.

The FlowHR web application (app.flowhr.com) uses HttpOnly, SameSite=Strict session cookies for authentication, alongside localStorage for user interface preferences. These are strictly necessary for the application to function.

12

Children's Privacy & Sensitive Groups

FlowHR is a B2B enterprise software platform intended for use by organisations and adults (18+) in a professional employment context. We do not knowingly collect personal data from individuals under the age of 18.

If an employer inadvertently uploads data relating to a minor (e.g., an intern below 18 years of age) without appropriate legal basis, they remain responsible for ensuring lawful processing. FlowHR recommends employers perform age verification as part of their onboarding process.

If you believe we have inadvertently collected data about a person under 18 years of age, please contact dpo@flowhr.com immediately and we will take prompt steps to delete such data.

13

Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, applicable laws, or our Services. When we make material changes, we will:

(a) Update the "Last Updated" date at the top of this page; (b) Send an in-app notification to all account administrators at least 30 days before the changes take effect; (c) For changes involving special-category data (e.g., biometrics), send an email notification to the registered DPA contact for each organisation.

Your continued use of our Services after the effective date of an updated Policy constitutes your acceptance of the revised terms. If you do not agree to the updated Policy, you must discontinue use of the Services and contact your account manager to arrange an orderly exit.

Previous versions of this Policy are archived and available upon request by emailing dpo@flowhr.com with the subject "Privacy Policy Archive".

Data Protection Officer

Contact Our DPO

For data subject requests, privacy concerns, DPA enquiries, or biometric data deletion requests, contact our Data Protection Officer directly. We respond within 30 calendar days.

Postal Address

FlowHR Technologies Pvt. Ltd.
Attn: Data Protection Officer
5th Floor, Tech Park Alpha,
Whitefield, Bengaluru — 560066
Karnataka, India

Response SLA

  • • Data access requests: 30 days
  • • Breach notifications: 72 hours
  • • Erasure requests: 30 days
  • • Biometric deletion: 72 hours

This Policy is governed by the laws of India. Disputes shall be subject to the exclusive jurisdiction of courts in Bengaluru, Karnataka. For EU residents, you also have the right to lodge a complaint with your local supervisory authority. Contact us with any questions.