Legal

Privacy Policy

Last updated: 15 September 2026

This Privacy Policy explains how Disa Global ("we", "us", "our") collects, uses, and protects personal data through the Employee Management System ("EMS", "the Service"). It applies to company administrators who register on EMS, and to the employee data that administrators upload into the Service.

1. Data We Collect

CategoryExamples
Account & company dataCompany name, email, phone, address, website; admin name, work email, phone, password (stored hashed)
Employee data (uploaded by admins)Name, role, department, contact details, attendance records, leave requests, documents
Payment dataPlan selected, amount paid, payment reference/ID from Razorpay. We do not receive or store full card numbers, UPI IDs, or netbanking credentials — these are handled directly by Razorpay
Usage & device dataLogin timestamps, device/browser info, attendance device identifiers registered to your company

2. How We Use Data

3. Legal Basis for Employee Data

Employee data is uploaded by the company administrator, not collected by us directly. The administrator is responsible for having a lawful basis (e.g. employment contract, legitimate interest, or consent, as applicable under local law) for storing that data in EMS, and for informing employees accordingly.

4. Sharing of Data

We do not sell personal data. We share data only with:

5. Data Retention

We retain company and employee data for as long as the workspace remains active, plus a reasonable period afterward for legal, accounting, or dispute-resolution purposes, after which it is deleted or anonymised, unless a longer retention period is required by law.

6. Data Security

We use industry-standard measures — encrypted connections (HTTPS), hashed passwords, and access controls — to protect data. No system is completely secure, and we encourage strong, unique passwords for admin accounts.

7. Your Rights

Subject to applicable law, you may request access to, correction of, or deletion of personal data associated with your account by contacting us. Employees with questions about their data should contact their company's EMS administrator first, as the administrator controls that data.

8. Cookies

The Service may use essential cookies/local session data required for login and functionality. We do not currently use third-party advertising cookies.

9. Children's Data

EMS is a business tool intended for use by company administrators managing adult employees, and is not directed at children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via your admin account email or a notice within the Service.

11. Contact

For privacy-related questions or requests, contact us using the details on our sign-in page or company website.

This is a general-purpose template and has not been reviewed by a lawyer. Please have it reviewed by qualified legal counsel — especially around applicable data protection law (e.g. India's DPDP Act) — before relying on it.