1. Overview & DPDP Notice
Intelliob Technologies Private Limited (“Intelliob”, “we”, “us”, or “our”) provides business cloud software products including MoneyFacts ERP, PayCare Payroll & HRMS, Accord eHR, TimeMate Attendance, and BillGini Expense Management. We are committed to transparency in our processing of personal data.
This Privacy Policy acts as the Privacy Notice under Section 5 of India's Digital Personal Data Protection Act, 2023 (DPDP Act). It applies to all users (individuals or business entities) accessing our website, subscribing to our SaaS services, or interacting with our mobile applications.
Definitions under the DPDP Act 2023:
- Data Principal: The individual to whom the personal data relates (e.g., your employees, customers, or you as an individual user).
- Data Fiduciary: Intelliob Technologies (determining the purpose and means of data processing).
- Data Processor: Any third-party entity processing personal data on behalf of the Data Fiduciary.
2. Information We Collect
We collect only the minimum personal data necessary to provide you with enterprise-grade cloud ERP, HR, payroll, and billing solutions.
A. User Account Details (Direct Collection)
When you sign up, request a demo, or contact sales, we collect account details such as your full name, business email address, company name, mobile phone number, and physical office address.
B. Customer Service Data (Data Uploaded by You)
In using our SaaS platforms, you (as the Data Fiduciary/Controller of your business) upload personal data of your employees, vendors, and clients. We process this purely on your instructions:
- PayCare & Accord eHR: Employee names, email addresses, contact details, date of birth, PAN, Aadhaar, salary structure, bank account numbers, tax declarations, and family details (for insurance/nomination).
- TimeMate: Daily attendance logs, check-in/check-out times, leaves, geolocational data (only for mobile check-in verification), and biometric templates (if integrated with on-premise hardware).
- MoneyFacts ERP & BillGini: Billing data, receipts, invoices, expense details, vendor names, GSTIN, tax records, bank transaction logs, and details of transactions.
C. Device and Usage Data (Automated Collection)
When accessing our web or mobile apps, we automatically log information such as your IP address, browser type, operating system version, device hardware model, API call logs, error logs, and session activity.
3. Purpose of Processing
Under Section 4 of the DPDP Act 2023, we process personal data only for lawful, specific, and declared purposes:
| Data Category | Specified Purpose | Lawful Basis |
|---|---|---|
| Account Credentials | Setting up subscriptions, verifying logins, and preventing fraud. | Contractual necessity |
| Employee Payroll & HR Data | Calculating monthly salaries, generating payslips, and executing PF/ESIC deposits. | Consent (by the employer) & Legal obligations |
| Geolocational Logs | Verifying field attendance and validating real-time punch locations (TimeMate). | Consent (explicitly granted by user) |
| Billing & Transaction Files | Generating GST-compliant invoices, processing e-Way bills, and expense receipt analysis. | Contractual performance & GST law compliance |
5. Security & Encryption
We maintain reasonable technical and organizational security measures to protect your digital personal data against loss, unauthorized access, or disclosure, in alignment with Section 8(5) of the DPDP Act:
- Data in Transit: Encrypted using TLS 1.3 protocol with SHA-256 signatures for all web and mobile traffic.
- Data at Rest: Customer database instances and file attachments are encrypted with AES-256 standards.
- Access Control: Logical isolation of databases per customer subscription, preventing cross-tenant access. Two-Factor Authentication (2FA) is enforced for admin users.
- Vulnerability Management: Periodic automated vulnerability scanning, penetration testing, and code audits.
6. Your Rights (DPDP Act)
Under India's DPDP Act, 2023, you (as a Data Principal) have specific statutory rights. You can exercise these by contacting our Grievance Officer:
- Right to Access: Request a summary of the personal data being processed, the names of subprocessors shared with, and the processing activities performed.
- Right to Correction & Completion: Correct inaccurate data or complete incomplete details across our databases.
- Right to Erasure (“Right to be Forgotten”): Request the deletion of your personal data when the purpose of collection has been served, or when you withdraw consent.
- Right to Withdraw Consent: You can withdraw consent at any time. Withdrawal stops further processing immediately, unless processing is required by other tax or labor statutes.
- Right to Nominate: Nominate another individual to exercise your rights under this Act in the event of death or physical/mental incapacity.
7. Data Retention & Deletion
In accordance with Section 8(4) of the DPDP Act, we delete your personal data as soon as the purpose of its collection is satisfied, or upon withdrawal of consent.
Retention Schedule:
- Active Accounts: Stored for the duration of your active subscription.
- Account Cancellation: Data is kept in a deactivated state for a 90-day grace period to allow account restoration. After 90 days, data is hard-deleted from production databases.
- Backups: Deletion from encrypted offline backups occurs automatically within 6 months of database erasure.
9. Grievance Redressal Officer
If you have any questions about this policy, wish to exercise your rights, or have a grievance regarding your personal data, you may contact our designated Grievance Officer:
Grievance Redressal Officer
Intelliob Technologies Private Limited
Email: support@intelliob.com
Phone: +91 9324088857 (Mon - Fri, 10 AM - 6 PM)
Address:
1/3, Liliya Nagar, Off. S.V. Road,
Goregaon West, Mumbai, Maharashtra - 400104
Under the DPDP Act 2023, if you are unsatisfied with our grievance response, you have the right to lodge a formal complaint with the Data Protection Board of India (DPBI).