Skip to content

New: HelloTime now integrates with HelloBooks — sync clients, hours, invoices and payroll.

Trust centre

Where we actually stand.

Every compliance claim HelloTime makes, with its real status. An attestation is either issued by an independent auditor or it is not, and we would rather you find out here than three weeks into a security review.

This page is generated from a single status registry in our source code. The homepage trust strip, the pricing matrix and this page all read the same file, so they cannot disagree with each other.

Compliance status

  • GDPR

    live

    EU data-protection ready — data subject rights and DPA in place

    Built and operated to the framework — not third-party audited

    Read the GDPR documentation

  • DPDP

    live

    India DPDP Act 2023 — data fiduciary and grievance officer published

    Built and operated to the framework — not third-party audited

    Read the DPDP documentation

  • DPA available

    live

    Data Processing Addendum available for enterprise legal review

    Document we execute with you

    Read the DPA available documentation

  • SOC 2 Type II

    in progress

    Independent Type II audit — controls in place, report not yet issued

    Independent third-party audit

    We will publish the report here once the auditor issues it. Until then we do not claim it as delivered.

  • ISO 27001

    planned

    Information security management certification

    Independent third-party audit

    Planned. No certification body engaged yet.

“Self-assessed” means we have built and operate to the framework and can walk you through the controls; it does not mean an auditor has signed anything. We keep the two labels separate on purpose — plenty of vendors do not.

Security posture

Hosting
Microsoft Azure, single-cloud. Custom data residency in the Azure region of your choice is available on the Business plan.
Encryption
TLS in transit; encryption at rest for the database and for stored files.
Biometric data
Face templates are generated, stored and matched on the worker's own device. No biometric template reaches HelloTime servers in normal operation — see the security page for the full architecture and its trade-offs.
Audit trail
Attendance corrections record actor, before value, after value and reason. Nobody can approve their own leave.
Retention
Screenshot and activity history auto-delete on a plan-based clock (60 days / 180 days / 2 years). Face templates are erased after 30 days of inactivity or on offboarding.
Sub-processors
Published and kept current on the sub-processors page.

We have not published a penetration test report or an external dependency-scan result. When we have one to publish, it will appear here rather than in a sales deck.

What has and has not shipped

The same principle applied to product capability. Anything below that is not marked live carries that label everywhere it is marketed — the hero, the pricing matrix, the feature pages.

CapabilityStatus
Face-recognition clock-inEarly-access pilot — onboarding pilot sites by request
GPS geofence + multi-siteLive
Tablet kiosk modeLive
Offline clock-in queueLive
WhatsApp / SMS clock-inComing soon — waitlist open
Leave & shift managementLive
Desktop productivity trackerLive
Optional screenshotsLive
App & URL trackingLive
Payouts (UPI, Razorpay, PayPal, Wise, Payoneer)Live
Payslip generationLive
Auto-payroll: TDS, PF, ESI, PT, LWFPrivate beta — private beta — production rollout in flight
Form 24Q + FVU exportComing soon
GST e-invoicing (via HelloBooks)Private beta — production rollout in flight
Pre-loaded national / state holidaysComing soon
AI manager assistLive
Compliance calendarLive
SSO (SAML / OIDC)Live

Security review or vendor questionnaire

Email [email protected] with the subject “Security review”. We will tell you what we can evidence and what we cannot, before you spend time on a questionnaire.