Trust centre
Where we actually stand.
Every compliance claim HelloTime makes, with its real status. An attestation is either issued by an independent auditor or it is not, and we would rather you find out here than three weeks into a security review.
This page is generated from a single status registry in our source code. The homepage trust strip, the pricing matrix and this page all read the same file, so they cannot disagree with each other.
Compliance status
GDPR
liveEU data-protection ready — data subject rights and DPA in place
Built and operated to the framework — not third-party audited
DPDP
liveIndia DPDP Act 2023 — data fiduciary and grievance officer published
Built and operated to the framework — not third-party audited
DPA available
liveData Processing Addendum available for enterprise legal review
Document we execute with you
SOC 2 Type II
in progressIndependent Type II audit — controls in place, report not yet issued
Independent third-party audit
We will publish the report here once the auditor issues it. Until then we do not claim it as delivered.
ISO 27001
plannedInformation security management certification
Independent third-party audit
Planned. No certification body engaged yet.
“Self-assessed” means we have built and operate to the framework and can walk you through the controls; it does not mean an auditor has signed anything. We keep the two labels separate on purpose — plenty of vendors do not.
Security posture
- Hosting
- Microsoft Azure, single-cloud. Custom data residency in the Azure region of your choice is available on the Business plan.
- Encryption
- TLS in transit; encryption at rest for the database and for stored files.
- Biometric data
- Face templates are generated, stored and matched on the worker's own device. No biometric template reaches HelloTime servers in normal operation — see the security page for the full architecture and its trade-offs.
- Audit trail
- Attendance corrections record actor, before value, after value and reason. Nobody can approve their own leave.
- Retention
- Screenshot and activity history auto-delete on a plan-based clock (60 days / 180 days / 2 years). Face templates are erased after 30 days of inactivity or on offboarding.
- Sub-processors
- Published and kept current on the sub-processors page.
We have not published a penetration test report or an external dependency-scan result. When we have one to publish, it will appear here rather than in a sales deck.
What has and has not shipped
The same principle applied to product capability. Anything below that is not marked live carries that label everywhere it is marketed — the hero, the pricing matrix, the feature pages.
| Capability | Status |
|---|---|
| Face-recognition clock-in | Early-access pilot — onboarding pilot sites by request |
| GPS geofence + multi-site | Live |
| Tablet kiosk mode | Live |
| Offline clock-in queue | Live |
| WhatsApp / SMS clock-in | Coming soon — waitlist open |
| Leave & shift management | Live |
| Desktop productivity tracker | Live |
| Optional screenshots | Live |
| App & URL tracking | Live |
| Payouts (UPI, Razorpay, PayPal, Wise, Payoneer) | Live |
| Payslip generation | Live |
| Auto-payroll: TDS, PF, ESI, PT, LWF | Private beta — private beta — production rollout in flight |
| Form 24Q + FVU export | Coming soon |
| GST e-invoicing (via HelloBooks) | Private beta — production rollout in flight |
| Pre-loaded national / state holidays | Coming soon |
| AI manager assist | Live |
| Compliance calendar | Live |
| SSO (SAML / OIDC) | Live |
Security review or vendor questionnaire
Email [email protected] with the subject “Security review”. We will tell you what we can evidence and what we cannot, before you spend time on a questionnaire.