G

GRAV CRM

Employee Management System

Privacy Policy

Last updated: 30 July 2026

1. Introduction

Welcome to GRAV CRM ("the App", "we", "our", or "us"). GRAV CRM is an internal employee management system developed and operated for use by authorised employees and managers within the organisation. This Privacy Policy explains how we collect, use, store, and protect information when you use our mobile application and web platform.

By using GRAV CRM, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Personal Information

When you use GRAV CRM, we collect the following personal information:

  • Full name, employee ID, and biometric ID
  • Email address and phone number
  • Department, designation, and reporting manager details
  • Date of joining and employment records
  • Address (current and permanent)
  • Salary, payslip, and financial records
  • Attendance and leave records
  • Profile photograph

2.2 Device & Usage Information

  • Device type, operating system, and version
  • Push notification tokens for sending leave and attendance alerts
  • App usage logs for debugging and performance monitoring

2.3 Camera & Media Access

The App requests access to your device camera and media storage solely for the following purposes:

  • Uploading medical certificates or supporting documents for sick leave applications
  • Uploading profile photographs
  • Scanning documents required for HR processes

We do not access your camera in the background, record video, or use camera access for any purpose other than what is explicitly triggered by you within the App.

3. How We Use Your Information

We use the information collected for the following purposes:

  • Managing employee leave applications, approvals, and balances
  • Generating payslips and salary records
  • Tracking attendance and work schedules
  • Sending push notifications for leave status updates and manager approvals
  • Enabling managers to review and action team leave requests
  • Maintaining HR records and compliance
  • Improving app performance and fixing technical issues

4. Data Storage & Security

All data is stored securely on our private servers. We implement the following security measures:

  • All data transmission is encrypted using HTTPS/TLS
  • Authentication tokens are stored securely using device-level secure storage (Expo SecureStore)
  • Access to employee data is role-restricted — employees can only view their own records
  • Managers can only access data for employees directly under their supervision
  • No employee data is shared with third parties for advertising or marketing purposes

5. Data Sharing

We do not sell, trade, or share your personal information with any third parties for commercial purposes. Data may only be accessed by:

  • Authorised HR personnel and system administrators within your organisation
  • Your direct reporting managers (limited to attendance, leave, and work-related data)
  • Cloud infrastructure providers (for hosting and storage) under strict confidentiality agreements

6. Push Notifications

GRAV CRM uses push notifications to alert you about leave approvals, rejections, and manager actions. Notification tokens are stored securely and used solely for delivering in-app notifications. You can disable push notifications at any time from your device settings.

7. Data Retention

Employee data is retained for the duration of employment and for a period thereafter as required by applicable labour laws and organisational policies. Upon termination of employment, personal access credentials are deactivated. Archived records may be retained for legal and compliance purposes.

8. Your Rights

As a user of GRAV CRM, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate personal data
  • Request deletion of your data (subject to legal and organisational obligations)
  • Withdraw consent for optional data processing at any time
  • Raise concerns with your HR department regarding data handling

9. Children's Privacy

GRAV CRM is intended exclusively for use by adult employees of the organisation. We do not knowingly collect information from individuals under the age of 18.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be reflected with an updated date at the top of this page. Continued use of the App after changes are posted constitutes your acceptance of the revised policy.

11. Contact Us

If you have any questions or concerns about this Privacy Policy or how your data is handled, please contact your HR department or system administrator.

GRAV CRM — HR Department

For data-related queries, please reach out through your organisation's internal HR portal or contact your system administrator directly.

© 2026 GRAV CRM. All rights reserved.  ·  This policy applies to the GRAV CRM mobile app and web platform.