Legal & Compliance

Privacy Policy

We believe privacy is a fundamental right, not a checkbox. This policy explains precisely how Chillsoft collects, uses, protects, and respects your personal information across every product and service we offer.

📅 Last updated: January 2025
🏢 Chillsoft Private Limited
📍 Chennai, India · Effective globally
Section 01

Who We Are

Chillsoft Private Limited ("Chillsoft", "we", "us", or "our") is an enterprise Human Capital Management (HCM) software company headquartered at No. 82 (116), Velachery Main Road, Saidapet, Chennai — 600015, Tamil Nadu, India. We operate the Chillsoft platform, including Theo AI, ChillPay, ChillStat, ChillFix, Chill Vybes, OKR & PMS, Time & Attendance, Recruitment Tracking, Employee Care, and all associated mobile and web applications (collectively the "Services").

For the purposes of applicable data protection law — including the EU General Data Protection Regulation (GDPR), UK GDPR, and India's Digital Personal Data Protection Act (DPDPA) — Chillsoft acts as a data processor on behalf of our enterprise customers (who are the data controllers) for employee and candidate data processed through the platform. Chillsoft acts as a data controller in its own right for data collected through our website, marketing activities, and account management.

📋 Data Controller Contact

Data Protection queries: reachus@chillsoft.in · Postal: Chillsoft Private Limited, No. 82 (116) Velachery Main Road, Saidapet, Chennai-600015, Tamil Nadu, India · Phone: +91 9600 122 973

Section 02

Data We Collect

We collect personal data in two primary capacities — as a controller (website visitors, prospects) and as a processor (enterprise customer employee data).

CategoryExamplesSourcePurpose
Identity DataFull name, employee ID, date of birth, gender, nationalityCustomer/employee inputAccount creation, HR administration
Contact DataWork email, personal email, phone, home addressCustomer/employee inputCommunication, payroll, compliance
Employment DataJob title, department, salary, benefits, performance reviews, attendance, leave recordsEmployer administratorHR process automation
Payroll DataBank account details, tax identification numbers, statutory deductionsEmployer / employeeSalary processing (ChillPay)
Location DataGPS coordinates, geo-fence check-ins, IP addressMobile app / deviceTime & attendance, remote work management
Device & Usage DataOS version, device type, browser, session logs, feature usageAutomated collectionPlatform improvement, security
Candidate DataCV/Resume, education, work history, interview notesJob applicantsRecruitment (via employer's use of platform)
Website Visitor DataName, work email, company, IP address, cookie identifiersContact forms, cookiesDemo requests, marketing, analytics
✅ Data Minimisation Principle

We only collect data that is strictly necessary for the specified purpose. We do not collect sensitive personal data (health, biometric, political views) unless explicitly required by your employer's use case and with appropriate legal safeguards in place.

Section 03

How We Use Data

🤖
Platform Delivery
To operate, maintain, and improve the Chillsoft HCM platform including Theo AI, payroll, attendance, performance, and all modules.
📊
Analytics & Insights
Aggregated, anonymised analytics to improve platform performance, detect usage patterns, and develop new features.
🔒
Security & Fraud Prevention
To monitor for suspicious activity, prevent unauthorised access, and maintain audit trails for compliance and security investigations.
📨
Communications
Transactional notifications, product updates, support responses, and (with consent) marketing communications about Chillsoft products.
⚖️
Legal Compliance
To fulfil legal obligations including tax reporting, statutory HR compliance, court orders, and regulatory requests from competent authorities.
🌍
Cross-Border Support
To deliver customer support from our Chennai headquarters while ensuring data remains in authorised cloud regions per your configuration.
Section 05

Data Sharing

We do not sell, rent, or trade personal data. We share data only in the following circumstances:

  • 🏢
    Your Employer (Data Controller)

    Employee data is shared with and controlled by the enterprise customer (your employer) who has deployed the Chillsoft platform. Chillsoft acts only on their documented instructions.

  • ☁️
    Cloud Infrastructure Providers

    Microsoft Azure and AWS host our platform data in dedicated Virtual Private Clouds across our authorised regions (Central India, Singapore, North Europe, South East Asia, UAE). These providers are bound by Data Processing Agreements and certified to ISO 27001, SOC 2, and GDPR standards.

  • 🔧
    Sub-Processors

    Carefully vetted third-party service providers (e.g. email delivery, payment gateways, customer support tools) access only the minimum data necessary under strict contractual data processing agreements. A full Sub-Processor List is available upon request.

  • ⚖️
    Legal Authorities

    We may disclose data when required by applicable law, court order, or legitimate regulatory authority request. We will notify you where legally permitted to do so.

  • 🔄
    Business Transfers

    In the event of a merger, acquisition, or asset sale, personal data may be transferred to the acquiring entity, subject to the same privacy protections and with advance notice to affected parties.

Section 06

Storage & International Transfers

Chillsoft stores customer data in the following cloud regions, selected based on your geographic location and contractual requirements:

🇮🇳
Central India
Primary region for Indian and South Asian enterprise customers. Microsoft Azure Central India data centre with full data sovereignty.
🇸🇬
Singapore (SEA)
South-East Asia cluster serving APAC enterprise customers. Azure Southeast Asia, compliant with Singapore PDPA.
🇪🇺
North Europe
EU/EEA region for European customers. Fully GDPR-compliant, data never leaves the EEA without adequate safeguards.
🇦🇪
UAE
Middle East and Africa cluster. Compliant with UAE Federal Data Protection Law and local data residency requirements.
🇺🇸
United States
US enterprise customers. AWS US East/West regions with SOC 2 Type II certification and CCPA compliance.
🔐
Dedicated VPCs
All regions operate in non-promiscuous, isolated Virtual Private Clouds with network segmentation, IAM controls, and end-to-end encryption.
🌍 Cross-Border Transfer Safeguards

Where data is transferred outside the EEA, we rely on EU Standard Contractual Clauses (SCCs), adequacy decisions, or Binding Corporate Rules. Support access from our Chennai headquarters does not result in customer data being stored in India; it is accessed securely via encrypted channels and governed by strict access controls and audit logs.

Section 07

Data Backup & Business Continuity

Chillsoft operates a world-class, multi-tier backup and disaster recovery infrastructure to ensure your data is always protected, available, and recoverable. Our backup architecture is designed to meet enterprise SLA commitments with zero tolerance for data loss.

⏱️ Backup Frequency

Every 6 hours — Full incremental backups are executed automatically every six hours across all customer data partitions, ensuring a maximum data exposure window of 6 hours in any worst-case scenario. Critical payroll and financial data is additionally backed up on a 1-hour rolling snapshot schedule.

⏱️
Every 1 Hour — Critical Financial Data Snapshot

ChillPay payroll data, salary records, and financial transactions undergo rolling 1-hour snapshots with point-in-time recovery (PITR). These snapshots are stored in encrypted, geo-redundant storage containers separate from primary application storage.

🔄
Every 6 Hours — Full Incremental Platform Backup

All customer data — HR records, attendance, performance data, documents, configurations — is captured in a full incremental backup every six hours (00:00, 06:00, 12:00, 18:00 UTC). Each backup is cryptographically hashed, compressed, and encrypted at rest using AES-256.

🌙
Daily — Full Differential Backup

A complete differential backup is performed nightly at 02:00 UTC. This creates a full baseline from which any 6-hour incremental can be applied. Daily backups are retained for 30 days in primary storage with geographic replication.

📅
Weekly — Long-Term Archive Backup

Weekly full backups are archived for 12 months in cold storage (Azure Archive / AWS Glacier). These are integrity-checked monthly and can be restored within 4 hours for compliance and audit purposes.

📦
Monthly — Compliance Archive

Monthly consolidated backups are retained for a minimum of 7 years (84 months) in compliance with statutory requirements including India's IT Act, GDPR Article 5(1)(e), and US labour laws. These are stored in tamper-evident, write-once storage.

🌍
Continuous — Cross-Region Geo-Replication

All backups are asynchronously replicated to a secondary cloud region within 15 minutes of creation. This provides geographic redundancy — if an entire cloud region fails, backup data remains intact and recoverable from the secondary region.

🧪
Quarterly — Backup Restoration Testing

Every quarter, our infrastructure team conducts a full disaster recovery drill — selecting random customer data partitions and performing a complete end-to-end restoration to a staging environment to verify backup integrity and measure actual RTO/RPO achievement.

MetricTargetAchieved
RPO (Recovery Point Objective)< 6 hours✅ < 6 hours (incremental) / < 1 hour (financial)
RTO (Recovery Time Objective)< 4 hours✅ < 2 hours for critical systems
Backup Success Rate99.99%✅ 99.99% verified monthly
Backup EncryptionAES-256 at rest✅ AES-256 + TLS 1.3 in transit
Geo-Redundancy2 regions minimum✅ 2–3 regions per customer geography
Backup Retention (Standard)30 days incremental✅ 30 days incremental, 12 months weekly
Compliance Retention7 years✅ 7 years write-once archive
Section 08

Data Retention

We retain personal data only for as long as is necessary for the purpose for which it was collected, or as required by applicable law. The following retention periods apply:

Data TypeRetention PeriodBasis
Active employee HR recordsDuration of employment + 7 yearsLegal obligation, statutory audit
Payroll and financial data7 years post-terminationTax law, labour law, audit requirements
Candidate/applicant data2 years from application dateLegitimate interest, legal compliance
Access and audit logs3 yearsSecurity, regulatory compliance
Website visitor / demo request data3 years from last contactLegitimate interest (CRM)
Cookie consent records3 yearsGDPR accountability obligation
Backup archives7 years (monthly), 30 days (incremental)Compliance, disaster recovery
Marketing contact dataUntil opt-out + 30 days suppression listConsent

After the applicable retention period, data is securely deleted using NIST SP 800-88 compliant data sanitisation methods. Deletion is logged and available for audit.

Section 09

Your Rights

Depending on your location, you have the following rights regarding your personal data. Note: If you are an employee using Chillsoft through your employer, many of these rights should be exercised through your employer (the data controller). We will assist employers in fulfilling these requests.

  • 👁️
    Right of Access (Art. 15 GDPR)

    You have the right to obtain confirmation of whether we process your personal data and to receive a copy of that data, along with information about how it is processed.

  • ✏️
    Right to Rectification (Art. 16 GDPR)

    You have the right to have inaccurate personal data corrected or incomplete data completed without undue delay.

  • 🗑️
    Right to Erasure / "Right to Be Forgotten" (Art. 17 GDPR)

    You may request deletion of your personal data where it is no longer necessary for the purpose it was collected, where you withdraw consent, or where processing is unlawful — subject to our legal retention obligations.

  • ⏸️
    Right to Restriction of Processing (Art. 18 GDPR)

    You may request that we restrict how we process your data in certain circumstances, such as while accuracy is contested or while an objection is being considered.

  • 📤
    Right to Data Portability (Art. 20 GDPR)

    Where processing is based on consent or contract and carried out by automated means, you may receive your data in a structured, commonly used, machine-readable format and transmit it to another controller.

  • 🚫
    Right to Object (Art. 21 GDPR)

    You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds.

  • 🤖
    Right Not to Be Subject to Automated Decisions (Art. 22 GDPR)

    You have the right not to be subject to decisions based solely on automated processing (including profiling) that produce significant legal effects, without human review.

  • ↩️
    Right to Withdraw Consent

    Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.

  • 📣
    Right to Lodge a Complaint

    You have the right to lodge a complaint with your local supervisory authority (e.g. the ICO in the UK, your country's Data Protection Authority in the EU, or India's Data Protection Board under the DPDPA).

📬 How to Exercise Your Rights

Submit a Data Subject Request (DSR) to reachus@chillsoft.in with subject line "Data Subject Request — [Your Name]". We will respond within 30 days (extendable to 90 days for complex requests, with notice). Identity verification will be required before processing requests.

Section 10

Children's Privacy

The Chillsoft platform is an enterprise B2B software solution intended exclusively for use by organisations and their adult employees (18 years and older). We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have inadvertently collected data from a minor, we will promptly delete such data and notify the relevant employer.

Section 11

Security Measures

Chillsoft implements comprehensive technical and organisational security measures aligned with ISO 27001, SOC 2 Type II, and NIST cybersecurity frameworks:

🔐
End-to-End Encryption
AES-256 encryption at rest, TLS 1.3 in transit. All database fields containing PII are individually encrypted. Encryption keys are rotated quarterly and managed via HSM.
🏰
Dedicated VPCs
Hosted in isolated Virtual Private Clouds in non-promiscuous mode with network segmentation, WAF, DDoS protection, and intrusion detection systems.
🪪
IAM & Zero Trust
Role-based access control (RBAC) with multi-factor authentication enforced for all administrative access. Principle of least privilege applied throughout.
📋
Audit Trails
Comprehensive, tamper-evident audit logs for all data access, modifications, and administrative actions. Logs are retained for 3 years and available for customer audit upon request.
🔍
Vulnerability Management
Regular penetration testing by certified third-party security firms. Automated SAST/DAST scanning in CI/CD pipelines. Bug bounty programme available for responsible disclosure.
🚨
Incident Response
GDPR Article 33/34 compliant breach notification process. Data breaches reported to supervisory authorities within 72 hours and to affected data subjects without undue delay where risk is high.
Section 12

Cookies & Tracking

Our website uses cookies and similar tracking technologies. For full details on the types of cookies we use, their purposes, and how to manage your preferences, please see our Cookie Policy.

Section 13

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in law, our data practices, or our business. We will notify you of material changes by posting the updated policy on this page with a revised "Last Updated" date. For significant changes that materially affect your rights, we will provide prominent notice via email or in-product notification at least 30 days before the change takes effect. Continued use of our services after the effective date constitutes acceptance of the updated policy.

Section 14

Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our Data Protection team:

📬 Data Protection Contact

Email: reachus@chillsoft.in
Phone (India): +91 9600 122 973
Phone (US): +1 (408) 401-6054
Postal Address: Data Protection Officer, Chillsoft Private Limited, No. 82 (116), Velachery Main Road, Saidapet, Chennai — 600015, Tamil Nadu, India
Response Time: We aim to acknowledge all privacy queries within 2 business days and provide a substantive response within 30 days.

Questions About Your Data?

Our Data Protection team is here to help. Reach out and we'll respond within 2 business days.

Contact Our Team →