1. Information We Collect
To provide enterprise HR, automated gross-to-net payroll, ATS candidate pipelines, and compliance filings, Kaamyatri processes data provided directly by Customer administrators and employees.
Full Name, Work Email, Contact Phone, Emergency Contacts, Department Pod, Job Title, Reporting Hierarchy.
Bank Account IFSC & Number, PAN Number, UAN Provident Fund ID, ESIC ID, Salary Structure, Reimbursements.
2. How We Use Your Data
Kaamyatri uses Customer data strictly to provide, maintain, and secure platform services as instructed in Customer's Service Agreement.
- Automating monthly salary calculation, PF/ESI deductions, and direct bank disbursal API transfers.
- Generating statutory Form-16 tax certificates and corporate compliance audit ledgers.
- Facilitating candidate ATS scorecards, interview scheduling, and e-signatures.
- Enforcing role-based access control (RBAC) permissions across administrative roles.
3. Encryption & Data Isolation
All Customer data stored in Kaamyatri is encrypted using industry-standard 256-bit AES keys at rest and TLS 1.3 in transit.
4. Third-Party Integrations & Banking Partners
Kaamyatri connects directly to authorized partner APIs solely to execute Customer-initiated actions:
- Banking Disbursal APIs: Direct salary credits via partner bank portals (HDFC, ICICI, RazorpayX).
- Statutory Portals: Automated submission of EPF ECR returns to EPFO and TDS filings to Income Tax Department.
- Google / Microsoft SSO: OAuth authentication for single sign-on security.
5. Employee Rights (DPDP Act 2023 & GDPR)
Under the Digital Personal Data Protection (DPDP) Act 2023 and GDPR, employees have the right to request access to their personal records, correct inaccurate data, and export their employment history.
6. Data Retention & Erasure
We retain Customer data for the active duration of the subscription agreement. Upon account termination, Customer data is preserved for 90 days for export before undergoing SHA-256 cryptographic wipe.
7. Cookies & Session Storage
Kaamyatri uses only essential HTTP cookies and local session tokens required for user authentication, security CSRF protection, and user preferences. We do not use third-party tracking or advertising cookies.
8. Data Protection Officer (DPO) Contact
If you have questions regarding data privacy, cryptographic security, or DPDP/GDPR data requests, please contact our Data Protection Officer:
