GroundIT Privacy Policy

Sysmedac Technologies · Last updated 25 August 2026

This explains what GroundIT does with personal data: what the app collects, why, who else gets to see it, how long it stays, and what you can do about it. It covers the GroundIT mobile app, the web portal and the APIs behind both.

If you use GroundIT because you work somewhere that subscribes to it, read section 1 first. Your employer, not Sysmedac, decides most of what happens to your data, and knowing that saves you asking the wrong party.

1. Who we are, and which side of this we are on

GroundIT is HR, payroll and workforce software made by Sysmedac Technologies. Almost everyone who opens this app does so because their employer subscribes to it. That matters for privacy, because it decides who is answerable for what.

So if you ask us to change your designation or delete your attendance history, we usually cannot do that on our own authority. We will tell you so plainly and pass the request to your employer rather than sit on it. Where we do act for ourselves — our website, sales enquiries, support tickets you raise with us directly — we are the controller and this policy applies to us in that role too.

2. What the app collects

Data your employer puts in

Your name, employee code, business contact details, department, designation, reporting line, joining date, work location, and the employment terms that payroll needs: salary structure, bank account for salary credit, and the statutory identifiers required for filings in your country (in India that means PAN, UAN or PF number, ESIC number, and professional tax details where applicable). Leave balances, attendance records, appraisal ratings and disciplinary records live here too, if your employer uses those modules.

Data you give us yourself

A profile photo if you upload one. Documents you attach — identity proofs, education certificates, medical bills, expense receipts. Text you write: leave reasons, expense notes, helpdesk tickets, goal descriptions, feedback and appraisal comments. Emergency contact and personal details, where your employer asks for them and you choose to fill them in.

Data the app records as you use it

The app carries no advertising SDKs and no cross-app trackers. We do not build advertising profiles, and we have nothing to sell to a data broker.

3. Device permissions the mobile app asks for

Each permission is requested at the moment it is first needed, with the reason on screen, and each one can be refused. Refusing narrows what the app can do; it does not lock you out.

4. Face data, in plain terms

Some employers require a face check at clock-in so that one person cannot punch in for another. This is off unless your employer turns it on, and where the law requires your consent first, the app asks for it and records the answer.

When you enrol, the photo is converted into a mathematical template — a set of numbers that describes the geometry of your face. Later punches are converted the same way and compared against your own template. We store the template, not a face album. The template is used for one purpose only, is never shared with another employer or any third party, is not used to identify you anywhere else, and is deleted when your enrolment is revoked or your employment ends, subject to the retention rules in section 8.

If you would rather not enrol, say so to your employer. The system supports attendance without a face check, and whether to allow that is their call, not ours.

5. Why we use any of it

We do not sell personal data. We do not share it for advertising. We do not use your employment data to train general-purpose AI models.

6. Who else sees it

7. How it is protected

Traffic between the app and our servers is encrypted with TLS. Data at rest is encrypted. Each customer's data sits behind tenant isolation enforced in the database itself, not merely by application code, so a query cannot wander into another company's records. Administrative access is limited to staff who need it, requires multi-factor authentication, and is written to an audit log that ordinary users, including our own engineers, cannot edit or delete.

No system is perfectly safe, and we will not pretend otherwise. If a breach affects your data we notify your employer without undue delay, help them work out the impact, and report to the Data Protection Board of India or the relevant regulator where the law requires it.

8. Where it is stored, and for how long

Data is hosted on servers in the region agreed with your employer; for Indian customers that means India. Retention is largely not our choice. Payroll and statutory records must be kept for years under tax, provident fund and labour law, and your employer sets the retention period within those limits.

When your employer's subscription ends they can export their data. After the agreed grace period we delete it from live systems, and backups age out on their own schedule. One exception is worth stating clearly: the audit trail — a record that an action happened, and by whom — survives the deletion of the data it refers to. It has to, or the log would be worthless as evidence.

9. Your rights, and how to use them

Depending on where you live you can ask to see the personal data held about you, have inaccurate data corrected, ask for erasure, withdraw a consent you gave earlier, nominate someone to act for you if you die or become incapacitated, and complain to a regulator.

There are two routes:

We aim to respond within 30 days. If we cannot do what you asked, we will say why rather than let the request lapse quietly. If you are not satisfied, you can escalate to your employer's grievance officer, or to the Data Protection Board of India.

10. Deleting your account

A GroundIT login belongs to the employment relationship, so you cannot delete it yourself the way you would a social media account — your employer needs the record while you work there, and the law needs parts of it afterwards. To ask for deletion, raise an erasure request under Profile → Privacy, or email support@sysmedac.com. We will confirm what can be deleted, what has to be retained and for how long, and who is making that decision.

Two things are removed on request without argument, since nothing legal depends on them: your face enrolment template, and your push notification token.

11. Children

GroundIT is workplace software and is not meant for children. We do not knowingly create accounts for anyone below the minimum legal working age in their country. If you think a child's data has ended up here, write to us and we will remove it.

12. Changes to this policy

When the product changes in a way that affects your privacy — a new category of data, a new sub-processor, a new permission — this page changes with it, and the date at the top moves. For anything significant we also notify subscribing organisations directly, so that they can pass it on. Old versions are kept and can be produced on request.

13. Contact

Sysmedac Technologies — GroundIT
Privacy queries and grievances: support@sysmedac.com

If your employer has named its own privacy or grievance officer, they are the faster route for anything about your own employment record, and we will point you to them.