This notice describes what Seers collects, why we collect it, where it is stored, who can see it, and how you can exercise your rights over it. Seers Pvt. Ltd. ("Seers", "we", "us") is incorporated and operates from Bengaluru, Karnataka, India. Plain language - no surprises. If anything here is unclear, email hello@seers.co.in.
Under India's Digital Personal Data Protection Act 2023 (DPDPA), Seers acts as a Data Fiduciary for data it collects for its own marketing, account management, and product improvement purposes, and as a Data Processor for all personal data your organisation (the Data Fiduciary / tenant) instructs Seers to process within your workspace. You, as the individual whose data is processed, are a Data Principal under DPDPA. Where the EU GDPR applies (for tenants with EU-based employees), the equivalent terms are Data Controller and Data Processor.
1. What we collect
We process personal data in four distinct contexts, each with its own lawful basis.
- Workspace data (Data Processor role) - employees, contractors, and candidates whose records your administrators enter into the platform. This includes identifiers (name, email, mobile, employee code), employment attributes (department, designation, hire date, employment type), payroll and compensation data (salary structure, deductions, net pay, payslip PDFs), attendance events (clock-in/out timestamps, source device, geolocation when your policy enables it), leave records, and the platform audit log. Lawful basis: contract between Seers and the tenant; instructions of the Data Fiduciary (your organisation).
- Account data (Data Fiduciary role) - your email address, display name, hashed password (argon2id, never stored in recoverable form), session metadata (token reference, expiry, IP at sign-in), and the roles assigned to your user account. Lawful basis: contract - necessary to provide the service you signed up for.
- Operational metadata (Data Fiduciary role) - IP address on each request (used for audit log entries and brute-force protection), browser timezone (for localised date display), HTTP request logs, and error traces. Lawful basis: legitimate interest in operating a secure and reliable service.
- Lead and contact data (Data Fiduciary role) - if you submit our contact or pricing-enquiry form: your name, work email, company name, message text, and any UTM attribution parameters present in the URL at the time. Lawful basis: consent (submission of the form).
We do not collect biometric data directly. If a tenant uploads biometric identifiers (e.g. fingerprint templates from a third-party device integration), those are processed under the tenant's Data Fiduciary instructions and subject to the DPA.
2. Where it lives and how long we keep it
All tenant workspace data is stored in a PostgreSQL database hosted on AWS Mumbai (ap-south-1). Automated backups are stored in the same region. Data does not leave India for normal operations. The table below shows our standard retention windows.
| Data category | Retention | Basis |
|---|---|---|
| Payslip PDFs and payroll period records | 7 years after generation | Statutory (Income-Tax Act) |
| Platform audit log rows | 7 years | Statutory + legitimate interest |
| Attendance events and leave records | 5 years or until tenant deletion | Contract + statutory (EPF records) |
| Lead / contact form submissions | 24 months from submission | Consent (legitimate interest in follow-up) |
| Session and request logs | 30 days rolling | Security / legitimate interest |
| Account data (post-cancellation) | 30-day export window, then deleted | Contract |
| Error traces / stack traces | 90 days | Legitimate interest |
Sub-processors for transactional email and error monitoring may receive limited metadata (email recipient address, subject line, anonymised stack trace) but not your full tenant data. The current sub-processor list is maintained at /sub-processors and is updated with 14 days' notice of additions.
Cross-border transfers: No personal data is transferred outside India under current operations. If a future sub-processor requires cross-border transfer (e.g. an international email deliverability service or global error-monitoring platform), Seers will update the sub-processor list, provide advance notice, and rely on contractual safeguards equivalent to Standard Contractual Clauses where required.
3. Who can see it
- Users in your tenant - see only what their assigned role permits. Row-level tenant scoping in the database prevents cross-tenant reads at the database boundary. Role permissions are configured by your tenant Owner.
- Seers engineering and support staff - may access tenant data only when investigating an active incident, fulfilling a documented support request you have raised, or performing a security audit. All such access is recorded in the platform audit log. Staff sign confidentiality agreements and are bound by our data access policy.
- Sub-processors - listed at /sub-processors. Each sub-processor is bound by a data processing agreement with Seers that requires equivalent protections.
- Government or law enforcement - only on receipt of a valid Indian legal order, court order, or statutory notice. Seers will notify the affected tenant unless legally prohibited from doing so. We will not voluntarily disclose data beyond what is strictly required by the order.
- We do not sell personal data. We do not share it with third parties for advertising, profiling, or marketing purposes. We do not use tenant workspace data to train AI models.
4. Your rights as a Data Principal (DPDPA)
Under the Digital Personal Data Protection Act 2023, Data Principals have the following rights. For data processed within a tenant workspace, you should first direct requests to your employer (the Data Fiduciary). Seers will assist the Data Fiduciary in honouring those requests within 7 days of a documented request.
- Right to access - request a summary of personal data Seers holds about you and the purposes for which it is processed.
- Right to correction - request correction of inaccurate or incomplete personal data.
- Right to erasure - request deletion of personal data, subject to statutory retention obligations (e.g. payroll records required by the Income-Tax Act cannot be erased early).
- Right to grievance redressal - raise a complaint with our Grievance Officer (see §6 below). If unresolved within 30 days, you may approach the Data Protection Board of India once constituted.
- Right of nomination - nominate another individual to exercise your rights in the event of death or incapacity.
- Right to withdraw consent - where processing is based on consent (e.g. lead form submissions), you may withdraw consent at any time. Withdrawal does not affect processing that occurred prior to withdrawal.
To exercise any of the above rights directly with Seers, email legal@seers.co.in with the subject line "Data Principal Request" and your full name, workspace or company, and the nature of your request. We will acknowledge within 3 business days and fulfil within 30 days.
5. Security
- Passwords are hashed with argon2id; never stored or logged in plaintext or recoverable form.
- Session cookies are httpOnly and SameSite=Lax; CSRF tokens are required on all state-changing requests.
- Platform credentials (SMTP keys, payment provider keys, storage credentials) are encrypted at rest using pgcrypto with key rotation on a defined schedule.
- All data in transit is protected by TLS 1.2 or higher. Database backups are encrypted at rest (AES-256).
- Role-based access control (RBAC) governs what each user within a tenant can read or modify. Tenant isolation is enforced at every API boundary and at the database layer.
- The platform audit log records every mutation with actor identity, action, affected resource, and timestamp - both for security review and for your own compliance visibility.
- We conduct periodic access reviews of production system credentials and maintain an incident response procedure.
Breach notification: In the event of a confirmed personal data breach, Seers will notify affected tenants within 72 hours of becoming aware, providing available details of the nature of the breach, categories of data affected, and recommended protective steps. For severe incidents (as defined by CERT-In directions), Seers will also file the required notification to CERT-In within 6 hours. Tenant owners bear responsibility for their own notifications to affected Data Principals once informed by Seers.
6. Grievance Officer
As required under the Digital Personal Data Protection Act 2023, Seers has designated a Grievance Officer for the purposes of receiving and redressing complaints from Data Principals.
- Name: [Grievance Officer - name to be published on constitution of the Data Protection Board]
- Email: grievance@seers.co.in
- Response SLA: 30 days from receipt of a written complaint.
- Escalation: If you are not satisfied with the resolution, you may lodge a complaint with the Data Protection Board of India once it is constituted under DPDPA 2023.
7. Cookies
We use one session cookie (seers_sid) and one CSRF cookie (seers_csrf). Both are strictly necessary for the application to function. The marketing site uses no tracking cookies and does not embed third-party analytics by default. Full details are in our Cookie Policy.
8. Children's data
Seers is a business-to-business service. We do not knowingly collect or process personal data of individuals under the age of 18. If you believe a minor's data has been entered into the platform in error, email legal@seers.co.in and we will delete it promptly.
9. Changes to this notice
Material changes will be announced via in-app notification to all tenant owners at least 14 days before they take effect. The "last updated" date at the top of this page always reflects the current version. Where changes reduce your rights or expand the categories of data we collect, we will seek fresh consent where that is the applicable lawful basis.
This notice is written in plain language for clarity. The binding legal terms governing use of Seers are in our Terms of Service and Data Processing Addendum. For enterprise customers requiring a signed counterpart, email legal@seers.co.in.