1. About this Privacy Policy
This Privacy Policy explains how Skyrocket Ventures LLP (Skyrocket, we, us or our) collects, uses, stores, shares and protects personal data in connection with EmplifyAI, our website, mobile applications, demonstrations, communications, support and related services (collectively, the Services). It also explains the choices and rights available to individuals.
It applies to website visitors, prospective customers, customer administrators, authorised users, employees, workers, contractors, candidates and other individuals whose personal data is handled through the Services, as well as people who contact us through email, telephone, forms, meetings, messaging platforms, social media, events or other channels.
This Policy should be read with the EmplifyAI Terms of Use, applicable Data Processing Addendum (DPA), Cookie Policy, subprocessor list and any just-in-time notice shown for a particular feature. If a customer's contract or DPA provides stronger protection for Customer HRMS Data, that document controls for that processing.
2. Who we are
EmplifyAI is provided by Skyrocket Ventures LLP, with its principal office in Hyderabad, Telangana, India. Skyrocket Consultancy is the designated implementation partner and may provide implementation, configuration, migration or related services under a customer Order Form or statement of work. Its role and access to personal data will be governed by the applicable contract and DPA.
3. Our role: Data Fiduciary/controller or Data Processor
3.1 When we determine the purpose
Skyrocket ordinarily acts as a Data Fiduciary or controller when it determines why and how personal data is used for operating our website, responding to enquiries, administering trials and customer relationships, processing billing records, providing support, securing the Services, meeting legal duties, recruiting for our own business and sending permitted marketing communications.
3.2 When a customer determines the purpose
For employee, worker, candidate and other HR records submitted to EmplifyAI by or for a customer (Customer HRMS Data), the customer—usually your employer or prospective employer—ordinarily acts as the Data Fiduciary/controller. Skyrocket acts as its Data Processor and handles that data on the customer's documented instructions, under the customer agreement and DPA. The customer decides which modules are enabled, which records are collected, who may access them, how they are used and how long they are retained.
If you are an employee or candidate: Your organisation's workforce or candidate privacy notice is the primary notice for its purposes and decisions. Requests about HR records should normally be made to that organisation first. We will assist it as required by the DPA and applicable law.
4. How we collect personal data
• Directly from you—for example when you complete a Contact, Demo, Trial, Newsletter, Event, Partner or Support form; create or use an account; upload a document; make a payment; apply for a role; or communicate with us.
• From a customer, administrator, employer, recruiter, implementation team or authorised user who creates your profile, uploads records, configures the account or connects another system.
• Automatically from browsers, devices, applications, cookies, SDKs, logs and security systems when you visit or use the Services.
• From integrations and third-party services that a customer or user enables, such as identity providers, attendance devices, payroll or accounting systems, payment gateways and communication tools.
• From public or commercial business sources, event organisers, referrals and professional networks where permitted by law and relevant to a business relationship.
5. Personal data we may collect
The exact data collected depends on the page, form, subscription plan, modules, permissions and customer configuration. We should not ask for personal data that is unnecessary for the stated purpose. If a form or feature requires materially different data, we will provide an additional notice at or before collection.
5.1 Browser and mobile permissions for attendance
Depending on the attendance method enabled by the customer, the browser or mobile operating system may ask the user to grant one or more device permissions. Permission labels and choices may vary by browser, device and operating-system version. EmplifyAI will request a permission when the user accesses the related feature and will use the resulting data only for the purposes described below.
For ordinary location-validated attendance, location is collected at or around the attendance event rather than used for continuous employee tracking. We do not use attendance location, photographs or device-permission data for advertising or unrelated monitoring. If a required permission is denied, the related attendance method may not work; the customer is responsible for providing an alternative attendance process where required by law, policy or reasonable accommodation.
6. Why we use personal data
We process personal data for a lawful purpose based on consent where required, performance of a contract or requested service, compliance with law, or another use permitted by applicable law. When we rely on consent, it may be withdrawn using the method stated at collection or by contacting us, without affecting processing already lawfully completed.
7. Customer HRMS Data
We process Customer HRMS Data only to provide, secure, support and improve the subscribed Services, follow the customer's documented instructions and meet applicable legal obligations. We do not own Customer HRMS Data. We do not sell it, use it to advertise third-party products to employees, or disclose it for another organisation's independent marketing.
Customers are responsible for giving workforce and candidate notices, establishing the permitted purpose or consent required for each data category and module, maintaining accurate records, applying appropriate access and retention settings, and providing a non-digital or alternative process where required.
We may use service telemetry and irreversibly aggregated or de-identified information to operate, secure and improve the Services and produce statistical insights. We will not attempt to re-identify such information or publish a result that identifies a customer or individual.
8. AI-assisted features
EmplifyAI may use artificial-intelligence or machine-learning technologies to provide features such as answers, summaries, recommendations, classifications, drafting assistance, document analysis and workflow assistance. An AI feature may process a user's prompt, uploaded content and the Customer HRMS Data that the user is authorised to access, but only to provide, secure and improve that feature in accordance with the customer's instructions and this Policy.
8.1 Access and data boundaries
AI features are subject to the same role-based permissions and access rules as the rest of the Services. They are not intended to give a user new or broader access to personal data. We design AI requests to remain within the relevant customer tenant, entity and user context, and use data minimisation so that only information reasonably necessary for the requested function is processed.
8.2 Human control and responsible use
AI-generated content may be incomplete, inaccurate or inappropriate and must be reviewed in context. AI features provide assistance and are not intended to be the sole basis for a decision that materially affects a candidate, employee or other individual. Where an AI feature proposes a change to HR records or another consequential action, an authorised user must review and explicitly confirm the action before it is completed.
8.3 Logging and traceability
We may record AI-interaction metadata, such as the requesting user, date and time, feature used, action requested and outcome, for security, troubleshooting, audit and accountability. Where an answer or recommendation is based on HRMS records, policies or reports, EmplifyAI may display relevant source references or context so an authorised user can verify it. The extent of logging and source traceability may vary by feature and customer configuration.
8.4 AI providers and model training
We may use approved third-party AI or large-language-model providers as subprocessors. We require appropriate confidentiality, security and data-protection commitments, use encrypted transmission, and restrict processing to the contracted service. We do not use, or permit an AI provider to use, Customer HRMS Data to train a general-purpose, shared or cross-customer model unless the customer expressly agrees through a separate written opt-in.
Because providers and configurations may change, our current subprocessor information or DPA will identify material AI providers, their functions and relevant processing locations. Provider retention and deletion commitments will be governed by the applicable contract and configuration rather than a fixed period stated in this Policy.
8.5 Security, retention and customer choices
We apply the safeguards described in Section 12 to personal data processed through AI features, including appropriate access controls, encryption, tenant separation, logging, monitoring and vendor due diligence. AI inputs, outputs and interaction records are retained only for as long as reasonably necessary for the feature, customer instructions, security, audit, legal obligations and the retention schedule in Section 13. Customers may control or disable available AI features and should configure access, review and retention settings appropriate to their workforce and permitted purposes.
9. Cookies, analytics and similar technologies
Our website and Services may use cookies, local storage, SDKs, pixels and similar technologies. A separate Cookie Policy and consent tool should identify each live technology, provider, purpose and duration. We will not enable non-essential analytics or marketing technologies before obtaining consent where applicable.
You may use our cookie-management tool or browser settings to manage non-essential cookies. Browser controls do not always remove technologies already stored, and blocking strictly necessary cookies may prevent login or core functions.
10. When we disclose personal data
Customer and authorised users. Customer administrators and other users may access data according to permissions configured by the customer.
Service providers and subprocessors. We use providers for cloud hosting, databases, security, authentication, communications, support, analytics, payment processing, document processing, AI and other technical operations. They may process only what is needed for their contracted function and must protect it under appropriate terms.
Skyrocket Consultancy. Where authorised under an Order Form, statement of work or DPA, the implementation partner may receive contact, configuration or Customer HRMS Data reasonably necessary for implementation, migration, training or support.
Customer-enabled integrations. At the customer's or user's direction, we exchange data with applications, identity providers, attendance devices, APIs or other services they enable. Those third parties may have their own terms and privacy practices.
Payment gateways. Payment providers process payment credentials under their own privacy terms. We receive transaction status, reference, amount and related billing information.
Professional advisers and insurers. We may disclose information where reasonably necessary for legal, accounting, audit, insurance and professional advice, subject to confidentiality.
Authorities and protection. We may preserve or disclose information when required by applicable law, valid legal process or a binding governmental request, or where reasonably necessary to prevent fraud, address a security incident or protect legal rights, safety or the Services. Where permitted, we will seek to notify the affected customer and challenge overbroad demands.
Business transactions. Information may be transferred in a merger, financing, acquisition, reorganisation or sale of all or part of the business, subject to confidentiality and applicable law.
We do not sell personal data. We do not share Customer HRMS Data for cross-context behavioural advertising or independent third-party marketing. A current list of material EmplifyAI subprocessors, their functions and processing locations will be published in the legal or policies section of the website.
11. International and cross-border processing
Our Services and subprocessors may process personal data in India and other countries where they operate. These countries may have different data-protection laws. We will disclose material processing locations in our subprocessor information and use contractual, technical and organisational safeguards appropriate to the processing.
Customer HRMS Data will be processed outside India only in accordance with the DPA, the customer's lawful instructions and restrictions imposed by applicable law or the Government of India. Where an approved AI subprocessor processes personal data outside India, its function and relevant processing location will be identified in our subprocessor information or DPA.
12. Security
We maintain reasonable technical and organisational safeguards designed to protect personal data against unauthorised access, loss, misuse, alteration and disclosure. Depending on the system and risk, these include encryption in transit and at rest, role-based access control, authentication controls, logging and monitoring, backups, vulnerability management, incident response, personnel confidentiality and vendor due diligence.
Access to sensitive records and supported AI interactions is logged to the extent appropriate to the feature and customer configuration. Customers remain responsible for configuring permissions, protecting credentials, managing user access, reviewing audit activity and promptly reporting suspected misuse. No internet transmission or storage method is completely secure, and we cannot promise absolute security.
If we confirm a personal-data breach affecting Customer HRMS Data, we will notify the affected customer without undue delay and provide information and cooperation required under the DPA and applicable law. We will notify directly affected individuals where we are responsible for doing so.
13. Retention and deletion
Deletion from routine backups may occur later than deletion from active systems because backups rotate on a schedule. During that interval, deleted data will remain protected, will not be restored except for disaster recovery or legal necessity, and will be removed through normal rotation. The final published policy must state the actual active-system and backup timeframes.
14. Your rights and choices
Depending on the law applicable to you and the context, you may request information about processing, access to personal data, correction or completion, erasure, withdrawal of consent, grievance redressal and nomination of another person to exercise rights in the event of death or incapacity. You may also unsubscribe from marketing at any time. Rights may be limited where retention or processing is required by law or necessary to establish or defend legal claims.
14.1 Customer HRMS Data
If your data was submitted by your employer, prospective employer or another EmplifyAI customer, contact that organisation first using its HR or privacy channel. We will route a request received directly by us to the relevant customer and assist it under the DPA. We will not change an employer-controlled record without its instruction unless required by law.
14.2 Data we control directly
For website, prospect, billing-contact, marketing and other data for which Skyrocket determines the purpose, submit a request to [privacy/grievance email to be confirmed]. We may verify your identity and authority, ask for information needed to locate records and maintain an audit record of the request. We will respond within the period required by applicable law.
15. Marketing communications
We may send business-to-business product information, event invitations or related communications where permitted. You can unsubscribe through the link in an email or contact us. Service, security, billing and legal notices are not marketing and may still be sent while relevant to an account or relationship. We do not use Customer HRMS Data to market third-party products to employees.
16. Children and dependant information
Our public website and direct account-registration processes are not intended for children. EmplifyAI may nevertheless process information about an employee's child, dependant, nominee or beneficiary when a customer lawfully uses an HR, benefits, insurance, payroll or statutory module. In that context, the customer is responsible for establishing the permitted purpose, giving required notice and obtaining verifiable parental consent where applicable; we process the information on the customer's instructions.
17. Third-party links and customer-enabled services
The website and Services may link to or integrate with services that we do not control. A customer's or user's direct relationship with such a third party is governed by that party's privacy notice and terms. Review those documents before enabling an integration or providing personal data. This does not reduce our responsibility for subprocessors we appoint to perform EmplifyAI obligations.
18. Changes to this Policy
We may update this Policy to reflect changes in law, products, vendors or practices. The current version and effective date will be posted on the EmplifyAI website. If a change materially affects how we use personal data, we will provide reasonable advance notice through email, the Services or a prominent website notice and obtain fresh consent where legally required.
19. Contact and grievance redressal
For privacy questions, rights requests or grievances concerning data for which Skyrocket is responsible, contact:
If your request concerns employer-controlled Customer HRMS Data, include the employer or customer organisation name so we can route it correctly. You may escalate an unresolved grievance to the authority or forum available under applicable law after first using our grievance process.