Dewmor
Sign InStart Free Trial
Legal

Privacy Policy

How Dewmor collects, uses, and protects your personal data.

This Privacy Policy ("Policy") explains how Combifer Technologies ("Company", "we", "our", "us") collects, uses, discloses, and protects your information when you use Dewmor ("Service"). This Policy is issued in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable laws.

Effective Date: 1 April 2026  ·  Last Updated: 1 July 2026

By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of the Service.

1. Company Information (Data Fiduciary)

  • Legal Name: Combifer Technologies
  • Registered Address: 406, 9th Main, 1st Block, HRBR Layout, Kalyan Nagar, Bengaluru, Karnataka 560043, India
  • GSTIN: 29AASFC1004G1ZM
  • Contact:

Under the DPDP Act 2023, Combifer Technologies is the Data Fiduciary responsible for determining the purpose and means of processing personal data through the Dewmor platform.

2. Scope

This Policy applies to:

  • The Dewmor web application (dewmor.com)
  • Any related services, features, APIs, or communications provided by Combifer Technologies
  • Data processed on behalf of organisations ("Data Processors") using the Dewmor platform

Where Dewmor is used by an organization to manage employee data, that organization is also a Data Fiduciary for its employees' data. Dewmor acts as a Data Processor in that context and processes data only on the organization's instructions.

3. Personal Data We Collect

3.1 Account & Identity Data

  • Full name and email address
  • Account credentials (password, stored in hashed form)
  • Organization name, GSTIN, and billing address
  • Profile photo (if uploaded)

3.2 HR & Employment Data (HR Module)

When an organization uses Dewmor's HR module, the following employee data may be collected and stored:

  • Date of birth, gender, blood group, personal email
  • Permanent and current address
  • Emergency contact details (name, relationship, phone number)
  • Bank account details (account number, IFSC code — used for payroll reference only)
  • Employment documents uploaded by the organization or employee
  • Attendance records and leave history
  • Onboarding checklist completion status

Bank account details and emergency contact information are treated as sensitive personal data. Access is restricted to HR administrators within the organization.

3.3 Usage & Technical Data

  • IP address, browser type, device information
  • Session activity logs (features used, timestamps)
  • Error logs for debugging and reliability

3.4 User Content

  • Files, documents, notes, or media uploaded to the Service
  • Task content, chat messages, and meeting notes
  • Stored solely to deliver the Service to you

3.5 Payment Data

  • We do not store card or payment instrument details
  • Payments are processed by Razorpay (PCI-DSS compliant)
  • We retain transaction IDs, order references, and payment status for billing records

4. Purpose of Processing

We process personal data for the following specified purposes:

  • Providing, operating, and maintaining the Service
  • Managing user accounts and organizational workspaces
  • Processing billing and subscription management
  • Sending service-related communications (account alerts, email notifications)
  • HR module operations — attendance, leave management, onboarding, employee records
  • Improving platform functionality and performance
  • Security monitoring, fraud prevention, and abuse detection
  • Complying with legal obligations under Indian law

We process your data only for the purposes listed above. We do not use your data for advertising, profiling for third-party commercial purposes, or any purpose not stated here.

5. Legal Basis for Processing (DPDP Act 2023)

Under the Digital Personal Data Protection Act, 2023, we process personal data on the following grounds:

  • Consent — For non-essential processing such as email notifications and optional profile data
  • Contractual necessity — To deliver the Service you have subscribed to
  • Legitimate use — For security, fraud prevention, and service improvement within the bounds permitted by the DPDP Act
  • Legal obligation — Where required by applicable Indian law

Where we rely on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. To withdraw consent, contact us at .

6. Your Rights as a Data Principal

Under the DPDP Act 2023, you have the following rights:

  • Right to access — Request a summary of personal data we hold about you and how it is being processed
  • Right to correction — Request correction of inaccurate or incomplete personal data
  • Right to erasure — Request deletion of your personal data, subject to legal retention requirements
  • Right to grievance redressal — Raise a complaint with our Grievance Officer (see Section 12)
  • Right to nominate — Nominate another individual to exercise your rights in the event of your death or incapacity
  • Right to withdraw consent — Withdraw consent for non-essential processing at any time

To exercise any of these rights, contact us at . We will respond within 30 days of receiving a verifiable request.

If you are unsatisfied with our response, you may escalate your complaint to the Data Protection Board of India once it is constituted under the DPDP Act.

7. Data Sharing & Disclosure

We do not sell your personal data. We may share data with:

  • Infrastructure providers — Cloud hosting and storage (data remains encrypted)
  • Payment processor — Razorpay, for billing transactions only
  • Email delivery — Resend, for transactional service emails
  • Legal authorities — When required by a court order or applicable Indian law

All third-party processors are bound by data processing agreements and are required to process personal data only as instructed by us and in compliance with applicable law.

8. Data Retention

We retain personal data as follows:

  • Active accounts — Data is retained for as long as the account is active
  • Deleted accounts — Data is purged within 90 days of account deletion, except where retention is required by law
  • Billing records — Retained for 7 years as required under Indian tax and accounting law
  • Usage logs — Retained for up to 12 months for security and debugging purposes

When the purpose for which data was collected is fulfilled and no legal retention requirement applies, we erase or anonymise the data.

9. Data Security

We implement the following security measures:

  • Encryption of data in transit (TLS) and at rest
  • Role-based access controls — employees access only data necessary for their function
  • JWT-based authentication with session expiry and force-logout capability
  • Audit logs for all critical data access and modification events
  • Regular security reviews of infrastructure and code

In the event of a personal data breach, we will notify each affected data principal without delay and report the breach to the Data Protection Board of India within 72 hours of becoming aware of it, as required under the DPDP Act, 2023 and the rules made under it.

10. Cookies & Tracking

We use cookies and similar technologies for:

  • Maintaining authenticated sessions
  • Remembering user preferences
  • Basic analytics on platform usage

You can manage or withdraw cookie consent via your browser settings or through our cookie consent banner. See our Cookie Policy for full details.

11. Cross-Border Data Transfers

Personal data is primarily processed and stored in India. Certain third-party service providers (such as email delivery and infrastructure services) may process data outside India. Where data is transferred outside India, we ensure appropriate safeguards are in place in accordance with the DPDP Act and any rules or whitelisted countries notified by the Central Government.

12. Grievance Officer

In accordance with the Digital Personal Data Protection Act, 2023, we have designated a Grievance Officer to address data-related concerns:

  • Name: Kiran
  • Designation: Founder & Data Protection Officer, Combifer Technologies
  • Email:
  • Address: 406, 9th Main, 1st Block, HRBR Layout, Kalyan Nagar, Bengaluru, Karnataka 560043
  • Response time: We acknowledge grievances within 24 hours and resolve them within 15 days, as required by Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021

13. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a minor has provided personal data without verifiable parental consent, we will delete that data promptly.

Organisations using Dewmor's HR module must ensure that they do not upload personal data of employees under 18 without obtaining verifiable parental consent as required under the DPDP Act.

14. Third-Party Links

The Service may contain links to third-party websites or integrations. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing personal data.

15. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or applicable law. Material changes will be communicated via email or a prominent notice within the Service at least 14 days before taking effect. Your continued use of the Service after that date constitutes acceptance of the updated Policy.

16. Contact Us

For any privacy-related inquiries, data requests, or grievances:

  • Email:
  • Post: Combifer Technologies, 406, 9th Main, 1st Block, HRBR Layout, Kalyan Nagar, Bengaluru, Karnataka 560043, India
Governing Law: This Privacy Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023. Any disputes arising from this Policy shall be subject to the exclusive jurisdiction of courts in Bengaluru, Karnataka, India.