Privacy Policy

EmpleYor (PeopleEdge & HireEdge) and NAVTRI — the StratEdge Global group

Products: EmpleYor — PeopleEdge & HireEdge; NAVTRI Version: V2.0 — August 2026

Effective Date: August 1, 2026

Issued by: StratGrid Private Limited (India) and StratEdge Global LLC (USA)

Privacy contact: compliance@stratedgeglobal.com

1. Introduction and Scope

This Privacy Policy explains how the StratEdge Global group — StratGrid Private Limited, a company incorporated in India (CIN: U62090KA2025PTC211862), registered office BHIVE Premium Campus, JBR Tech Park, 6th Rd, EPIP Zone, Whitefield, Bengaluru, Karnataka 560066, India (“StratGrid”), and StratEdge Global LLC, a Wyoming limited liability company (EIN: 36-5144101), registered office 30 N Gould St Ste R, Sheridan, WY 82801, USA (“StratEdge”) — collects, uses, shares, and protects personal data in connection with:

  • The EmpleYor platform (PeopleEdge and HireEdge);
  • The NAVTRI platform;
  • Our websites: stratedgeglobal.com, stratgrid.in, empleyor.com, and navtri.com;
  • Our EOR, staff augmentation, and managed services engagements.

This Policy applies to customers, their authorised users, employees and candidates whose data is processed in EmpleYor, CRM contacts whose data is processed in NAVTRI, workers deployed under EOR arrangements, and visitors to our websites.

2. Who Is the Data Controller?

The controller depends on the context:

  • Employee data uploaded by an HR SaaS Customer to EmpleYor — Controller: the Customer. Processor: StratGrid.
  • Candidate profile/resume self-created in the HireEdge talent pool — Controller: StratGrid (platform/talent pool); the Client also becomes controller upon application — see Candidate Terms of Service & Privacy Notice.
  • CRM Contact data in NAVTRI (including synced email content) — Controller: the Customer. Processor: StratGrid.
  • Deployed worker data under EOR / staff augmentation — Controller: the Local Employing Entity named in the applicable MSA/SOW (see EOR Client Data Access Addendum).
  • Customer account, billing, and relationship data — Controller: StratGrid and/or StratEdge (per Contracting Entity).
  • Website visitor data — Controller: StratGrid (India sites) / StratEdge (stratedgeglobal.com).

Where the Customer is the controller, we process personal data only on the Customer’s documented instructions under our Data Processing Agreement. Individuals whose data has been uploaded by a Customer should direct rights requests to that Customer in the first instance; we will assist the Customer in responding.

Candidates who create their own HireEdge profile have a direct relationship with StratGrid governed by the Candidate Terms of Service & Privacy Notice, which takes precedence over this Policy for matters it specifically addresses (including talent-pool visibility).

3. What Personal Data We Collect

3.1 Data provided by Customers and users

  • Account data: name, work email, phone, organisation, role, login credentials.
  • EmpleYor HR data (uploaded by Customers): employee identity and contact details, employment terms, attendance, timesheets, leave, performance, skills, assets, reimbursements, payroll inputs, and candidate/recruitment data.
  • EOR worker data: identity documents, bank details, statutory registration data (PF/ESI/tax), employment contracts, payroll data.
  • NAVTRI CRM data (uploaded or synced by Customers): lead and contact names, emails, phone numbers, company details, notes, deal and pipeline data, tasks, and the content of emails synced from the Customer’s connected email and calendar accounts.
  • Billing data: invoicing details, payment references, tax identifiers (GSTIN etc.).

3.2 Data we collect automatically

  • Log data: IP address, browser type, device identifiers, timestamps, pages visited.
  • Usage data: feature usage, session metrics, error reports.
  • Cookies and similar technologies, per Section 9.

3.3 A note on synced email content (NAVTRI)

When a Customer connects an email or calendar account to NAVTRI, the platform syncs message content and metadata relating to the Customer’s CRM Contacts. Synced content may include personal data of third parties who appear in those messages. The Customer, as controller, is responsible for ensuring a lawful basis for this processing. We process synced content solely to provide CRM functionality to that Customer — it is not used for advertising, not sold, and not used to train AI models serving other customers.

4. Legal Basis for Processing

Where we act as controller, we rely on the following legal bases (GDPR Art. 6 and equivalent provisions of the DPDP Act 2023):

  • Performance of a contract — providing the Platforms and services you have signed up for.
  • Legitimate interests — securing our systems, preventing fraud, improving our products, and business administration, balanced against your rights.
  • Legal obligation — tax, accounting, employment, and statutory compliance (including PF/ESI and GST obligations in India).
  • Consent — where required, for example marketing communications and non-essential cookies. Consent can be withdrawn at any time.

5. How We Use Personal Data

  • To provide, operate, secure, and support the Platforms and our services;
  • To administer EOR employment relationships, payroll, and statutory filings;
  • To invoice and collect payment, and maintain accounting records;
  • To communicate service, security, and account notices;
  • To improve the Platforms using anonymised, aggregated usage data;
  • To comply with legal obligations and enforce our agreements;
  • With your consent, to send marketing communications, which you can opt out of at any time.

6. Who We Share Data With

6.1 Within the StratEdge Global group

StratGrid and StratEdge share personal data with each other where necessary to deliver the services — for example, where StratEdge is the Contracting Entity and StratGrid delivers the platform and operations. Intra-group sharing is governed by an intercompany agreement containing data protection obligations.

6.2 Third-party service providers

We use vetted sub-processors for hosting, infrastructure, email delivery, payment processing, and analytics. A current list of sub-processors is available on request at compliance@stratedgeglobal.com. All sub-processors are bound by written data protection obligations.

6.3 Legal disclosures

We may disclose personal data where required by law, court order, or governmental authority, or to protect our rights, users, or the public. We will notify affected Customers of such requests where legally permitted.

6.4 No sale of data

We do not sell personal data, and have not sold personal data in the preceding 12 months (as “sale” is defined under the CCPA).

7. Cross-Border Data Transfers

  • Platform data is hosted in India and/or such other regions as notified in our DPA;
  • Transfers from India comply with the DPDP Act 2023 and rules thereunder;
  • Transfers from the EEA/UK rely on adequacy decisions or Standard Contractual Clauses (and the UK Addendum/IDTA), as set out in our DPA;
  • Transfers between StratGrid (India) and StratEdge (USA) are governed by the intercompany agreement and, where EEA/UK data is involved, appropriate safeguards under the DPA.

8. Data Retention

  • Customer Data (EmpleYor and NAVTRI): Duration of subscription + 30 days post-termination export window, then deleted.
  • EOR employment and payroll records: As required by Indian employment, tax, and statutory law (typically 7–8 years).
  • Invoices and accounting records: Minimum 7 years (GST and accounting requirements).
  • Account and contract records: Duration of relationship + limitation periods.
  • Website analytics and logs: Up to 24 months.

9. Cookies

Our websites use essential cookies (required for the sites and Platforms to function) and, with consent where required, analytics cookies to understand site usage. You can manage non-essential cookies through your browser settings or our cookie banner where displayed. Disabling essential cookies may break platform functionality.

10. Security

  • Encryption of data in transit (TLS) and at rest;
  • Role-based access control and least-privilege access;
  • Logical data separation between customer tenants, and between EOR and HR SaaS data layers;
  • Access logging and audit trails;
  • Regular security reviews, patching, and vendor assessment;
  • Breach response procedures, including notification without undue delay and in any event within seventy-two (72) hours of becoming aware of a breach affecting your data.

11. Your Rights

Depending on your jurisdiction, you may have the right to: access your personal data; correct inaccurate data; delete your data; restrict or object to processing; data portability; withdraw consent; nominate a person to exercise your rights in case of death or incapacity (DPDP Act); and complain to a supervisory authority (including the Data Protection Board of India, or your EEA/UK supervisory authority).

To exercise any right, contact compliance@stratedgeglobal.com. If your data was uploaded by a Customer (for example, your employer uses EmpleYor, or a company using NAVTRI holds your contact details), we may redirect your request to that Customer as controller, and will assist them in responding. We respond to verified requests within the timelines required by applicable law.

12. Children’s Data

The Platforms are business tools and are not directed at children. We do not knowingly collect personal data of anyone under 18. If you believe a child’s data has been uploaded, contact compliance@stratedgeglobal.com and we will work with the relevant controller to delete it.

13. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified by email and/or in-app notice at least thirty (30) days before taking effect. The “Last updated” date below reflects the current version.

14. Contact and Grievance Officer

  • All privacy questions, requests, and complaints: compliance@stratedgeglobal.com
  • Grievance Officer (India — DPDP Act 2023): Nity Niharika, Director & Grievance Officer — compliance@stratedgeglobal.com
  • EU/UK Privacy Contact: compliance@stratedgeglobal.com
  • Postal — India: StratGrid Private Limited, BHIVE Premium Campus, JBR Tech Park, 6th Rd, EPIP Zone, Whitefield, Bengaluru, Karnataka 560066, India
  • Postal — USA: StratEdge Global LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA

Last updated: August 1, 2026 | V2.0 — August 2026 | Published at empleyor.com/privacy and navtri.com/privacy