1. Who we are
ORGASOFT GLOBAL PRIVATE LIMITED (“we”, “us”, “our”), a private limited company incorporated in India under the Companies Act, 2013, having CIN U70200HR2025PTC138716 and its registered office at B-603, The Roselia, Signature Global, Sector 95A, Garhi Harsaru, Gurugram, Haryana 122505, India, is the entity responsible for the personal data described in this policy.
EZER HRMS (“EZER”) is the HR and payroll product operated by ORGASOFT GLOBAL PRIVATE LIMITED, available at https://www.ezerhrms.com. References to “EZER” in this policy mean the product; the legal entity accountable for it is ORGASOFT GLOBAL PRIVATE LIMITED.
This policy explains what personal data we collect, why, who we share it with, how long we keep it, and the rights you have under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025.
In this policy, “you” or “Data Principal” means the individual the personal data relates to. “Personal data” means any data about an individual who is identifiable by or in relation to that data.
2. Our two roles — please read this first
EZER handles personal data in two very different capacities, and your rights are exercised differently in each. This distinction matters more than anything else in this policy.
Role 1 — Data Fiduciary: our website and our own business contacts
When you visit our website, request a demo, or contact us, we decide why and how your data is used. Here EZER is the Data Fiduciary, and you exercise your rights directly with us using the contact details in Section 22.
Role 2 — Data Processor: employee data inside a customer’s EZER account
When a company subscribes to EZER and loads its employee records — salary structures, attendance, PF and ESIC details, investment declarations — that company is the Data Fiduciary, not us. It decides what to collect and why. EZER only processes that data on its written instructions, as a Data Processor.
If you are an employee of a company that uses EZER: your employer controls your data, not us. Please send requests to access, correct or erase your records to your employer’s HR or grievance contact. If you approach us directly, we will refer you to your employer and, where appropriate, notify them of your request — we are not permitted to alter their records on our own initiative.
3. Personal data we collect
3.1 When you request a demo or contact us
Our demo form collects only what you type into it:
| Data | Required? | Why we need it |
|---|---|---|
| Full name | Yes | To address you correctly and know who we are speaking to |
| Phone number | Yes | To contact you about the demo you requested |
| Work email | Yes | To send the demo invitation and follow-up |
| Company name | Yes | To prepare a demo relevant to your organisation |
| Your role and company size | No | To pitch at the right level of detail |
| Free-text message | No | To answer anything specific you ask |
How the form works today, stated plainly: submitting the demo form does not send data to an EZER server. It opens WhatsApp on your device with a pre-filled message that you choose to send to +91 87967 46222. Your message therefore passes through WhatsApp (Meta Platforms) and is governed by WhatsApp’s own privacy policy in addition to ours. Nothing is stored by us until you actually send that message.
3.2 When you simply browse the website
Nothing that identifies you is loaded before you choose. Until you answer the cookie banner, no analytics or advertising script runs at all. Four things happen either way:
- Our hosting provider records standard server logs (IP address, timestamp, page requested, browser type) for security and reliability.
- We store your cookie choice itself in your browser (
ezer_cookie_consent), so we do not ask again on every page. Without it we could not honour a refusal. - If you arrived from a campaign or a shared link, we keep which one in your browser for the current session only (
ezer_attribution), so that an enquiry you send can be attributed to the channel it came from. - If — and only if — you accept analytics cookies, we then load Google Analytics 4 and Microsoft Clarity. See Section 15 and our cookie policy, which lists each one and how long it is kept.
Fonts are served from our own domain, not from a third-party font CDN, so loading a page does not disclose your IP address to a font provider.
3.3 Employee data inside the EZER product
Where a customer uses EZER for HR and payroll, the account may contain identity and contact details, employment and salary information, attendance and leave records, statutory identifiers such as PAN, Aadhaar, UAN and ESIC numbers, bank account details for salary credit, and investment declarations. This data is collected and controlled by the employer — see Section 2.
4. Why we use your data
Where EZER is the Data Fiduciary, we use personal data only for these specified purposes:
- To respond to a demo request or enquiry you sent us
- To arrange, run and follow up on a product demonstration
- To provide, support and administer the EZER service to a customer
- To send service and compliance updates relevant to a customer’s use of EZER
- To keep our systems secure and to investigate misuse
- To comply with a legal obligation, or to establish or defend a legal claim
We do not sell personal data, and we do not use it for behavioural advertising or automated decisions that produce legal effects.
5. Consent and how to withdraw it
Under the DPDP Act, consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the data necessary for the stated purpose. When you fill in our demo form and send the message, you consent to us contacting you about that request.
You may withdraw consent at any time, and it must be as easy to withdraw as it was to give. Write to [privacy email to be confirmed] or call +91 87967 46222 and ask us to stop. On withdrawal we will stop processing and erase your data within a reasonable period, unless we are required by law to retain it. Withdrawal does not affect processing already carried out lawfully before you withdrew.
6. Children’s and persons with disability data
Our website and the EZER product are intended for businesses and are not directed at children. We do not knowingly collect personal data of anyone under 18 through this website.
Where processing of a child’s data is required, the DPDP Act obliges us to obtain verifiable consent of a parent or lawful guardian, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. The same consent requirement applies to a person with disability who has a lawful guardian. If you believe a child’s data has reached us, contact us and we will erase it.
7. Who we share data with
We share personal data only with service providers who process it on our instructions under contract, and only as far as needed:
| Recipient | What reaches them | Why |
|---|---|---|
| WhatsApp / Meta Platforms | The demo message you choose to send | It is the channel our contact form uses |
| Google (Google Analytics 4) | Pages visited, how you arrived, and device and browser details. IP addresses are anonymised | To understand which pages are used — loaded only after you accept analytics cookies |
| Microsoft (Clarity) | Aggregated interaction data and session recordings, with form input masked | To see where visitors get stuck — loaded only after you accept analytics cookies |
| Our website hosting provider | Server logs | To host and secure the website |
| Our cloud infrastructure and database provider | Customer account and HR data | To run the EZER product |
We may also disclose data where required by law, court order, or a lawful request from a government agency. We do not sell or rent personal data to anyone.
8. Where data is stored and cross-border transfers
Personal data processed through the EZER product is hosted in India.
Some third-party services listed in Section 7 may process limited technical data outside India. The DPDP Act permits transfer of personal data outside India except to countries the Central Government restricts by notification; we will comply with any such restriction, and with any additional obligations that apply to us if we are ever designated a Significant Data Fiduciary.
9. How we protect data
We are required to take reasonable security safeguards to prevent a personal data breach. Ours include:
- Encryption of data in transit (HTTPS/TLS) and at rest
- Role-based access control, so a user sees only the records their role requires
- Masking of sensitive fields such as full Aadhaar and bank account numbers, except for the specific roles that need them
- Access logging and monitoring, with logs retained for at least one year as required under the DPDP Rules
- Contractual security obligations on every processor we engage
No system is perfectly secure. We commit to reasonable, current safeguards and to telling you promptly if something goes wrong — see Section 14.
10. How long we keep data
| Data | Retention |
|---|---|
| Demo enquiries that do not convert | [retention period to be confirmed] from last contact, then erased |
| Customer account and HR data | For the term of the subscription, plus [export window to be confirmed] for export, then erased or returned |
| Server and access logs | At least 1 year, as required by the DPDP Rules |
| Analytics data, if you accepted analytics cookies | Google Analytics 4: up to 2 years. Microsoft Clarity: up to 1 year. Nothing is collected if you declined |
| Records we must keep by law (tax, statutory) | For the period the relevant law requires |
We erase personal data when the purpose is no longer being served, or when you withdraw consent, unless retention is required by law.
11. Your rights as a Data Principal
Under the DPDP Act you have the right to:
- Access — a summary of the personal data we hold about you, how we are processing it, and who we have shared it with.
- Correction, completion, updating and erasure — to have inaccurate or misleading data corrected, incomplete data completed, and data erased where it is no longer needed and no law requires us to keep it.
- Grievance redressal — a readily available means of raising a complaint with us, which we must respond to. See Section 13.
- Nomination — to nominate another individual to exercise these rights on your behalf if you die or become incapacitated.
To exercise any of these, write to [privacy email to be confirmed]. We may need to verify your identity first. We will respond within [response window to be confirmed]. These rights are free of charge.
If your data sits inside your employer’s EZER account, send the request to your employer — see Section 2.
12. Your duties as a Data Principal
The DPDP Act also places duties on individuals. You must not impersonate another person when providing data, must not suppress material information, must not register a false or frivolous grievance or complaint, and must provide only verifiably authentic information when exercising the right to correction or erasure. Breaching these duties can attract a penalty under the Act.
13. Grievance redressal
If you are unhappy with how we handle your personal data, contact our Grievance Officer first. We are obliged to respond and will do so within [response window to be confirmed].
Grievance Officer
- Name: [name to be confirmed] · Designation: [designation to be confirmed]
- Email: [grievance email to be confirmed]
- Phone: +91 87967 46222
- Address: ORGASOFT GLOBAL PRIVATE LIMITED, B-603, The Roselia, Signature Global, Sector 95A, Garhi Harsaru, Gurugram, Haryana 122505, India
Escalation. If we do not respond, or you are not satisfied with our response, you may complain to the Data Protection Board of India, which is constituted and accepting complaints. Please raise the matter with us first — the Board expects you to have exhausted our grievance process.
14. If there is a data breach
If a personal data breach occurs, we will notify the Data Protection Board of India and every affected Data Principal without delay, in plain language, describing the nature and extent of the breach, its likely consequences, the measures we have taken, and what you can do to protect yourself. A detailed report follows to the Board within 72 hours, as the DPDP Rules require.
15. Cookies and tracking
We use two kinds of browser storage, and the difference is the consent.
Essential, always present. Your cookie choice (ezer_cookie_consent) and, for the current session only, which campaign or link brought you here (ezer_attribution). Neither tracks you across other websites, and the first exists so that a refusal can be honoured.
Analytics, only if you accept. Google Analytics 4 and Microsoft Clarity. Nothing from either is loaded, and no request is made to either company, until you choose Accept on the banner — declining leaves them uninstalled rather than merely inactive. Clarity records sessions with form input masked; Analytics anonymises IP addresses. Neither is used to build an advertising profile of you.
Our cookie policylists each item, what it does and how long it is kept. You can change your mind at any time by clearing this site’s storage in your browser, which brings the banner back.
16. Marketing communications and opt-out
If you give us your contact details, we may send you product updates, compliance notes and event invitations relevant to HR and payroll in India. Every such message carries a one-click unsubscribe, and you can also write to [privacy email to be confirmed] at any time to stop.
Opting out of marketing does not stop service messages — for example, notices about billing, security, downtime, or a change to this policy — which we must send to customers while their subscription is active.
17. Job applicants
If you apply for a role at EZER, we collect the personal data in your application: name, contact details, CV, work history, education and anything else you choose to send. We use it only to assess your application, to communicate with you about it, and to meet our record-keeping obligations.
We keep applications for [retention period to be confirmed] so we can consider you for future openings, unless you ask us to erase them sooner. Write to [privacy email to be confirmed] to withdraw an application or have your data erased.
18. Customers — Data Processing Agreement
Where EZER acts as a Data Processor for a customer (see Section 2), our processing is governed by a written Data Processing Agreement forming part of the subscription contract. That agreement sets out:
- The scope, nature and purpose of processing, and the categories of Data Principals involved
- Our obligation to process only on the customer’s documented instructions
- Security safeguards, confidentiality undertakings and personnel controls
- The approved sub-processors we may engage, and notice before we change them
- Our duty to assist the customer in responding to Data Principal requests and to breach obligations
- Return or deletion of the customer’s data on termination
Existing and prospective customers can request a copy of the current DPA and our sub-processor list from [privacy email to be confirmed].
19. Third-party links
Our website and product may link to sites we do not operate. We are not responsible for their content or their privacy practices, and this policy does not apply to them. Please read the privacy policy of any site you visit from ours.
20. Governing law and jurisdiction
This policy is governed by the laws of India. Disputes arising from it are subject to the exclusive jurisdiction of the courts at Gurugram, Haryana, without prejudice to your statutory right to complain to the Data Protection Board of India under Section 13.
21. Changes to this policy
We may update this policy as our product, our processors, or the law changes. The “last updated” date at the top will always reflect the current version. Where a change materially affects how we use your personal data, we will notify you and, where required, obtain fresh consent.
22. Contact us
ORGASOFT GLOBAL PRIVATE LIMITED
- Operator of EZER HRMS · CIN: U70200HR2025PTC138716
- Registered office: B-603, The Roselia, Signature Global, Sector 95A, Garhi Harsaru, Gurugram, Haryana 122505, India
- Privacy: [privacy email to be confirmed]
- Phone: +91 87967 46222
- Web: https://www.ezerhrms.com
See also our terms of use. This policy is provided for transparency and does not constitute legal advice. It should be reviewed by qualified legal counsel before publication.
