Privacy Policy

Applies to the Circuvent HRMS web application and the Circuvent HR mobile app for Android and iOS.

Last updated: 15 August 2026

Who is responsible for your data

If you are an employee using this product, your employer is the data controllerand Circuvent Technologies is the processor acting on their instructions. We do not decide what employment data is collected about you or how long it is kept — your employer does, within the limits of the law that applies to them. Requests about your own record should go to your employer's HR team first; see Access and deletion.

1. Information we collect

Account information. Name, work email address, employee identifier, job title, department and role. This is created by your employer, not by you.

Employment records. Attendance, leave, shifts, payroll and tax figures, performance records, assets issued to you, helpdesk tickets and any documents your employer stores against your record.

Authentication data. A hash of your password — never the password itself — and, if enabled, a secret used to verify your authenticator app codes.

Technical data. IP address and device information attached to sign-in events and to the audit log, so that unauthorised access can be investigated.

2. The Circuvent HR mobile app

Location. If your employer has configured a geofenced work location, the app reads your device location only at the moment you tap clock in or clock out. The coordinates, their accuracy and the resulting inside-or-outside verdict are stored on that attendance record, because that is what a geofenced clock-in is. Your employer can see where a punch was made; it cannot see where you are at any other time.

The app cannot collect location in the background. The background location permission is blocked in the app manifest itself, not merely left unrequested, so the operating system will refuse it even if a future version were to ask.

Biometrics.If you turn on biometric unlock, the check is performed by your device's operating system. Your fingerprint or face is never sent to us and never leaves your device; the app receives only a yes or no. Biometric unlock protects a session you already have — it is not a way of signing in.

Stored on your device. Your sign-in tokens are held in the platform keystore (Keychain on iOS, Keystore on Android). Actions taken while you have no connection — a clock-in, a leave request — are held in a local database until they can be sent. Payslips are deliberately not stored on the device.

What the app does not do. There is no advertising identifier, no analytics or tracking software, no access to your contacts, photos, messages or calendar, and no sale or sharing of any data with third parties.

3. How we use information

To operate the service your employer has bought: recording attendance, processing leave and payroll, and meeting statutory obligations such as provident fund, employee state insurance, professional tax and income tax reporting in India. We do not use employment data for advertising, and we do not profile you for any purpose your employer has not configured.

4. Where your data is held

Application data is stored in Neon (PostgreSQL) and the applications are hosted on Vercel. Each customer organisation is isolated at the database level by row-level security, so a query that omits an organisation filter still cannot return another organisation's rows. Transport is encrypted with TLS; sensitive columns including bank details, government identifiers and authenticator secrets are encrypted at rest.

5. Retention

Retention is set by your employer, subject to the law that applies to them — payroll and statutory records generally have to be kept for several years and cannot be deleted on request. Where a legal hold is in force, erasure is refused and the refusal is recorded.

6. Access and deletion

You may ask for a copy of the personal data held about you, or ask for it to be erased. Send the request to your employer's HR team, who are the controller; the product provides them with subject access export and erasure tools, and every such request is logged.

If your employer does not act, or you cannot reach them, write to privacy@circuvent.com and we will pass the request on and tell you that we have. We cannot delete an employer's records on your instruction alone — doing so would let one person destroy another party's statutory records.

Deleting the mobile app removes everything held on your device. It does not delete your employment record, and it is not a deletion request.

7. Children

This is a workplace product and is not directed at children. We do not knowingly collect data from anyone below the minimum working age in their jurisdiction.

8. Changes

Material changes will be notified to the administrators of each customer organisation before they take effect. The date at the top of this page always reflects the current version.

9. Contact

Circuvent Technologies — privacy@circuvent.com