Last updated: May 15, 2026 (IST)

In short

Headx Monitor collects only the data needed to deliver the monitoring service to your organisation. We do not sell personal data. We store Cloud-plan data in Mumbai. On-Premise data stays on your servers. You can request access, correction, or deletion of your personal data at any time by writing to privacy@headx.in.

In this policy
  1. Who we are
  2. Scope of this policy
  3. Data we collect
  4. Why we collect it
  5. Legal basis
  6. Who we share data with
  7. How long we keep it
  8. How we protect it
  9. Your rights
  10. International transfers
  11. Cookies and tracking
  12. Children
  13. Changes to this policy
  14. Contact and Grievance Officer

1. Who we are

Headx Monitor (hereafter "Headx," "we," "us," "our") is an employee monitoring and data loss prevention platform headquartered in Hyderabad, Telangana, India. We provide our services to corporate customers (Data Fiduciaries under the DPDP Act 2023) who in turn use the platform to monitor their own workforces. For most personal data we handle, the corporate customer is the Data Fiduciary and Headx is the Data Processor.

2. Scope of this policy

This policy describes how we handle personal data in two distinct contexts:

If you are an employee whose company has deployed Headx, your employer's privacy policy and consent process are the primary governing documents. We honour our customers' instructions in handling your data.

3. Data we collect

From website visitors and prospects

From customer administrators

From monitored employees (where Headx is Data Processor)

We do not knowingly collect: contents of personal email accounts, banking applications, healthcare applications, password fields, biometric facial recognition data, or location data outside of work hours.

4. Why we collect it

For data we collect from our corporate customers and prospects, our legal basis is consent or the performance of a contract. For employee monitoring data, the corporate customer (Data Fiduciary) is responsible for obtaining consent from the monitored employees under the Indian IT Act 2000, IT Rules 2011, and DPDP Act 2023. We process such data only on the customer's documented instructions.

6. Who we share data with

We do not sell personal data. We share limited data with the following categories of recipients:

RecipientPurposeLocation
Amazon Web ServicesCloud hosting, storage, computeMumbai, India (ap-south-1)
CloudflareCDN, DDoS protection, WAFGlobal edge; no inspection of payloads
Cashfree PaymentsSubscription billing for Indian customersIndia
RazorpayAlternative subscription billingIndia
Postmark / ResendTransactional email deliveryUS (only operational metadata, no customer activity data)
SentryApplication error monitoringUS (stack traces only, no customer payloads)

We may also disclose personal data when required by law, court order, or government request from a competent authority — and only the minimum data needed to comply.

7. How long we keep it

Data typeRetention period
Marketing leads (uncontacted)24 months from last interaction
Customer account dataDuration of subscription + 90 days
Monitoring data (Cloud plan, default)30 days, customer-configurable up to indefinite
DLP and security-incident records3 years from the event
Billing and tax records8 years (Indian tax requirement)
Backups30 days from last write
Web server logs90 days

On-Premise deployments — customer controls all retention. We do not hold a copy of your data.

8. How we protect it

See our Security & Compliance page for the full technical and organisational measures. Headlines: TLS 1.3 in transit, AES-256 at rest, AWS Mumbai data residency for Cloud, named-admin access with audit logging, code-signed agent, written incident response programme.

9. Your rights

Under the IT Rules 2011 and DPDP Act 2023, you have the following rights with respect to your personal data:

To exercise any of these rights, email privacy@headx.in. We acknowledge within 48 hours and resolve within 30 days.

10. International transfers

For Cloud-plan customers, all monitoring data stays within India (AWS Mumbai). Operational metadata (error logs, transactional email metadata) may transit through US-hosted services. We do not transfer monitoring data outside India for Cloud customers.

For customers outside India (UAE, Singapore, Malaysia via partners), we host data in the customer's chosen region. We sign appropriate data-transfer agreements where personal data crosses borders.

11. Cookies and tracking

headx.in uses the following categories of cookies:

We do not use third-party advertising cookies. We do not track you across other websites. You can disable cookies in your browser; some site features will not work without strictly-necessary cookies.

12. Children

Headx services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a minor, write to privacy@headx.in and we will delete it within 7 days.

13. Changes to this policy

We review this policy at least annually and update it when laws or our practices change materially. The "Last updated" date at the top reflects the current version. For material changes, we notify customer administrators by email at least 30 days before the change takes effect.

14. Contact and Grievance Officer

General privacy queries: privacy@headx.in

Grievance Officer (under IT Rules 2011 and DPDP Act 2023):

Data Protection Board of India: for unresolved grievances after the 30-day window, you may approach the Data Protection Board of India (once constituted) under Section 27 of the DPDP Act 2023.

Ready to try Headx on your team?

Cloud from ₹1,900/PC/month or On-Premise from ₹1,499/PC/month. 30-day money-back guarantee on the Cloud plan.

Get Started