Legal

Privacy Policy

Oasis (Oasis HRMS) · Effective September 3, 2026 · Last updated September 3, 2026

This Privacy Policy describes how Subedge Technology Pvt Ltd (“Company”, “we”, “us”, or “our”), as the developer and legal entity responsible for the mobile application Oasis (also referred to as Oasis HRMS, Application ID com.oasis.hrms), collects, uses, stores, and protects information gathered from users (“you” or “employee”) who download, access, or use our mobile application and related services.

By installing or using Oasis, you agree to the collection and use of information in accordance with this Privacy Policy.

1. Developer and Legal Entity Information

2. Information We Collect and How We Use It

Oasis is an enterprise Human Capital Management (HCM) and Human Resource Management System (HRMS) designed to facilitate workforce operations, attendance recording, payroll management, and employee communication.

Oasis is provided to you through your employer. Your employer determines what information is collected about you and for how long it is retained, and acts as the data controller (or data fiduciary) for that information. Subedge Technology Pvt Ltd processes this information on your employer’s behalf as a data processor. Where a request concerns your employment records, we will coordinate with your employer before acting on it.

A. Location Data

  • What we collect: Precise location (ACCESS_FINE_LOCATION) and approximate location (ACCESS_COARSE_LOCATION).
  • Purpose: To verify employee clock-in and clock-out locations against employer-designated office geofences or designated job sites.
  • Storage and sharing: Location coordinates are recorded only at the moment you record an attendance check-in or check-out. Oasis does not collect location in the background, does not track your location continuously, and does not track you when you are off duty. We never sell location data.

B. Camera and Imagery

  • What we collect: Images captured via your device camera (CAMERA).
  • Purpose: Capturing employee profile pictures; facial verification during attendance clock-in and clock-out to prevent proxy attendance (“buddy punching”); and uploading profile documents, expense claim receipts, and identity proofs.
  • Facial verification: Where your employer enables facial verification for attendance, the image captured at clock-in is transmitted to our servers and compared against the reference photograph held on your employee record. This comparison uses a facial template derived from those images, which constitutes biometric information under some laws. It is used solely to confirm your identity for attendance purposes, is never used for surveillance, identification of third parties, advertising, or training third-party models, and is retained only as long as your employer’s attendance records require.
  • Storage: Captured images are transmitted using encrypted HTTPS/TLS connections and stored in private, access-controlled cloud storage. We do not use your images for marketing and do not share them with third parties other than the sub-processors listed in Section 3.

C. Device Biometric Authentication (Fingerprint and Face Unlock)

  • What we use: Your device’s biometric authentication prompt (USE_BIOMETRIC, USE_FINGERPRINT).
  • Purpose: To provide fast, secure authentication when signing in to the application.
  • Storage: This is separate from the facial verification described in Section 2(B). We do not collect, receive, transmit, or store your fingerprint or device face-unlock data. That authentication is handled entirely on your device by the operating system’s secure hardware enclave, and Oasis receives only a success or failure result.

D. Personal and Employment Information

  • What we collect: Name, corporate email address, employee ID, phone number, job title, department, manager details, leave requests, timesheets, and compensation and payslip records.
  • Purpose: To administer your employment records, process leave, generate payslips, and enable team directory features.

E. Device and Technical Information

  • What we collect: Device model, operating system version, push notification tokens, IP address, and application crash diagnostics.
  • Purpose: To deliver push notifications such as approval alerts and shift reminders, to protect the security of the application, and to diagnose bugs and crashes.

3. Third-Party Services and Sub-processors

To support core functionality, the application relies on the following service providers, who process data strictly on our behalf under data protection agreements and are prohibited from using your personal information for their own purposes:

  • Google Play Services and Firebase: analytics, crash reporting, and Cloud Messaging for push notifications.
  • Supabase: cloud database, authentication, and file storage.
  • Resend: transactional email delivery, including leave approvals, welcome emails, and verification codes.

We do not sell your personal information, and we do not share it with third parties for advertising or independent marketing purposes.

4. Data Security and Retention

  • Encryption: All data in transit is encrypted using industry-standard TLS over HTTPS. Data stored in our databases and storage buckets is encrypted at rest.
  • Access control: Access to employee records is restricted to authorised personnel at your employer and to Subedge staff who require it to operate and support the service.
  • Retention: We retain employee personal data for the duration of your employer’s service agreement with Subedge Technology Pvt Ltd, or for longer where required by applicable labour, tax, and employment law. On termination of that agreement, data is deleted or returned to your employer.

5. Your Rights and Data Deletion

Depending on your jurisdiction, you may have the right to:

  • Request access to the personal data we hold about you.
  • Request correction of inaccurate or incomplete information.
  • Request deletion of your account and personal data.
  • Withdraw consent for optional processing, such as facial verification, where your employer offers a manual alternative.

How to request account and data deletion. You may request deletion of your account and associated personal data by contacting your employer’s HR administrator, or by writing directly to our data privacy team at privacy@subedge.com or ayushbindhani001@gmail.com with the subject line “Oasis Account Deletion Request” and your name and employee ID. We will acknowledge your request and respond within 30 days, coordinating with your employer where their statutory record-keeping obligations require certain data to be retained. Where data must be retained for legal reasons, we will tell you which categories and why.

6. Children’s Privacy

Oasis is an enterprise workforce management tool intended exclusively for working professionals. It is not directed to individuals under the age of 18, and we do not knowingly collect personal information from children. If we learn that we have collected such information, we will delete it.

7. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material change by updating the “Last updated” date above and, where appropriate, by providing an in-app notification.

8. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy, please contact us at: