Privacy Policy

Last updated: 30 June 2026

Madhan Raj P, sole proprietor, trading as InsaIndo (“InsaIndo,” “we,” “us,” or “our”) operates InsaIndo HR. This Privacy Policy explains how we collect, use, store, and protect personal data in connection with our service, in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and applicable Indian law.

1. Data We Collect

We collect personal data necessary to provide HR and payroll services, including:

  • Employee identity and contact information
  • Employment and compensation details
  • Attendance and biometric check-in records (where enabled by your organization)
  • Statutory identifiers required for payroll compliance (e.g., PAN, PF/ESI numbers)
  • Account and usage information

2. Purpose of Processing

We process this data solely to provide the InsaIndo HR service to your organization, including payroll processing, attendance tracking, compliance reporting, and related HR functions. We do not sell personal data to third parties.

3. Data Fiduciary and Data Processor Roles

Your organization, as the employer, is the Data Fiduciary for your employees’ personal data under the DPDP Act. InsaIndo HR acts as a Data Processor, processing data on your organization’s instructions and for the purposes you direct.

4. Data Storage and Security

Data is stored using industry-standard cloud infrastructure with access controls restricting data to your own organization. We apply reasonable technical and organizational measures to protect personal data against unauthorized access, loss, or misuse.

5. Data Retention

We retain personal data for as long as your organization’s account is active, or as required to comply with legal, tax, or labour-law obligations, whichever is longer. Data is deleted or anonymized upon request, subject to statutory retention requirements.

6. Your Rights

Under the DPDP Act, individuals whose data we process have the right to access their personal data, request correction, and request erasure, subject to applicable legal retention requirements. Requests should be directed to your employer (the Data Fiduciary) or to our Grievance Officer below.

7. Third-Party Service Providers

We use trusted third-party providers (such as payment processors and cloud infrastructure providers) to operate the service. These providers are contractually bound to protect your data and use it only for the purposes we specify.

8. Data Breach Notification

In the event of a personal data breach, we will notify affected organizations and, where required, the Data Protection Board of India, in accordance with applicable timelines under the DPDP Act.

9. Grievance Officer

For privacy-related concerns or to exercise your data rights, contact our Grievance Officer at:
Madhan Raj P
hello@insaindo.in

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to registered organizations.

11. Contact

hello@insaindo.in