Version 2026-09-26
ReliTime Privacy Notice
This notice explains how Aadeepra Rail Assure Private Limited ("we", "us") handles personal data in connection with ReliTime, the relitime.com website, and our emails.
We are a company registered in India (CIN U70200KA2025PTC208230), with our registered office at 235, Binnamangala, 2nd Floor, 13th Cross Road, 2nd Stage, Indira Nagar, Bengaluru - 560038. We follow the Digital Personal Data Protection Act, 2023 (the "DPDP Act"), the DPDP Rules, 2025, and the Information Technology Act, 2000 and its rules.
1. Two different roles
When we act for our customers
Organisations that subscribe to ReliTime ("customers") put their people's data into it: names, work emails, hours worked, leave, attendance, expenses and project assignments. For that data, the customer decides what is collected and why. The customer is the Data Fiduciary, and we are its Data Processor. We process it only to provide ReliTime under our contract with that customer.
If you use ReliTime through your employer or a firm you work with, please send questions and requests about your timesheet data to that organisation first. We will help them respond.
When we decide for ourselves
For the data described in section 2, we are the Data Fiduciary. That covers website visitors, people who book a walkthrough or subscribe to our newsletter, and the account and billing details of customer administrators.
2. What we collect and why
- Name, work email and organisation, when you book a walkthrough or email us. We use it to reply and arrange the demo. The basis is your consent, given when you contact us.
- Email address, when you subscribe to the newsletter. We use it to send product news, and every newsletter has an unsubscribe link. The basis is your consent, which you can withdraw at any time.
- Account details of users invited to ReliTime: name, email, role, sign-in and two-factor authentication records. We use them to run your account securely. The basis is providing the service you or your organisation requested.
- Billing contact, GSTIN and invoice records of customers. We use them to bill you and to meet GST and accounting law. The basis is legal obligation and the contract.
- Basic technical data: IP address, browser type, pages requested, and security logs. We use it to keep the website and the application secure and working. The basis is the legitimate uses the DPDP Act permits, including security and preventing fraud.
- Aggregate website statistics. We use them to understand which pages are useful. They are collected without cookies and without identifying you (see section 5).
We do not sell personal data, and we do not use it for advertising. We do not use ReliTime timesheet data for any purpose other than providing the service to the customer that entered it.
3. Who helps us run ReliTime
We use a small number of service providers. They process data only on our instructions and under contracts that require them to protect it.
- Render, in Singapore: the application servers that run ReliTime.
- Neon, in Singapore: the database.
- Cloudflare R2, in Australia: backups and monthly archives.
- Cloudflare, on its global network: delivering the website and the application's pages, network security, and cookieless web analytics.
- Resend, in Japan: sending account, notification and newsletter emails.
- Razorpay, in India: taking subscription payments. It receives the paying business's billing contact and payment details, and none of the records kept in ReliTime.
Some of this processing takes place outside India. We transfer personal data only to countries the Government of India has not restricted under section 16 of the DPDP Act.
We may also disclose personal data when the law requires it, for example in response to a lawful order from a court or government authority.
4. How long we keep data
- Customer data in ReliTime: for as long as the customer's subscription lasts. After it ends, the customer has 30 days to export its data, as our Terms of Use set out, and we then delete it. Copies in backups are removed as the backups expire, within 35 days.
- Newsletter subscriptions: until you unsubscribe.
- Walkthrough and email enquiries: up to 2 years after our last contact, unless you become a customer.
- Invoices and tax records: for the period Indian tax and company law requires.
- Security logs: at least one year, as the DPDP Rules require, and deleted about thirteen months after the event.
5. Cookies and analytics
The relitime.com website does not set cookies. We use Cloudflare Web Analytics, which counts page visits without cookies and without building a profile of you.
The ReliTime application uses only the cookies needed to keep you signed in and secure.
6. Security
We protect personal data with reasonable security safeguards. Today these are:
- data travels encrypted, over HTTPS, and stored data is encrypted at rest by our hosting providers;
- a second factor is required to sign in for every owner and administrator of a ReliTime account, and for everybody on our staff who can use our support console;
- repeated failed sign-ins are slowed and then refused, a session ends after 30 days at most, and changing a password signs you out everywhere else;
- a person is told by email when a second factor on their account is turned on, turned off or reset;
- each organisation's data is kept separate in the part of ReliTime that reads and writes it, and the application connects to its database with a restricted role that cannot delete a record or rewrite a time entry;
- sign-ins and changes are recorded in audit logs that cannot be edited, and security events are kept for at least one year;
- the database is backed up every night to a separate provider;
- a quarterly review of access to our hosting accounts; and
- an annual review of these controls.
If a personal data breach occurs, we will act as the law requires:
- Where we are the Data Fiduciary, we will inform the Data Protection Board of India and the people affected.
- Where we act for a customer, we will notify that customer within 24 hours of confirming the breach, so it can meet its own obligations.
- In every case, we will report cyber incidents to CERT-In as required.
7. Your rights
Under the DPDP Act, you can ask us to:
- tell you what personal data we hold about you and how we use it;
- correct, complete or update it;
- erase it, where we no longer need it or you withdraw consent;
- withdraw consent you have given, as easily as you gave it;
- nominate another person to exercise your rights if you die or become unable to act.
To make a request, email contact@aadeepra.com. We may need to confirm your identity first. We will respond within the time the law requires.
For data held in a customer's ReliTime account, we will pass your request to that customer and help them respond.
8. Grievances
If you have a concern about how we handle personal data, contact our Grievance Officer: Deepa H, Disputes Manager, Aadeepra Rail Assure Private Limited, 235, Binnamangala, 2nd Floor, 13th Cross Road, 2nd Stage, Indira Nagar, Bengaluru - 560038, at contact@aadeepra.com.
If you are not satisfied with our response, you may complain to the Data Protection Board of India.
9. Children
ReliTime and this website are meant for businesses and are not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe we have, contact us and we will delete it.
10. Changes to this notice
We will post any update on this page with a new version date. For material changes, we will also notify customers by email before the change takes effect.
11. Contact
General questions: hello@relitime.com. Privacy and legal matters: contact@aadeepra.com.