FlexziOne LogoFlexziOne

Legal

DPDP Compliance

How FlexziOne supports compliance with India's Digital Personal Data Protection Act, 2023 — and how responsibilities are divided between us and the organisations using the platform.

Version 2.0Last updated 21 August 2026

1. What the DPDP Act Requires

This page is for general information and does not constitute legal advice. Organisations using FlexziOne remain responsible for assessing their own obligations as Data Fiduciaries and for obtaining independent legal advice where necessary.

FlexziOne is an HR Infrastructure Tool designed to help organisations manage and streamline HR infrastructure, recruitment, staffing, employee administration, workforce coordination and related business processes. This page explains how FlexziOne approaches compliance with India's Digital Personal Data Protection Act, 2023 (“DPDP Act”) and how responsibilities are divided between FlexziOne and organisations using the platform.

The DPDP Act establishes requirements relating to the processing and protection of digital personal data. It identifies key roles, including:

Data Principal

The Data Principal is the individual to whom the personal data relates. For example, an employee or candidate whose personal information is entered into FlexziOne by an organisation may be a Data Principal.

Data Fiduciary

A Data Fiduciary is the person or organisation that determines the purpose and means of processing personal data and is responsible for complying with applicable obligations under the DPDP Act.

Data Processor

A Data Processor is a person or entity that processes personal data on behalf of a Data Fiduciary.

2. Our Role and Your Role

The applicable role depends on the nature and purpose of the processing.

Customer Data

Where an organisation uses FlexziOne to manage employee, candidate, workforce or other personal data and determines why and how that information is processed, the organisation acts as the Data Fiduciary.

FlexziOne acts as the Data Processor for such data, processing the information on the customer's behalf and in accordance with the applicable agreement and instructions.

As the Data Fiduciary, the customer is responsible for determining the lawful purpose of processing, providing required notices, handling applicable Data Principal requests, and meeting its obligations under applicable law.

FlexziOne processes such customer data primarily to provide, maintain, secure, support and operate the contracted Service.

FlexziOne's Own Data

For personal data relating directly to FlexziOne's own customers, administrators, users, prospects, vendors, employees or other individuals where FlexziOne determines the purpose and means of processing, FlexziOne acts as the Data Fiduciary. Such processing is governed by the FlexziOne Privacy Policy (flexzione.com/privacy).

3. How FlexziOne Supports Customer Obligations

FlexziOne provides features and operational support that may assist customers in meeting their data protection responsibilities. Depending on the applicable configuration and Service, these may include:

Access and Correction

Authorised administrators may view and update employee, candidate or other records through the platform. Customers remain responsible for determining whether a request should be fulfilled and for ensuring that the appropriate verification and legal requirements are followed.

Erasure

Where the platform provides deletion functionality, authorised customers may delete records through the platform. For bulk deletion, technical deletion or other verified requests, customers may contact FlexziOne support for assistance. Deletion may be subject to applicable contractual, legal, statutory, security or record-retention requirements.

Consent Management for Biometric Attendance

Where face-based attendance verification is enabled, the platform maintains a per-employee consent record capturing whether consent was given, when it was given, the version of the consent notice presented, and the originating IP address. Consent may be withdrawn, and the withdrawal is recorded with its own timestamp. No facial image is submitted for biometric processing unless an active consent record exists for that employee. See Section 6.

Data Export

Where supported by the Service, customers may export relevant data from the platform. This may assist customers in responding to applicable Data Principal requests or transferring information to another system or service.

Audit Records

FlexziOne maintains logs of relevant administrative and system activities to support security, troubleshooting, accountability and operational requirements.

Personal Data Breaches

Where FlexziOne becomes aware of a personal data breach affecting customer data processed on the customer's behalf, FlexziOne will notify the affected customer in accordance with applicable law and contractual obligations, and will provide reasonably available information necessary to assist the customer in meeting its obligations.

4. Data Storage, Sub-processors and Transfers

FlexziOne hosts customer data on Microsoft Azure infrastructure in India. Application services, databases and file storage are located in the South India region, and biometric face processing is performed in the Central India region.

FlexziOne implements appropriate contractual and technical measures relating to third-party service providers and sub-processors used in providing the Service. Our current material sub-processors are:

Sub-processorPurposeProcessing Location
Microsoft Azure (Microsoft Corporation)Cloud infrastructure, application hosting, databases and encrypted file storageIndia — South India region
Microsoft Azure AI Face (Azure Cognitive Services)Biometric facial verification for attendance, where enabled by the customer and consented to by the employeeIndia — Central India region
Zoho CorporationTransactional and notification email deliveryIndia
Google Firebase (Google LLC)Phone-number OTP authentication and push notifications for the mobile applicationOutside India — United States
Google Play (Google LLC)Android application distribution and aggregate installation statisticsOutside India — United States

As set out in the table above, two current sub-processors — Google Firebase and Google Play, both operated by Google LLC — process limited personal data outside India. Firebase processes the phone number used for one-time-password authentication and the device token used for push notifications. Google Play processes aggregate installation statistics for the Android application.

Where a sub-processor or service provider located outside India processes customer personal data, FlexziOne handles such processing in accordance with applicable law, contractual requirements, and any restriction or notification issued by the Government of India under Section 16 of the DPDP Act. FlexziOne will update this page where material service providers are added or removed.

5. Security Safeguards

FlexziOne maintains commercially reasonable technical and organisational safeguards designed to protect customer data against unauthorised access, misuse, alteration, disclosure, loss or destruction. Depending on the applicable environment and Service configuration, safeguards may include:

Data Isolation

Customer environments and data are logically separated to reduce the risk of unauthorised access between organisations.

Encryption in Transit

Data transmitted between users and FlexziOne services is protected using industry-standard transport encryption (TLS).

Access Controls

Access to platform functionality and customer data is controlled through authentication and role-based permissions.

Consent Gating for Biometric Processing

Facial data is never submitted for biometric comparison unless an active, recorded consent exists for the individual employee. This check is enforced by the platform, not by administrative process alone.

Audit Logging

Relevant administrative and system activities may be recorded with information such as the user account, action and timestamp to support security and accountability.

Least-Privilege Access

Internal access to customer data is restricted based on business requirements, job responsibilities and authorised support or operational activities.

FlexziOne periodically reviews its security practices and may enhance safeguards as technology, risks and regulatory requirements evolve. FlexziOne is working towards ISO 27001 readiness and does not currently claim ISO 27001 certification.

6. Biometric and Facial Attendance Data

Face-based attendance verification is an optional feature. It is disabled unless a customer organisation deliberately enables it, and it operates only for employees who have given recorded consent.

Where enabled, FlexziOne processes facial images captured at enrolment, a biometric face template derived from those images and held by Microsoft Azure AI Face in the Central India region, facial images captured at check-in for comparison, and the resulting verification outcome and timestamp.

The customer organisation is the Data Fiduciary for this processing. It is responsible for:

  • Determining whether biometric attendance verification is lawful and appropriate for its workforce.
  • Providing each affected employee with clear notice before enrolment.
  • Obtaining and maintaining a valid lawful basis, including consent where required.
  • Providing a reasonable alternative attendance method for employees who do not consent or who later withdraw consent, and ensuring no employee is penalised for declining.
  • Responding to employee requests relating to biometric data, with FlexziOne's reasonable assistance.

On withdrawal of consent, the employee's enrolment is revoked and no further biometric comparison is performed. Enrolment samples and the associated template are deleted in accordance with the customer's instructions and applicable retention requirements.

7. Retention and Erasure

Customers determine the appropriate retention period for personal data processed through FlexziOne based on their business requirements and applicable legal obligations.

FlexziOne retains customer data only for as long as reasonably necessary to:

  • Provide the contracted Service.
  • Meet contractual obligations.
  • Comply with applicable legal or statutory requirements.
  • Maintain security and operational records.
  • Resolve disputes.
  • Enforce contractual rights.
  • Meet other legitimate and lawful business requirements.

Following termination of the customer's account, customer data may be returned, exported, retained or deleted in accordance with the applicable agreement, customer instructions, legal requirements and FlexziOne's data retention practices.

Where applicable law requires certain employment, payroll, tax, accounting or other records to be retained, those requirements may take precedence over a deletion request.

9. Children's Data

The DPDP Act contains additional requirements relating to the processing of personal data of children. A child is an individual who has not completed eighteen years of age.

FlexziOne is primarily an HR Infrastructure Tool intended for business and workforce-related use and is not designed for children's services.

Where an organisation processes personal data relating to individuals under the age of 18 through FlexziOne, the organisation is responsible for ensuring compliance with applicable requirements relating to children's data, including any requirements concerning verifiable parental consent or other applicable safeguards.

10. Grievance Redressal

FlexziOne provides channels through which customers and other relevant individuals may raise concerns relating to privacy, data protection or use of personal data.

If you are an employee or candidate of a FlexziOne customer

Where your personal data is processed by an organisation using FlexziOne, that organisation is generally responsible for addressing requests and grievances relating to its processing of your personal data. You should first contact your employer, recruitment agency, staffing organisation or other relevant organisation's HR or designated privacy contact.

If you are a FlexziOne customer or user

You may contact FlexziOne regarding concerns relating to FlexziOne's own processing of personal data or the operation of the platform.

Grievance Officer
Nagendra C Lokaraj
Designation
Business Head — Sales & Operations
Address
1st Floor, No. 2, Rajarajan Street, Above Punjab National Bank, Navarathna Garden, Ekkatuthangal, Chennai, Tamil Nadu 600032, India

FlexziOne aims to acknowledge privacy or data protection-related grievances within 72 hours and endeavours to resolve them within 30 days, subject to the nature and complexity of the matter and applicable legal requirements.

Where applicable, individuals may have the right to escalate unresolved grievances to the Data Protection Board of India after completing the applicable grievance process.

11. Data Processing Agreements

Where FlexziOne acts as a Data Processor on behalf of a customer, the parties may enter into a Data Processing Agreement (DPA) setting out the applicable responsibilities, processing instructions, confidentiality obligations, security measures, sub-processors, breach notification procedures and other relevant data protection requirements.

Customers requiring a DPA may contact support@flexzione.com.

12. Ongoing Compliance

The DPDP Act, associated rules, notifications, directions and regulatory requirements may develop over time. FlexziOne will review its privacy, security, contractual and operational practices as applicable requirements evolve and will update this page where appropriate.

This page describes FlexziOne's general approach to data protection and should not be treated as legal advice. Organisations using FlexziOne remain responsible for assessing their own obligations as Data Fiduciaries and obtaining independent legal or professional advice where necessary.

13. Contact

For questions relating to this DPDP Compliance Statement or to request information regarding a Data Processing Agreement, please contact:

Entity
FlexziOne
Website
flexzione.com
Registered Office
1st Floor, No. 2, Rajarajan Street, Above Punjab National Bank, Navarathna Garden, Ekkatuthangal, Chennai, Tamil Nadu 600032, India
Grievance Officer
Nagendra C Lokaraj — support@flexzione.com

FlexziOne · flexzione.com · support@flexzione.comDPDP Compliance, version 2.0, last updated 21 August 2026.