1. Who is responsible for your data?
For the processing described in this policy, the Privilix service is operated by Privilix .
Privacy contact: [email protected] .
Privacy grievances may be sent to: [email protected] .
2. Personal data Privilix may process
The information Privilix processes depends on how you interact with the service. It may include:
- Identity information such as your name, work email address and mobile number where supplied.
- Account information including user role, company association and account status.
- Company information including company name, company code and GSTIN where provided.
- Authentication and security information including password hashes, email-verification records, session information, access records and security or audit events.
- Information submitted through Privilix employee or company workspace features.
- Communications sent to Privilix for support, demonstrations, enquiries, privacy requests or service administration.
- Technical and operational information reasonably necessary to secure the service, diagnose problems, prevent abuse and understand platform operation.
Privilix aims to collect and retain only information reasonably necessary for the purpose for which it is being processed.
3. Public website and demo enquiries
You may browse Privilix public information without creating a company workspace.
If you submit a Book a Demo or other public enquiry, Privilix may process the information you provide, which may include your name, work email, company, workforce range, optional phone number and message.
This information is used to respond to the enquiry, prepare an appropriate Privilix walkthrough and maintain reasonable operational and security records.
Submitting a demo enquiry does not create a company workspace, start a trial, approve billing or activate paid membership.
4. Company account and workspace information
When an authorised company representative creates a Privilix workspace, Privilix processes the account and company information presented on the signup form.
This information is used to create, verify, secure and operate the company administrator account and workspace, provide the requested Basic trial, prevent duplicate or unauthorised registration, maintain necessary consent and audit evidence, and provide service communications.
GSTIN is processed only where it is supplied or otherwise required for an applicable business or commercial purpose.
5. Employee accounts and workspace use
Companies may provision authorised employees and administrators into their Privilix workspace.
Depending on the features available to the company, employee account information may be processed to provide recognition, benefits, wellbeing, employee communication, feedback, financial tools, housing, growth, privileges, rewards and other Privilix experiences.
Access remains subject to company membership, role and permission controls and the applicable Privilix feature configuration.
6. Financial calculators and personal financial privacy
Privilix provides guided financial calculators and planning tools for employees.
Calculator information may include values relating to salary, take-home pay, retirement, gratuity, budgeting, savings, loans, housing, work hours, tax, investments or other financial planning topics.
These tools are designed so that an employee's personal calculator inputs and individual results are not exposed to the employee's company through company analytics or administrative views.
Where calculator engagement analytics are provided to a company, they are intended to report aggregate usage or adoption information rather than the employee's underlying personal financial values.
Calculator outputs are informational tools and are not a substitute for personalised financial, legal, tax or investment advice.
7. Company administration and analytics
A company may manage its Privilix workspace, authorised users, administrators, company-provided content and other company-controlled settings.
Company administration does not create an unrestricted right to access private employee information.
Where Privilix provides company analytics, the product is designed to favour aggregate engagement, participation and adoption measures rather than exposing employee-level private financial information.
8. Why Privilix processes personal data
Depending on the relevant interaction, Privilix may process information to:
- Create, verify and secure accounts.
- Create and operate company workspaces.
- Provide trials, memberships and permitted features.
- Provide employee and company experiences.
- Respond to demonstrations, support requests and enquiries.
- Enforce role, permission, membership and tenant boundaries.
- Prevent duplicate, fraudulent, abusive or unauthorised registrations or activity.
- Maintain security, privacy, consent and audit evidence.
- Produce aggregate company engagement information where the applicable Privilix feature supports it.
- Comply with legal obligations and lawful requests.
9. Consent and other permitted processing grounds
Where Privilix relies on consent, the applicable notice describes the relevant information and purpose before consent is requested.
Privilix maintains evidence of applicable consent activity, including relevant notice and policy versions where supported by the product.
Processing may also be necessary to provide a service requested by you or your company, perform an applicable agreement, maintain service security, meet a legal obligation or rely on another basis permitted by law.
Optional consent should not be used as a condition for unrelated processing where that consent is not necessary.
10. Service providers, processors and subprocessors
Privilix may use service providers for functions such as hosting, email delivery, infrastructure, backups, security, monitoring, support or other service operations.
Providers should receive only the information reasonably necessary to perform their role and should be subject to appropriate confidentiality, security and contractual controls.
As part of its privacy-governance programme, Privilix maintains processor and subprocessor assessment information covering matters such as service purpose, data categories, contractual protections, processing location and cross-border considerations where applicable.
11. Data location and international processing
Infrastructure or service providers may process information in different locations depending on the provider and service configuration.
Privilix assesses relevant processing locations, contractual protections, data-location requirements and applicable cross-border transfer considerations when reviewing processors that handle personal data.
Where applicable law requires additional safeguards for an international transfer, Privilix will apply the required control before relying on that transfer arrangement.
12. Data security
Privilix uses technical and organisational safeguards intended to protect personal information.
Depending on the applicable system and information, controls may include:
- Password hashing and authentication controls.
- Email verification and session-security controls.
- Role- and permission-based access control.
- Company tenant isolation.
- CSRF and request-integrity protection.
- Security headers and request validation.
- Security and audit logging.
- Restricted administrative access.
- Secure privacy-request and data-access workflows.
No online service can guarantee absolute security. Privilix reviews and strengthens controls as the platform and its risks evolve.
13. Security incidents and personal-data breaches
Privilix maintains processes for recording and assessing security incidents that may affect personal information.
Where an incident requires notification under applicable law, Privilix will follow the relevant assessment, escalation and notification obligations.
Security incident information may be retained on a restricted basis where necessary for investigation, remediation, compliance or future security improvement.
14. Retention, deletion and anonymisation
Privilix maintains retention and deletion classifications for categories of information used by the platform.
Retention periods may differ depending on the information, purpose, contractual requirement, security need and applicable law.
- Account and employee-profile information is retained while reasonably required to provide and secure the relevant account or workspace.
- Temporary authentication information such as expired reset tokens or revoked credentials should be removed when no longer required.
- User-specific information may be erased or anonymised when the relevant purpose ends, subject to applicable retention requirements.
- Consent evidence, privacy-rights records, security records and necessary audit evidence may be retained where reasonably required for compliance, security, disputes or another permitted purpose.
- Information subject to a mandatory retention requirement may be retained for that required period before deletion or anonymisation.
An erasure request does not necessarily require immediate deletion of every associated record. Information that must temporarily remain identifiable for an applicable legal, security or compliance purpose may be restricted and retained only for that justified purpose.
Information contained in backups is removed through the applicable backup lifecycle. Backups are intended for security and disaster recovery rather than ordinary access to deleted account information.
15. Cookies, sessions and technical storage
Privilix may use cookies, sessions or similar technical mechanisms where required to operate, secure and maintain the website or authenticated workspace.
These mechanisms may support functions such as authentication, session continuity, request security, preferences and abuse prevention.
If Privilix introduces optional analytics, advertising or other non-essential tracking that requires additional notice or consent, that use should be addressed separately before the relevant technology is enabled.
16. Your privacy rights
Subject to applicable law and the circumstances of the processing, you may have rights to:
- Request information about processing.
- Access personal information associated with you.
- Request correction or completion.
- Request erasure where applicable.
- Withdraw consent where processing depends on consent.
- Raise a privacy grievance.
- Exercise other rights available under applicable data-protection law.
If you have a Privilix account, use the Privacy Rights Center for verified in-app privacy requests.
You may also contact [email protected] .
Privilix may need to verify your identity before completing a privacy-rights request.
17. Withdrawing consent
Where processing depends on consent, you may withdraw that consent using the method Privilix provides or by contacting the privacy address above.
Withdrawal does not invalidate processing that was lawful before the withdrawal.
Where the withdrawn processing is necessary to operate an account or feature, withdrawal may mean that the relevant account or feature can no longer be provided, except where processing must continue for another permitted reason.
Signed-in account holders may manage applicable account-processing consent through the Privacy Rights Center .
18. Privacy grievances
Privacy concerns or grievances may be sent to: [email protected] .
Signed-in users may also submit a grievance through the Privacy Rights Center .
Where applicable, you may also use remedies available under relevant data-protection law after using the grievance process provided by Privilix.
19. Third-party services and external links
Privilix may provide access or links to third-party providers, professional services, partner services, affiliate services or other external resources.
A third party may operate under its own terms and privacy practices when you leave Privilix or choose to interact directly with that provider.
You should review the applicable third-party information before providing personal information directly to that service.
20. Children
The current Privilix corporate account experience is not designed for children.
A company should not provision an account for a person below the applicable age threshold unless the legally required process for that use case, including any required consent or verification, has been implemented.
21. Changes to this Privacy Policy
Privilix may update this policy as the platform, service providers, processing activities or legal requirements evolve.
Material updates will be versioned. Where required, Privilix may provide an updated notice or request renewed consent before information is used for a materially different purpose.
22. Contact us
For privacy questions, contact: [email protected] .
For a formal privacy-rights request, you can also use the Privacy Rights Center .