D'CoreHR Privacy Policy

D'Bugged Programmers

Last Updated: 5 October 2026  |  Effective Date: 5 October 2026

1. Scope of This Privacy Policy

D'Bugged Programmers, operating D'CoreHR ("D'CoreHR", "we", "us", or "our"), respects the privacy of individuals and is committed to protecting personal data processed through the D'CoreHR platform.

D'CoreHR is a cloud-based Human Resources Management System that enables organizations to manage employee information, attendance, leave, payroll, statutory compliance, documents, reimbursements, assets, reports, and related HR processes.

This Privacy Policy explains how personal data is collected, used, stored, disclosed, and otherwise processed when you use D'CoreHR.

2. Our Role and the Customer's Role

D'CoreHR is primarily a technology platform provider. When an organization subscribes to D'CoreHR and uploads or otherwise provides employee information to the platform, the customer organization determines the purposes for which that employee information is processed.

  • The customer organization may act as the relevant Data Fiduciary/controller for employee data.
  • D'CoreHR may process that information on behalf of the customer as its service provider/data processor.
  • D'CoreHR may independently act as a Data Fiduciary/controller for certain information relating to its own customers, users, website visitors, billing contacts, support contacts, and marketing activities.

The customer organization remains responsible for ensuring that it has an appropriate legal basis and required permissions/authorizations to provide employee or other personal data to D'CoreHR.

3. Personal Data We May Process

Identity Information

  • Full name
  • Employee ID
  • Date of birth
  • Gender, where configured
  • Photograph
  • Nationality, where required
  • Signature, where uploaded

Contact Information

  • Personal email address
  • Official email address
  • Mobile number
  • Residential address
  • Emergency contact information

Employment Information

  • Job title
  • Department
  • Designation
  • Reporting manager
  • Date of joining
  • Employment type
  • Employee status
  • Work location
  • Probation information
  • Confirmation information
  • Notice period
  • Separation information
  • Employee lifecycle records

Attendance and Leave Information

  • Attendance records
  • Check-in/check-out information
  • Attendance corrections
  • Leave applications
  • Leave balances
  • Leave history
  • Holidays
  • Comp-off
  • Work-from-home information
  • LOP information
  • Geo-location information where enabled

Payroll and Compensation Information

  • Salary
  • Salary structure
  • Salary components
  • Salary revisions
  • Allowances
  • Deductions
  • Bonuses
  • Incentives
  • Reimbursements
  • Loans
  • Advances
  • Payroll records
  • Payslips
  • Full & Final Settlement information

Statutory and Tax Information

  • PAN
  • Tax declarations
  • Tax regime selection
  • TDS information
  • Previous-employer income and TDS information
  • PF information
  • ESI information
  • Professional Tax information
  • Labour Welfare Fund information
  • Gratuity information
  • Other information required to administer applicable employment/payroll obligations

Banking Information

  • Bank name
  • Account number
  • IFSC
  • Account holder name
  • Cancelled cheque or related banking documentation

Employee Documents

  • Identity documents
  • Address documents
  • Educational documents
  • Previous employment documents
  • Joining documents
  • Employment agreements
  • Statutory documents
  • Bank documents
  • Other HR-related documents

Asset Information

  • Asset assigned to an employee
  • Asset identifier
  • Assignment history
  • Warranty information
  • Maintenance records
  • Related documentation

Technical Information

  • IP address
  • Browser type
  • Device information
  • Operating system
  • Application version
  • Login information
  • Authentication information
  • Access timestamps
  • Error logs
  • Security logs
  • Audit logs

4. Purposes for Processing Personal Data

  • Employee management and onboarding
  • Attendance management
  • Leave management
  • Payroll processing and salary administration
  • Tax calculation and TDS processing
  • Statutory payroll processing
  • Reimbursements, loans and advances
  • Full & Final Settlement
  • Employee document and asset management
  • HR reporting and employee self-service
  • Manager approvals and workflow processing
  • Audit and compliance
  • Security monitoring, fraud and abuse prevention
  • Troubleshooting and customer support
  • System maintenance, backups and disaster recovery
  • Product improvement
  • Integration with customer-authorized systems

Where D'CoreHR processes information on behalf of a customer, processing will generally be performed according to the customer's instructions and applicable contractual arrangements.

5. Legal Basis for Processing

  • Consent
  • Compliance with applicable legal obligations
  • Performance of a contract
  • Legitimate business purposes where legally applicable
  • Other lawful grounds permitted under applicable law

Where consent is used as the basis for processing, consent should be appropriately obtained and may be withdrawn in accordance with applicable law.

6. Employee Data Submitted by Customers

D'CoreHR customers may upload employee information into the platform. The customer is responsible for providing appropriate notices, obtaining required consent where applicable, ensuring an appropriate legal basis, providing accurate information, configuring appropriate access permissions, managing employee access rights, ensuring uploaded documents are appropriate for the intended purpose, and complying with applicable employment, tax, labour, privacy and data-protection requirements.

D'CoreHR does not independently determine the employment purposes for which a customer uploads employee information.

7. How We Use Customer Data

  • Provide D'CoreHR services
  • Maintain customer accounts
  • Authenticate users
  • Provide customer support
  • Maintain system security
  • Detect and prevent abuse
  • Perform backups
  • Maintain system reliability
  • Diagnose technical problems
  • Perform authorized integrations
  • Meet contractual and legal obligations
  • Improve reliability and functionality of the platform

We do not sell customer employee data as a commercial product.

8. Data Sharing and Disclosure

D'CoreHR may disclose or provide access to personal data where appropriate for legitimate business, contractual, legal, security, or service-delivery purposes.

Customer Organization

Employee information may be accessible to authorized personnel of the customer according to the customer's configuration and role-based access controls.

Service Providers

We may use carefully selected third-party service providers for cloud infrastructure, hosting, database infrastructure, backup, email, SMS, push notifications, authentication, monitoring, security, analytics, customer support, payment processing, and other services necessary to operate D'CoreHR.

Legal and Regulatory Authorities

We may disclose information where required or permitted by applicable law, legal process, court order, regulatory requirement, or governmental request.

Security and Protection

Information may be disclosed where reasonably necessary to investigate or prevent fraud, security incidents, unauthorized access, abuse, illegal activity, or threats to individuals or systems.

9. Third-Party Integrations

D'CoreHR may integrate with third-party services such as biometric attendance systems, accounting systems, ERP systems, communication platforms, banking/payment systems, identity services, or other customer-authorized applications.

The information exchanged through an integration will depend on the integration and the customer's configuration. Customers should review the privacy practices of third-party services before enabling integrations.

10. Data Security

We implement reasonable technical and organizational safeguards designed to protect personal data against unauthorized access, disclosure, modification, loss, destruction, and misuse.

  • Encryption in transit
  • Encryption at rest where supported
  • Role-based access control
  • Authentication controls
  • Password security
  • Access logging
  • Audit trails
  • Tenant isolation
  • Database access controls
  • Backup mechanisms
  • Monitoring
  • Vulnerability management
  • Security testing
  • Incident response procedures

However, no internet-based system can guarantee absolute security.

11. Role-Based Access

D'CoreHR uses role-based access controls to restrict access to information according to user permissions. Depending on configuration, roles may include Super Admin, Admin, HR, Manager, and Employee.

Customers are responsible for assigning appropriate permissions and promptly disabling accounts when users no longer require access.

12. Tenant Isolation

D'CoreHR is designed as a multi-tenant platform. Customer data is logically separated between customer organizations. Users should only be able to access information belonging to their organization and according to their assigned permissions.

13. Data Retention

We retain personal data only for as long as reasonably necessary for providing services, meeting contractual obligations, meeting applicable legal or regulatory requirements, maintaining accounting and financial records, resolving disputes, preventing fraud and abuse, maintaining security, and enforcing contractual rights.

Retention periods may differ depending on the type of data, customer instructions, applicable law, contractual requirements, and regulatory obligations.

At the end of the applicable retention period, data may be deleted, anonymized, or otherwise securely disposed of, subject to applicable legal and contractual requirements.

14. Customer-Controlled Data

For employee information submitted by a customer, the customer generally controls what information is entered, which employees are added, which users can access the information, how information is used within the organization, how long the customer requires the information to be retained, and when information should be deleted, subject to applicable law and contractual obligations.

Customers may contact D'CoreHR regarding data export, deletion, or other account-level data requests.

15. Data Principal / Individual Rights

  • Access information
  • Request correction of inaccurate information
  • Request deletion where applicable
  • Withdraw consent where consent is the basis of processing
  • Obtain information regarding processing
  • Raise grievances
  • Exercise other rights provided under applicable law

For employee data processed on behalf of a customer's organization, individuals should generally first contact their employer/HR department because the customer determines the employment-related processing.

16. Consent Withdrawal

Where processing is based on consent, an individual may withdraw consent in accordance with applicable law. Withdrawal does not invalidate processing lawfully performed before withdrawal. Certain information may continue to be processed where required or permitted by applicable law or where another lawful basis applies.

17. Grievance Redressal

Privacy / Grievance Contact

D'Bugged Programmers

Address
602, 9th Floor, The Platina Building, Tanvi Complex,S. V. Road, Near Petrol Pump, Dahisar East,Mumbai, Maharashtra – 400068, India

For employee data processed on behalf of a customer organization, we may direct the request to the relevant customer organization where appropriate.

18. Data Breach and Security Incidents

We maintain procedures designed to detect, investigate, respond to, and mitigate security incidents involving personal data. Where applicable, we will provide notifications to affected customers, individuals, or regulatory authorities in accordance with applicable law and contractual obligations.

Customers are responsible for promptly notifying D'CoreHR of suspected unauthorized access or security incidents involving their D'CoreHR account.

19. Cookies and Similar Technologies

Our website and applications may use cookies and similar technologies for authentication, session management, security, preferences, performance, analytics, and improving user experience. Where required, users will be provided appropriate choices regarding cookies and similar technologies.

20. Children's Data

D'CoreHR is an enterprise HRMS and is not intended to be used as a service directly targeted at children. Customers should not enter children's personal data into D'CoreHR unless such processing is necessary, lawful, and appropriately authorized.

21. International Data Transfers

Depending on infrastructure, customer configuration, third-party service providers, and applicable contractual arrangements, personal data may be processed or stored in India or other jurisdictions. Where personal data is transferred outside India, we will apply appropriate safeguards and comply with applicable legal requirements.

Customers with specific data-residency requirements should discuss those requirements with D'CoreHR before entering into a subscription or enabling relevant services.

22. Automated Processing and AI

D'CoreHR may provide features that use automation, analytics, machine learning, or artificial intelligence. Where such functionality processes personal data, it will be used for defined purposes, access will be controlled, appropriate safeguards will be applied, and customer data will not automatically be used for unrelated purposes.

Any specific AI training, analytics, or model-use practices should be addressed in the applicable product terms, customer agreement, or data-processing agreement.

23. Marketing Communications

Where permitted by law, D'CoreHR may send communications relating to product updates, service announcements, security notifications, account information, product education, and marketing.

Users may opt out of non-essential marketing communications. Transactional and security-related communications may continue where necessary.

24. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes to D'CoreHR, applicable law, data-processing practices, new features, security improvements, or regulatory requirements.

The updated policy will be published with a revised Last Updated date. Where legally required, we will provide additional notice regarding material changes.

25. Contact Us

D'Bugged Programmers

D'CoreHR

Address
602, 9th Floor, The Platina Building, Tanvi Complex,S. V. Road, Near Petrol Pump, Dahisar East,Mumbai, Maharashtra – 400068, India