Griomed Global (“we”, “our”, or “us”) operates the Griomed Global HR management web service and mobile application (collectively, the “Service”). This Privacy Policy explains what personal information we collect, why we collect it, and how we handle it.
If you have any questions, write to privacy@griomedglobal.com.
1. Information we collect
We collect the following categories of information from employees and admins using the Service on behalf of their employer (the “Company”):
1.1 Account & profile
- Name, email, employee code, mobile, role, reporting manager, designation, department, branch.
- Date of birth, gender, blood group, marital status, alternate phone, current and permanent addresses, emergency contact, profile photo.
- Authentication tokens (Sanctum bearer) stored encrypted on the device.
1.2 Attendance
- Check-in / check-out timestamps and the public IP at the time of the action.
- Approximate location (latitude / longitude) only when the employee selects the “Geo-fence” check-in mode. Location is never collected in background.
1.3 Self-service workflow data
- Leave applications, expense claims, daily work reports, comments, attached supporting documents.
1.4 Device & diagnostic
- OS version, device model, app version.
- FCM push token, used solely to deliver notifications the user has opted into.
- Anonymous crash and error reports (Sentry / Firebase Crashlytics).
We do not collect contacts, SMS, browsing history, microphone, or biometric data.
2. How we use information
- To authenticate users and serve their Company’s HR records.
- To run attendance, leave, expense, payroll, and task workflows.
- To send push notifications about approvals, reminders, and announcements.
- To diagnose crashes and improve reliability.
We do not sell personal information to anyone.
3. Storage & security
- Data is stored on our servers at hrms.griomedglobal.com.
- All app↔server traffic uses HTTPS (TLS 1.2+).
- Tokens are kept in Android EncryptedSharedPreferences / iOS Keychain on device.
- Access to Company data inside our backend is restricted by role.
4. Sharing
- Your Company. Managers, HR staff, and admins of your tenant can see your data as part of normal HR operations.
- Service providers. Google Firebase (push), Sentry (crash reports), our hosting provider. Each processes data on our instructions only.
- Legal. When required by law, court order, or to protect our rights.
We do not share data with advertisers.
5. Your rights
- Access & correct — use the Profile screen, or contact your HR admin.
- Delete — write to privacy@griomedglobal.com; we delete within 30 days except where retention is legally required (e.g. payroll under tax law).
- Notifications — disable in your phone Settings.
- Location — switch from “Geo-fence” to “Self” mode in Attendance.
6. Children
The Service is intended for working adults. We do not knowingly collect data from anyone under 18.
7. Changes
We may update this policy from time to time. Material changes will be notified inside the app and via email to the address on file. The “Last updated” date at the top reflects the most recent revision.
8. Contact
Griomed Global
Email: privacy@griomedglobal.com
Web: hrms.griomedglobal.com