1Overview
PrimeHR (operated by Techstuff Pvt Ltd, Indore, India) takes data protection seriously. This page explains how GDPR applies to our platform and what rights EEA data subjects have when their data is processed through PrimeHR.
The GDPR applies to PrimeHR when:
- We provide services to an organisation based in the EEA
- EEA residents' personal data (e.g., employees working remotely in Europe) is processed through our platform
- We monitor the behaviour of individuals in the EEA
2Data Controller vs Processor
Under GDPR, the roles are clearly defined:
Your Organisation · Data Controller
The subscribing organisation (your company) determines why and how employee personal data is collected and used. Your organisation is the Data Controller responsible for obtaining valid legal bases and employee consents.
PrimeHR · Data Processor
PrimeHR processes personal data only on your instructions and only to the extent necessary to provide the platform services. We do not use Customer Data for our own purposes beyond what is agreed in our Data Processing Agreement (DPA).
For data collected directly through our marketing website (contact forms, newsletter sign-ups), PrimeHR acts as the Data Controller.
3Lawful Basis for Processing
Under GDPR Article 6, we rely on the following lawful bases:
| Processing Activity | Lawful Basis | Article |
|---|---|---|
| Providing platform services (payroll, attendance, etc.) | Contract performance | Art. 6(1)(b) |
| Statutory filing (PF, ESI, TDS) | Legal obligation | Art. 6(1)(c) |
| Security monitoring, fraud prevention | Legitimate interests | Art. 6(1)(f) |
| Marketing emails & newsletters | Consent | Art. 6(1)(a) |
| Product analytics (anonymised) | Legitimate interests | Art. 6(1)(f) |
For special categories of data (e.g., health-related leave, disability accommodations), we rely on Art. 9(2)(b) · processing necessary for employment law obligations.
4Your GDPR Rights
EEA data subjects have the following rights under GDPR Chapter III:
Right to Access
Obtain a copy of your personal data we hold and how it is used.
Right to Rectification
Request correction of inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your personal data ("right to be forgotten").
Right to Restrict
Limit how we process your data in certain circumstances.
Right to Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests or direct marketing.
Automated Decisions
Not be subject to solely automated decisions with significant effect.
Withdraw Consent
Withdraw consent at any time without affecting prior processing.
5Data Subject Requests
To exercise any of the rights listed above:
- Employee data · Contact your HR administrator first, as they are the Data Controller for your employment records
- Website / marketing data · Email support@primehr.in with subject line "GDPR Data Subject Request"
We will:
- Acknowledge your request within 5 business days
- Verify your identity before processing the request
- Respond within 30 calendar days (extendable by 60 days for complex requests, with notice)
- Respond free of charge for reasonable requests
6Data Transfers Outside the EEA
India is not yet recognised by the European Commission as providing an adequate level of data protection (adequacy decision pending). For EEA customers, we ensure lawful transfer mechanisms are in place:
- Standard Contractual Clauses (SCCs) · EU Commission-approved SCCs (2021 version) are incorporated into our DPA for all EEA customers
- Technical & organisational measures · AES-256 encryption, access controls, and VPC isolation supplement the SCCs
- Transfer Impact Assessment (TIA) · available to EEA enterprise customers upon request
All data is stored on AWS ap-south-1 (Mumbai). EEA data is not replicated to other regions.
7Data Retention
We retain personal data only as long as necessary for the purpose it was collected:
- Active subscription data · retained for the duration of the subscription
- Post-cancellation · 90-day grace period for data export; then securely deleted
- Payroll & statutory records · 7 years under Indian law (or applicable EEA member state law)
- Marketing consent records · retained until consent is withdrawn + 1 year
- Security & access logs · 12 months
Upon expiry, data is deleted or anonymised using industry-standard methods.
8Data Processing Agreement (DPA)
As required by GDPR Article 28, PrimeHR provides a Data Processing Agreement to all customers processing EEA personal data through our platform. The DPA covers:
- Subject matter, duration, and nature of processing
- Categories of personal data and data subjects
- Obligations and rights of the controller
- Sub-processor authorisation and management
- Security obligations (Article 32)
- Breach notification obligations (Article 33/34)
- Assistance with data subject rights
- Standard Contractual Clauses for international transfers
Request a DPA
EEA customers can request our standard DPA by emailing support@primehr.in with subject "DPA Request". We will respond within 5 business days. Enterprise customers may negotiate custom DPA terms.
9Security Measures (Art. 32)
In accordance with GDPR Article 32, we implement appropriate technical and organisational measures:
- Pseudonymisation & encryption · AES-256 at rest, TLS 1.3 in transit, field-level encryption for sensitive fields
- Confidentiality & integrity · VPC isolation, strict RBAC, audit logging
- Availability & resilience · Multi-AZ deployments, daily backups, RTO < 4h, RPO < 1h
- Regular testing · Annual penetration tests, quarterly vulnerability scans, automated SAST on every build
Full details are available on our Security page.
10Breach Notification
In the event of a personal data breach affecting EEA data subjects, PrimeHR will:
- Notify the affected Data Controller (your organisation) within 48 hours of becoming aware of the breach · providing sufficient information for you to meet your 72-hour supervisory authority notification obligation under GDPR Art. 33
- Provide a detailed incident report including: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed
- Cooperate fully with your investigation and any supervisory authority inquiry
11Sub-processors
We use the following sub-processors to deliver our services. All are bound by GDPR-compliant data processing agreements:
| Sub-processor | Purpose | Location | Transfer Mechanism |
|---|---|---|---|
| Amazon Web Services | Cloud infrastructure & storage | India (ap-south-1) | Standard Contractual Clauses |
| Razorpay | Payment processing | India | Indian data only |
| SendGrid (Twilio) | Transactional email delivery | USA | Standard Contractual Clauses |
| Google Workspace | Internal communication & docs | USA | Standard Contractual Clauses |
| AWS CloudWatch | Monitoring & logging | India (ap-south-1) | Standard Contractual Clauses |
We will notify you of any intended changes to sub-processors (additions or replacements) with at least 14 days' notice, giving you the opportunity to object.
12Contact & DPO
For any GDPR-related enquiries, Data Subject Requests, or DPA requests:
- Email: support@primehr.in · subject line "GDPR Enquiry"
- Postal: Techstuff Pvt Ltd, Indore, Madhya Pradesh, India
- Response time: 5 business days for acknowledgement; 30 days for resolution
Need a DPA or have a GDPR question?
Our team responds within 5 business days for all GDPR-related requests.