Privacy Policy
Last Updated: December 13, 2025
IMPORTANT: This Privacy Policy governs the collection, processing, and storage of biometric data and personal information by SuperGrid. By using our services, you acknowledge and consent to the practices described herein, as required under the Digital Personal Data Protection Act, 2023 and Information Technology Act, 2000.
1. Introduction
SuperGrid ("we," "us," "our") is operated by NeuralNetworki.ng. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our facial recognition and GPS-based attendance verification system (the "Service").
2. Data Controller and Contact Information
Data Controller: NeuralNetworki.ng
Contact Email: hello@neuralnetworki.ng
Contact Phone: +91 87458 84947
Grievance Officer: Samnit Mehandiratta, Founder
3. Legal Basis for Processing
We process personal data and biometric information under the following legal bases:
- Consent: Explicit consent obtained from employees for biometric data processing
- Contractual Necessity: Processing necessary to fulfill our service agreement with the employer
- Legal Obligation: Compliance with Indian employment and tax laws
- Legitimate Interest: Fraud prevention and accurate attendance tracking
4. Information We Collect
4.1 Biometric Data (Sensitive Personal Data)
We collect and process the following biometric information:
- Facial Recognition Data: Mathematical representations (facial encodings) derived from facial images. These are 128-dimensional numerical vectors that cannot be reverse-engineered to reconstruct the original photograph.
- IMPORTANT: We do NOT store photographs or images. Only irreversible mathematical encodings are stored.
- Liveness Detection Data: Temporary analysis to verify the presence of a live person (not stored after verification)
4.2 Location Data
- GPS coordinates at time of attendance marking
- Geofencing verification data
- Timestamps of location capture
4.3 Personal Information
- Name and employee identification number
- Mobile phone number
- Email address
- Employer name and work location
- Attendance records and timestamps
- Device information (model, OS version, IP address)
4.4 Usage Data
- Login times and session duration
- App usage patterns
- Error logs and diagnostic data
5. How We Use Your Information
We use collected data for the following purposes:
- Identity Verification: Matching facial encodings to verify employee identity
- Location Verification: Confirming employees are at authorized work locations
- Attendance Tracking: Recording clock-in/clock-out times
- Fraud Prevention: Detecting and preventing buddy punching and time theft
- Payroll Support: Generating timesheet data for employer payroll processing
- Service Improvement: Analyzing usage patterns to improve accuracy and user experience
- Legal Compliance: Maintaining records as required by Indian employment laws
- Dispute Resolution: Providing audit trails for attendance disputes
6. Data Sharing and Disclosure
6.1 We Share Data With:
- Your Employer: Attendance records, timestamps, and verification status (NOT biometric encodings)
- Cloud Service Providers: Dedicated single-tenant cloud hosting infrastructure in India (your data is isolated and never shared with other companies)
- Service Providers: Technical support and maintenance contractors under strict NDAs
6.2 We DO NOT Share:
- Biometric facial encodings with employers or third parties
- Data for marketing purposes
- Data with data brokers or advertisers
- Personal information for purposes unrelated to attendance verification
6.3 Legal Disclosures
We may disclose information when required by:
- Court orders, subpoenas, or legal process
- Government authorities under lawful demand
- Protection of our legal rights or safety
- Investigation of fraud or security incidents
7. Data Storage and Security
7.1 Storage Location and Architecture
- Single-Tenant Architecture: Your Employer receives a dedicated, isolated deployment. Your data is never co-located or shared with other companies' data
- Data Location: All data is stored on servers located in India on secure cloud infrastructure
- Data Isolation: Biometric encodings and attendance records are stored in databases dedicated exclusively to your Employer's organization
7.2 Security Measures
- Encryption in Transit: All data transmissions protected using industry-standard HTTPS/TLS encryption
- Secure Storage: Data stored on secure cloud infrastructure with access controls
- Authentication: Password-based authentication with secure credential storage
- Access Logging: System access and data retrieval logged for monitoring purposes
- Regular Updates: Security patches and software updates applied regularly
- Limited Data Collection: We store only irreversible mathematical encodings (not facial photographs), which cannot be used to reconstruct your image
7.2.1 Security Limitations and Transparency
Important Notice: We implement reasonable security practices appropriate for a biometric attendance system. However, we acknowledge that:
- No security system is completely immune to all threats
- Biometric encodings are irreversible mathematical representations (128-dimensional vectors) that cannot be used to reconstruct photographs, which inherently limits potential harm from unauthorized access
- We continuously improve security measures as the service evolves
We believe our security measures are reasonable and appropriate for the sensitivity of data involved and comply with applicable Indian legal requirements.
7.3 Data Retention
7.3.1 Active Service Period
- Biometric Data: Retained during active employment AND active subscription (deleted when either ends)
- Attendance Records: Retained during active employment AND active subscription (deleted when either ends)
- Location Data: Retained with associated attendance records
7.3.2 After Service Termination
- Export Period: Upon account termination, Employer has 30 days to export all data via CSV download
- Deletion: After the 30-day export period, we will delete all data including biometric encodings, attendance records, and location data
- No Long-Term Archival: SuperGrid does not serve as a long-term data archive. Exported data is Employer's responsibility to retain.
7.3.3 Employer's Retention Responsibility
Important: Your Employer is legally required to retain attendance and payroll records for 7 years under Indian tax and employment laws (Income Tax Act, Companies Act). This is the EMPLOYER's obligation, not SuperGrid's. We provide CSV export functionality so Employers can fulfill their legal retention requirements.
7.3.4 Exceptions to Deletion
We will retain data beyond the standard deletion period only if:
- Required by law or court order
- Needed for ongoing legal disputes or investigations
- Necessary to defend against legal claims
8. Your Rights Under Indian Law
8.1 Digital Personal Data Protection Act, 2023 Rights:
- Right to Access: Request copies of your personal data we hold
- Right to Correction: Request correction of inaccurate data
- Right to Erasure: Request deletion of data (subject to legal retention requirements)
- Right to Grievance Redressal: File complaints with our Grievance Officer
- Right to Nominate: Nominate another person to exercise your rights in case of death or incapacity
8.2 Biometric Data Specific Rights:
- Right to Withdraw Consent: You may withdraw biometric consent at any time (may affect employment relationship - consult your employer)
- Right to Know Processing Purpose: Be informed of how biometric data is used
- Right to Data Portability: Request your attendance data in machine-readable format (CSV)
8.3 How to Exercise Your Rights:
Contact our Grievance Officer at:
- Email: hello@neuralnetworki.ng
- Phone: +91 87458 84947
- Response Time: Within 30 days of verified request
9. Children's Privacy
SuperGrid is not intended for use by individuals under 18 years of age. We do not knowingly collect biometric data from minors. If we discover such data has been collected, we will delete it immediately.
10. Cross-Border Data Transfer
If data is transferred outside India, we ensure:
- Transfers only to countries with adequate data protection (as approved by Indian authorities)
- Use of Standard Contractual Clauses (SCCs) or similar safeguards
- Prior notification to users of international transfers
- Explicit consent for biometric data transfers outside India
11. Automated Decision Making
Important Notice: Our facial recognition system uses automated processing to verify identity. However:
- Final employment decisions (hiring, termination, promotions) remain with your employer
- You have the right to human review if verification fails
- False rejections can be contested through manual verification
- We are NOT responsible for employment decisions made based on attendance data
12. Data Breach Notification
In the event of a data breach involving biometric or personal data:
- We will notify affected users within 72 hours of discovery
- We will notify the relevant Indian authorities (CERT-In, Data Protection Board)
- We will provide details of the breach, data affected, and remedial actions
- We will offer credit monitoring or identity theft protection if warranted
13. Third-Party Links
Our website may contain links to third-party sites. We are not responsible for their privacy practices. Please review their privacy policies independently.
14. Changes to This Privacy Policy
We may update this Privacy Policy to reflect:
- Changes in Indian data protection laws
- New features or services
- Improved security measures
Notice of Changes: Material changes will be notified via email and in-app notification at least 30 days before taking effect. Continued use after changes constitutes acceptance.
15. Consent and Acknowledgment
By using SuperGrid, you:
- Acknowledge you have read and understood this Privacy Policy
- Consent to collection and processing of biometric data as described
- Understand you may withdraw consent (subject to legal and contractual obligations)
- Acknowledge your employer has the right to use attendance data for payroll and HR purposes
16. Grievance Redressal
For privacy concerns, complaints, or data rights requests:
Grievance Officer: Samnit Mehandiratta, Founder
Company: NeuralNetworki.ng
Email: hello@neuralnetworki.ng
Phone: +91 87458 84947
Response Timeline:
- Acknowledgment: Within 24 hours
- Resolution: Within 30 days
Escalation: If unsatisfied with our response, you may file a complaint with:
- Data Protection Board of India (once operational)
- Cyber Crime Cell of local police
- Consumer Courts under Consumer Protection Act, 2019
17. Compliance Frameworks
SuperGrid complies with:
- Digital Personal Data Protection Act, 2023
- Information Technology Act, 2000
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
- Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
18. Complete Limitation of Liability
CRITICAL DISCLAIMER - NO LIABILITY:
TO THE MAXIMUM EXTENT PERMITTED BY LAW, SUPERGRID AND NEURALNETWORKI.NG SHALL HAVE ZERO LIABILITY FOR:
- Data Breaches: ANY data breach, unauthorized access, data loss, theft, or security incident, regardless of cause (including our negligence)
- Biometric Data: Loss, theft, misuse, or unauthorized disclosure of facial encodings or biometric data
- Personal Data: Loss, corruption, or unauthorized access to attendance records, location data, or personal information
- Service Failures: System errors, downtime, inaccuracies, or unavailability
- False Results: False verification results (false positives or negatives)
- Employment Impact: ANY employment decisions, termination, discipline, or payroll errors based on our data
- Identity Theft: Identity theft, fraud, or financial losses resulting from compromised data
- Regulatory Penalties: Fines, penalties, or legal costs under DPDP Act, IT Act, or any law
- Third-Party Claims: Claims by employees, unions, regulators, or any third party
- Force Majeure: Cyberattacks, hacking, cloud provider failures, or events beyond our control
ABSOLUTE LIABILITY CAP: In jurisdictions where complete liability exclusion is not permitted, our maximum liability shall not exceed ₹10,000 (Ten Thousand Rupees) OR the fees your Employer paid in the 1 month preceding the incident, WHICHEVER IS LOWER.
DATA BREACH WAIVER: You and your Employer expressly waive all claims against us for data breaches or security failures under any theory of law, including Information Technology Act, 2000 and Digital Personal Data Protection Act, 2023.
ASSUMPTION OF RISK: You acknowledge that biometric systems and internet-based services carry inherent security risks, and you voluntarily assume all such risks by consenting to this system.
INSURANCE REQUIREMENT: Your Employer is required to maintain cyber liability insurance. Recovery for any losses must be sought from your Employer's insurance, not from us.
19. Dispute Resolution and Governing Law
- Governing Law: Laws of India
- Jurisdiction: Courts of Delhi, India
- Arbitration: Disputes may be referred to arbitration under the Arbitration and Conciliation Act, 1996
Acknowledgment: I have read, understood, and agree to this Privacy Policy.
This is a legally binding document. Please save or print a copy for your records.
Contact Us:
For questions about this Privacy Policy or our data practices:
Email: hello@neuralnetworki.ng
Phone: +91 87458 84947
Website: https://supergrid.app