DPDP Act Compliance
Last updated: May 28, 2026
NityaHR is designed to help customers comply with India's Digital Personal Data Protection Act, 2023 (DPDP Act).
Our role
We are a Data Processor. Your employer (Data Fiduciary) controls the purpose and means of processing.
Built-in controls
1. Lawful basis & consent
- Mandatory features (payroll, attendance) rest on the employment contract.
- Optional features (face recognition, AI helpers) are opt-in per-company AND per-user.
- Consent records are timestamped + IP-logged.
2. Data minimisation
- Mobile API only returns fields the app needs.
- AI prompts are PII-redacted before transmission.
- Audit logs store redacted payloads.
3. Encryption
- In transit: TLS 1.2+ everywhere.
- At rest: PAN / Aadhaar / UAN / bank / face embeddings / 2FA secrets all encrypted.
- Backups: password-encrypted archives.
4. Data-subject rights
- Access: My Account → Request my data.
- Correction: via HR.
- Erasure: post-exit, subject to statutory retention.
- Withdraw consent: per-feature toggles.
5. Breach notification
72-hour notification to affected Customers.
Contact
DPDP queries, data-subject requests, DPO correspondence: hello@nityahr.com
Questions about this page? Email hello@nityahr.com