Legal

Privacy Policy

Effective date: 15 September 2026

Product: adoraHR

Controller: Callidora Technology Private Limited (“Callidora”, “we”, “us”, or “our”)

1. Introduction

adoraHR (“adoraHR,” “we,” “us,” “our”) provides a Human Resource Management System (HRMS) covering payroll, attendance, performance management, and organizational records for businesses and their employees (the “Service”), accessible at adorahr.com and through our mobile and desktop applications.

This Privacy Policy explains what personal data we collect, how we use it, who can access it, and the rights available to you. It applies to HR administrators, managers, and employees who use the Service on behalf of a client organization (“Client,” “your employer”).

Your employer (the business that has subscribed to adoraHR) is generally the data controller for the personal data processed through the Service — they decide which modules are enabled and who has access. adoraHR acts as the data processor, operating the platform on their behalf.

For account and billing relationships directly with adoraHR (e.g., a Client’s own registration), adoraHR acts as controller for that limited purpose.

2. Who this applies to

  • Client organisations (businesses that have subscribed to adoraHR)
  • HR administrators and managers who use the Service on behalf of a Client
  • Employees whose employment, attendance, payroll, or performance records are managed through the Service
  • Website visitors to adorahr.com and related pages

3. Information we collect

3.1 Identity and employment data

  • Name, employee ID, designation, department, branch, and reporting line (manager/reportees), as shown in the org hierarchy and directory.
  • Contact details (email, phone) and login credentials.

3.2 Attendance and location data

  • Facial recognition data: a biometric template captured during self-enrollment and used for face-matching and liveness detection at clock-in/out. We do not store raw photographs indefinitely for this purpose — enrollment produces an encrypted biometric template used solely for verification.
  • GPS location data at the moment of clock-in/out, used to confirm you are within an approved geofenced radius of your assigned branch (e.g., “Inside office bounds, ±3m accuracy”).
  • Punch-in/punch-out timestamps, shift assignments, leave balances, and regularization/overtime records.

3.3 Payroll and statutory data

  • Salary structure, gross-to-net calculations, bonuses, and variable pay.
  • Statutory identifiers and deductions required for compliance: PF (Provident Fund), ESI (Employee State Insurance), and TDS (Tax Deducted at Source), including data needed to generate Form 16 and Form 24Q.
  • Bank account details for direct salary disbursement (NEFT/RTGS export files).

3.4 Performance data

  • Self-assessments, manager and peer reviews, 360° feedback, KPI/OKR tracking, ratings history, recognition/kudos entries, and skill/development goals.

3.5 Organizational and access data

  • Role, permission level, and branch scope (used for role-based access control).
  • System audit logs (logins, access to records, admin actions).

The Service is intended for use by working-age employees of business clients and is not directed at children.

4. How we use personal information

PurposeData used
Verify identity and record attendanceFacial biometric template, GPS location, timestamps
Prevent buddy-punching / attendance fraudFacial verification, geofencing
Run payroll and meet statutory obligationsSalary data, PF/ESI/TDS identifiers, bank details
Conduct performance reviews and goal trackingReview forms, ratings, OKRs, feedback
Enforce who can see whatRole, branch, RBAC configuration
Maintain multi-branch and multi-tenant separationBranch/org identifiers
Security, audit, and complianceAccess logs, audit trails

We do not use your biometric or attendance data for advertising, and we do not sell personal data to third parties.

5. Biometric data — additional safeguards

Facial recognition is sensitive personal data and is treated with additional care:

  • Enrollment is required only once per employee and can typically be redone if a re-enrollment is authorized by HR.
  • Biometric templates are encrypted at rest and in transit.
  • Verification uses liveness/anti-spoofing detection to prevent use of a photo or video in place of a live face.
  • Access to raw biometric data is restricted; most staff — including most HR users — see only the match result (“Verified, 99.4% confidence”), not the underlying biometric template.
  • Where local law requires separate consent or notice for biometric processing (this varies by country/state), your employer is responsible for obtaining it before enabling this feature for you; you should raise questions about consent with your HR team.

6. How we share information

  • HR administrators at your organization: full scope, including payroll, attendance, and performance records for their organization.
  • Branch managers: scoped by design to their own branch only — RBAC is enforced so a manager at one branch cannot see another branch’s employees or data.
  • Employees: their own attendance, payslips, performance self-assessments, and directory information; not other employees’ payroll or biometric data.
  • adoraHR personnel: limited engineering/support staff may access systems for maintenance, under confidentiality obligations, not for routine viewing of individual employee data.
  • Other organizations on the platform: never. adoraHR is architected with multi-tenant isolation — each Client’s data is walled off at the architecture level, not just hidden in the interface.

We share data with third parties only where necessary to operate the Service (e.g., cloud hosting and storage, email and SMS/WhatsApp delivery) under confidentiality and data-processing agreements, or where required by law.

7. Data retention

  • Attendance and biometric verification logs: retained for the duration of employment plus any period required for statutory audit and compliance purposes (e.g., labor law record-keeping requirements).
  • Payroll and statutory records (PF/ESI/TDS, Form 16, Form 24Q): retained for the periods required by applicable tax and labor law.
  • Performance review records: retained for the duration of employment and a reasonable period afterward for reference and dispute-resolution purposes.
  • Upon account closure, your employer determines retention/deletion in line with their own record-keeping obligations; adoraHR follows the Client’s instructions except where law requires otherwise.

8. Security

Per our published security posture:

  • Bank and financial data protected with 256-bit encryption.
  • Security practices aligned with ISO 27001.
  • Multi-tenant architectural isolation between client organizations.
  • Granular role-based access control (RBAC) scoped by branch and role.
  • Encrypted biometric templates rather than storage of raw enrollment images for ongoing use.

No system is perfectly secure, and we encourage you to use strong, unique credentials and report any suspected unauthorized access immediately.

9. Your rights and how to request data deletion

Subject to your jurisdiction and to your employer’s role as controller, you may have the right to:

  • Access the personal data held about you.
  • Correct inaccurate data (e.g., a wrong branch assignment or designation).
  • Request re-enrollment or removal of biometric data where permitted.
  • Object to or request restriction of certain processing.
  • Lodge a complaint with a relevant data protection authority.

To exercise these rights, contact your HR department first, or reach adoraHR directly at info@adorahr.com.

India-specific note: Where the Service processes personal data of individuals in India, we aim to handle it consistently with the Digital Personal Data Protection Act, 2023 and applicable labor law requirements around statutory deductions (PF/ESI/TDS) and record-keeping.

10. International transfers

If your organization operates across multiple branches, states, or countries, your data may be processed in a region different from where you work, subject to the Client’s configuration (e.g., “local state taxes, branch-specific allowances… across unlimited offices”). Appropriate contractual safeguards are used for any cross-border transfer.

11. Third-party links

The Service may use third-party infrastructure and services to operate (for example, cloud hosting and storage, email and SMS/WhatsApp delivery). Third-party services are governed by their own terms, and we are not responsible for their availability, accuracy, or performance.

12. Changes to this policy

We may update this Privacy Policy periodically. Material changes will be reflected by an updated “Effective date” at the top, and, where required, communicated through the Service or by your HR department.

13. Contact us

Callidora Technology Private Limited

  • Product: adoraHR
  • Privacy / support email: info@adorahr.com
  • Company website: www.callidoratechnology.com
  • Phone / WhatsApp: +91 99155 21444 (10:00 AM – 6:00 PM IST, Mon–Sat)
  • Callidora, SCO 12, Industrial Area Phase 9, Sahibzada Ajit Singh Nagar, Punjab 160062