Legal
DPDP Compliance
How FlexziOne supports compliance with India's Digital Personal Data Protection Act, 2023 — and how responsibilities are divided between us and the organisations using the platform.
1. What the DPDP Act Requires
This page is for general information and does not constitute legal advice. Organisations using FlexziOne remain responsible for assessing their own obligations as Data Fiduciaries and for obtaining independent legal advice where necessary.
FlexziOne is an HR Infrastructure Tool designed to help organisations manage and streamline HR infrastructure, recruitment, staffing, employee administration, workforce coordination and related business processes. This page explains how FlexziOne approaches compliance with India's Digital Personal Data Protection Act, 2023 (“DPDP Act”) and how responsibilities are divided between FlexziOne and organisations using the platform.
The DPDP Act establishes requirements relating to the processing and protection of digital personal data. It identifies key roles, including:
Data Principal
The Data Principal is the individual to whom the personal data relates. For example, an employee or candidate whose personal information is entered into FlexziOne by an organisation may be a Data Principal.
Data Fiduciary
A Data Fiduciary is the person or organisation that determines the purpose and means of processing personal data and is responsible for complying with applicable obligations under the DPDP Act.
Data Processor
A Data Processor is a person or entity that processes personal data on behalf of a Data Fiduciary.
2. Our Role and Your Role
The applicable role depends on the nature and purpose of the processing.
Customer Data
Where an organisation uses FlexziOne to manage employee, candidate, workforce or other personal data and determines why and how that information is processed, the organisation acts as the Data Fiduciary.
FlexziOne acts as the Data Processor for such data, processing the information on the customer's behalf and in accordance with the applicable agreement and instructions.
As the Data Fiduciary, the customer is responsible for determining the lawful purpose of processing, providing required notices, handling applicable Data Principal requests, and meeting its obligations under applicable law.
FlexziOne processes such customer data primarily to provide, maintain, secure, support and operate the contracted Service.
FlexziOne's Own Data
For personal data relating directly to FlexziOne's own customers, administrators, users, prospects, vendors, employees or other individuals where FlexziOne determines the purpose and means of processing, FlexziOne acts as the Data Fiduciary. Such processing is governed by the FlexziOne Privacy Policy (flexzione.com/privacy).
3. How FlexziOne Supports Customer Obligations
FlexziOne provides features and operational support that may assist customers in meeting their data protection responsibilities. Depending on the applicable configuration and Service, these may include:
Access and Correction
Authorised administrators may view and update employee, candidate or other records through the platform. Customers remain responsible for determining whether a request should be fulfilled and for ensuring that the appropriate verification and legal requirements are followed.
Erasure
Where the platform provides deletion functionality, authorised customers may delete records through the platform. For bulk deletion, technical deletion or other verified requests, customers may contact FlexziOne support for assistance. Deletion may be subject to applicable contractual, legal, statutory, security or record-retention requirements.
Consent Management for Biometric Attendance
Where face-based attendance verification is enabled, the platform maintains a per-employee consent record capturing whether consent was given, when it was given, the version of the consent notice presented, and the originating IP address. Consent may be withdrawn, and the withdrawal is recorded with its own timestamp. No facial image is submitted for biometric processing unless an active consent record exists for that employee. See Section 6.
Data Export
Where supported by the Service, customers may export relevant data from the platform. This may assist customers in responding to applicable Data Principal requests or transferring information to another system or service.
Audit Records
FlexziOne maintains logs of relevant administrative and system activities to support security, troubleshooting, accountability and operational requirements.
Personal Data Breaches
Where FlexziOne becomes aware of a personal data breach affecting customer data processed on the customer's behalf, FlexziOne will notify the affected customer in accordance with applicable law and contractual obligations, and will provide reasonably available information necessary to assist the customer in meeting its obligations.
4. Data Storage, Sub-processors and Transfers
FlexziOne hosts customer data on Microsoft Azure infrastructure in India. Application services, databases and file storage are located in the South India region, and biometric face processing is performed in the Central India region.
FlexziOne implements appropriate contractual and technical measures relating to third-party service providers and sub-processors used in providing the Service. Our current material sub-processors are:
| Sub-processor | Purpose | Processing Location |
|---|---|---|
| Microsoft Azure (Microsoft Corporation) | Cloud infrastructure, application hosting, databases and encrypted file storage | India — South India region |
| Microsoft Azure AI Face (Azure Cognitive Services) | Biometric facial verification for attendance, where enabled by the customer and consented to by the employee | India — Central India region |
| Zoho Corporation | Transactional and notification email delivery | India |
| Google Firebase (Google LLC) | Phone-number OTP authentication and push notifications for the mobile application | Outside India — United States |
| Google Play (Google LLC) | Android application distribution and aggregate installation statistics | Outside India — United States |
As set out in the table above, two current sub-processors — Google Firebase and Google Play, both operated by Google LLC — process limited personal data outside India. Firebase processes the phone number used for one-time-password authentication and the device token used for push notifications. Google Play processes aggregate installation statistics for the Android application.
Where a sub-processor or service provider located outside India processes customer personal data, FlexziOne handles such processing in accordance with applicable law, contractual requirements, and any restriction or notification issued by the Government of India under Section 16 of the DPDP Act. FlexziOne will update this page where material service providers are added or removed.
5. Security Safeguards
FlexziOne maintains commercially reasonable technical and organisational safeguards designed to protect customer data against unauthorised access, misuse, alteration, disclosure, loss or destruction. Depending on the applicable environment and Service configuration, safeguards may include:
Data Isolation
Customer environments and data are logically separated to reduce the risk of unauthorised access between organisations.
Encryption in Transit
Data transmitted between users and FlexziOne services is protected using industry-standard transport encryption (TLS).
Access Controls
Access to platform functionality and customer data is controlled through authentication and role-based permissions.
Consent Gating for Biometric Processing
Facial data is never submitted for biometric comparison unless an active, recorded consent exists for the individual employee. This check is enforced by the platform, not by administrative process alone.
Audit Logging
Relevant administrative and system activities may be recorded with information such as the user account, action and timestamp to support security and accountability.
Least-Privilege Access
Internal access to customer data is restricted based on business requirements, job responsibilities and authorised support or operational activities.
FlexziOne periodically reviews its security practices and may enhance safeguards as technology, risks and regulatory requirements evolve. FlexziOne is working towards ISO 27001 readiness and does not currently claim ISO 27001 certification.
6. Biometric and Facial Attendance Data
Face-based attendance verification is an optional feature. It is disabled unless a customer organisation deliberately enables it, and it operates only for employees who have given recorded consent.
Where enabled, FlexziOne processes facial images captured at enrolment, a biometric face template derived from those images and held by Microsoft Azure AI Face in the Central India region, facial images captured at check-in for comparison, and the resulting verification outcome and timestamp.
The customer organisation is the Data Fiduciary for this processing. It is responsible for:
- Determining whether biometric attendance verification is lawful and appropriate for its workforce.
- Providing each affected employee with clear notice before enrolment.
- Obtaining and maintaining a valid lawful basis, including consent where required.
- Providing a reasonable alternative attendance method for employees who do not consent or who later withdraw consent, and ensuring no employee is penalised for declining.
- Responding to employee requests relating to biometric data, with FlexziOne's reasonable assistance.
On withdrawal of consent, the employee's enrolment is revoked and no further biometric comparison is performed. Enrolment samples and the associated template are deleted in accordance with the customer's instructions and applicable retention requirements.
7. Retention and Erasure
Customers determine the appropriate retention period for personal data processed through FlexziOne based on their business requirements and applicable legal obligations.
FlexziOne retains customer data only for as long as reasonably necessary to:
- Provide the contracted Service.
- Meet contractual obligations.
- Comply with applicable legal or statutory requirements.
- Maintain security and operational records.
- Resolve disputes.
- Enforce contractual rights.
- Meet other legitimate and lawful business requirements.
Following termination of the customer's account, customer data may be returned, exported, retained or deleted in accordance with the applicable agreement, customer instructions, legal requirements and FlexziOne's data retention practices.
Where applicable law requires certain employment, payroll, tax, accounting or other records to be retained, those requirements may take precedence over a deletion request.
8. Notice and Consent
Where the DPDP Act or other applicable law requires notice, consent or another lawful basis for processing personal data, the relevant Data Fiduciary is responsible for determining and implementing the appropriate basis.
For employee and candidate information controlled by a customer, the customer is generally responsible for:
- Providing appropriate privacy notices.
- Obtaining consent where consent is required.
- Providing information regarding the purpose of processing.
- Responding to applicable Data Principal requests.
- Maintaining appropriate records and documentation.
- Ensuring that processing is lawful.
Not all employment-related processing necessarily depends on consent. Certain processing may be based on legal obligations, specified purposes, contractual requirements or other lawful grounds recognised under applicable law. The customer is responsible for determining the appropriate legal basis for its processing activities.
FlexziOne does not independently determine the customer's legal basis for processing employee or candidate data.
9. Children's Data
The DPDP Act contains additional requirements relating to the processing of personal data of children. A child is an individual who has not completed eighteen years of age.
FlexziOne is primarily an HR Infrastructure Tool intended for business and workforce-related use and is not designed for children's services.
Where an organisation processes personal data relating to individuals under the age of 18 through FlexziOne, the organisation is responsible for ensuring compliance with applicable requirements relating to children's data, including any requirements concerning verifiable parental consent or other applicable safeguards.
10. Grievance Redressal
FlexziOne provides channels through which customers and other relevant individuals may raise concerns relating to privacy, data protection or use of personal data.
If you are an employee or candidate of a FlexziOne customer
Where your personal data is processed by an organisation using FlexziOne, that organisation is generally responsible for addressing requests and grievances relating to its processing of your personal data. You should first contact your employer, recruitment agency, staffing organisation or other relevant organisation's HR or designated privacy contact.
If you are a FlexziOne customer or user
You may contact FlexziOne regarding concerns relating to FlexziOne's own processing of personal data or the operation of the platform.
- Grievance Officer
- Nagendra C Lokaraj
- Designation
- Business Head — Sales & Operations
- Address
- 1st Floor, No. 2, Rajarajan Street, Above Punjab National Bank, Navarathna Garden, Ekkatuthangal, Chennai, Tamil Nadu 600032, India
FlexziOne aims to acknowledge privacy or data protection-related grievances within 72 hours and endeavours to resolve them within 30 days, subject to the nature and complexity of the matter and applicable legal requirements.
Where applicable, individuals may have the right to escalate unresolved grievances to the Data Protection Board of India after completing the applicable grievance process.
11. Data Processing Agreements
Where FlexziOne acts as a Data Processor on behalf of a customer, the parties may enter into a Data Processing Agreement (DPA) setting out the applicable responsibilities, processing instructions, confidentiality obligations, security measures, sub-processors, breach notification procedures and other relevant data protection requirements.
Customers requiring a DPA may contact support@flexzione.com.
12. Ongoing Compliance
The DPDP Act, associated rules, notifications, directions and regulatory requirements may develop over time. FlexziOne will review its privacy, security, contractual and operational practices as applicable requirements evolve and will update this page where appropriate.
This page describes FlexziOne's general approach to data protection and should not be treated as legal advice. Organisations using FlexziOne remain responsible for assessing their own obligations as Data Fiduciaries and obtaining independent legal or professional advice where necessary.
13. Contact
For questions relating to this DPDP Compliance Statement or to request information regarding a Data Processing Agreement, please contact:
- Entity
- FlexziOne
- Website
- flexzione.com
- Registered Office
- 1st Floor, No. 2, Rajarajan Street, Above Punjab National Bank, Navarathna Garden, Ekkatuthangal, Chennai, Tamil Nadu 600032, India
- Grievance Officer
- Nagendra C Lokaraj — support@flexzione.com
FlexziOne · flexzione.com · support@flexzione.com — DPDP Compliance, version 2.0, last updated 21 August 2026.