Worksphere

Employee help & privacy

Privacy Policy

How Worksphere handles information used for your workplace services.

Last updated: 11 September 2026

1. Who this notice covers

Worksphere is a workplace HR management service operated by Innovatesphere Private Limited. This notice describes the employee mobile app, the related HRMS web service and enquiries sent to our support team.

Your employer provisions your account, supplies employment records, decides which HR workflows are enabled and controls access for its authorised staff. We operate the service for participating organisations. Your employer may provide an additional employment privacy notice; contact its HR team about decisions concerning your employment records.

The employee mobile app has no public account registration. It is a workplace service, not a service directed to children.

2. Information processed and why

The information available depends on your employer’s configuration and the features you use. Records can be supplied by you, your employer or an authorised approver.

  • Account and employment information: company and employee codes, name, work contact details, department, designation, work location, reporting relationships and account permissions, to identify you and provide the correct workplace services.
  • Employer-provided HR records may also include birth date, postal address, emergency contacts, bank details and tax or government identifiers such as PAN and Aadhaar. The mobile app does not ask you to supply every underlying HRMS field; availability depends on the record and enabled workflow.
  • Attendance and requests: punch timestamps, attendance records, leave dates, regularization requests, reasons, remarks and approval decisions, to administer attendance and employee requests.
  • Location: latitude and longitude associated with every mobile punch, to record where attendance was submitted and check any applicable workplace location rules. See the location section below.
  • Payroll and tax information: payslips, salary components, tax regime, declarations, forecast information and supporting documents, to provide employee payroll and tax workflows. Employer-held records may also contain bank and statutory identifiers included in those documents.
  • Documents and reading records: files you choose to upload, generated documents, assigned policies, page-reading progress and acknowledgement records, to process evidence and record completion of workplace requirements. Documents and free-text remarks may contain sensitive personal information; provide only what the workflow requires.
  • Service and support information: IP address, browser/device information in request logs, account/activity audit records and the messages or attachments you send to support, to operate the service, investigate problems and handle enquiries.

3. Location and device permissions

The mobile app requests a fresh current location every time you choose Punch In or Punch Out, including unrestricted ANYWHERE attendance mode. ANYWHERE removes the branch-distance restriction; it does not remove the mobile location requirement. The coordinates are sent to the HRMS backend and can be stored with the attendance record. A rejected location check can also create a diagnostic record containing the submitted coordinates. Web attendance continues to follow its separate employer-configured location rules.

The app does not continuously track location or request background location access. You can deny or revoke location permission in your device settings. A mobile punch cannot be completed without enabled location services, permission and a usable fresh location; contact your HR team about an approved alternative. Other enabled features do not need this permission.

Proof uploads use the file picker for the file you choose. Document exports use the device share sheet. The mobile app does not request access to your contacts or microphone and does not scan your full photo library.

4. Who can receive information

Your employer’s authorised HR, payroll and administrative users, and employees assigned to approve a particular workflow, can access records within their permitted scope. Information is not made publicly available through employee mobile screens.

If you are an assigned approver, your permitted queue may include employee or candidate information needed to decide that request. This access is for the assigned workplace purpose, not general access to other people’s records.

The operator identifies Neon and Google services as database and cloud infrastructure providers used for Worksphere, depending on the deployment. These providers process information to provide the service; using them does not mean that information is handled only by your employer. Uploaded documents can be held separately from database records in the configured file or cloud storage.

We do not provide employee information to unrelated operators for their own independent purposes. Necessary hosting, storage, email or support providers, employer-enabled integrations and authorised document recipients may process information to deliver the service.

Information may also need to be disclosed to meet applicable legal obligations, respond to a valid legal request, or protect the service and affected users.

5. Device storage and security

Release connections use HTTPS. Account roles and company scoping restrict access to server records.

The employee mobile app keeps authentication tokens in app memory, rather than persistent browser storage. Logging out clears that local session; restarting after the app process ends requires sign-in again. The web HRMS has a separate browser-persisted sign-in session, so use its logout control on shared computers.

Files prepared for native sharing are placed in app-owned temporary cache storage. The app attempts to clear that sharing cache at its next launch and at logout. Device or browser caches and copies exported to other apps may have different lifetimes. Clearing the app or logging out does not delete employer-held server records.

6. Retention and deletion

Our retention approach is to keep personal information only while needed for the workplace services described in this notice, lawful employer recordkeeping, applicable legal obligations and the resolution of active claims or disputes. Retention is assessed by the type of information, its purpose and the employer’s lawful instructions, rather than one fixed period for all records.

Ending employment or a client relationship, disabling an account, cancelling a request or uninstalling the app does not itself erase employment, attendance, payroll, tax, document or audit records. Relevant information may still be needed for the purposes above. When those reasons no longer apply, the information is to be deleted or irreversibly anonymised through an authorised process, unless applicable law requires continued retention.

You may request access, correction or deletion through support@innovatesphere.in. The Customer Support team handles these requests and coordinates with the relevant employer, including verification of identity and authority where needed. A deletion request must be assessed against applicable rights and any lawful need to retain particular records. Where information must be retained, the reason and available options should be explained. Account deactivation alone is not data deletion.

Database records, uploaded documents and backups can have different storage lifecycles. Deletion from an active system does not necessarily remove an existing backup copy at the same time. Backup copies may remain until removed or overwritten under the applicable backup arrangements. Approved deletion requests also need to be considered when restoring data from a backup. This notice does not promise immediate erasure from every copy.

7. Your choices and requests

Use your device settings to change location permission, and choose which files you upload or share. Contact HR to correct employment data or ask about required workplace processing. Where a processing activity depends on consent, you can ask how to withdraw that consent; withdrawal does not itself remove records that must otherwise be retained.

The Customer Support team monitors support@innovatesphere.in and handles support, privacy and data-deletion requests, coordinating with the relevant employer where needed. For access, correction, deletion, privacy concerns or complaints, use the subject “Worksphere privacy request”. Provide only enough information to identify the relevant organisation and issue. Do not send your password, one-time codes, complete bank details or identity documents in an initial email. Support can explain a suitable verification route if one is needed.

The rights and response obligations that apply depend on the relevant law and the circumstances of the request. This notice does not limit rights available under applicable law.

8. Changes to this notice

When data handling changes, this notice should be updated with a new date. Material changes may also require a notice through the service or your employer, and additional permission where required. Review this page before using a newly introduced feature.

Contact the operator

Innovatesphere Private Limited

C/216/SF, SAFAL BUSINESS PARK 2, Behind Vanijya Bhavan, Kankariya, Ahmedabad - 380022

Email a privacy request