Vortex Application privacy policy

Privacy Policy

Vortex HRMS Application Privacy Policy

This Privacy Policy explains how the Vortex HRMS application collects, uses, stores, discloses, and protects personal data processed through the platform in connection with employee administration, recruitment, onboarding, attendance, payroll, performance management, expenses, assets, approvals, support workflows, and related workforce operations.

Effective date: August 27, 2026 Scope: Web application, secure upload pages, APIs, and access workflows

1. Scope of This Policy

This policy applies to the Vortex HRMS platform and associated application surfaces, including authenticated user areas, administrative modules, employee self-service screens, secure onboarding document upload pages, application programming interfaces, mobile or gateway-linked access flows, and related support or operational features.

The policy is intended to describe how personal data is processed through the application itself. A customer organization using the platform may also be required to issue its own employee, applicant, contractor, or regional privacy notices depending on the jurisdictions in which it operates.

2. Roles and Responsibilities

In a typical deployment, the employer or customer organization determines what workforce data is entered into the platform and why it is processed. In that context, the customer organization generally acts as the primary controller or decision-maker for employee and candidate data.

The platform generally operates as the software and service environment through which that data is processed. Limited data relating to platform administration, support, system security, service continuity, and auditability may also be processed for platform-operation purposes.

3. Categories of Data Collected

Category Examples Relevant application areas
Identity and profile information Name, employee code, email address, phone number, date of joining, profile image, reporting structure, role, shift, and location. People, employee profile, accounts, organization management.
Recruitment and onboarding information Candidate details, contact information, offer status, onboarding records, verification items, uploaded documents, joining letters, and probation-related records. Onboarding, secure upload flows, employee creation workflows.
Employment and organizational records Department, designation, grade, reporting lines, responsibilities, letters, internal notes, and employment history. People, organization, document management.
Attendance and access information Punch times, leave records, regularizations, comp-off records, rosters, timesheets, device registration data, and access-related security records. Attendance, access gateway, approvals, security settings.
Payroll and tax information Salary structures, payrun records, payslips, bank information, tax declarations, statutory forms, and tax preferences. Payroll, payroll settings, employee payroll views.
Performance and workflow information Goal plans, self-appraisals, reviewer actions, appeals, workflow decisions, and related audit trails. Appraisals and approvals.
Expense, asset, and support information Expense submissions, reimbursements, asset allocation records, maintenance events, return requests, helpdesk tickets, and notifications. Expenses, assets, helpdesk.
Technical and security information Authentication events, session data, API activity, device identifiers, uploaded file metadata, and audit or log entries. Accounts, APIs, support, security, access workflows.

4. Sources of Data

  • Data may be provided directly by employees, candidates, managers, HR teams, payroll users, administrators, or support personnel.
  • Data may be uploaded, imported, or configured by the customer organization using the platform.
  • Data may be generated as part of system workflows such as approvals, payroll calculations, attendance records, audit logs, document reviews, and security events.
  • Data may also originate from connected systems, integrations, or tenant-enabled processes where the relevant data is lawfully supplied to the application.

5. How Data Is Used

  • To manage user accounts, employee records, and workforce profiles.
  • To support recruitment, onboarding, verification, employee setup, probation, and offboarding workflows.
  • To administer attendance, leave, timesheets, rosters, regularizations, and related approvals.
  • To process payroll, compensation, payslips, tax declarations, bank outputs, and statutory reporting support.
  • To manage appraisals, goal plans, review workflows, and performance reporting.
  • To support expenses, reimbursements, assets, helpdesk, notifications, and internal operational workflows.
  • To protect the application, maintain access controls, investigate issues, preserve auditability, and support service continuity.

6. Legal and Operational Basis for Processing

Depending on the deployment context and applicable law, data may be processed because it is necessary for employment administration, payroll processing, statutory compliance, contractual performance, legitimate internal business operations, service security, or user-directed actions. Some workflows may also rely on consent where consent is the appropriate legal basis under the applicable legal framework.

7. Internal Access to Data

Access to personal data should be limited to authorized users and personnel with a legitimate business or operational need. Internal access may occur for administration, troubleshooting, implementation support, security review, backup validation, audit support, incident response, or legal compliance.

Access should be limited to the minimum reasonably necessary scope and governed by role-based controls, confidentiality obligations, and logging where available.

8. Data Sharing and Disclosures

  • Data may be shared with authorized members of the customer organization according to configured roles, permissions, and workflow assignments.
  • Data may be shared with service providers supporting hosting, storage, backups, notifications, maintenance, and security operations.
  • Data may be disclosed to banks, payroll counterparties, statutory bodies, or compliance-related recipients where necessary for configured business processes.
  • Data may be disclosed where required by law, legal process, audit, regulatory inquiry, fraud investigation, or protection of legal rights.

9. Sensitive and High-Risk Data

Because this is an HRMS application, some processed data may be sensitive or high-risk under privacy, employment, labor, tax, or sector-specific law. This may include compensation information, bank details, tax proofs, identity documents, onboarding verification files, attendance-related location signals, and records that may reveal personal circumstances.

Customer organizations should collect only the data they need, define clear access rules, and ensure their internal policies and legal notices are aligned with the actual features enabled in the platform.

10. Data Retention

Different categories of records may be retained for different periods depending on business needs, legal obligations, audit requirements, and the retention policy adopted by the customer organization.

  • Employee records may be retained during the employment lifecycle and for a period afterward.
  • Payroll and tax-related records may be retained longer for statutory, accounting, and audit purposes.
  • Candidate and onboarding records should be reviewed and removed, archived, or anonymized when no longer required.
  • Audit, security, and backup records may remain available for continuity, recovery, investigation, or legal-defense purposes.

11. Security Measures

  • Role-based navigation and access control.
  • Configurable permission and approval structures.
  • Security settings for sessions, access policies, IP rules, and related controls.
  • Audit logging across sensitive workflows such as onboarding, payroll, document review, employee changes, and approvals.
  • Structured handling of document uploads and workflow-linked file records.

No system can guarantee absolute security. Organizations using the platform remain responsible for appropriate credential management, local access governance, endpoint security, and lawful operational practices.

12. International Transfers

If data is stored, accessed, backed up, or supported across jurisdictions, the deploying organization should ensure that appropriate contractual, legal, and organizational safeguards are in place for any required international transfer of personal data.

13. Individual Rights

Depending on applicable law, individuals may have rights relating to access, correction, deletion, restriction, objection, portability, withdrawal of consent where relevant, and complaint to a regulator or supervisory authority.

In most workforce contexts, such requests should first be directed to the employer or customer organization that controls the employment or applicant relationship.

14. Cookies and Browser Storage

The application may use sessions, browser storage, or similar technical mechanisms to support authentication, user preferences, navigation state, and essential application behavior. If additional analytics or tracking technologies are introduced, they should be disclosed through the appropriate notice and consent mechanism where required.

15. Automated Processing

Certain features may use rules, workflow routing, policy engines, or automated calculations to support attendance processing, payroll operations, approval routing, or lifecycle status handling. These functions are intended to support operational workflow execution within the platform.

16. Children's Data

The application is intended for workplace administration and employment-related processing. It is not designed as a service for children. If a tenant stores dependent, emergency contact, beneficiary, or related family information, that tenant is responsible for ensuring an appropriate legal and policy basis for such processing.

17. Changes to This Policy

This policy may be updated to reflect changes in application functionality, legal requirements, regional operations, security measures, or service arrangements. The effective date should be updated whenever a material revision is made.

18. Contact and Privacy Requests

For workforce-record questions, correction requests, payroll-related privacy concerns, or applicant data requests, users should contact their employer, HR team, or tenant administrator first.

For platform-level privacy or legal questions, this page should be supplemented before production rollout with the organization's legal entity name, privacy contact email address, mailing address, and any jurisdiction-specific rights wording that applies to its users.