Privacy Notice

What we collect, and what your employer can never see

EECly is a workplace compliance and wellbeing application operated by Annotatory AI Projects Private Limited. It is provided to you through your employer. This notice explains what EECly collects, who can see it, what your employer can never see, how long it is kept, and the control you keep over it.

EECly is not a medical service. It does not diagnose, treat, or provide medical advice. Where it connects you to counselling or clinical support, that support is delivered by the relevant qualified provider, not by EECly.

Effective 1 August 2026 · Last updated 2026-08-08 · Reviewed by Venkat Reddy Avula

1. Who is responsible for your data

EECly handles several different kinds of information, and the responsible party is not the same for all of them. Under India’s Digital Personal Data Protection Act, the “Data Fiduciary” is the party that decides why and how data is processed, and owes you the legal duties.

What it is Data Fiduciary Our role
Complaints of sexual harassment (PoSH) Your employer We process on their behalf
Whistleblower / vigil reports Your employer We process on their behalf
Data-protection grievances Your employer We process on their behalf
Engagement and pulse surveys Your employer We process on their behalf
Training completion records Your employer We process on their behalf
Statutory attendance registers Your employer We process on their behalf
Counselling / employee-assistance Jointly, employer and Annotatory Shared
Your wellbeing and health signals Annotatory We are directly responsible

For anything where your employer is the Fiduciary, we act on their documented instructions and cannot use that data for our own purposes. For your wellbeing and health data, we are directly responsible to you — and your employer does not get to decide what happens to it.

2. What EECly collects

Identity and employment information. Your name, work email, employee identifier, department, location and reporting structure. This normally reaches us from your employer’s HR or identity system — you do not usually type it in.

Sign-in information. If your employer uses single sign-on, we receive a verified sign-in assertion from their identity provider. We do not receive or store your corporate password.

Compliance and workplace records. Policy acknowledgements, training completions, and statutory register entries the law requires your employer to keep.

Content you choose to submit. Complaints, reports, grievances, survey responses, and anything you write or attach in them.

Wellbeing information you choose to record, and counselling engagement if you use those features. Plus technical information — device type, app version and operational logs — needed to run the service securely.

The EECly Android app requests only one device permission: internet access. It does not request your camera, microphone, location, contacts or files.

3. What your employer can — and cannot — see

This is enforced in software, at the point every read happens. It is not a promise about intentions; it is a property of the system.

Your employer can never see, at an individual level:

What your employer does see

Compliance status — whether you completed a required training or acknowledged a policy, which is evidence they are legally required to hold. The statutory registers the law obliges them to maintain. And group-level patterns only for wellbeing, counselling uptake and survey results — never you individually.

How the group-level protection actually works

A group figure is released only when the group is large enough that no individual can be identified. That threshold is higher for the most sensitive information: wellbeing and counselling figures require a materially larger group than routine workplace statistics, and statistical noise is added to those figures. We also limit how many such questions can be asked in a period, so a series of narrow queries cannot be combined to isolate a person, and a team that is permanently too small is never reported on. For harassment, whistleblower and grievance data, the system is configured so that no group figure is releasable at all.

The one narrow exception, stated plainly

Where there is a credible risk of imminent harm to someone, a designated responder may escalate. That escalation is restricted to named safety roles, limited to the minimum information necessary, and permanently logged. It exists to keep people alive, and it is the only path by which counselling information can move.

4. Why we are allowed to process it

If you withdraw consent while a case is open: wellbeing processing stops. The case record does not disappear — the law requires it to be retained. We consider it important to tell you this rather than let you discover it later.

5. Who else is involved

ProviderWhat for
Amazon Web Services Hosting and storage
Email delivery Notifications and case correspondence
WhatsApp Notifications, where your employer has enabled it
Okta Single sign-on, where your employer uses it
Razorpay Your employer’s subscription billing (no employee data)

We do not sell your personal data. We do not use it for advertising. We do not use your wellbeing, case, or counselling data to train artificial-intelligence models.

EECly contains no artificial-intelligence feature. Nothing you write — no complaint, no report, no survey answer, no wellbeing entry — is sent to any AI provider, because this application does not use one. Should that ever change, we will name the provider here and ask for your consent before it applies to you.

6. Where your data is held

EECly’s production systems run in India (AWS Mumbai, ap-south-1), and this is enforced rather than merely intended: an automated check fails the build if a non-Indian region is ever configured.

7. How long it is kept, and what deletion means

Deletion works differently by data type, because the law requires different things:

We would rather state this plainly than imply a right to erasure we cannot lawfully deliver.

8. Your rights

You may access your data, ask us to correct it, and request erasure, subject to section 7. You may withdraw consent for wellbeing features at any time without losing access to the compliance parts of EECly. You may raise a grievance and nominate someone to act for you.

Requests are handled through EECly. Where your employer is the Fiduciary for the data in question, we will route your request to them and support them in answering it.

Contact

Data Protection Officer: Venkat Reddy Avula — dpo@annotatory.com

Grievance Officer: legal@annotatory.com

Annotatory AI Projects Private Limited
Sy No. 31, 5th Floor, Plot No. 12, Trendz Avenue, Gafoor Nagar, Madhapur, Hyderabad, Telangana 500081, India

If you are not satisfied with our response, you may escalate to the Data Protection Board of India.

9. Security

Data is encrypted in transit and at rest. Access is enforced per role at the database itself, so a request that should not see something cannot see it even if application code is wrong. Sensitive case material is held in a separate protected store, and every access to a case is logged. Access decisions fail closed — an unrecognised role is granted nothing rather than everything.

No system is perfectly secure, but the controls above are structural, not procedural.

10. Children

EECly is a workplace application and is not intended for anyone under 18.

11. Changes

We will update this policy as EECly changes. Material changes will be notified in-app and reflected in the “Last updated” date above.