PRIVACY POLICY

HRMates Platform — operated by SysMates

Version

1.0

Effective Date

August 22, 2026

 

1. Introduction

Welcome to HRMates (“HRMates”, “the Platform”), an HRMS and workforce management platform operated by SysMates Technologies (Partnership Firm), Reg. No.- 06-018-2024-00033 and registered address at Vatika Business Center, 2nd Floor, First India Place, M.G. Road, Gurgaon-122002, Haryana (“SysMates”, “we”, “our”, “us”). This Privacy Policy explains how personal data is collected, used, disclosed and protected in connection with the HRMates website, mobile applications and related services (collectively, the “Services”), in accordance with the Digital Personal Data Protection Act, 2023 (“the Act”) and the Digital Personal Data Protection Rules, 2025 (“the DPDP Rules”).

This notice is available in English: -YES

Please read this Privacy Policy carefully. If you do not agree with its terms, please do not access or use the Services.

2. Roles of SysMates Under This Policy

2.1 As Data Processor (Customer HR Personal Data)

Where a customer uses HRMates to process personal data of its employees, applicants, contractors or other individuals (“Customer HR Personal Data”), the Customer acts as the Data Fiduciary and determines the purpose and means of such processing. SysMates, as operator of HRMates, acts as the Data Processor and processes Customer HR Personal Data only on the Customer’s documented instructions, the applicable agreement between SysMates and the Customer, and applicable law.

3. Purpose and Scope of Processing (Data Processor Role)

SysMates shall process Customer HR Personal Data only for the purposes of providing, maintaining, securing and supporting the HRMates Services, and for other purposes expressly authorised or instructed by the Customer under the applicable agreement. SysMates shall not use Customer HR Personal Data for any independent purpose unrelated to the Customer’s instructions or the provision of the contracted Services.

4. Customer Responsibilities

For Customer HR Personal Data, the Customer is responsible for determining the applicable lawful basis for processing, providing the required notice to Data Principals, and obtaining consent where consent is the applicable basis. SysMates shall process such personal data strictly in accordance with the Customer’s documented instructions and the applicable agreement.

5. Personal Data We Collect

5.1 Data Provided Directly to SysMates

       Personal Identification Information: name, email address, phone number, job title, company name, and billing/payment information, when you register for an account, request a demo, or contact support.

       Technical and Usage Data: IP address, browser type, operating system, device information, pages visited, time spent on pages, and analytical data regarding how you navigate and interact with the Platform.

       Cookies and Tracking Technologies: SysMates uses cookies, web beacons and similar technologies to track activity on the website and improve user experience.

5.2 Data Provided by a Customer (Customer HR Personal Data)

Depending on the HRMates modules and functionality enabled by the Customer, personal data processed may include: identification and profile information; contact information; employment and professional information; attendance and leave information; payroll and compensation information; performance and expense information; location or field-visit information (where enabled); and other information configured by the Customer for legitimate HR and workforce-management purposes.

6. How We Use Personal Data

       Providing and Managing the Services: operating the HRMS platform, processing payroll integrations, managing leave and attendance, and fulfilling customer support requests.

       Account Administration: managing user accounts, setting up profiles, and authenticating logins.

       Improving Our Platform: SysMates may process technical, diagnostic and service-usage information generated through operation of HRMates for maintaining, securing, troubleshooting and improving the Services. Customer HR Personal Data shall not be used for any independent purpose unrelated to the Customer’s instructions or the contracted Services.

       Communications: sending administrative emails, updates, security alerts, and — with consent, where required — marketing or promotional materials.

       Legal Compliance: complying with applicable laws, legal process, and regulatory requirements.

7. Legal Basis, Consent and Withdrawal

Where consent is the applicable basis for processing, a Data Principal may withdraw consent through the mechanism provided by the Customer, with the ease of withdrawal comparable to the ease with which consent was given. On receiving an instruction from the Customer following withdrawal of consent, SysMates shall cease the relevant processing within a reasonable time, unless continued processing is required or authorised under applicable law.

8. How We Share Personal Data

SysMates does not sell, trade, or rent personal data to third parties. Personal data may be shared only in the following circumstances:

       With Employers / Administrators: if you are an employee using HRMates, your organisation’s designated administrators have access to the HR data associated with your profile (such as attendance, payroll and leave records).

       Sub-processors: SysMates may engage hosting, infrastructure, security, communications, support or other service providers as sub-processors, where authorised under the applicable Customer agreement. Such sub-processors shall process Customer HR Personal Data only for authorised purposes and shall be subject to appropriate confidentiality, security and data protection obligations. [Refer- SysMates - Subprocessor & Security Assessment Register]

       Legal Obligations: SysMates may disclose personal data where required by law or in response to valid requests by public authorities (e.g., a court or government agency).

9. Cross-Border Transfer of Personal Data

All Customer HR Personal Data and SysMates proprietary data are stored and processed exclusively within India, with no cross-border data transfers or processing in territories restricted under Section 16 of the Digital Personal Data Protection Act.

10. Data Security

SysMates implements reasonable technical and organisational security safeguards appropriate to the nature of personal data processed through HRMates, including, as applicable: encryption or other appropriate protection of personal data; access controls and restricted privileged access; authentication controls; logging and monitoring of access; security testing and monitoring; backup and recovery measures; vulnerability management; and confidentiality obligations for personnel and service providers with access to personal data.

11. Personal Data Breach Notification

Where SysMates becomes aware of a personal data breach affecting Customer HR Personal Data, SysMates shall notify the affected Customer without undue delay, and shall provide reasonably available information regarding the nature and extent of the breach to enable the Customer to meet its own notification obligations to the Data Protection Board of India and affected Data Principals under the Act and the DPDP Rules.

SysMates commits to notifying the Customer of any security or data incident within 72 hours of becoming aware of the event.

12. Data Retention

SysMates shall retain Customer HR Personal Data only for the period necessary to provide the HRMates Services or as instructed by the Customer, subject to applicable contractual, legal and regulatory retention requirements. On expiry or termination of the Customer relationship, or receipt of a valid deletion instruction, SysMates shall delete or return Customer HR Personal Data in accordance with the applicable agreement, except where retention is required by applicable law. Personal data in backup systems may remain until securely overwritten or purged in accordance with the applicable backup lifecycle, and shall remain protected during that period.

13. Rights of Data Principals

Data Principals have the following rights under the Digital Personal Data Protection Act, 2023:

       Right to Access Information: request information regarding personal data being processed and the processing activities undertaken, as provided under applicable law.

       Right to Correction, Completion and Updating: request correction of inaccurate or misleading personal data, completion of incomplete personal data, or updating of personal data.

       Right to Erasure: request erasure of personal data where it is no longer necessary for the purpose for which it was processed, subject to applicable legal and retention requirements.

       Right to Grievance Redressal: raise a grievance regarding the processing of personal data through the grievance redressal mechanism of the applicable Data Fiduciary.

       Right to Nominate: nominate one or more individuals to exercise these rights in the event of death or incapacity, in accordance with the Act and applicable rules.

       Right to Withdraw Consent: where consent is the applicable basis for processing, withdraw consent through the mechanism provided by the applicable Data Fiduciary. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and is subject to continued processing permitted or required under applicable law.

Where SysMates processes personal data as a Data Processor on behalf of a customer, requests relating to the above rights should ordinarily be submitted to the relevant Customer (Data Fiduciary) through the mechanism specified by that Customer. SysMates shall provide reasonable assistance to the Customer in responding to such requests, in accordance with the applicable agreement and applicable law.

14. Grievance Redressal

Where SysMates processes personal data on behalf of a Customer, Data Principals may submit privacy-related grievances to the relevant Customer (Data Fiduciary) through the mechanism provided by the Customer. SysMates shall provide reasonable assistance to the Customer in investigating and resolving such grievances.

For processing activities where SysMates acts as a Data Fiduciary, grievances may be submitted to the privacy contact identified in Section 17 and shall be acknowledged and resolved within the timelines specified in the HRMates SaaS SLA document. (Refer - HRMates_SaaS_SLA)

15. Children’s and Dependents’ Personal Data

HRMates is primarily designed for business and workforce management and is not directed at children. Where a Customer instructs SysMates to process personal data relating to a child — including dependent, nominee, or family information submitted for HR or benefits administration purposes — such processing shall be undertaken only in accordance with the Customer’s instructions and applicable legal requirements relating to children’s personal data, including verifiable parental/guardian consent obligations under Section 9 of the Act, which remain the Customer’s responsibility as Data Fiduciary.

The collection of children’s personal data (such as name, age, email, and mobile number) is optional, client-driven, and strictly limited to specific purposes like insurance and events in compliance with applicable consent requirements.

16. Changes to This Privacy Policy

SysMates may update this Privacy Policy from time to time. Any changes will be notified by posting the revised Privacy Policy on this page and updating the “Last Updated” date. Please review this Privacy Policy periodically.

17. Contact Us

For questions regarding Customer HR Personal Data processed by SysMates on behalf of a customer, please contact the relevant customer (Data Fiduciary).

For questions concerning SysMates’ own processing activities, or SysMates’ role as a Data Processor, please contact:

       Data Protection Officer / Grievance Officer: Amrita Singh, E Mail ID: singh.amrita@sysmates.com

       Website: https://hrmates.com

       Email: info@hrmates.com

       Address: 2nd Floor, First India Place, M G Road, Gurgaon, Haryana 122002, India