DutyTick

Privacy policy

Last updated 12 August 2026

DutyTick is a product of Hardcode Consulting Private Limited, a company registered in India. In this policy, we and us mean that company.

Two roles are in play, and the Digital Personal Data Protection Act, 2023 gives them names. For early access requests, we are the data fiduciary: we decide why they are held and what happens to them. For the employee data inside a customer's account, that customer is the fiduciary and we are their processor, acting on their instructions.

DutyTick is not yet in general release. Today the only personal data we hold is what people have sent us when asking for early access. The sections about the product describe what will happen when companies begin using it, and are here so you can read them before you decide, rather than after.

This website sets nothing of its own

No cookies from us. No analytics, no tracking pixels, no fingerprinting, no advertising tags.

One thing is loaded from elsewhere. The early access form uses Cloudflare Turnstile to check that a submission comes from a person rather than a script. It runs inside a frame served by Cloudflare and keeps one value there, held separately for each site that uses it, which is how it remembers the check on this page has been passed. That value sits under Cloudflare's domain rather than ours and we cannot read it. It is a bot check, not analytics: it does not profile you, follow you between sites, or feed advertising.

There is no consent banner, and that is not an oversight. The only thing kept is Cloudflare's record that the form's check has passed, which is there to stop the form being abused rather than to learn anything about you. Storage that exists only to make something work safely is not the kind that asks permission.

The site is served by a hosting provider, and as with any web server, requests reach access logs that include IP addresses. We do not build profiles from them.

What we collect when you request early access

The form on the front page submits to us. What you type goes to our server, and on the way it passes Cloudflare's bot check and our own mail service. So what we hold is what you filled in:

Your email address
Typed into the form, so we can reply and so we can send you a confirmation that we have your request. It is not verified, and anybody could type in an address that is not theirs, which is why that confirmation says plainly where it came from and that ignoring it is enough.
Name, and the products you are interested in
Filled in on the form. Your name so we can address you properly.
Company, team size, and anything you wrote in the details box
Optional. They help us understand who is interested and which problems to build for first. Leaving them blank changes nothing.

We use it to answer your request. We do not use it for anything else, we do not add you to a mailing list, and we do not pass it to anyone for their own purposes.

How consent works, how often we write, and how to stop it are all set out in the email policy.

What the product will collect

When DutyTick is running for a company, that company decides what goes into it. They are the fiduciary for their own employee data, the controller where the GDPR applies, and we process it on their instructions. Expect it to include:

If a company enables clocking in through Telegram, we receive the Telegram user ID and the content of messages sent to our bot, so that a message can be matched to an employee. We do not read anything else in the chat. Those messages pass through Telegram's own infrastructure, outside India, before they reach us.

Where it is stored

Account and billing records sit on our central systems. They hold no workforce data.

Where a customer's employee data sits, and where it is processed, is set in their agreement with us rather than by a default we apply to everyone. We operate in India at present.

Early access requests are held on our own systems in India.

Email leaves the country

Outbound email is delivered through a provider processing it in the United States, so a recipient's name and address, and the contents of the message, are handled there.

The transfer is permitted under the Digital Personal Data Protection Act, 2023, which restricts transfers only to countries the Government of India has notified. Where the GDPR applies, the provider contracts on standard contractual clauses.

Who can see it

Inside a customer's account, visibility is decided by that customer through roles they configure. An employee sees their own record. A manager sees their team. An administrator sees the organisation.

On our side, access is limited to those who need it to run and support the service. We do not sell, rent or share personal data for anyone else's marketing.

We use a small number of outside providers to operate, covering hosting, storage and email delivery. They act on our instructions and only for the purposes described here. We will name them on request.

We disclose data to authorities only where the law requires it, and we tell the affected customer unless we are legally barred from doing so.

Security

At present the only personal data we hold is the early access list, which is to say the mail people have sent us and the list built from it. It is held in India and reachable only by the people who need it to answer you.

The product is being built to encrypt data in transit and at rest, to limit access by role, to require multi-factor authentication on administrative accounts, and to log actions on records. These are design commitments for software that is not yet in service.

We hold no security certifications at present. SOC 2 and ISO 27001 are planned.

How long we keep it

Early access requests
Until you ask us to delete them, or until they are no longer of use to us.
Suppression records
An address that has unsubscribed, bounced or complained is kept indefinitely, precisely so that it is never contacted again. This is the one record deletion does not remove, because removing it would let the address back onto the list.
Customer employee data
For as long as the customer's account is open, and then per the retention terms agreed with them. Some records, such as payroll, carry statutory retention periods that override a deletion request.

Your rights

Under the Digital Personal Data Protection Act, 2023, you can ask for access to the personal data we hold about you, ask for a correction, ask for it to be erased, withdraw consent you have given, and nominate someone to act for you if you die or become incapacitated. If you are in the EEA or the UK, the equivalent rights under the GDPR apply, including data portability and the right to object.

Write to hi@dutytick.com. We respond within the period the applicable law allows.

If you are an employee of a company that uses DutyTick, your request is usually one for that company to answer, since they decide what is held about you. Write to us anyway and we will point you to the right place and tell them.

You have the right to complain to the Data Protection Board of India, or to your local supervisory authority if you are in the EEA or the UK. We would rather you told us first, but it is your right either way.

Children

DutyTick is workplace software and is not intended for anyone under 18. We do not knowingly collect data about children. If you believe we have, tell us and we will remove it.

Changes

If this policy changes materially, the date at the top changes and we tell the people it affects. We will not narrow your rights quietly.

Contact

Hardcode Consulting Private Limited
CIN U58200OD2024PTC047252
hi@dutytick.com