WebHR
Legal

Privacy Policy

What we collect, why we hold it, and what you can ask us to do with it.

Last updated: 28 September 2026

Who we are

WebHR is an HR, payroll and workforce management platform operated by Appable Technologies Private Limited. This policy explains what personal data we collect, why we hold it, and what you can ask us to do with it.

Two different relationships are covered here. When you browse this website or ask for a demo, we are the controller of your data. When your employer uses WebHR to run their HR, they are the controller and we are the processor acting on their instructions — in that case their own privacy notice governs, and requests about your employment records should go to them first.

Write to us at hello@webhr.in. For a complaint about how we handle personal data, see “Grievance officer” below.

What we collect

  • Account and contact details — name, work email, phone if you give it, employer, role.
  • Workspace data your employer puts into the platform — employment records, attendance, leave, payroll inputs, documents they choose to store.
  • Attendance evidence where your employer has enabled it — a selfie at check-in, device identifier, and location at the moment of the punch. Collected only when a punch is made, never in the background.
  • Technical data — IP address, browser and device type, and pages visited, used to keep the service secure and working.
  • Support and sales correspondence you send us.

Demo requests and the newsletter

When you ask for a demo we collect your name and work email and, if you give them, your phone, company, company size and message. The newsletter form collects only your email. Both are stored in WebHR’s own database, read only by our team to reply to you or send the newsletter, and never sold or shared.

We send you marketing email only if you asked for it, and only after you click the confirmation link we email you. Every marketing email has an unsubscribe link. Ask us to delete your details at any time.

Face verification at check-in

Where your employer uses face verification for attendance, the photo taken when you check in is compared with a reference photo of you that your employer’s administrator enrolled. Enrolment is done by that administrator, never from your own account, and it records your consent together with the date and the wording you agreed to.

From the reference photo we derive a numerical face template, which we store encrypted; we do not keep the reference photo itself. The photo taken at check-in is used to confirm that it shows a live person rather than a picture, and to compare it with that template where your employer uses face verification. When the check-in is accepted, a reduced copy of the photo, with the location and device data inside the image file removed, is kept for 90 days as evidence of that punch. It can be seen by you and by the people at your employer who can already see your attendance, and every viewing is logged. A photo from a check-in that was refused is not kept. If you check in without a connection, the photo waits on your phone, encrypted, until it can be sent; it is deleted as soon as it is, and never kept on the phone for more than 72 hours.

The comparison runs on our own servers. No face data is sent to a third-party recognition service. Face data is used only to verify attendance for your employer, including spotting one person checking in for another; it is never sold, never used for advertising, and never used to identify you for any other purpose. Your employer can remove your enrolment at any time, and your face template is deleted with your other biometric attendance evidence at the end of its retention period.

AI features

The in-app assistant sends the messages you type to the AI provider your employer has chosen and configured for their workspace; your employer decides whether it is on at all. Nothing else from your records is attached to those messages by WebHR.

Workforce insights such as attrition risk are statistics about a workspace as a whole, calculated inside WebHR. They are not scores about you, and WebHR makes no decision about you by automated means alone — hiring, pay and employment decisions are made by people at your employer.

Why we hold it

We do not sell personal data, and we do not use workspace data to train models for other customers. Each use has a legal basis:

What we doBasis under the GDPRBasis under the DPDP Act
Reply to a demo requestSteps you asked for before a contract (Art. 6(1)(b))Your consent, given by sending the form (s.6)
Send the newsletter, or product news when you ticked the boxYour consent, which you can withdraw at any time (Art. 6(1)(a))Your consent (s.6)
Provide WebHR to your employerWe are the processor; your employer’s basis appliesWe process for your employer, the Data Fiduciary (s.8(2))
Keep accounts secure: sign-in records, audit logs, lockoutOur legitimate interest in security (Art. 6(1)(f))Reasonable security safeguards (s.8(5))
Face verification at check-inYour explicit consent, recorded at enrolment with its wording and date (Art. 9(2)(a))Your consent, recorded (s.6)
Keep payroll, tax and social-security records after someone leavesLegal obligation (Art. 6(1)(c))Retention required by law (s.8(7))

Who we share it with

Infrastructure and communication providers who process data on our behalf under contract, and nobody else except where the law requires it or you have asked us to. They are listed, with where they are and what they handle, on our sub-processors page.

Where your data is stored

WebHR’s servers and database are hosted by Contabo GmbH in Germany, inside the European Union. Data of customers and users in India is therefore transferred from India to Germany, which the Digital Personal Data Protection Act, 2023 permits.

Some of our team and service providers are outside the European Economic Area: our staff work from India, and the push-notification provider and the optional email and AI providers are in the United States. Where personal data of people in the EEA or the UK is accessed from or sent to those countries, we rely on the European Commission’s Standard Contractual Clauses and, for the UK, the International Data Transfer Addendum, or on the recipient’s certification under the EU–US Data Privacy Framework.

How long we keep it

Workspace data is kept while your employer’s subscription runs. After that, and after someone leaves an employer, these are the periods WebHR applies unless your employer’s contract sets others. Records the law requires us to keep override a deletion request until their period ends.

DataKept forWhy
Payroll, payslips, TDS workings, Form 16, tax declarations and proofs8 years after the financial yearIncome-tax record-keeping
EPF and ESI contribution records and challans8 yearsESI regulations; aligned with tax records
Wage, attendance and leave registers8 yearsLabour-law registers; aligned with payroll
Other data of someone who has left (contact details, documents, photo, reviews)3 years after the leaving date, then pseudonymisedThe period for most employment claims
Face templateUntil enrolment is removed or employment endsThe purpose you consented to has ended
Selfie taken at a check-in or check-out90 days after the punchLong enough to settle a dispute about that day’s attendance
Rejected candidates6 months after the decision, or 24 months if you agreeTo answer questions about a hiring decision
Demo requests and newsletter sign-ups24 months after last contact, or until you withdrawConsent and our legitimate interest
Security and access audit logs7 yearsAccountability
Sign-in and traffic logs1 yearDPDP Rules 2025
Backups30 days, rollingRecovery

Your rights

You can ask for a copy of your data, ask us to correct it, ask for deletion, ask us to restrict how it is used, object to a particular use, or withdraw a consent you previously gave. Write to hello@webhr.in and we will respond within 30 days.

If your data sits inside your employer’s workspace, you can also ask from inside the WebHR app, under My Account → Your data & privacy. That request goes to your employer, because it is their record to release, and you can follow it there.

If you are not satisfied with our answer you can complain to the Data Protection Board of India or, in the EU or UK, to your data protection authority.

Grievance officer

Questions or complaints about how we handle personal data can be sent to our Grievance Officer at grievance@webhr.in. We acknowledge a grievance within two working days and resolve it within 90 days, as the Digital Personal Data Protection Rules, 2025 require. If you are not satisfied, you may complain to the Data Protection Board of India; where the GDPR applies, to your local data protection authority.

Cookies

This website sets no cookies for visitors. What the WebHR app keeps in your browser is listed on our cookies page.

Changes

We will post any change on this page and move the date at the top. Material changes affecting your rights will also be sent to the account owner by email.

Questions about this page? Write to hello@webhr.in or see our contact page.

Ready to make HR feel effortless?

Join 5,000+ companies replacing spreadsheets and legacy HRMS with WebHR. Setup in 7 days. First 14 days free.