Data Processing Agreement
How we process your organisation’s data on your behalf.
Last updated: 28 September 2026
Parties and scope
This Data Processing Agreement is between the customer (the “Controller”, or “Data Fiduciary” under Indian law) and Appable Technologies Private Limited (the “Processor”). It applies to personal data the Controller puts into WebHR (“Customer Data”) and forms part of the Terms of Service.
It reflects Article 28(3) of the GDPR, the UK GDPR, and section 8(2) of the Digital Personal Data Protection Act, 2023.
Details of processing
- Subject matter: providing the WebHR HR, payroll and workforce platform.
- Duration: the subscription, plus the return and deletion period below.
- Nature and purpose: hosting, storage, computation of payroll and attendance, communication and support.
- Data subjects: the Controller’s employees, contractors, candidates and administrators.
- Categories: identity and contact data; employment, attendance and leave; payroll, bank and tax identifiers (PAN, UAN, ESI number); documents; performance data; location at check-in; and, where enabled, face templates (biometric, a special category).
Instructions and confidentiality
The Processor processes Customer Data only on the Controller’s documented instructions: the Terms, this agreement, and the Controller’s use and configuration of WebHR. If an instruction appears to break the law, the Processor will say so. Everyone authorised to process Customer Data is bound by confidentiality.
Security
The Processor maintains technical and organisational measures including:
- tenant isolation enforced by the database (row-level security);
- TLS for all data in transit;
- salted one-way password hashing;
- role-based access, with multi-factor authentication available;
- append-only audit logging, including access to salary, bank, identity and review data;
- optional account lockout after repeated failed sign-ins;
- field-level encryption of bank, PAN, Aadhaar and passport numbers, being rolled out;
- regular backups.
Sub-processors
The Controller authorises the sub-processors listed on our sub-processors page. The Processor gives 30 days’ notice of a new one. The Controller may object on reasonable data-protection grounds; if the parties cannot agree, the Controller may end the affected service with a pro-rata refund. The Processor imposes equivalent obligations on each sub-processor and remains liable for it.
Data subjects’ rights and assistance
WebHR includes tools to export, correct, restrict and erase a person’s data, and to record each request and its outcome. The Processor passes any request it receives directly to the Controller without delay, and helps the Controller with security, breach notification, data protection impact assessments and prior consultation, taking into account the information available to it.
Personal data breaches
The Processor notifies the Controller without undue delay and in any case within 48 hours of becoming aware of a personal data breach affecting Customer Data, with what is known and updates as it learns more. This lets the Controller inform the Data Protection Board of India within 72 hours and, where the GDPR applies, the supervisory authority within 72 hours.
International transfers
Customer Data is hosted in Germany. Access from India by the Processor’s staff, and transfers to sub-processors outside the European Economic Area, are covered by the Standard Contractual Clauses (Commission Decision 2021/914, Module 2 or 3 as applicable) and, for the UK, the International Data Transfer Addendum. Transfers from India are made in line with section 16 of the DPDP Act.
Return and deletion
For 30 days after the subscription ends, the Controller can export Customer Data. The Processor then deletes it, and removes it from backups as they rotate, except where law requires the Controller or the Processor to keep it. Such data is kept only for the period the law sets and used only for that purpose.
Audits
The Processor makes available the information needed to show compliance. It allows an audit by the Controller or its auditor once a year, on 30 days’ notice, at the Controller’s cost, during business hours and under confidentiality, or answers a reasonable written questionnaire instead.
Liability and precedence
Liability is as set out in the Terms. If this agreement and the Terms conflict on data protection, this agreement prevails.
To receive a copy for signature, write to hello@webhr.in.
Ready to make HR feel effortless?
Join 5,000+ companies replacing spreadsheets and legacy HRMS with WebHR. Setup in 7 days. First 14 days free.

