1. Scope and our role
Subhx Infotech OPC Pvt Ltd (“Subhx”, “we”, “us”) operates SubhX Nexus, an HR and project-management platform. This Privacy Policy describes how we collect, use, disclose, retain and protect personal data, and the rights available to individuals (“Data Principals”) under India's Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and other applicable laws.
For most data inside a customer workspace — employee, payroll, attendance, onboarding and project records — the customer organisation is the Data Fiduciary(controller) that decides the purposes and means of processing, and we act as a Data Processor processing that data on the organisation's documented instructions. For data we collect for our own purposes (such as account administration, billing and the marketing of the Service) we act as a Data Fiduciary in our own right.
2. Personal data we collect
Depending on how the Service is used, we may process the following categories of data:
- Account & identity
- Name, work and personal email addresses, phone number, role, organisation, and authentication data such as one-time passcodes and single sign-on identifiers.
- Employee & HR records
- Employee profiles, designations, reporting lines, attendance, leave, payroll and salary details, reimbursements, documents and onboarding information added by the organisation.
- KYC & sensitive identifiers
- Where the organisation enables KYC, identifiers such as Aadhaar, PAN and bank details. Aadhaar numbers are masked in the interface and held in a segregated, encrypted vault; full values are revealed only with authorisation and the access is logged.
- Usage & device data
- Log data, IP address, device and browser information, and actions taken in the Service, used for security, troubleshooting and analytics.
- Communications
- Messages, support requests, tickets and content you submit through chat, email and meeting features of the Service.
3. Purposes and lawful basis
We process personal data for the following purposes:
- Providing, operating, securing and maintaining the Service, and authenticating users.
- Performing HR and project operations configured by the organisation — onboarding, attendance, leave, payroll, reimbursements, tasks and reporting.
- Processing payments, issuing GST-compliant invoices, and administering subscriptions and wallet balances in INR.
- Communicating service notices, security alerts and, where permitted, product updates.
- Preventing fraud and abuse, enforcing our Terms, and complying with legal obligations.
- Improving and developing the Service, using aggregated or de-identified data where possible.
Under the DPDP Act, our lawful basis is the consent of the Data Principal or one of the recognised legitimate uses (for example, a purpose for which the Data Principal has voluntarily provided their data, employment-related purposes, or compliance with a legal obligation). Where we act as a Data Processor, the customer organisation is responsible for establishing the lawful basis and for providing any required notice to, and obtaining any required consent from, its Data Principals.
5. Data retention
We retain personal data for as long as it is needed to provide the Service to the organisation, and thereafter only as required to comply with legal, tax and accounting obligations, to resolve disputes and to enforce our agreements. Customer Data is retained on the organisation's instructions; on termination, we make data available for export for 30 days and then delete or anonymise it in line with Section 9 of our Terms, except where retention is legally required. When personal data is no longer required and there is no legal basis to keep it, we delete or de-identify it.
6. Security
- We apply reasonable technical and organisational security measures designed to protect personal data against unauthorised access, alteration, disclosure or destruction.
- Sensitive identifiers and secrets are encrypted at rest using strong encryption (including AES-based encryption such as AES-256), and transport is protected with TLS in transit. Aadhaar values are kept in a segregated, encrypted vault with masked display and audit-logged reveals.
- Access to personal data is restricted on a need-to-know basis through role-based access controls, OTP/SSO authentication and audit logging of sensitive actions.
- We maintain backups and operate on hardened cloud infrastructure (AWS Mumbai). In the event of a personal data breach that is likely to affect Data Principals, we will notify the Data Protection Board of India and affected parties as required by the DPDP Act, and assist customers with their own notification obligations.
7. Your rights as a Data Principal
Subject to applicable law, Data Principals have the right to:
- Access a summary of the personal data being processed and the processing activities.
- Request correction, completion or updating of inaccurate or incomplete personal data.
- Request erasure of personal data that is no longer necessary for the purpose for which it was collected, unless retention is required by law.
- Withdraw consent at any time, where processing is based on consent (withdrawal does not affect prior lawful processing).
- Nominate another individual to exercise rights in the event of death or incapacity.
- Raise a grievance with us and, if unresolved, escalate to the Data Protection Board of India.
Where we act as a Data Processor, we will forward requests we receive directly to the relevant customer organisation (the Data Fiduciary), or assist that organisation in responding. To exercise your rights, contact your organisation administrator or write to us at the address below.
9. Children's data
The Service is intended for use by businesses and their adult workforce. We do not knowingly process the personal data of children except where an organisation lawfully does so as a Data Fiduciary with verifiable parental consent as required by the DPDP Act.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will update the “Last updated” date above and, for material changes, take reasonable steps to inform affected organisations. Please review this page periodically.
11. Grievance Officer and contact
In accordance with the DPDP Act and the Information Technology Act, 2000, you may contact our Grievance Officer with any privacy questions, requests or complaints. We will acknowledge and respond within the timelines prescribed by applicable law.
Grievance Officer — Subhx Infotech OPC Pvt Ltd
- Product
- SubhX Nexus
- support@subhx.in
- Jurisdiction
- India
If you are not satisfied with our response, you may escalate your grievance to the Data Protection Board of India established under the DPDP Act.