Legal

Privacy Policy

How Skyrocket Ventures LLP handles personal data in connection with EmplifyAI services.

1. About this Privacy Policy

This Privacy Policy explains how Skyrocket Ventures LLP (Skyrocket, we, us or our) collects, uses, stores, shares and protects personal data in connection with EmplifyAI, our website, mobile applications, demonstrations, communications, support and related services (collectively, the Services). It also explains the choices and rights available to individuals.

It applies to website visitors, prospective customers, customer administrators, authorised users, employees, workers, contractors, candidates and other individuals whose personal data is handled through the Services, as well as people who contact us through email, telephone, forms, meetings, messaging platforms, social media, events or other channels.

This Policy should be read with the EmplifyAI Terms of Use, applicable Data Processing Addendum (DPA), Cookie Policy, subprocessor list and any just-in-time notice shown for a particular feature. If a customer's contract or DPA provides stronger protection for Customer HRMS Data, that document controls for that processing.

2. Who we are

EmplifyAI is provided by Skyrocket Ventures LLP, with its principal office in Hyderabad, Telangana, India. Skyrocket Consultancy is the designated implementation partner and may provide implementation, configuration, migration or related services under a customer Order Form or statement of work. Its role and access to personal data will be governed by the applicable contract and DPA.

3. Our role: Data Fiduciary/controller or Data Processor

3.1 When we determine the purpose

Skyrocket ordinarily acts as a Data Fiduciary or controller when it determines why and how personal data is used for operating our website, responding to enquiries, administering trials and customer relationships, processing billing records, providing support, securing the Services, meeting legal duties, recruiting for our own business and sending permitted marketing communications.

3.2 When a customer determines the purpose

For employee, worker, candidate and other HR records submitted to EmplifyAI by or for a customer (Customer HRMS Data), the customer—usually your employer or prospective employer—ordinarily acts as the Data Fiduciary/controller. Skyrocket acts as its Data Processor and handles that data on the customer's documented instructions, under the customer agreement and DPA. The customer decides which modules are enabled, which records are collected, who may access them, how they are used and how long they are retained.

If you are an employee or candidate: Your organisation's workforce or candidate privacy notice is the primary notice for its purposes and decisions. Requests about HR records should normally be made to that organisation first. We will assist it as required by the DPA and applicable law.

4. How we collect personal data

• Directly from you—for example when you complete a Contact, Demo, Trial, Newsletter, Event, Partner or Support form; create or use an account; upload a document; make a payment; apply for a role; or communicate with us.

• From a customer, administrator, employer, recruiter, implementation team or authorised user who creates your profile, uploads records, configures the account or connects another system.

• Automatically from browsers, devices, applications, cookies, SDKs, logs and security systems when you visit or use the Services.

• From integrations and third-party services that a customer or user enables, such as identity providers, attendance devices, payroll or accounting systems, payment gateways and communication tools.

• From public or commercial business sources, event organisers, referrals and professional networks where permitted by law and relevant to a business relationship.

5. Personal data we may collect

CategoryExamples
Website, enquiry and prospect dataName, work email, telephone number, job title, employer, business location, headcount range, product interest, enquiry text, preferred contact method, meeting details, campaign source and communication preferences, depending on the form or channel used.
Commercial and account dataOrganisation details, administrator and billing contacts, order and subscription information, GST and invoicing details, payment status, transaction reference, account identifiers, credentials, authentication events and permissions. Payment gateways process full card or payment credentials; we should retain only the transaction and billing records needed for service and compliance.
Profile and contact dataName, employee code, photograph, date of birth, gender where provided, personal/work contact details, address, emergency contacts, dependants and nominees where configured by the customer.
Employment and organisation dataEmployer, role, designation, department, location, manager, employment type, dates of joining or exit, work history, skills, qualifications, onboarding, assets, policies, letters and workflow records.
Attendance, leave and location dataClock-in/out events, shifts, schedules, leave, timesheets, attendance-device events and precise or approximate location where an enabled attendance feature requires it.
Payroll, tax and financial dataCompensation, deductions, benefits, reimbursement and expense records, bank account or payment details, tax declarations, PAN, provident-fund or social-security identifiers and statutory payroll records.
Identity and uploaded documentsPAN or Aadhaar documents, passport, driving licence, bank proof, certificates, receipts, offer or employment letters and other files uploaded under a customer's configuration.
Recruitment and performance dataResumes, applications, interview and assessment records, references, offers, goals, KRAs/KPIs, feedback, surveys, reviews, ratings, training and disciplinary or grievance records where a customer uses those modules.
Support and communications dataSupport tickets, chat or messaging content, emails, call or meeting notes and recordings where notice is provided, feedback, screenshots, attachments, diagnostic files and authorised support-access records.
Device, usage and security dataIP address, device and browser type, operating system, app version, device or session identifiers, login and audit events, timestamps, pages and features used, referring URL, approximate location, cookie identifiers, crash/error reports and security signals.
Custom and integration dataFields created by a customer and data imported from or sent to integrations the customer enables. The customer is responsible for limiting custom fields to information necessary for a lawful HR purpose.

The exact data collected depends on the page, form, subscription plan, modules, permissions and customer configuration. We should not ask for personal data that is unnecessary for the stated purpose. If a form or feature requires materially different data, we will provide an additional notice at or before collection.

5.1 Browser and mobile permissions for attendance

Depending on the attendance method enabled by the customer, the browser or mobile operating system may ask the user to grant one or more device permissions. Permission labels and choices may vary by browser, device and operating-system version. EmplifyAI will request a permission when the user accesses the related feature and will use the resulting data only for the purposes described below.

Environment / permissionWhen and why it may be requestedUser control
Browser — locationWhen a user initiates clock-in, clock-out or another location-validated attendance event, to obtain the device's approximate or precise location, accuracy and event time and check them against the customer's permitted workplace or geofence.The browser displays the permission request. The user may allow or deny it and may later withdraw it through browser or device settings.
Browser — cameraWhen an enabled attendance method requires a live photograph, selfie, visual evidence or QR-code scan.Requested when the camera-based feature is used. EmplifyAI does not activate the camera after permission is denied or outside the requested feature.
Browser — notificationsTo deliver attendance reminders, missed-punch alerts or attendance-status messages where the user opts in.Optional and revocable through browser settings. Denial does not prevent ordinary use of the Services.
Mobile app — location while using the app or one timeFor a user-initiated attendance event, workplace or geofence validation, and prevention or investigation of attendance misuse. Precise location is requested only where the configured rule reasonably requires it.The operating system provides options such as approximate or precise location, one-time access or access while using the app. Available choices depend on the device.
Mobile app — cameraFor an enabled selfie, live photograph, attendance evidence or QR-code attendance feature.Requested in context. The camera is not used for unrelated monitoring.
Mobile app — photos, media or filesOnly when a user chooses an existing image or file as attendance evidence or an authorised attachment. Where supported, a system file or photo picker is used to limit access to the selected item.The user chooses the item to upload and may remove it subject to customer permissions and retention rules.
Mobile app — notificationsTo send attendance reminders, missed-punch alerts, approval updates or service and security notices.Optional and revocable through device settings; some essential account or legal communications may still be sent by another channel.
Mobile app — background locationNot required for ordinary user-initiated clock-in or clock-out. It may be requested only if the customer enables a separate field-duty, continuous-location or geofence feature that genuinely requires location while the app is not actively in use.Before requesting it, EmplifyAI will provide an additional prominent notice explaining the purpose, frequency and customer visibility. The user may deny or revoke it through device settings.

For ordinary location-validated attendance, location is collected at or around the attendance event rather than used for continuous employee tracking. We do not use attendance location, photographs or device-permission data for advertising or unrelated monitoring. If a required permission is denied, the related attendance method may not work; the customer is responsible for providing an alternative attendance process where required by law, policy or reasonable accommodation.

6. Why we use personal data

PurposeHow the data is used
Respond and develop a business relationshipAnswer enquiries, arrange demos, provide proposals, administer trials, manage contracts and maintain business-contact records.
Provide the ServicesCreate accounts, authenticate users, host Customer HRMS Data, operate enabled HR workflows, process payroll inputs, generate reports and support customer configurations.
Administer attendanceRecord authorised clock-in and clock-out events, validate workplace or geofence rules, attach permitted evidence, send reminders, investigate attendance misuse and provide attendance records to the customer and authorised users.
Support and implementationMigrate and configure data, resolve tickets, investigate errors, communicate service information and provide authorised customer assistance.
Billing and paymentsCalculate subscription charges, issue invoices, reconcile gateway payments, maintain tax records, prevent payment fraud and manage overdue accounts.
Security and reliabilityControl access, maintain audit logs, detect abuse, prevent fraud, monitor performance, debug failures, back up systems and respond to incidents.
CommunicateSend account, billing, security, product, support and policy notices, and request service feedback.
MarketingSend relevant product information or event invitations where permitted and honour unsubscribe and do-not-contact preferences.
Improve responsiblyAnalyse use, quality and performance; develop features; and create aggregated or irreversibly de-identified statistics that do not identify a person or customer.
Comply and protectMeet legal, tax, accounting and regulatory duties; respond to valid legal process; enforce agreements; establish or defend claims; and protect people, customers and the Services.

We process personal data for a lawful purpose based on consent where required, performance of a contract or requested service, compliance with law, or another use permitted by applicable law. When we rely on consent, it may be withdrawn using the method stated at collection or by contacting us, without affecting processing already lawfully completed.

7. Customer HRMS Data

We process Customer HRMS Data only to provide, secure, support and improve the subscribed Services, follow the customer's documented instructions and meet applicable legal obligations. We do not own Customer HRMS Data. We do not sell it, use it to advertise third-party products to employees, or disclose it for another organisation's independent marketing.

Customers are responsible for giving workforce and candidate notices, establishing the permitted purpose or consent required for each data category and module, maintaining accurate records, applying appropriate access and retention settings, and providing a non-digital or alternative process where required.

We may use service telemetry and irreversibly aggregated or de-identified information to operate, secure and improve the Services and produce statistical insights. We will not attempt to re-identify such information or publish a result that identifies a customer or individual.

8. AI-assisted features

EmplifyAI may use artificial-intelligence or machine-learning technologies to provide features such as answers, summaries, recommendations, classifications, drafting assistance, document analysis and workflow assistance. An AI feature may process a user's prompt, uploaded content and the Customer HRMS Data that the user is authorised to access, but only to provide, secure and improve that feature in accordance with the customer's instructions and this Policy.

8.1 Access and data boundaries

AI features are subject to the same role-based permissions and access rules as the rest of the Services. They are not intended to give a user new or broader access to personal data. We design AI requests to remain within the relevant customer tenant, entity and user context, and use data minimisation so that only information reasonably necessary for the requested function is processed.

8.2 Human control and responsible use

AI-generated content may be incomplete, inaccurate or inappropriate and must be reviewed in context. AI features provide assistance and are not intended to be the sole basis for a decision that materially affects a candidate, employee or other individual. Where an AI feature proposes a change to HR records or another consequential action, an authorised user must review and explicitly confirm the action before it is completed.

8.3 Logging and traceability

We may record AI-interaction metadata, such as the requesting user, date and time, feature used, action requested and outcome, for security, troubleshooting, audit and accountability. Where an answer or recommendation is based on HRMS records, policies or reports, EmplifyAI may display relevant source references or context so an authorised user can verify it. The extent of logging and source traceability may vary by feature and customer configuration.

8.4 AI providers and model training

We may use approved third-party AI or large-language-model providers as subprocessors. We require appropriate confidentiality, security and data-protection commitments, use encrypted transmission, and restrict processing to the contracted service. We do not use, or permit an AI provider to use, Customer HRMS Data to train a general-purpose, shared or cross-customer model unless the customer expressly agrees through a separate written opt-in.

Because providers and configurations may change, our current subprocessor information or DPA will identify material AI providers, their functions and relevant processing locations. Provider retention and deletion commitments will be governed by the applicable contract and configuration rather than a fixed period stated in this Policy.

8.5 Security, retention and customer choices

We apply the safeguards described in Section 12 to personal data processed through AI features, including appropriate access controls, encryption, tenant separation, logging, monitoring and vendor due diligence. AI inputs, outputs and interaction records are retained only for as long as reasonably necessary for the feature, customer instructions, security, audit, legal obligations and the retention schedule in Section 13. Customers may control or disable available AI features and should configure access, review and retention settings appropriate to their workforce and permitted purposes.

9. Cookies, analytics and similar technologies

Our website and Services may use cookies, local storage, SDKs, pixels and similar technologies. A separate Cookie Policy and consent tool should identify each live technology, provider, purpose and duration. We will not enable non-essential analytics or marketing technologies before obtaining consent where applicable.

Technology categoryPurpose
Strictly necessaryAuthentication, session continuity, load balancing, security, fraud prevention and user-requested settings. Disabling these may prevent the Services from working.
FunctionalRemember language, region, interface and similar preferences where enabled.
Analytics and performanceUnderstand pages and features used, errors, performance and navigation so we can improve the website and Services.
MarketingMeasure campaigns or show relevant business advertising where used and consented. Customer HRMS Data will not be used for this purpose.

You may use our cookie-management tool or browser settings to manage non-essential cookies. Browser controls do not always remove technologies already stored, and blocking strictly necessary cookies may prevent login or core functions.

10. When we disclose personal data

Customer and authorised users. Customer administrators and other users may access data according to permissions configured by the customer.

Service providers and subprocessors. We use providers for cloud hosting, databases, security, authentication, communications, support, analytics, payment processing, document processing, AI and other technical operations. They may process only what is needed for their contracted function and must protect it under appropriate terms.

Skyrocket Consultancy. Where authorised under an Order Form, statement of work or DPA, the implementation partner may receive contact, configuration or Customer HRMS Data reasonably necessary for implementation, migration, training or support.

Customer-enabled integrations. At the customer's or user's direction, we exchange data with applications, identity providers, attendance devices, APIs or other services they enable. Those third parties may have their own terms and privacy practices.

Payment gateways. Payment providers process payment credentials under their own privacy terms. We receive transaction status, reference, amount and related billing information.

Professional advisers and insurers. We may disclose information where reasonably necessary for legal, accounting, audit, insurance and professional advice, subject to confidentiality.

Authorities and protection. We may preserve or disclose information when required by applicable law, valid legal process or a binding governmental request, or where reasonably necessary to prevent fraud, address a security incident or protect legal rights, safety or the Services. Where permitted, we will seek to notify the affected customer and challenge overbroad demands.

Business transactions. Information may be transferred in a merger, financing, acquisition, reorganisation or sale of all or part of the business, subject to confidentiality and applicable law.

We do not sell personal data. We do not share Customer HRMS Data for cross-context behavioural advertising or independent third-party marketing. A current list of material EmplifyAI subprocessors, their functions and processing locations will be published in the legal or policies section of the website.

11. International and cross-border processing

Our Services and subprocessors may process personal data in India and other countries where they operate. These countries may have different data-protection laws. We will disclose material processing locations in our subprocessor information and use contractual, technical and organisational safeguards appropriate to the processing.

Customer HRMS Data will be processed outside India only in accordance with the DPA, the customer's lawful instructions and restrictions imposed by applicable law or the Government of India. Where an approved AI subprocessor processes personal data outside India, its function and relevant processing location will be identified in our subprocessor information or DPA.

12. Security

We maintain reasonable technical and organisational safeguards designed to protect personal data against unauthorised access, loss, misuse, alteration and disclosure. Depending on the system and risk, these include encryption in transit and at rest, role-based access control, authentication controls, logging and monitoring, backups, vulnerability management, incident response, personnel confidentiality and vendor due diligence.

Access to sensitive records and supported AI interactions is logged to the extent appropriate to the feature and customer configuration. Customers remain responsible for configuring permissions, protecting credentials, managing user access, reviewing audit activity and promptly reporting suspected misuse. No internet transmission or storage method is completely secure, and we cannot promise absolute security.

If we confirm a personal-data breach affecting Customer HRMS Data, we will notify the affected customer without undue delay and provide information and cooperation required under the DPA and applicable law. We will notify directly affected individuals where we are responsible for doing so.

13. Retention and deletion

Data categoryDraft retention position
Customer HRMS DataFor the subscription term and customer-configured retention. On expiry, cancellation or termination, the customer may place an export request within 14 days as described in the Terms. After that period, data may be deleted from active systems and then routine backups under the published deletion schedule, unless law requires retention.
Attendance location and attendance evidenceAs part of the related attendance record for the period configured by the customer or required for attendance, payroll, employment, dispute or legal purposes. Location and evidence should not be retained separately or longer than necessary for those purposes.
Uploaded identity documentsUntil deleted by an authorised customer/user, under the customer's configured retention, or when the organisation's account is deleted or purged, subject to legal holds and backup deletion.
AI inputs, outputs and interaction recordsFor the period reasonably necessary to provide the feature, follow customer instructions, investigate security or quality issues, support audit requirements and meet legal obligations. Provider-side retention is governed by the applicable contract and configuration and should be stated in the subprocessor information or DPA.
Website enquiries and prospectsFor [24 months] after the last meaningful interaction, unless a shorter period is requested, consent supports longer contact, or records are needed for a live opportunity or legal purpose.
Customer, contract, billing and tax recordsFor the customer relationship and the statutory accounting, tax, limitation or audit period that applies after it ends.
Support, security and audit logsFor the period reasonably necessary to support the account, investigate events and protect the Services, according to the internal retention schedule and customer agreement.
Marketing preferencesUntil opt-out or withdrawal; a minimal suppression record may be retained so the preference can be honoured.
Cookies and analyticsFor the duration stated in the Cookie Policy. Identifiable analytics should be deleted or aggregated when no longer required.

Deletion from routine backups may occur later than deletion from active systems because backups rotate on a schedule. During that interval, deleted data will remain protected, will not be restored except for disaster recovery or legal necessity, and will be removed through normal rotation. The final published policy must state the actual active-system and backup timeframes.

14. Your rights and choices

Depending on the law applicable to you and the context, you may request information about processing, access to personal data, correction or completion, erasure, withdrawal of consent, grievance redressal and nomination of another person to exercise rights in the event of death or incapacity. You may also unsubscribe from marketing at any time. Rights may be limited where retention or processing is required by law or necessary to establish or defend legal claims.

14.1 Customer HRMS Data

If your data was submitted by your employer, prospective employer or another EmplifyAI customer, contact that organisation first using its HR or privacy channel. We will route a request received directly by us to the relevant customer and assist it under the DPA. We will not change an employer-controlled record without its instruction unless required by law.

14.2 Data we control directly

For website, prospect, billing-contact, marketing and other data for which Skyrocket determines the purpose, submit a request to [privacy/grievance email to be confirmed]. We may verify your identity and authority, ask for information needed to locate records and maintain an audit record of the request. We will respond within the period required by applicable law.

15. Marketing communications

We may send business-to-business product information, event invitations or related communications where permitted. You can unsubscribe through the link in an email or contact us. Service, security, billing and legal notices are not marketing and may still be sent while relevant to an account or relationship. We do not use Customer HRMS Data to market third-party products to employees.

16. Children and dependant information

Our public website and direct account-registration processes are not intended for children. EmplifyAI may nevertheless process information about an employee's child, dependant, nominee or beneficiary when a customer lawfully uses an HR, benefits, insurance, payroll or statutory module. In that context, the customer is responsible for establishing the permitted purpose, giving required notice and obtaining verifiable parental consent where applicable; we process the information on the customer's instructions.

17. Third-party links and customer-enabled services

The website and Services may link to or integrate with services that we do not control. A customer's or user's direct relationship with such a third party is governed by that party's privacy notice and terms. Review those documents before enabling an integration or providing personal data. This does not reduce our responsibility for subprocessors we appoint to perform EmplifyAI obligations.

18. Changes to this Policy

We may update this Policy to reflect changes in law, products, vendors or practices. The current version and effective date will be posted on the EmplifyAI website. If a change materially affects how we use personal data, we will provide reasonable advance notice through email, the Services or a prominent website notice and obtain fresh consent where legally required.

19. Contact and grievance redressal

For privacy questions, rights requests or grievances concerning data for which Skyrocket is responsible, contact:

Contact itemDetail
EntitySkyrocket Ventures LLP
ProductEmplifyAI HRMS
Privacy / grievance emailprivacy@skyrocetventures.in
Product supportsupport@emplifyai.com (support requests, not the primary privacy-rights channel)
Agreement queriesprivacy@skyrocketventures.in (user-agreement queries only)

If your request concerns employer-controlled Customer HRMS Data, include the employer or customer organisation name so we can route it correctly. You may escalate an unresolved grievance to the authority or forum available under applicable law after first using our grievance process.