Who we are
Digitally Next Management System ("DNMS", "we", "us") is operated by Digitally Next, registered at New Delhi, India. We provide a workforce and operations platform that companies use to run HR, attendance, leave, payroll, projects, recruitment and client communication.
This policy explains what we do with personal data. It covers dnms.digitallynext.com and the application behind it.
Two roles, and why the difference matters
We handle personal data in two distinct capacities, and your rights differ depending on which applies.
- As a data fiduciary (controller), for people who visit our website, enquire about the product, or administer a subscription. We decide why and how that data is used.
- As a data processor, for the employee and client records a customer company puts into their workspace. That company decides what to collect and why; we only act on their instructions. If you are an employee whose employer uses DNMS, your employer is the fiduciary and your first point of contact.
What we collect
The categories below reflect what the application genuinely stores.
- Account and identity
- Name, work email, employee number, designation, department, reporting line, profile photo and role assignments.
- Contact and personal details
- Phone number, date of birth, gender, address and emergency contacts, where your employer chooses to record them.
- Attendance records
- Punch timestamps from biometric terminals on your employer's premises, plus derived data such as hours worked, late marks and regularisation requests. We receive the punch event and the device identifier. Fingerprint and face templates stay on the device and are never transmitted to or stored by DNMS.
- Leave, WFH and payroll
- Leave balances, applications and approvals; work-from-home requests; salary structures, payslips and payroll runs where the payroll module is used.
- Performance and recruitment
- Evaluations, KPI records, goals and feedback; and for applicants, the details and documents submitted through a careers form.
- Work content
- Projects, tasks, requirements, documents, chat messages, comments, announcements and files you upload.
- Technical data
- IP address, browser and device type, and timestamped security and audit events such as sign-ins, permission changes and administrative actions.
Why we use it
We do not sell personal data. We do not use your work content to train AI models, and we do not use it to advertise to you.
- To provide the service your employer or your company has subscribed to.
- To authenticate you, enforce permissions and keep accounts secure.
- To send transactional messages: password resets, approvals, reminders and notifications you have enabled.
- To maintain audit trails, which exist to protect you as much as us: they record who changed what and when.
- To diagnose faults, monitor availability and improve reliability.
- To meet legal, tax and statutory obligations.
Legal bases
Where we act as fiduciary we rely on your consent (which you may withdraw), on the necessity of performing a contract with you, on our legitimate interests in securing and improving the service, and on compliance with law. Where we act as processor, the lawful basis is determined by the customer company that engaged us.
Tenant isolation
DNMS is multi-tenant: several companies share the same infrastructure while their data stays strictly separated. Every record carries a tenant identifier, and every database query is scoped to the tenant of the signed-in session by a guard that refuses unscoped access rather than defaulting to a broad result. One company's workspace cannot read or write another's.
Where data is stored
Application data is held in a PostgreSQL database on servers we control. Uploaded files are held in Backblaze B2. Some sub-processors listed above may process data outside India; where they do, we rely on their contractual commitments and standard safeguards.
How long we keep it
- Workspace data is retained for as long as the customer's subscription is active.
- After termination, data is retained for 30 days so it can be exported or an account restored, then deleted.
- Audit logs and records required for tax, statutory or legal purposes are kept for the period the applicable law requires.
- Backups are retained on a rolling cycle and overwritten in the ordinary course.
How we protect it
No system is perfectly secure. We do not claim otherwise, and we will notify affected users and the relevant authority of a personal data breach as required by law.
- Encryption in transit (HTTPS/TLS) across the entire application.
- Passwords stored only as salted one-way hashes, never in a readable form, and never recoverable by us.
- Sensitive stored values, such as integration credentials, encrypted at rest.
- Role-based access control with granular permission scopes, so people see only what their role allows.
- Uploaded files served through short-lived signed URLs rather than public links.
- Audit logging of administrative and security-relevant actions.
Your rights
Subject to applicable law, you may request access to your personal data, correction of inaccurate data, erasure, a portable copy, or restriction of certain processing, and you may withdraw consent where consent is the basis.
If your employer administers your workspace, please raise the request with them first, and we will act on their instruction. Otherwise write to privacy@digitallynext.com and we will respond within the statutory period.
Children
DNMS is a workplace product and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child's data has been provided to us, contact us and we will delete it.
Grievance Officer
In accordance with India's Digital Personal Data Protection Act, 2023 and the Information Technology Rules, complaints about the handling of personal data may be addressed to our Grievance Officer at grievance@digitallynext.com, or by post to Digitally Next, New Delhi, India. We acknowledge complaints within 24 hours and aim to resolve them within 30 days.
Changes to this policy
We will update this page when our practices change and revise the date at the top. Material changes will be notified in the application or by email before they take effect.

