Privacy Policy
Last updated: 25 April 2026
1. Who we are
FactoryHUBx LabourFlow (“LabourFlow”, “we”, “us”) is a contract-labour management platform for Indian factories. The service is operated by [OPERATOR-NAME](the “Operator”), the legal entity behind FactoryHUBx. This policy explains what personal data LabourFlow handles, why, and on what legal basis.
2. Data we collect
LabourFlow handles personal data about four kinds of people: the tenant-owner (factory owner / operator), their HR / staff users, the contractors they engage, and the labour (workers) those contractors supply. Depending on the role, we may collect:
- Full name, contact phone in E.164 format, and email where given.
- Profile photo and biometric-style facial reference used only for in-person attendance verification at factory gates.
- Government-issued ID document images (Aadhaar, PAN, voter ID, driving licence, etc.) for KYC and statutory filings. ID numbers are masked at rest; full values are envelope-encrypted per ADR-2026-04-25-secrets-at-rest.
- Engagement records (which contractor, which factory, which shift), attendance scans, leave records, and payable / payout data required to run statutory wage compliance.
- Operational metadata: device fingerprint of the gate scanner, IP and timestamp of each event, and the correlation ID we attach to every request for audit.
3. Why we collect it
The platform is built around legal obligations imposed on factory operators in India. We collect this data to:
- Enable a tenant-owner to comply with the Contract Labour (Regulation & Abolition) Act 1970 (CLRA), the Factories Act 1948, and ESI / EPF obligations.
- Operate the tenant’s own day-to-day labour engagement and attendance.
- Produce wage statements, statutory registers, and audit trails the tenant-owner is required to keep.
- Authenticate users and prevent unauthorised access to tenant data.
We do not sell personal data, we do not share it with advertisers, and we do not use it to train third-party AI models.
4. Who sees what
LabourFlow enforces strict data scoping per ADR-2026-04-24-config-scope-and-whitelabel:
- A tenant-ownersees only data inside their own tenant. They cannot see another factory’s data.
- A contractor sees only their own engagements, their own labour roster, and their own payouts.
- A worker sees only their own profile and attendance through the contractor portal.
- FactoryHUBx platform administrators may access tenant data cross-tenant for support, incident response, and audit. Every such access is itself logged in an audit trail.
5. Where data lives
Production data is hosted in an Indian data centre on [VERIFY-DC] (target: Hostinger VPS, India region). We do not transfer personal data of Indian residents outside India.
We use the following categories of subprocessor. Specific names will be listed and kept current here as each goes live:
- Messaging (WhatsApp / SMS / voice notifications):
[SUBPROC-TWILIO]. - Transactional email:
[SUBPROC-EMAIL]. - Object storage for ID and photo blobs:
[SUBPROC-OBJECT-STORAGE].
6. How long we keep it
Retention is governed per tenant-owner via owner_policy_packs. The August 2024 default policy pack (overridable per tenant within legal bounds) is:
- Unused intake records: deleted after
unused_intake_delete_days = 7days. - Inactive labour photos: retained for
inactive_labor_photo_retention_days = 90days, then removed. - Inactive labour profiles are masked after
profile_mask_days = 365days, then anonymised, then permanently deleted on a schedule defined in module 18 (privacy-lifecycle).
Statutory records that the Factories Act / CLRA / wage law requires a factory operator to retain are kept for the legally mandated period even after a worker becomes inactive.
7. Your rights
Subject to applicable law (IT Act 2000 §43A, the SPDI Rules 2011, and the Digital Personal Data Protection Act 2023) you have the right to:
- Access the personal data we hold about you.
- Ask us to correct it if it is inaccurate.
- Ask us to delete it, subject to statutory retention obligations.
- Request a portable copy in machine-readable form.
- Withdraw consent for any processing that relies on consent.
How to exercise these rights:
- Contractors and workers: use the in-product DSR controls inside /contractor/portal.
- HR / owner users: raise the request from inside the LabourFlow web app, or email
[SUPPORT-EMAIL].
8. Security
We protect personal data with the following technical measures:
- Passwords are stored as bcrypt hashes; we never see the plaintext.
- Authentication tokens are signed RS256 ID tokens issued by our SSO (LSAuth) per ADR-2026-04-24-sso-central-service.
- Sensitive identifiers (Aadhaar / PAN etc.) are masked at rest and envelope-encrypted via KMS per ADR-2026-04-25-secrets-at-rest.
- Database uniqueness is enforced at the schema level (partial unique constraints on tenant + identifier).
- All traffic between the browser, the API, and SSO is TLS-encrypted.
9. Children
LabourFlow is a B2B service for licensed factory operators and their contractors. We do not knowingly collect personal data from anyone under 18. The contractor onboarding a worker is responsible for verifying the worker’s age against a government ID before adding them to the platform.
10. Cookies
We set only first-party session cookies necessary to keep you signed in:
lf_session— HR / owner SSO session.lf_contractor_session— contractor portal session.lf_contractor_scope— current contractor tenant scope.refresh_token— SSO refresh, http-only.
We do not use analytics, advertising, or third-party tracking cookies in v1.
11. Changes to this policy
We will update this policy as the product, our subprocessors, or applicable law change. The “Last updated” date at the top will move whenever we revise it. For material changes affecting tenant-owners, we will additionally notify the registered owner contact by email.
12. Contact
Privacy questions, DSR requests, and grievances:
Email: [SUPPORT-EMAIL]
Registered office: [REGISTERED-ADDRESS]
