Privacy Policy
What we collect, why we hold it, and what you can ask us to do with it.
Last updated: 28 September 2026
Who we are
WebHR is an HR, payroll and workforce management platform operated by Appable Technologies Private Limited. This policy explains what personal data we collect, why we hold it, and what you can ask us to do with it.
Two different relationships are covered here. When you browse this website or ask for a demo, we are the controller of your data. When your employer uses WebHR to run their HR, they are the controller and we are the processor acting on their instructions — in that case their own privacy notice governs, and requests about your employment records should go to them first.
Write to us at hello@webhr.in. For a complaint about how we handle personal data, see “Grievance officer” below.
What we collect
- Account and contact details — name, work email, phone if you give it, employer, role.
- Workspace data your employer puts into the platform — employment records, attendance, leave, payroll inputs, documents they choose to store.
- Attendance evidence where your employer has enabled it — a selfie at check-in, device identifier, and location at the moment of the punch. Collected only when a punch is made, never in the background.
- Technical data — IP address, browser and device type, and pages visited, used to keep the service secure and working.
- Support and sales correspondence you send us.
Demo requests and the newsletter
When you ask for a demo we collect your name and work email and, if you give them, your phone, company, company size and message. The newsletter form collects only your email. Both are stored in WebHR’s own database, read only by our team to reply to you or send the newsletter, and never sold or shared.
We send you marketing email only if you asked for it, and only after you click the confirmation link we email you. Every marketing email has an unsubscribe link. Ask us to delete your details at any time.
Face verification at check-in
Where your employer uses face verification for attendance, the photo taken when you check in is compared with a reference photo of you that your employer’s administrator enrolled. Enrolment is done by that administrator, never from your own account, and it records your consent together with the date and the wording you agreed to.
From the reference photo we derive a numerical face template, which we store encrypted; we do not keep the reference photo itself. The photo taken at check-in is used to confirm that it shows a live person rather than a picture, and to compare it with that template where your employer uses face verification. When the check-in is accepted, a reduced copy of the photo, with the location and device data inside the image file removed, is kept for 90 days as evidence of that punch. It can be seen by you and by the people at your employer who can already see your attendance, and every viewing is logged. A photo from a check-in that was refused is not kept. If you check in without a connection, the photo waits on your phone, encrypted, until it can be sent; it is deleted as soon as it is, and never kept on the phone for more than 72 hours.
The comparison runs on our own servers. No face data is sent to a third-party recognition service. Face data is used only to verify attendance for your employer, including spotting one person checking in for another; it is never sold, never used for advertising, and never used to identify you for any other purpose. Your employer can remove your enrolment at any time, and your face template is deleted with your other biometric attendance evidence at the end of its retention period.
AI features
The in-app assistant sends the messages you type to the AI provider your employer has chosen and configured for their workspace; your employer decides whether it is on at all. Nothing else from your records is attached to those messages by WebHR.
Workforce insights such as attrition risk are statistics about a workspace as a whole, calculated inside WebHR. They are not scores about you, and WebHR makes no decision about you by automated means alone — hiring, pay and employment decisions are made by people at your employer.
Why we hold it
We do not sell personal data, and we do not use workspace data to train models for other customers. Each use has a legal basis:
| What we do | Basis under the GDPR | Basis under the DPDP Act |
|---|---|---|
| Reply to a demo request | Steps you asked for before a contract (Art. 6(1)(b)) | Your consent, given by sending the form (s.6) |
| Send the newsletter, or product news when you ticked the box | Your consent, which you can withdraw at any time (Art. 6(1)(a)) | Your consent (s.6) |
| Provide WebHR to your employer | We are the processor; your employer’s basis applies | We process for your employer, the Data Fiduciary (s.8(2)) |
| Keep accounts secure: sign-in records, audit logs, lockout | Our legitimate interest in security (Art. 6(1)(f)) | Reasonable security safeguards (s.8(5)) |
| Face verification at check-in | Your explicit consent, recorded at enrolment with its wording and date (Art. 9(2)(a)) | Your consent, recorded (s.6) |
| Keep payroll, tax and social-security records after someone leaves | Legal obligation (Art. 6(1)(c)) | Retention required by law (s.8(7)) |
Who we share it with
Infrastructure and communication providers who process data on our behalf under contract, and nobody else except where the law requires it or you have asked us to. They are listed, with where they are and what they handle, on our sub-processors page.
Where your data is stored
WebHR’s servers and database are hosted by Contabo GmbH in Germany, inside the European Union. Data of customers and users in India is therefore transferred from India to Germany, which the Digital Personal Data Protection Act, 2023 permits.
Some of our team and service providers are outside the European Economic Area: our staff work from India, and the push-notification provider and the optional email and AI providers are in the United States. Where personal data of people in the EEA or the UK is accessed from or sent to those countries, we rely on the European Commission’s Standard Contractual Clauses and, for the UK, the International Data Transfer Addendum, or on the recipient’s certification under the EU–US Data Privacy Framework.
How long we keep it
Workspace data is kept while your employer’s subscription runs. After that, and after someone leaves an employer, these are the periods WebHR applies unless your employer’s contract sets others. Records the law requires us to keep override a deletion request until their period ends.
| Data | Kept for | Why |
|---|---|---|
| Payroll, payslips, TDS workings, Form 16, tax declarations and proofs | 8 years after the financial year | Income-tax record-keeping |
| EPF and ESI contribution records and challans | 8 years | ESI regulations; aligned with tax records |
| Wage, attendance and leave registers | 8 years | Labour-law registers; aligned with payroll |
| Other data of someone who has left (contact details, documents, photo, reviews) | 3 years after the leaving date, then pseudonymised | The period for most employment claims |
| Face template | Until enrolment is removed or employment ends | The purpose you consented to has ended |
| Selfie taken at a check-in or check-out | 90 days after the punch | Long enough to settle a dispute about that day’s attendance |
| Rejected candidates | 6 months after the decision, or 24 months if you agree | To answer questions about a hiring decision |
| Demo requests and newsletter sign-ups | 24 months after last contact, or until you withdraw | Consent and our legitimate interest |
| Security and access audit logs | 7 years | Accountability |
| Sign-in and traffic logs | 1 year | DPDP Rules 2025 |
| Backups | 30 days, rolling | Recovery |
Your rights
You can ask for a copy of your data, ask us to correct it, ask for deletion, ask us to restrict how it is used, object to a particular use, or withdraw a consent you previously gave. Write to hello@webhr.in and we will respond within 30 days.
If your data sits inside your employer’s workspace, you can also ask from inside the WebHR app, under My Account → Your data & privacy. That request goes to your employer, because it is their record to release, and you can follow it there.
If you are not satisfied with our answer you can complain to the Data Protection Board of India or, in the EU or UK, to your data protection authority.
Grievance officer
Questions or complaints about how we handle personal data can be sent to our Grievance Officer at grievance@webhr.in. We acknowledge a grievance within two working days and resolve it within 90 days, as the Digital Personal Data Protection Rules, 2025 require. If you are not satisfied, you may complain to the Data Protection Board of India; where the GDPR applies, to your local data protection authority.
Cookies
This website sets no cookies for visitors. What the WebHR app keeps in your browser is listed on our cookies page.
Changes
We will post any change on this page and move the date at the top. Material changes affecting your rights will also be sent to the account owner by email.
Ready to make HR feel effortless?
Join 5,000+ companies replacing spreadsheets and legacy HRMS with WebHR. Setup in 7 days. First 14 days free.

