Privacy Policy
This Privacy Policy explains how Disa Global ("we", "us", "our") collects, uses, and protects personal data through the Employee Management System ("EMS", "the Service"). It applies to company administrators who register on EMS, and to the employee data that administrators upload into the Service.
1. Data We Collect
| Category | Examples |
|---|---|
| Account & company data | Company name, email, phone, address, website; admin name, work email, phone, password (stored hashed) |
| Employee data (uploaded by admins) | Name, role, department, contact details, attendance records, leave requests, documents |
| Payment data | Plan selected, amount paid, payment reference/ID from Razorpay. We do not receive or store full card numbers, UPI IDs, or netbanking credentials — these are handled directly by Razorpay |
| Usage & device data | Login timestamps, device/browser info, attendance device identifiers registered to your company |
2. How We Use Data
- To create and operate your company workspace and admin account
- To process payments and verify subscriptions via Razorpay
- To provide attendance, leave, payroll-adjacent, and reporting features you configure
- To send account, billing, and service-related communications
- To detect fraud, abuse, or security issues, and to improve the Service
3. Legal Basis for Employee Data
Employee data is uploaded by the company administrator, not collected by us directly. The administrator is responsible for having a lawful basis (e.g. employment contract, legitimate interest, or consent, as applicable under local law) for storing that data in EMS, and for informing employees accordingly.
4. Sharing of Data
We do not sell personal data. We share data only with:
- Razorpay — to process payments (payment method details go directly to Razorpay, not through us)
- Infrastructure/hosting providers who store data on our behalf under confidentiality obligations
- Authorities, where required by law or a valid legal process
5. Data Retention
We retain company and employee data for as long as the workspace remains active, plus a reasonable period afterward for legal, accounting, or dispute-resolution purposes, after which it is deleted or anonymised, unless a longer retention period is required by law.
6. Data Security
We use industry-standard measures — encrypted connections (HTTPS), hashed passwords, and access controls — to protect data. No system is completely secure, and we encourage strong, unique passwords for admin accounts.
7. Your Rights
Subject to applicable law, you may request access to, correction of, or deletion of personal data associated with your account by contacting us. Employees with questions about their data should contact their company's EMS administrator first, as the administrator controls that data.
8. Cookies
The Service may use essential cookies/local session data required for login and functionality. We do not currently use third-party advertising cookies.
9. Children's Data
EMS is a business tool intended for use by company administrators managing adult employees, and is not directed at children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via your admin account email or a notice within the Service.
11. Contact
For privacy-related questions or requests, contact us using the details on our sign-in page or company website.
This is a general-purpose template and has not been reviewed by a lawyer. Please have it reviewed by qualified legal counsel — especially around applicable data protection law (e.g. India's DPDP Act) — before relying on it.