Skip to content
Request an invite
Request an invite

Security · how employee data is protected

What we don't write down, and how we guard what we do.

LekhaHR holds people's records, pay and attendance. This page lists the data we never collect and how we protect what we hold.

Data LekhaHR never collects

What we don't write down

the data LekhaHR never collects

  1. Location between punches

    Location is read once, when a person punches in or out, and checked against the office geofence.

    Status: Never collected

  2. Travel routes and location history

    No trail is built from one punch to the next.

    Status: Never collected

  3. Face or fingerprint templates

    Attendance does not use face recognition or biometric matching.

    Status: Never collected

No. 01

Isolation and access


because every request is checked before any data is read.

How is one company's employee data kept apart from another's?

Every request is checked on the server against the signed-in person's company, role and reach before any data is read. Roles see only the modules and people they are given, and changes such as approvals and manual corrections are written to an audit log with who made them and when.

  1. Every request is checked against the company and the role

    Before data is read, the signed-in person's company, role and reach (self, team or organisation) are checked on the server.

  2. Roles reach only what they are given

    A role is a set of modules and a reach. An office manager can run attendance and leave without seeing payroll.

  3. An audit log of changes

    Changes such as policy edits, manual corrections and approvals are written to an audit log with who made them and when.

No. 02

Privacy by design


because staff accept a check-in that records where they punched. They should not accept being followed.

Location at the punch. Private leave stays private.

Two rules that shape the product for every employee, whatever the employer's settings.

Location

attendance · every plan

Read at
the punch only

because the geofence check needs one reading, not a trail

Between punches
nothing

because LekhaHR does not track in the background

Protected leave

leave · every plan

Team calendar
On leave

because colleagues only need to know who is away

Type and documents
the person and HR roles you allow

because someone has to process it, and nobody else needs to know

Employee data is held for the purposes of employment, which the DPDP Act, 2023 treats as a legitimate use (s.7(i)). The employer does not need consent; a privacy notice is good practice. The Act's main duties apply from 13 May 2027. See the privacy policy. Location is read only when a person punches in or out; how punching from a phone works.

No. 03

Questions

Straight answers about employee data.

Is LekhaHR DPDP compliant?

We do not claim compliance as a status. Under the DPDP Act, 2023, an employer holds employee data as a legitimate use for employment (s.7(i)) and does not need consent; a privacy notice is good practice; the Act's main duties apply from 13 May 2027. Compliance also depends on how each company uses the product.

How is one company's data kept apart from another's?

Every request is checked on the server against the signed-in person's company and role before any data is read. Roles reach only the modules and people they are given, so an office manager can run attendance and leave without seeing payroll.

Who can see salary and bank details?

Only roles that are given payroll or those fields. Roles are least-privilege: a manager or an office manager sees the modules and people their role reaches, and nothing else.

How do I report a security issue or send a questionnaire?

Email hello@lekhahr.in with what you found or what you need answered. A person reads that inbox and replies.

No. 04 · By invitation

Ask us anything about where your data goes.

because we would rather answer a hard question now than after you have moved in.