Back to Home
Airborne HRS Legal
Legal Documentation

Data Processing Agreement

Please review the following agreement carefully.

Data Processing Agreement

Data Processor: Kunwar Shatrujit Singh, Sole Proprietor trading as Airborne HRS

Address: 37A/13, Defence Colony, Agra, Uttar Pradesh – 282001, India

Data Controller: The subscribing Client organisation identified in the Subscription Agreement or account registration

Applicable Laws: DPDPA 2023 (upon commencement of applicable provisions) & IT Rules 2021 (India) | Privacy Act 1988 (Australia) | Law No. 13 of 2016 (Qatar)

How this DPA operates: This Data Processing Agreement forms part of, and is incorporated into, the Terms and Conditions agreed between you (the Data Controller / Client) and Airborne HRS (the Data Processor) when you subscribe to the Airborne HRMS. By activating the HRMS, you confirm acceptance of this DPA. Where a separate signed Master Services Agreement exists, this DPA is incorporated by reference into that agreement.

1. Definitions

In this Data Processing Agreement, the following terms have the meanings set out below. Terms not defined here carry the meaning given in the Airborne HRS Terms and Conditions.

  • "Agreement" means this Data Processing Agreement together with the Terms and Conditions and any executed Subscription Agreement or Master Services Agreement.
  • "Client Data" means all Personal Data provided to or processed by Airborne HRS on behalf of the Client in connection with the HRMS, including Employee Data.
  • "Controller" or "Data Controller" means the Client, who determines the purposes and means of processing Client Data.
  • "Processor" or "Data Processor" means Airborne HRS, which processes Client Data on behalf of and under the instructions of the Controller.
  • "Employee Data" means Personal Data relating to the Client's employees, contractors, or other personnel processed through the HRMS.
  • "Personal Data" means any information relating to an identified or identifiable natural person, as defined under applicable Data Protection Laws.
  • "Data Protection Laws" means all applicable laws governing the protection of Personal Data, including (as applicable): the Information Technology Act, 2000; the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011; the Digital Personal Data Protection Act, 2023 (India); the Privacy Act 1988 and Australian Privacy Principles (Australia); and the Personal Data Privacy Protection Law, Law No. 13 of 2016 (Qatar).
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, transfer, deletion, or destruction.
  • "Personal Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
  • "Sub-Processor" means any third party engaged by Airborne HRS to process Client Data on its behalf.
  • "Services" means the Airborne HRMS cloud platform and associated features as described in the Subscription Agreement and Terms and Conditions.
  • "Sensitive Personal Data" has the meaning given under the SPDI Rules, 2011, and includes payroll data, location data, and any health-related employee records processed through the HRMS.

2. Subject Matter and Details of Processing

2.1 Subject Matter

Airborne HRS processes Client Data for the sole purpose of providing the HRMS to the Client, as described in the Subscription Agreement and Terms and Conditions.

2.2 Nature and Purpose of Processing

The processing activities carried out by Airborne HRS on behalf of the Client include:

  • Storage and retrieval of employee identity and contact records;
  • Recording and calculating attendance, clock-in/clock-out timestamps, and leave balances;
  • Capturing GPS-based location data at designated attendance events, where enabled by the Client;
  • Processing payroll data as entered or configured by the Client;
  • Storing HR documents, offer letters, and employment contracts uploaded by the Client;
  • Generating HR reports and analytics from stored Employee Data;
  • Processing webhook event signals from biometric attendance devices (employee identifiers and timestamps only — no biometric data is received or stored by Airborne HRS).

2.3 Categories of Personal Data

The categories of Employee Data processed include:

  • Identity data: full name, employee ID, designation, department;
  • Contact data: work email, work phone number;
  • Attendance and location data: timestamps, GPS coordinates at clock events;
  • Leave data: leave requests, types, approvals, and balances;
  • Payroll data: gross salary, deductions, net pay, and payment records;
  • Authentication data: login timestamps, device type, IP address, browser metadata;
  • HR documentation: contracts, offer letters, and other employment documents uploaded by the Client.

2.4 Categories of Data Subjects

The data subjects whose Personal Data is processed are the Client's current and former employees, contractors, and other personnel whose HR records are managed within the HRMS.

2.5 Duration of Processing

Processing shall continue for the duration of the Client's active subscription and for such period thereafter as required for data deletion in accordance with Section 11 of this DPA and the Privacy Policy (which explicitly includes a 3-year post-termination retention period for audit and compliance purposes).

3. Controller Obligations

The Client, as Data Controller, represents, warrants, and agrees that:

  • Lawful Basis: It has established and maintains a valid lawful basis under applicable Data Protection Laws for each category of Employee Data it directs Airborne HRS to process, including obtaining all necessary employee consents where required;
  • Employee Notice: It has provided, and will continue to provide, clear, adequate, and compliant privacy notices to all employees whose data is processed through the HRMS, covering the purposes of processing, data sharing with Airborne HRS, location and attendance monitoring, and employee rights;
  • Data Accuracy: It will ensure that Personal Data provided to Airborne HRS is accurate, current, and limited to what is necessary for the stated HR management purposes;
  • Authorised Instructions: All instructions given to Airborne HRS for processing Client Data are lawful under applicable Data Protection Laws;
  • Local Compliance: It will comply with all Data Protection Laws applicable in its jurisdiction, including any jurisdiction-specific requirements for employee monitoring, payroll data, and location tracking;
  • Biometric Compliance: Where the Client uses biometric attendance devices connected to the HRMS via webhook, the Client is solely responsible for compliance with all biometric data laws in its jurisdiction, including obtaining employee biometric consent at the device level.

4. Processor Obligations

Airborne HRS, as Data Processor, agrees to:

4.1 Documented Instructions Only

Process Client Data only on documented instructions from the Client, as set out in this DPA, the Terms and Conditions, and the Subscription Agreement, except where required to process by applicable law, in which case Airborne HRS will inform the Client of that legal requirement before processing (unless the law prohibits such disclosure).

4.2 Purpose Limitation

Not process Client Data for any purpose other than providing the Services to the Client. Airborne HRS will not use Client Data for its own commercial purposes, analytics outside the scope of the Services, or any other purpose not authorised by the Client.

4.3 Confidentiality of Personnel

Ensure that personnel authorised to process Client Data have committed to confidentiality, whether under formal confidentiality agreements or statutory obligations, and receive appropriate data protection training.

4.4 Sub-Processor Engagement

Not engage Sub-Processors for the processing of Client Data beyond those listed in Section 5 of this DPA without first providing the Client with advance written notice and an opportunity to object, in accordance with Section 5.3.

4.5 Assistance with Rights

Assist the Client in fulfilling its obligations to respond to Data Subject rights requests, as further described in Section 6 of this DPA.

4.6 Security

Implement and maintain the technical and organisational security measures described in Section 7 of this DPA.

4.7 Breach Notification

Notify the Client without undue delay upon becoming aware of a Personal Data Breach affecting Client Data, in accordance with Section 8 of this DPA.

4.8 Deletion or Return

At the Client's request or upon termination of the Services, delete or return Client Data in accordance with Section 11 of this DPA.

4.9 Audit Cooperation

Make available to the Client all information reasonably necessary to demonstrate compliance with this DPA and cooperate with audits as described in Section 10.

5. Authorised Sub-Processors

5.1 Current Sub-Processors

The Client authorises Airborne HRS to engage the following Sub-Processors for the processing of Client Data in connection with the Services:

Sub-ProcessorProcessing ActivityData LocationSafeguard
Google LLC
(Firebase / Firestore)
User authentication; database hosting; cloud storage of Employee Data and HR recordsGlobal (Google Cloud infrastructure; may include regions outside India)Google Data Processing and Security Terms; Google Cloud Data Processing Addendum
Supabase, Inc.
(Supabase)
Secure storage and serving of HR documents, employee resumes, and media avatars.Global (AWS Infrastructure via Supabase)Supabase Data Processing Addendum (DPA)
Vercel Inc.
(Vercel)
Application hosting, edge network delivery, and secure API routing for platform services.GlobalVercel Data Processing Addendum (DPA)
Resend, Inc.
(Resend)
Email delivery services (delivering transaction notifications, password resets, and platform notifications to users and employees)United States / GlobalResend Data Processing Addendum (DPA) incorporating Standard Contractual Clauses (SCCs)
Wise Payments Limited
(Wise)
Processing subscription payments; invoice management (Client billing contact name, email, payment amounts)UK / EU / Global (Wise regulated infrastructure)Wise Data Processing Agreement; regulated by FCA (UK) and applicable authorities. Note: Wise is an independent Data Controller for payment data — not a Sub-Processor of Employee Data.
DigiLocker / Meri Pehchaan
(MeitY, Gov. of India)
Identity verification for Indian employees. We receive specific verification tokens/data to verify identity.IndiaGoverned by Indian Government Data Policies. Airborne HRS does not store actual Aadhaar numbers unencrypted unless explicitly stated.
Video Infrastructure Providers
(Stream, Agora)
Delivering real-time audio and video streams during live interviews and team meetings.GlobalStandard Contractual Clauses / Vendor DPA. Audio/video data passes through these providers but is not recorded or stored by Airborne HRS.

Note on Wise: Wise processes only the Client's billing contact information and payment transaction data. Wise does not have access to Employee Data or any HRMS records. Wise acts as an independent data controller for its payment processing activities under its own privacy policy.

5.2 Sub-Processor Obligations

Airborne HRS will ensure that Sub-Processors are bound by data protection obligations no less protective than those set out in this DPA, and will remain liable to the Client for the acts and omissions of Sub-Processors to the same extent as if Airborne HRS performed such processing directly.

5.3 New Sub-Processors

Airborne HRS will provide the Client with at least 30 calendar days' advance written notice (by email to the Client's registered billing or administrator email address) before engaging any new Sub-Processor for the processing of Client Data. The Client may object to the new Sub-Processor within 14 days of such notice by written notice to legal@airbornehrs.in, setting out the grounds for objection. If the Client objects and Airborne HRS is unable to address the objection, the Client may terminate the Services with 30 days' notice. No refund of any prepaid subscription fees shall be provided upon such termination, except to the extent required by applicable law.

6. Data Subject Rights

6.1 General

Data subjects (employees and other personnel) whose data is processed through the HRMS may exercise their rights under applicable Data Protection Laws — including rights to access, correction, deletion, and objection — by contacting the Client directly, as the Data Controller. The Client is responsible for responding to such requests within the timeframes required by applicable law.

6.2 Processor Assistance

Where a data subject submits a rights request directly to Airborne HRS, Airborne HRS will promptly (and in any event within 5 business days) forward the request to the Client. Airborne HRS will not respond directly to data subject rights requests without the Client's prior written authorisation, except as required by applicable law.

6.3 Technical Assistance

Airborne HRS will, taking into account the nature of the processing, assist the Client by reasonable technical and organisational measures to fulfil the Client's obligations to respond to data subject requests. This includes:

  • Providing the Client with the ability to access, export, and delete Employee Data via the HRMS platform;
  • Supporting data rectification and suppression requests where these cannot be performed directly by the Client within the platform;
  • Providing anonymised or aggregated data to satisfy access requests where technically feasible.

Where such assistance requires work beyond the standard platform functionality, Airborne HRS may charge reasonable fees for the additional effort, agreed in advance with the Client.

7. Security Measures

7.1 Technical and Organisational Measures

Airborne HRS implements and maintains the following technical and organisational security measures appropriate to the risks of the processing:

  • Encryption in Transit: All data transmitted between users and the HRMS platform is encrypted using TLS 1.2 or higher (HTTPS);
  • Encryption at Rest: Client Data stored in Google Firestore is protected by Google's encryption at rest by default;
  • Access Control: Role-based access controls are implemented within the HRMS, restricting access to Employee Data to authorised users only. Firestore security rules enforce data isolation between Clients;
  • Authentication: User authentication is handled via Google Firebase Authentication with session token management, session expiry controls, and brute-force protection;
  • Access Logging: All authentication events and significant data access actions are logged with timestamps, user identifiers, and IP addresses;
  • Monitoring: Real-time monitoring for suspicious or anomalous access patterns is in place;
  • Personnel Security: All personnel and contractors with access to Client Data are bound by confidentiality obligations and receive data protection training;
  • Need-to-Know Access: Internal access to Client Data is restricted to personnel whose role requires it for support, maintenance, or compliance purposes;
  • Vulnerability Management: Regular security reviews, code audits, and vulnerability assessments are conducted;
  • Data Minimisation: Only data necessary for the performance of the Services is collected and retained.

7.2 Adaptation of Measures

Airborne HRS will regularly review the security measures described in this Section and update them to address evolving threats and changes in Data Protection Laws, taking into account the state of the art, the cost of implementation, and the risks presented by the processing.

8. Personal Data Breach

8.1 Notification to Client

In the event that Airborne HRS becomes aware of a Personal Data Breach affecting Client Data, Airborne HRS will notify the Client without undue delay and in any event within 72 hours of becoming aware of the breach. Notification will be made to the Client's registered administrator email address on the HRMS platform.

8.2 Content of Notification

The breach notification will include, to the extent known at the time of notification:

  • The nature of the Personal Data Breach, including the categories and approximate number of data subjects and records affected;
  • The name and contact details of the Airborne HRS point of contact for further information;
  • The likely consequences of the breach;
  • The measures taken or proposed to address the breach, including steps to mitigate its possible adverse effects.

Where it is not possible to provide all information simultaneously, information may be provided in phases as it becomes available, without undue further delay.

8.3 Client Responsibility for Reporting

The Client, as Data Controller, is responsible for determining whether the Personal Data Breach must be reported to the relevant supervisory authority or to affected data subjects under applicable Data Protection Laws, and for making such notifications within legally required timeframes. Airborne HRS will cooperate with and support the Client in making such notifications.

8.4 Breach Register

Airborne HRS will maintain an internal record of all Personal Data Breaches, including the facts relating to the breach, its effects, and the remedial actions taken. This record will be made available to the Client upon request.

9. International Data Transfers

9.1 Processing Locations

Client Data is primarily stored and processed in India and on Google Firebase's global cloud infrastructure, which may include servers in regions outside the Client's home jurisdiction. Airborne HRS does not proactively transfer Client Data outside of the Firebase infrastructure.

9.2 Safeguards for International Transfers

Where Client Data is transferred to or accessed from a country outside the Client's jurisdiction, the following safeguards apply:

  • Australia: Cross-border disclosures are governed by Australian Privacy Principle 8 (APP 8). Airborne HRS takes reasonable steps to ensure that any overseas recipient handles data consistently with the APPs. Google's compliance with the APPs and standard contractual protections are relied upon for Firebase infrastructure transfers;
  • Qatar: Transfers of Qatari resident data are subject to the requirements of Law No. 13 of 2016. Airborne HRS ensures that adequate data protection is maintained at the destination by relying on Google's global compliance framework and contractual protections;
  • India (outbound): Where data is transferred outside India, Airborne HRS complies with applicable provisions of the Digital Personal Data Protection Act, 2023, and the Information Technology Act, 2000, and relies on Google's Data Processing Addendum as a safeguard.

9.3 Client Instructions on Transfer Restrictions

If the Client requires specific data localisation (e.g., data must remain within a specific country or region), the Client must notify Airborne HRS in writing at legal@airbornehrs.in prior to activating the HRMS. Airborne HRS will use reasonable efforts to accommodate such requirements, subject to technical feasibility, and will advise the Client of any limitations.

10. Audit Rights

10.1 Documentation and Information

Airborne HRS will make available to the Client, upon reasonable written request, all information reasonably necessary to demonstrate compliance with the obligations set out in this DPA. Such information will be provided within 15 business days of a written request to legal@airbornehrs.in.

10.2 Audit

Where information provided under Section 10.1 is insufficient to satisfy the Client's compliance obligations under applicable Data Protection Laws, the Client may, with 30 calendar days' advance written notice, request an audit of Airborne HRS's data processing activities. Airborne HRS will cooperate with such an audit, subject to the following conditions:

  • Audits will be conducted at the Client's cost and must not unreasonably interfere with Airborne HRS's operations;
  • Audits are limited to no more than once per calendar year, unless a Personal Data Breach has occurred;
  • Any third-party auditor engaged by the Client must execute a confidentiality agreement acceptable to Airborne HRS before accessing any Airborne HRS systems or documentation;
  • Audit scope must be limited to matters relevant to this DPA and applicable Data Protection Laws.

10.3 Third-Party Certifications

Where such certifications, penetration tests, or assessments have been obtained by Airborne HRS, Airborne HRS may rely on and provide them to satisfy audit requests in whole or in part, subject to appropriate confidentiality protections.

11. Deletion and Return of Data

11.1 On Client Request

The Client may, at any time, request deletion of specific Employee Data records via the HRMS platform (where self-service deletion is available) or by written request to legal@airbornehrs.in. Airborne HRS will complete verified deletion requests within 30 calendar days, subject to any legal retention obligations.

11.2 On Termination of Services

Upon termination or expiry of the Client's subscription, Airborne HRS will:

  • Provide the Client with a 30-day data export window to download Client Data in a structured, commonly used format (CSV or equivalent) via the HRMS platform;
  • Delete or irreversibly anonymise all remaining Client Data within 90 days of the end of the export window, except where retention is required by applicable law;
  • Provide written confirmation of deletion to the Client upon request.

11.3 Legal Retention Obligations

Airborne HRS may retain Client Data beyond the periods above solely to the extent required by applicable Indian law (including financial record retention requirements under Indian tax law — currently 7 years for payment records). Data retained under legal obligation will be isolated, marked accordingly, and not used for any other purpose.

11.4 Data Export Format

Client Data will be made available for export in CSV, JSON, or equivalent machine-readable formats. Airborne HRS does not guarantee the compatibility of exported data with any specific third-party system.

11.5 Webhook and Biometric Event Signal Retention

Biometric event signal data received via the attendance webhook interface (comprising solely employee identifier, timestamp, and event type) will be stored in our active database for a maximum of 90 calendar days. Following this 90-day period, such event signals will be permanently deleted or anonymised, except where aggregate attendance reports derived from this data are explicitly saved by the Client within the HRMS dashboard.

12. Confidentiality

Airborne HRS will treat all Client Data as strictly confidential. Airborne HRS will not disclose Client Data to any third party except:

  • To authorised Sub-Processors listed in Section 5, subject to confidentiality obligations;
  • As required by applicable law, court order, or binding regulatory direction — in which case Airborne HRS will, to the extent permitted by law, provide the Client with prior written notice;
  • With the Client's prior written authorisation.

Confidentiality obligations under this Section survive the termination of this DPA and the underlying Services Agreement for a period of 5 years from the date of termination, or such longer period as required by applicable law.

13. Liability

13.1 Allocation

Each party is responsible for its own compliance with applicable Data Protection Laws. The Client is solely responsible for the lawfulness of its instructions to Airborne HRS and for its obligations as Data Controller. Airborne HRS is responsible for its obligations as Data Processor as set out in this DPA.

13.2 Processor Liability

Airborne HRS is liable to the Client for damage caused by its processing of Client Data only where:

  • It has not complied with obligations under this DPA specifically applicable to Data Processors; or
  • It has acted outside or contrary to the Client's lawful documented instructions.

13.3 Limitation

Airborne HRS's total liability under or in connection with this DPA is subject to the limitation of liability provisions set out in the Terms and Conditions. Nothing in this DPA expands the liability cap set out therein. Nothing in this DPA limits or excludes liability for fraud, fraudulent misrepresentation, or any liability that cannot be limited under applicable law.

14. Duration and Termination

This DPA enters into force when the Client accepts the Terms and Conditions (or executes a Subscription Agreement that incorporates this DPA by reference) and remains in force for the duration of the Client's subscription to the Airborne HRMS Services.

This DPA terminates automatically on the date that is 90 days after the termination or expiry of the Client's subscription, being the date by which data deletion under Section 11.2 is to be completed. Provisions of this DPA that by their nature should survive termination — including Sections 11 (deletion), 12 (confidentiality), and 13 (liability) — will continue in full force after termination.

15. Governing Law

This DPA is governed by the laws of India. Any dispute arising from this DPA that cannot be resolved by good-faith negotiation will be referred to arbitration in accordance with the dispute resolution provisions of the Terms and Conditions.

For Clients in Australia, this DPA must be interpreted and applied consistently with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. For Clients in Qatar, it must be applied consistently with Law No. 13 of 2016.

16. Entire Agreement and Execution

This DPA, together with the Terms and Conditions and any applicable Subscription Agreement, constitutes the entire agreement between the parties with respect to the processing of Client Data by Airborne HRS. In the event of any conflict between this DPA and the Terms and Conditions, this DPA prevails with respect to data protection matters.

Digital Acceptance: This DPA is accepted by the Client digitally at the time of HRMS account activation or subscription commencement. A record of acceptance — including the Client's account identifier, accepting user, IP address, and timestamp — is maintained by Airborne HRS and constitutes valid execution of this DPA for all legal purposes.

Where a signed paper or PDF version is required, please contact legal@airbornehrs.in to arrange a countersigned copy.

Execution — Signed DPA (where required)

Data Processor — Airborne HRS

Signed by:

Kunwar Shatrujit Singh

Proprietor, Airborne HRS

Date: ___________________

Data Controller — Client

Signed by:

Name: ___________________

Designation: ___________________

Company: ___________________

Date: ___________________

Contact for Data Protection Matters

Legal, Privacy & DPA Requests: legal@airbornehrs.in

Breach Notification: legal@airbornehrs.in (mark subject: URGENT — DATA BREACH)

Postal: Kunwar Shatrujit Singh, 37A/13, Defence Colony, Agra, Uttar Pradesh – 282001, India

DPA Version 1.2 — Last reviewed 14 June 2026. For the most current version, visit airbornehrs.in