Legal

GDPR Compliance

PrimeHR's commitment to the EU General Data Protection Regulation · your rights, our obligations, and how we protect European data subjects.

Last updated: 15 May 2026 · Regulation (EU) 2016/679
The General Data Protection Regulation (GDPR) is EU Regulation 2016/679, which provides rights to individuals in the European Economic Area (EEA) over their personal data. Although PrimeHR is primarily an India-focused platform, we are committed to GDPR compliance for any EEA customers or employees whose data we process.

1Overview

PrimeHR (operated by Techstuff Pvt Ltd, Indore, India) takes data protection seriously. This page explains how GDPR applies to our platform and what rights EEA data subjects have when their data is processed through PrimeHR.

The GDPR applies to PrimeHR when:

  • We provide services to an organisation based in the EEA
  • EEA residents' personal data (e.g., employees working remotely in Europe) is processed through our platform
  • We monitor the behaviour of individuals in the EEA
For non-EEA customers (the majority of our user base in India), our Privacy Policyand India's Digital Personal Data Protection Act 2023 (DPDP Act) apply.

2Data Controller vs Processor

Under GDPR, the roles are clearly defined:

Your Organisation · Data Controller

The subscribing organisation (your company) determines why and how employee personal data is collected and used. Your organisation is the Data Controller responsible for obtaining valid legal bases and employee consents.

PrimeHR · Data Processor

PrimeHR processes personal data only on your instructions and only to the extent necessary to provide the platform services. We do not use Customer Data for our own purposes beyond what is agreed in our Data Processing Agreement (DPA).

For data collected directly through our marketing website (contact forms, newsletter sign-ups), PrimeHR acts as the Data Controller.

3Lawful Basis for Processing

Under GDPR Article 6, we rely on the following lawful bases:

Processing ActivityLawful BasisArticle
Providing platform services (payroll, attendance, etc.)Contract performanceArt. 6(1)(b)
Statutory filing (PF, ESI, TDS)Legal obligationArt. 6(1)(c)
Security monitoring, fraud preventionLegitimate interestsArt. 6(1)(f)
Marketing emails & newslettersConsentArt. 6(1)(a)
Product analytics (anonymised)Legitimate interestsArt. 6(1)(f)

For special categories of data (e.g., health-related leave, disability accommodations), we rely on Art. 9(2)(b) · processing necessary for employment law obligations.

4Your GDPR Rights

EEA data subjects have the following rights under GDPR Chapter III:

Right to Access

Obtain a copy of your personal data we hold and how it is used.

Right to Rectification

Request correction of inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data ("right to be forgotten").

Right to Restrict

Limit how we process your data in certain circumstances.

Right to Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests or direct marketing.

Automated Decisions

Not be subject to solely automated decisions with significant effect.

Withdraw Consent

Withdraw consent at any time without affecting prior processing.

5Data Subject Requests

To exercise any of the rights listed above:

  • Employee data · Contact your HR administrator first, as they are the Data Controller for your employment records
  • Website / marketing data · Email support@primehr.in with subject line "GDPR Data Subject Request"

We will:

  • Acknowledge your request within 5 business days
  • Verify your identity before processing the request
  • Respond within 30 calendar days (extendable by 60 days for complex requests, with notice)
  • Respond free of charge for reasonable requests
We may refuse or charge a reasonable fee for requests that are manifestly unfounded or excessive, in line with GDPR Article 12(5).

6Data Transfers Outside the EEA

India is not yet recognised by the European Commission as providing an adequate level of data protection (adequacy decision pending). For EEA customers, we ensure lawful transfer mechanisms are in place:

  • Standard Contractual Clauses (SCCs) · EU Commission-approved SCCs (2021 version) are incorporated into our DPA for all EEA customers
  • Technical & organisational measures · AES-256 encryption, access controls, and VPC isolation supplement the SCCs
  • Transfer Impact Assessment (TIA) · available to EEA enterprise customers upon request

All data is stored on AWS ap-south-1 (Mumbai). EEA data is not replicated to other regions.

7Data Retention

We retain personal data only as long as necessary for the purpose it was collected:

  • Active subscription data · retained for the duration of the subscription
  • Post-cancellation · 90-day grace period for data export; then securely deleted
  • Payroll & statutory records · 7 years under Indian law (or applicable EEA member state law)
  • Marketing consent records · retained until consent is withdrawn + 1 year
  • Security & access logs · 12 months

Upon expiry, data is deleted or anonymised using industry-standard methods.

8Data Processing Agreement (DPA)

As required by GDPR Article 28, PrimeHR provides a Data Processing Agreement to all customers processing EEA personal data through our platform. The DPA covers:

  • Subject matter, duration, and nature of processing
  • Categories of personal data and data subjects
  • Obligations and rights of the controller
  • Sub-processor authorisation and management
  • Security obligations (Article 32)
  • Breach notification obligations (Article 33/34)
  • Assistance with data subject rights
  • Standard Contractual Clauses for international transfers

Request a DPA

EEA customers can request our standard DPA by emailing support@primehr.in with subject "DPA Request". We will respond within 5 business days. Enterprise customers may negotiate custom DPA terms.

9Security Measures (Art. 32)

In accordance with GDPR Article 32, we implement appropriate technical and organisational measures:

  • Pseudonymisation & encryption · AES-256 at rest, TLS 1.3 in transit, field-level encryption for sensitive fields
  • Confidentiality & integrity · VPC isolation, strict RBAC, audit logging
  • Availability & resilience · Multi-AZ deployments, daily backups, RTO < 4h, RPO < 1h
  • Regular testing · Annual penetration tests, quarterly vulnerability scans, automated SAST on every build

Full details are available on our Security page.

10Breach Notification

In the event of a personal data breach affecting EEA data subjects, PrimeHR will:

  • Notify the affected Data Controller (your organisation) within 48 hours of becoming aware of the breach · providing sufficient information for you to meet your 72-hour supervisory authority notification obligation under GDPR Art. 33
  • Provide a detailed incident report including: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed
  • Cooperate fully with your investigation and any supervisory authority inquiry
Our 48-hour controller notification gives you ample time to meet the GDPR Art. 33 72-hour supervisory authority deadline.

11Sub-processors

We use the following sub-processors to deliver our services. All are bound by GDPR-compliant data processing agreements:

Sub-processorPurposeLocationTransfer Mechanism
Amazon Web ServicesCloud infrastructure & storageIndia (ap-south-1)Standard Contractual Clauses
RazorpayPayment processingIndiaIndian data only
SendGrid (Twilio)Transactional email deliveryUSAStandard Contractual Clauses
Google WorkspaceInternal communication & docsUSAStandard Contractual Clauses
AWS CloudWatchMonitoring & loggingIndia (ap-south-1)Standard Contractual Clauses

We will notify you of any intended changes to sub-processors (additions or replacements) with at least 14 days' notice, giving you the opportunity to object.

12Contact & DPO

For any GDPR-related enquiries, Data Subject Requests, or DPA requests:

  • Email: support@primehr.in · subject line "GDPR Enquiry"
  • Postal: Techstuff Pvt Ltd, Indore, Madhya Pradesh, India
  • Response time: 5 business days for acknowledgement; 30 days for resolution
Supervisory Authority: If you believe we have not handled your data lawfully, you have the right to lodge a complaint with your local EEA supervisory authority (e.g., ICO in the UK, CNIL in France, BfDI in Germany). We would, however, appreciate the opportunity to address your concerns first.

Need a DPA or have a GDPR question?

Our team responds within 5 business days for all GDPR-related requests.