Privacy Policy
Last updated: 13 September 2026
How Comhard Technologies Pvt Ltd collects, uses, protects and shares personal data in Comsky HRMS — written to align with India's Digital Personal Data Protection Act, 2023.
This document is a standard template provided for convenience. It is not legal advice and should be reviewed and adapted by qualified legal counsel before you rely on it.
1. Introduction & scope
Comhard Technologies Pvt Ltd (“Comhard”, “we”, “us”) operates Comsky HRMS, an India-first HR and payroll platform. This Privacy Policy explains how we collect, use, disclose, retain and protect personal data, and the rights available to individuals. It is designed to align with the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and other applicable Indian law.
This Policy applies to our marketing website, the Comsky HRMS application, and related services. It does not apply to third-party services that have their own privacy policies.
2. Our role: Data Fiduciary and Data Processor
Under the DPDP Act, our role depends on the data in question:
- Employee & workspace data. When a customer organisation uses Comsky HRMS to manage its employees, that organisation is the Data Fiduciary and decides why and how employee personal data is processed. Comhard acts as a Data Processor, processing that data only on the customer's documented instructions and to provide the Service. For questions about how a specific employer handles data, please contact that employer.
- Account, billing & website data. When we collect data directly — for example, from a person who signs up, contacts us, or visits our website — Comhard is the Data Fiduciary for that data, and this Policy governs our handling of it.
3. Personal data we collect
Depending on how you interact with us, we may process:
- Identity & contact data — name, work email, phone number, organisation and role.
- Account data — workspace and profile details, roles and permissions, and preferences. Sign-in itself is handled by Comsky Identity (account.comsky.in); we do not store your password.
- Employee & payroll data (as Processor) — data our customers upload about their workforce, which may include statutory identifiers such as PAN, UAN, ESIC and Aadhaar-related references, bank details, compensation, attendance and leave. Sensitive identifiers such as PAN and bank details are encrypted at rest.
- Usage & device data — log data, IP address, device and browser information, and actions taken in the Service, used for security, audit and product improvement.
- Communications — records of your correspondence with support, sales or grievance channels.
4. How & why we use personal data
We use personal data for specified, lawful purposes, including to:
- Provide, operate, secure and improve the Service, and compute payroll and statutory outputs as configured by the customer;
- Authenticate users (via Comsky Identity), manage access, and maintain an audit trail;
- Communicate with you about your account, service updates, security notices and support requests;
- Process billing, issue tax invoices and meet accounting and tax obligations;
- Detect, prevent and respond to fraud, abuse and security incidents;
- Comply with legal obligations and enforce our agreements.
Where we act as a Data Fiduciary, we process personal data on the basis of your consent or another lawful ground permitted under the DPDP Act (such as certain legitimate uses and legal obligations). Where consent is the basis, you may withdraw it at any time, and we will provide a clear means to do so. Where we act as a Data Processor, the customer is responsible for establishing the lawful basis and for issuing notices to its employees.
7. Data storage & security
We implement reasonable technical and organisational safeguards designed to protect personal data, including encryption of sensitive identifiers at rest, encryption in transit, role-scoped access controls, verified tenant isolation, and an append-only audit trail recording who changed what and when. No method of transmission or storage is completely secure; while we work to protect your data, we cannot guarantee absolute security.
8. Data retention
We retain personal data only for as long as necessary for the purposes described in this Policy, to provide the Service, and to comply with legal, tax and accounting obligations (for example, statutory record-retention periods applicable to payroll and financial records in India).
Where we act as a Data Processor, retention of employee data is directed by the customer. On termination of a customer's Subscription, Customer Data may be exported within the retrieval window described in our Refund & Cancellation Policy, after which it may be deleted or anonymised in the ordinary course, subject to any legal retention requirement.
9. Your rights as a Data Principal
Subject to applicable law, and depending on whether we act as Data Fiduciary or Data Processor, you may have the following rights under the DPDP Act:
- Right to access — to obtain a summary of the personal data being processed and the processing activities.
- Right to correction & updating — to have inaccurate or incomplete data corrected, completed or updated.
- Right to erasure — to request deletion of personal data that is no longer necessary for the purpose for which it was collected, subject to legal retention obligations.
- Right to grievance redressal — to a readily available means of registering a grievance with us (see Grievance Officer below).
- Right to nominate — to nominate another individual to exercise your rights in the event of death or incapacity.
- Right to withdraw consent — where processing is based on consent, to withdraw it as easily as it was given.
If we act as a Data Processor for your employer, we will direct or forward your request to the relevant Data Fiduciary (your employer), who is responsible for responding. We may need to verify your identity before acting on a request.
10. Children’s data
The Service is intended for use by organisations and their adult personnel and is not directed at children. We do not knowingly collect personal data of children except where an employer lawfully provides limited dependant information (for example, for benefits administration), in which case such data is processed under the DPDP Act's requirements and the employer's instructions.
11. Data location & transfers
We aim to store and process personal data in a manner consistent with applicable Indian law. Where personal data is transferred to or processed by a sub-processor, we take steps designed to ensure an appropriate level of protection and to comply with any restrictions on cross-border transfer under the DPDP Act and other applicable law.
12. Grievance Officer & contact
In accordance with the DPDP Act and applicable rules, we have designated a Grievance Officer to address questions and complaints about our handling of personal data. We will acknowledge and respond to grievances within the timelines prescribed by applicable law.
Grievance Officer: [Name of Grievance Officer]
Email: grievance@comsky.in · Privacy queries: privacy@comsky.in
Comhard Technologies Pvt Ltd
Registered office: [Registered office address], India
13. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be notified by posting the updated Policy with a new “Last updated” date and, where appropriate, by additional notice. Your continued use of the Service after an update takes effect indicates your awareness of the revised Policy.
Related: Terms & Conditions · Acceptable Use · SLA