Privacy policy
Privacy Policy
Draft last updated 12 July 2026.
What this covers
This policy applies to the LekhaHR marketing site and the LekhaHR application. It's written for the two audiences who interact with the product: the company that subscribes ("customer") and the employees whose records a customer's admins enter.
What we collect
The application holds the employee, attendance and leave records that a customer's admins enter or that employees submit themselves — names, contact details, job details, attendance punches, leave requests and the documents attached to them. Some fields, like PAN, are stored masked with the raw value encrypted; see how we build for security for the practices behind that.
Attendance can capture location at the moment of a punch, to validate a configured office geofence. It does not track movement in the background or build a travel history between punches. A punch-in selfie, where used, is stored privately and deleted automatically after 30 days.
The marketing site itself does not run a contact form; email sent to hello@lekhahr.com is handled like any other email you send us.
How we use it
Data entered into LekhaHR is used to operate the product for the customer that owns it — running attendance, leave and employee-record workflows, and letting employees see their own information. We do not sell employee or customer data.
Who can see it
Access follows the role assigned within a customer's account. Field-level restrictions (for example, hiding finance details from a manager's view of a report) are enforced on the server, not just in what the interface displays. See our security practices for more detail.
Retention
Some records, like statutory and audit-relevant history, are expected to be retained after an employee's record becomes inactive; punch-in selfie evidence is deleted automatically after 30 days. Specific retention periods for every data category are still being finalized as part of legal review and will be published here once settled — we are not stating fixed retention guarantees on this draft.
Third parties
We rely on infrastructure providers to run the product (for example, database and file-storage hosting). We are not publishing a named list of processors on this draft page; that list will be added once legal review is complete.
Your choices and requests
If you want to ask about, correct or request removal of data associated with you, email hello@lekhahr.com. For an employee record entered by a customer's admin, we will generally direct the request to that customer first, since they own the record.
Changes to this policy
We expect this policy to change materially once legal review is complete and again as new modules ship. We'll update the date at the top of this page when that happens.
Contact
Questions about this draft: hello@lekhahr.com.