Legal
Privacy Policy
What personal data FlexziOne collects, how we use and protect it, who we share it with, and the rights available to you under India's Digital Personal Data Protection Act, 2023.
1. Our Role in Processing Personal Data
Scope of this Policy. This Privacy Policy applies to the FlexziOne HRMS platform, the FlexziOne website at flexzione.com, and the FlexziOne WorkForce mobile application. Other services operated by FlexziOne — including the Flexzi Jobs candidate and employer marketplace — are provided under their own separate terms and privacy notices, and are not covered by this Policy.
FlexziOne operates as business software and processes personal data in different capacities depending on the type of information and the purpose of processing.
1.1 Personal Data We Process as a Data Fiduciary
For information relating to customer account administrators, authorised users, website visitors, prospective customers, and individuals who communicate directly with us, FlexziOne determines the purposes and means of processing. This may include:
- Name
- Work email address
- Phone number
- Job title
- Organisation name
- Account and login information
- Billing and transaction-related information
- Support requests and correspondence
- Information submitted through our website or enquiry forms
- Technical and usage information
For this information, FlexziOne is responsible for processing the data in accordance with applicable law and this Privacy Policy.
1.2 Personal Data We Process on Behalf of Customer Organisations
FlexziOne also provides HRMS functionality that allows customer organisations to store and manage employee information. Depending on the features used by the customer organisation, this may include:
- Employee identification and contact information
- Employment and onboarding information
- Attendance and leave records
- Payroll and salary-related information
- Statutory information required for employment compliance
- Facial images and related biometric data, where the organisation enables face-based attendance verification (see Section 2.3)
- Documents uploaded by the organisation
- Other HR information configured by the customer organisation
In these circumstances, the customer organisation determines what employee information is collected, why it is collected, and how it is used. FlexziOne processes such information on the organisation's instructions and in accordance with the applicable agreement between FlexziOne and the customer.
If you are an employee, candidate, or other individual whose information has been entered into FlexziOne by an organisation, requests concerning your personal data should generally be directed to that organisation's HR or authorised representative first.
2. Personal Data We Collect
The information we collect depends on how you interact with FlexziOne.
2.1 Account and User Information
When an account is created or you are invited to use FlexziOne, we may collect your name, work email address, phone number, job title or designation, organisation name, login credentials and authentication information, and your user role and access permissions.
2.2 Employee Information
Customer organisations may choose to store employee information in FlexziOne, including employee identification details, contact details, employment details, department and designation, salary and payroll information, attendance and leave records, onboarding information, statutory information, and documents submitted during onboarding or employment.
The actual information stored depends on the configuration and features used by each customer organisation.
2.3 Biometric and Facial Attendance Data
This section describes biometric processing. Where a customer organisation enables face-based attendance verification, FlexziOne processes facial images and derived biometric data. This is the most sensitive category of personal data handled by the platform, and it is processed only on the basis of the employee's recorded consent.
Face-based attendance verification is an optional feature. It is disabled unless a customer organisation deliberately enables it, and it operates only for employees who have given consent.
What is processed
- Facial images (enrolment samples) captured during employee enrolment, stored as files in encrypted cloud storage.
- A biometric face template derived from those images and held by Microsoft Azure AI Face (Azure Cognitive Services) in the Central India region, referenced by an identifier linked to the employee record.
- Facial images captured at check-in, submitted for comparison against the enrolled template to verify the employee's identity.
- Verification results and timestamps recorded against the attendance entry.
Consent
No facial image is sent for biometric processing unless an active consent record exists for that employee. FlexziOne records the fact of consent, the date and time it was given, the version of the consent notice presented, and the originating IP address. An employee may withdraw consent, and the withdrawal is recorded with its own date and time.
Withdrawal and deletion
On withdrawal of consent, the employee's face enrolment is revoked and no further biometric comparison is performed for that employee. Enrolment samples and the associated biometric template are deleted in accordance with the customer organisation's instructions and applicable retention requirements. The customer organisation must provide an alternative attendance method for employees who do not consent or who withdraw consent.
Responsibility
The customer organisation is the Data Fiduciary for this processing. It is responsible for deciding whether to enable face-based attendance, for providing the required notice to its employees, for obtaining and maintaining a valid lawful basis, and for ensuring that no employee is disadvantaged for declining. FlexziOne processes this data solely on the organisation's instructions.
2.4 Technical and Usage Information
When you access FlexziOne, we may automatically collect limited technical information such as IP address, browser type, device type, operating system, login and access timestamps, application activity and usage information, and error and diagnostic information.
This information is used primarily for security, authentication, troubleshooting, service reliability, and improving the platform.
2.5 Communications
If you contact us, we may retain information contained in your communication, including your name, contact details, organisation details, the content of your enquiry or support request, and relevant correspondence and attachments.
3. How We Use Personal Data
We may process personal data for the following purposes:
- To create and administer FlexziOne accounts.
- To authenticate users and manage access permissions.
- To provide, operate and maintain the FlexziOne platform.
- To provide HRMS functionality configured by customer organisations.
- To support attendance, leave, payroll and related HR processes.
- To verify employee attendance where a customer organisation has enabled that functionality and the employee has consented.
- To provide customer and technical support.
- To investigate and resolve technical problems.
- To maintain platform security and prevent unauthorised access.
- To detect, prevent and respond to fraud, misuse and security incidents.
- To comply with applicable legal, tax, accounting and regulatory requirements.
- To maintain business records and resolve disputes.
- To communicate important service, security or administrative information.
- To analyse aggregated or de-identified usage information for service improvement.
- To develop and improve FlexziOne's features, functionality and reliability.
We do not use individual customer employee records for advertising purposes.
4. We Do Not Sell Personal Data
FlexziOne does not sell, rent or trade personal data.
We do not use employee information stored by customer organisations for advertising purposes, and we do not provide such information to advertising networks or data brokers.
We may disclose information where necessary to provide the Service, comply with law, protect our rights, or complete a legitimate business transaction, as described in this Privacy Policy.
5. Data Storage and Hosting
FlexziOne's production infrastructure is hosted on Microsoft Azure in India. Application services, databases and file storage are located in the South India region, and biometric face processing is performed in the Central India region.
Customer data is logically isolated between organisations. Access to customer information is controlled through authentication, authorisation and role-based permissions.
We take reasonable technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss or destruction.
6. Sharing of Personal Data
6.1 Sub-processors and Service Providers
We use third-party service providers to support the operation of FlexziOne. Such providers are permitted to process personal data only to the extent necessary to perform their services for us or our customers, and are subject to appropriate contractual safeguards.
Our current material sub-processors are:
| Sub-processor | Purpose | Processing Location |
|---|---|---|
| Microsoft Azure (Microsoft Corporation) | Cloud infrastructure, application hosting, databases and encrypted file storage | India — South India region |
| Microsoft Azure AI Face (Azure Cognitive Services) | Biometric facial verification for attendance, where enabled by the customer and consented to by the employee | India — Central India region |
| Zoho Corporation | Transactional and notification email delivery | India |
| Google Firebase (Google LLC) | Phone-number OTP authentication and push notifications for the mobile application | Outside India — United States |
| Google Play (Google LLC) | Android application distribution and aggregate installation statistics | Outside India — United States |
Where a sub-processor processes personal data outside India, we handle that processing in accordance with applicable law, contractual requirements, and any applicable restrictions or notifications issued by the Government of India under Section 16 of the DPDP Act.
6.2 Within the Customer Organisation
Where employee data is processed on behalf of a customer organisation, information may be accessible to administrators, HR personnel, managers and other users whom the organisation has authorised. Access is controlled according to the permissions and roles configured by the customer organisation.
6.3 Legal and Regulatory Requirements
We may disclose personal data where reasonably necessary to comply with applicable law or regulation; respond to a valid legal process, court order or lawful government request; protect the rights, property or safety of FlexziOne, our customers, users or others; or investigate suspected fraud, security incidents or unlawful activity.
6.4 Business Transfers
If FlexziOne or substantially all of its business or assets are involved in a merger, acquisition, restructuring, financing, sale or similar transaction, personal data may be transferred as part of that transaction, subject to applicable law and appropriate protections.
7. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
For customer account information, we generally retain relevant information while the account remains active and thereafter for as long as reasonably necessary for legal, tax, accounting, audit, security or dispute-resolution purposes.
For employee information stored on behalf of a customer organisation, retention is determined by the customer organisation and the applicable agreement.
Biometric enrolment data is retained only while the employee's consent remains active and the employee remains enrolled. It is deleted following withdrawal of consent, revocation of enrolment, or termination of the customer relationship, subject to applicable legal requirements.
Following termination of a customer relationship, employee information may be deleted or returned in accordance with the applicable agreement, subject to legal or regulatory retention requirements, statutory payroll or employment requirements, legitimate dispute-resolution requirements, and technical backup or disaster-recovery processes.
8. Data Security
We take reasonable technical and organisational measures designed to protect personal data. Depending on the relevant system and processing activity, these measures may include:
- Encryption of data in transit using industry-standard transport security (TLS).
- Authentication and access controls.
- Role-based access permissions.
- Logical segregation of customer environments and data.
- Consent gating for biometric processing, enforced before any facial data is submitted for comparison.
- Monitoring and logging of relevant administrative activities.
- Security monitoring and incident-response procedures.
- Restricted access to systems containing personal data.
- Backup and recovery procedures.
Access permissions are designed so that users can access only the modules and information permitted by their assigned role.
No internet-based service or information system can be guaranteed to be completely secure. Accordingly, while we take reasonable measures to protect personal data, we cannot guarantee absolute security.
We are working towards ISO 27001 readiness. FlexziOne does not currently claim ISO 27001 certification.
If we become aware of a personal data breach that requires notification under applicable law, we will take appropriate steps to notify affected customer organisations and the relevant authorities as required.
9. Your Privacy Rights
Subject to applicable law and any limitations or exceptions under the DPDP Act and other applicable legislation, individuals may have the following rights relating to their personal data.
9.1 Right to Access Information
You may request information regarding the personal data processed about you and information relating to its processing, subject to applicable law.
9.2 Right to Correction
You may request correction or completion of inaccurate or incomplete personal data.
9.3 Right to Erasure
You may request deletion of personal data where it is no longer necessary for the purpose for which it was collected or where otherwise permitted by applicable law. Deletion may be subject to legal, regulatory, contractual or other legitimate retention requirements.
9.4 Right to Withdraw Consent
Where processing is based on consent, you may withdraw that consent at any time. In particular, an employee enrolled in face-based attendance verification may withdraw biometric consent, after which no further biometric processing will be performed for that employee.
9.5 Right to Grievance Redressal
You may raise a grievance regarding the processing or handling of your personal data.
9.6 Right to Nominate
Where applicable under the DPDP Act, you may nominate another individual to exercise your rights in accordance with applicable law.
9.7 Requests Relating to Employee Data
If your personal data has been entered into FlexziOne by your employer or another customer organisation, that organisation determines the purposes for which your data is processed. Accordingly, employees and other individuals should normally contact their employer's HR team or the relevant customer organisation first.
FlexziOne will provide reasonable assistance to the customer organisation in responding to valid data-related requests in accordance with applicable law and our contractual obligations.
10. How to Exercise Your Rights
For questions, requests or grievances relating to personal data for which FlexziOne is responsible, you may contact us using the details provided in Section 13.
If your personal data is processed in FlexziOne on behalf of your employer or another customer organisation, please contact that organisation first.
When submitting a request, we may need to verify your identity and request sufficient information to understand and process your request. We will handle valid requests within the period required by applicable law.
12. Children's Privacy
FlexziOne is workplace and business software and is not intended for children. Under the DPDP Act, a child is an individual who has not completed eighteen years of age.
We do not knowingly collect personal data directly from children through our website or account registration process. Where a customer organisation processes data relating to individuals under eighteen, the organisation is responsible for meeting the additional requirements that apply to children's data, including verifiable parental consent where required.
If you believe that a child has provided personal data to us without appropriate authorisation, please contact us so that we can take appropriate action.
13. Contact and Grievance Officer
If you have questions about this Privacy Policy, wish to exercise a privacy right, or have a grievance concerning the handling of personal data, please contact us:
- Entity
- FlexziOne
- Website
- flexzione.com
- Registered Office
- 1st Floor, No. 2, Rajarajan Street, Above Punjab National Bank, Navarathna Garden, Ekkatuthangal, Chennai, Tamil Nadu 600032, India
Grievance Officer
- Name
- Nagendra C Lokaraj
- Designation
- Business Head — Sales & Operations
- Address
- 1st Floor, No. 2, Rajarajan Street, Above Punjab National Bank, Navarathna Garden, Ekkatuthangal, Chennai, Tamil Nadu 600032, India
We aim to acknowledge privacy-related grievances within 72 hours and seek to resolve them within 30 days, subject to the nature and complexity of the grievance and applicable legal requirements.
Where applicable under Indian data protection law, individuals may have the right to approach the Data Protection Board of India after completing the applicable grievance process.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our products and services, our data processing practices, applicable laws and regulations, our security practices, or our business operations.
When we make material changes, we may provide notice through the FlexziOne platform, website, email or other appropriate communication channels. The “Last updated” date shown at the top of this Privacy Policy indicates when it was most recently revised.
15. Governing Law
This Privacy Policy is governed by the laws of India, subject to applicable statutory requirements and regulatory provisions.
Any disputes relating to this Privacy Policy or the processing of personal data will be subject to the jurisdiction of the competent courts at Chennai, Tamil Nadu, India, being the location of the registered office of FlexziOne, subject to applicable law.
FlexziOne · flexzione.com · support@flexzione.com — Privacy Policy, version 2.0, last updated 21 August 2026.