1. Who We Are
ADMINFACE ("we", "us", "our") is a free, ad-supported web-based HR and office management
platform available to any organisation at no cost. Our mission is to give every
organisation complete HR tools — free of charge — so teams of every size can operate
efficiently, focus on work that matters, and grow without per-seat penalties.
How we stay free: We display non-intrusive display advertisements within the
application interface. Organisations that prefer no advertising can subscribe to our
Ad-Free Plan at ₹9,999 per year (excluding applicable taxes).
This Privacy Policy explains how we collect, use, store, and protect information about
you and your organisation when you use ADMINFACE. By registering or using ADMINFACE, you agree to
the practices described in this policy.
2. Data We Collect
ADMINFACE collects only the data you voluntarily enter to operate the system. This includes:
Organisation & Account Data
- Organisation name, subdomain, and registration details
- Administrator name, email address, and hashed password
- Company settings (name, address, financial year, logo)
- Billing contact and payment reference — Ad-Free Plan subscribers only (see Section 7 for UPI data details)
Employee & HR Data
- Employee profiles: name, email, phone, designation, department, join date, address, photo
- Organization hierarchy data: optional Sub Organization, Business Unit, Region, Branch/Location, and Team assignments per employee, where your organisation chooses to configure them
- Branch/location records: branch name, office address, working hours, timezone, geo-coordinates, contact details, and assigned branch manager, where configured
- Attendance records: daily clock-in / clock-out times, status, biometric punch logs
- Leave records: applications, types, dates, approval status, balance
- Comp-off credit records: holiday date, credit date, source (auto/manual), awarded/revoked status
- Leave encashment records: leave type, days requested, per-day value, status, remarks
- Payroll data: basic salary, allowances, deductions (PF, ESI, TDS), net salary, payslips
- Expense claims: amount, category, receipts, approval history
- WFH requests: dates, reasons, approval status
- Assets: assigned equipment, serial numbers, condition
- Documents: files uploaded by HR or employees
- Notices: internal announcements created by your team
- Audit logs: records of who changed what within your account
- Chat messages: messages within organisation, group, and direct conversations
- WhatsApp Bulk Messaging data: contact names and phone numbers, message template content, campaign delivery/read status, and inbound opt-out replies — only collected if your organisation enables and configures this optional module with its own Meta WhatsApp Business API credentials (see Section 5 for third-party sharing details)
- Daily notes / work logs: daily work entries and important notes created by employees
- Biometric device data: device IP, attendance punch timestamps — raw biometric templates never reach us
- GPS location data: real-time coordinates shared voluntarily by field employees while tracking is active
- Performance data: review records, self-assessments, manager ratings, goals
- Internal email content: messages in the platform's internal email system
- Tasks & projects: tasks, assignments, milestones, and project records
- Shift records: shift definitions, assignments, and swap requests
- Recruitment data: job posts and candidate applications submitted via your portal
- LMS records: enrolled courses, completion status, and assessment results
- Certificates: certificates issued to employees — type, date, personal message, issue date, and view/download status
- Exit management: resignation, clearance, and exit interview records
- OKR / Goals data: objectives, key results, check-in notes, and progress records
- 360° Feedback data: review cycle responses, star ratings, strengths, improvement notes — anonymous responses contain no identity fields
- HR Helpdesk tickets: ticket content, replies, internal HR notes, priority and status
- Recognition records: badges given, recognition messages, points — public feed visible to all employees in the organisation
- Survey responses: answers to organisation surveys; anonymous surveys store no respondent identity
- Org chart data: manager–employee reporting relationships derived from employee profiles
- Offer letter data: candidate name, role, letter content, secure acceptance token, response status
- Benefit enrolment records: benefit plan assignments, enrolment dates, contribution figures per employee
- Family member data: names, relationships (Spouse / Child / Parent / Sibling / Other), dates of birth, contact phone numbers, and insurance nomination status voluntarily entered by employees or HR for insurance and emergency contact purposes
Technical & Usage Data
- Login timestamps and IP addresses (for security audit logs)
- Browser type and device information (for technical support)
- Session data stored in cookies necessary for authentication
- Push notification tokens (FCM): device-level Firebase Cloud Messaging tokens, stored with your explicit permission to deliver real-time alerts (new messages, email notifications, and important updates). Tokens are deleted when you revoke notification permission or log out.
3. Hospital Category — Patient Health Data
This section only applies to organisations that have opted into the Hospital category
(OPD/IPD clinic and hospital management). If your organisation has not enabled this category,
none of the data described below is collected, and the rest of this policy applies to you as normal.
Organisations that enable the Hospital category use ADMINFACE to manage outpatient (OPD) and
inpatient (IPD) care, in addition to the standard employee/HR features described in Section 2.
Doing so involves collecting health-related information about the organisation's
patients — a different category of person from the organisation's employees,
and one that many organisations and regulators treat as sensitive.
Patient & Medical Data Collected
- Patient identity & demographic details: name, date of birth, gender, phone number, blood group, known allergies, and a unique hospital ID (UHID) assigned by your organisation
- Consultation records: vital signs recorded at each visit (blood pressure, pulse, temperature, weight, height, oxygen saturation), diagnosis notes, prescriptions, and the doctor's advice
- Case history files: medical reports, scans, and other documents uploaded against a patient's case history, stored in an access-gated directory on our servers
- Admission (IPD) records: ward and bed assignment, admission and discharge dates, and discharge summaries
- Billing records: invoices and payment records raised by your organisation for consultations, admissions, and other services provided to the patient (see Billing & Payments below)
This data is entered by the organisation's doctors, front-desk, and billing staff — or by
patients themselves through the Patient Portal described below — solely to operate the
OPD/IPD features the organisation uses. As with all other data on ADMINFACE (Section 4), we
do not read, analyse, profile, or otherwise use this clinical data for any purpose beyond
storing and displaying it for the organisation.
Same Data Isolation Guarantee as Employee Data
Patient and medical data is held to exactly the same isolation guarantee described in
Section 9: it lives exclusively inside your organisation's own separate database, alongside
your employee/HR data. Staff of one organisation — including its doctors and administrators —
cannot see, query, or access patient data belonging to any other organisation, ever.
Patient Portal — A Separate Login for Patients
Hospital-category organisations may offer their patients a self-service Patient Portal. This
is a distinct login, kept in its own session, entirely separate from staff/employee accounts
— a patient signing in can only ever view their own appointments, case history, and bills,
never another patient's or an employee's data.
Patients are not ADMINFACE customers and do not have a direct account relationship with us —
the hospital organisation that treats them is the data controller for their information, in
the same way it is the controller of its employees' HR data. Mirroring Section 12 (Your
Rights) for employee data, a patient who wants to access, correct, export, or delete their
personal data should contact the hospital organisation directly; the organisation can view,
edit, export, or delete patient records using the tools ADMINFACE provides, and may request
our help in doing so at privacy@adminface.com.
Billing & Payments
Patient invoices and payments are currently recorded manually within the application by
hospital staff — for example, marking an invoice as paid after receiving payment, or showing
the patient a static QR code to pay against. ADMINFACE does not itself process, transmit, or
route live payment transactions for patient billing. Where an organisation configures payment
gateway credentials for its own use, those credentials are encrypted before storage and are
never shared outside that organisation's isolated database.
4. How We Use Your Data
All data you enter is used exclusively to operate ADMINFACE features for your organisation:
- To display, manage, and report on your HR records within your dashboard
- To send system-generated emails (password reset, notifications you configure)
- To maintain audit trails and login activity logs for your security
- To process attendance sync from biometric devices you configure
- To generate payslips, expense reports, and attendance reports
- To process and manage your Ad-Free Plan upgrade request and UPI payment verification
- To review and respond to organisation ad requests submitted via the Advertising Programme
- To send WhatsApp template messages to your contacts via Meta's WhatsApp Business Platform, using your organisation's own connected API credentials, only when you enable and use the WhatsApp Bulk Messaging module
We do not use your HR data for analytics, profiling, training, marketing, or
any purpose beyond operating the features you explicitly use.
Your salary figures, employee names, attendance records, and documents are never
read, processed, or analysed by us for any purpose outside of serving your requests.
5. Data Sharing — We Share Nothing
We do not sell, rent, trade, or share your organisation's data with any third party
for any reason, with the single explicit exception described below for the optional
WhatsApp Bulk Messaging module — which only applies if your organisation chooses to enable it.
- No employee data is shared with advertisers, data brokers, or analytics companies
- No payroll, HR, or attendance information is transmitted to any external service
- No government or regulatory body receives your data unless compelled by a legally binding court order, in which case we will notify you to the extent permitted by law
- Biometric punch data stays within your organisation's isolated database
- UPI payment references (UTR numbers) are held exclusively within the ADMINFACE master database and are not shared with any payment processor or third party
- Exception — WhatsApp Bulk Messaging: if your organisation enables this module, the contact names, phone numbers, and message content you send are transmitted to Meta Platforms, Inc. via the WhatsApp Business Platform, using your organisation's own connected API credentials, in order to actually deliver the messages. This only happens for this specific opt-in feature — it never happens for any other part of ADMINFACE. See Section 14 for details.
6. Advertising, How ADMINFACE Stays Free & the Ad-Free Plan
ADMINFACE is free for all organisations, forever. To fund development and
hosting, we display non-intrusive display advertisements in the application.
If you prefer zero ads, you can subscribe to our Ad-Free Plan at ₹9,999 per year
(excluding applicable taxes). Both plans include identical HR features and the
same data privacy guarantees.
Ad Priority (Three-Tier System)
When the Free Plan is active, ads are displayed in the following priority order:
| # | Ad Type | Source | Data to Advertisers |
| 1 |
Custom Platform Ad |
Configured by ADMINFACE operator (Superadmin) |
None — static banner image only |
| 2 |
Organisation Ad |
Submitted and approved via Advertising Programme |
None — static banner image only |
| 3 |
Google AdSense |
Google Ads network |
Standard browser signals only (see below) |
Free Plan — Google AdSense Ads
- Ad content: Served by Google AdSense when no custom or organisation ad is active. These ads may use cookies based on general browsing context — not your HR data.
- No HR data to Google: Google AdSense receives only standard browser signals (IP address, browser type, general location). It never receives employee names, salaries, attendance records, or any organisational HR information.
- Cookie consent: Google may place advertising cookies on your device. You can manage these through your browser settings or opt out via Google Ad Settings.
- We use Google AdSense publisher account
ca-pub-4072905345026114. Ad slots are served from Google's CDN.
Ad-Free Plan — ₹9,999/year (excl. taxes)
- All display advertisements are removed from the application interface
- No third-party advertising cookies are set under this plan
- Subscriptions are billed annually via UPI (see Section 7). The plan reverts to Free on non-renewal.
- Ad-Free status is active from the date ADMINFACE confirms the UPI payment for 12 months
- Payment details and receipts are handled securely within our master database. We do not process card numbers.
7. UPI Payment Data
When you subscribe to the Ad-Free Plan, you submit a UPI payment and provide the following
information via the in-portal upgrade page:
- UTR number (Unique Transaction Reference) — the 10–25 character alphanumeric reference generated by your UPI app
- Payment screenshot (optional) — an image upload stored in our server's private directory, accessible only to ADMINFACE staff
- Notes (optional) — any remarks you include with your submission
How this data is used and stored:
- The UTR is used solely to verify payment with our bank records — it is not shared with any payment processor
- Screenshots are stored in a non-public server directory and are never shared externally
- Payment records are retained for legally required accounting periods
- We do not store your UPI ID, UPI PIN, bank account number, or any banking credentials — we only receive the UTR from you
- On approval, a flag is set in your organisation's isolated database to remove ads — no financial data is stored in your tenant DB
8. Organisation Ad Request Data
When your organisation submits an ad request via the portal's Advertising Programme, we collect:
- Contact details: name, email address, and optional phone number of the person submitting the request
- Ad creative: the banner image you upload (stored in our server)
- Click URL: the destination URL where ad clicks will be sent
- Alt text and description: accessibility label and notes you provide
- Preferred duration: the duration you request for the campaign
How this data is used:
- Contact details are used only to communicate about your ad request (approval, rejection, pricing discussions)
- Your contact details are never shared with other organisations, third parties, or used for marketing
- If your ad is approved, the banner image and click URL are displayed to portal users during the approved date range — the image and URL are visible to all portal visitors by design
- Ad request records are retained while your organisation account is active and for a reasonable period after for record-keeping
- You may request removal of your ad creative image at any time by contacting ads@adminface.com
9. Data Isolation Between Organisations
Each organisation registered on ADMINFACE receives its own completely separate database.
Administrators from Organisation A cannot see, query, or influence any data belonging
to Organisation B — ever.
The only data stored in our shared master database is: your organisation's name, subdomain, registration status, plan level, and (for Ad-Free subscribers) payment references. All HR data — employees, attendance, payroll, documents — lives exclusively in your isolated tenant database. For organisations that have enabled the Hospital category, this includes patient records, consultations, case history files, admissions, and patient billing data (see Section 3) — none of it is stored in, or accessible from, our shared master database or any other organisation's tenant database.
10. Data Security
- Passwords are hashed using bcrypt — we never store plaintext passwords
- All forms are CSRF-protected with per-session tokens
- Database credentials are isolated per organisation
- All admin and HR actions are written to a tamper-evident audit log
- Login activity (IP, timestamp, device) is recorded for your security review
- Biometric device communications are authenticated via unique per-device tokens
- Ad request images and UPI payment screenshots are stored in non-public server directories, not accessible via direct URL
While we implement strong security practices, no system is 100% immune to breaches.
We will notify affected organisations promptly in the event of a security incident.
11. Data Retention & Deletion
- Your data is retained for as long as your organisation account is active
- You can delete individual employees, records, and documents at any time from within the application
- To delete your entire organisation and all associated data, contact us at the email below — we will process the deletion within 30 days
- Audit logs are retained for 2 years for security purposes
- Ad-Free Plan subscription records (including UTR references) are retained for the legally required period for accounting purposes
- Organisation ad request records are retained while the account is active; contact ads@adminface.com to request removal of ad creatives
12. Your Rights
- Access: Export attendance, payroll, and employee data via the built-in CSV export tools at any time
- Correct: Edit any employee record, attendance entry, or document directly in the application
- Delete: Remove any individual record, or request full account deletion
- Portability: Export your data in CSV format from Reports, Attendance, and Payroll modules
- Patients (Hospital category): the same access, correction, deletion, and export rights apply to patient records — administered by the hospital organisation, since ADMINFACE does not have a direct account relationship with patients (see Section 3)
- Opt out of personalised ads: Manage via browser settings or Google Ad Settings (Free Plan)
- Go ad-free: Subscribe to the Ad-Free Plan at ₹9,999/year + taxes via UPI to remove all ads permanently
- Ad creative removal: Request removal of any ad image you submitted by contacting ads@adminface.com
13. Cookies
- Essential cookies: Session cookies required for login and CSRF protection. These cannot be disabled without breaking the application.
- Advertising cookies (Free Plan — Google AdSense only): Set by Google when AdSense ads are displayed. You can disable these in your browser or via Google Ad Settings.
- No advertising cookies for custom/organisation ads: Static banner ads (custom platform ad and approved organisation ads) do not set any third-party cookies — they are simple image links with no tracking code.
- No advertising cookies on Ad-Free Plan: Ad-Free subscribers are not subject to any advertising cookies.
We do not use analytics tracking cookies (e.g., Google Analytics) on portal users.
14. WhatsApp Bulk Messaging & Meta Platforms
The WhatsApp Bulk Messaging module is optional and off by default. If your organisation
enables it and connects its own Meta WhatsApp Business API credentials, the following data
is sent to Meta Platforms, Inc. in order to deliver messages:
- Recipient phone numbers and names, and the content of the message templates you send
- Delivery, read, and failure status is received back from Meta and stored against each recipient so your organisation can see campaign results
- Inbound replies (used only to detect opt-out keywords such as "STOP") are received from Meta via webhook and processed to update that contact's subscription status
Meta processes this data under its own privacy policy and WhatsApp Business Terms of
Service as an independent data processor/controller for the messaging service — ADMINFACE
does not control how Meta uses data once it leaves our servers.
Your organisation's access token and optional app secret are stored encrypted and are used
solely to authenticate API calls made on your organisation's behalf.
You are responsible for having recipients' consent before sending — see Section 17 of our
Terms of Service.
15. Children's Privacy
ADMINFACE is a professional business application for organisations and their adult employees.
We do not knowingly collect data from individuals under 16 years of age.
16. Changes to This Policy
If we make material changes to this Privacy Policy, we will post a notice within the
application at least 14 days before the changes take effect. Continued use of ADMINFACE
after the effective date constitutes acceptance of the revised policy.
For privacy questions, data deletion requests, Ad-Free Plan enquiries, or any concerns:
Privacy & Data Requests
privacy@adminface.com
Data deletion, export requests, GDPR/IT Act queries, privacy concerns.
General & Ad-Free Plan
info@adminface.com
Ad-Free Plan subscription, general questions, account help.
Advertising & Ad Removal
ads@adminface.com
Organisation ad requests, creative removal, ad campaign queries.
Response Time
Within 2 business days
Mon – Sat, 9 AM – 6 PM IST. Data deletion requests: within 30 days.
Export Your Data
Self-service via the app
Use Attendance, Payroll, and Reports export features — no need to contact us.
Governing Jurisdiction
India
This policy is governed by the laws of India (IT Act 2000 and applicable rules).