⚙️ Admin & PlatformFor: Admin
DPDP, data retention & audit log
How PayCraft handles consent, PII encryption, tenant isolation and the audit trail.
PayCraft is built to be defensible under India's DPDP Act.
Data protection
- PII encryption at rest (AES-256-GCM) for sensitive fields like PAN and bank account; Aadhaar is stored masked.
- Tenant isolation is verified — one company's session cannot read another's data.
- Statutory rates are versioned data, so historical runs stay reproducible and audit-defensible.
Retention & consent
- DPDP-aware handling of consent, retention and breach processes underpins the platform; data is hosted in India.
Tip: Pair retention policy with the audit log so you can always answer *who saw or changed what, and when* — see *Audit log*.
Was this helpful?
Related guides
The audit logReview an append-only trail of logins, payroll runs, salary changes and employee edits.RBAC & custom rolesUse the four base roles or build granular custom roles from the permission matrix.Global search, report builder & exportsFind anything fast, build custom reports, and export data to CSV.