AlignHub Security, Privacy, and Accessibility Compliance
Last Updated: July 21, 2026
AlignHub is a B2B work management and business operations platform owned and operated by SpreadMe Digital Pvt. Ltd.. This page explains our current approach to privacy, security, data processing,
accessibility, and responsible product use.
This page is a transparency statement, not a certification report or legal opinion. We claim a certification or formal attestation only where it is expressly identified and supported by current
documentation.
1. Our Compliance Approach
We use a risk-based approach designed to support applicable legal, contractual, security, and accessibility
requirements. Because obligations vary by customer, industry, data type, and country, customers remain
responsible for evaluating whether AlignHub is appropriate for their own compliance needs.
Our policies and product controls are reviewed as the platform, applicable laws, technical standards, and customer requirements evolve.
2. Legal Entity and Product Scope
AlignHub is a product of SpreadMe Digital Pvt. Ltd.. The platform may provide credential management, task and
project management, leave administration, payroll calculation and payslip generation, asset management,
collaboration, reporting, integrations, and optional white-label configurations.
Core access may be offered without charge. Organizations may purchase optional white-label customization,
custom domains, implementation, migration, enterprise support, and related professional services.
AlignHub does not transfer salaries, execute payroll payments, hold employee funds, or provide legal,
accounting, tax, financial, or employment advice.
3. Privacy and Data Protection
3.1 Our roles
SpreadMe Digital Pvt. Ltd. generally acts as a Data Fiduciary or controller for information collected for
account administration, website operations, sales, support, billing, security, and our own business
purposes.
When a customer submits or generates personal data through its Workspace and we process that data on the
customer’s instructions, the customer generally acts as the Data Fiduciary or controller and we act as
the Data Processor or processor.
3.2 Applicable privacy framework
Our privacy program is designed to address applicable provisions of India’s Digital Personal Data
Protection Act, 2023 and implementing rules as they take effect, and to support contractual obligations
under other applicable privacy laws when AlignHub is used internationally.
Customers using AlignHub to process employee, contractor, client, supplier, payroll, credential, or other
personal data are responsible for providing notices, establishing a lawful basis, limiting collection,
managing access, and responding to individuals.
3.3 Privacy documentation
- Privacy Policy - explains how we handle personal data for our own purposes and the rights available to individuals;
- Data Processing Agreement - governs processing of Customer Personal Data on behalf of customers;
- Terms of Service - governs access to and use of AlignHub; and
- Professional Services Agreement - governs paid implementation, migration, configuration, training, and white-label services.
4. Security Controls
We use technical and organizational safeguards appropriate to the nature of the Services and the risks
involved. Depending on the module and configuration, controls may include:
- End-to-end encryption for supported data and communications;
- Encryption in transit and, where supported, encryption at rest;
- Role-based access and permission management;
- Authentication controls and separation of administrative privileges;
- Logging and monitoring of relevant security and access events;
- Encrypted handling and restricted access for supported Credential Vault content;
- Secure development, code review, change management, and vulnerability-management practices;
- Backups, recovery procedures, and service-resilience measures;
- Incident detection, investigation, containment, and response procedures;
- Personnel confidentiality obligations and security awareness; and
- Review of service providers and Subprocessors appropriate to the services they perform.
No cloud service can guarantee absolute security. Customers must use strong credentials, protect devices and networks, limit administrator access, review permissions, secure integrations, and promptly remove access that is no longer needed.
5. Credential Vault Security
The Credential Vault is intended for supported team credentials, access keys, tokens, and secure notes.
Supported data is protected through encryption and access controls, including end-to-end encryption where
the relevant feature supports it.
Customers are responsible for determining which users may access credentials, reviewing credential-use logs,
rotating secrets where appropriate, and immediately removing access for users who no longer require it.
Customers must not use the Credential Vault or any other module to store prohibited payment-card
authentication data such as CVV codes.
6. Payroll and Workforce Data
AlignHub provides administrative tools for payroll calculations, compensation records, statutory-deduction
fields, and payslip generation. It does not transfer salaries or execute payroll payments.
Payroll, tax, leave, attendance, employment, and statutory outputs must be reviewed and approved by the
customer and its qualified legal, tax, accounting, payroll, or employment advisers. The customer remains
responsible for compliance with the laws that apply to its workforce and jurisdiction.
7. White-label and Customer-Controlled Environments
A customer may purchase approved white-label configuration, including branding, themes, custom domains, and
implementation services. White-label customers generally control the purposes for which user data is
processed in their environment and must publish appropriate privacy notices and terms for their users.
White-label configuration does not transfer ownership of the AlignHub technology, platform, source code,
security architecture, or underlying intellectual property.
8. Data Hosting, Service Providers, and International Transfers
AlignHub is operated from India. Personal data may be processed in India and in other countries where
approved service providers or customer-selected integrations operate.
Where applicable law restricts international transfers, we use or support appropriate contractual,
organizational, and technical safeguards. Customers may contact us for information relevant to their use
case and may request current Subprocessor information.
9. Accessibility
We are committed to improving access to the AlignHub public website and supported user interfaces for people
with disabilities. Our ongoing goal is to align relevant web content with the Web Content Accessibility
Guidelines (WCAG) 2.2, Level AA, where reasonably applicable.
Accessibility work may include:
- Clear heading structures and meaningful page organization;
- Keyboard-accessible navigation and interactive controls;
- Visible focus indicators;
- Readable contrast and scalable text;
- Alternative text for meaningful images;
- Labels, instructions, and error identification for forms;
- Responsive layouts and support for common assistive technologies; and
- Ongoing review and remediation of identified barriers.
Accessibility is an ongoing process, and a particular page, integration, third-party component, or newly
released feature may not fully satisfy every WCAG success criterion at all times. We welcome reports so we
can investigate and prioritize improvements.
10. Incident and Vulnerability Reporting
Customers and security researchers should report suspected unauthorized access, data incidents, or security
vulnerabilities to info@spreadme.digital. Please provide enough detail to reproduce or investigate the
issue, but do not include passwords, private keys, sensitive Customer Data, or exploit data that could
create additional risk in an unsecured email.
Do not access data that does not belong to you, disrupt services, use social engineering, or publicly
disclose an unresolved vulnerability. We will review good-faith reports and respond based on severity and
available information.
11. Accessibility Feedback
If you encounter an accessibility barrier, email info@spreadme.digital and include the page URL, the task you
were trying to complete, the browser or assistive technology used, and a description of the issue. We aim to
acknowledge accessibility feedback promptly and investigate reasonable remediation options.
12. Certifications and Customer Assessments
We do not claim ISO, SOC, PCI DSS, HIPAA, or another third-party certification or attestation unless the
certification is current and specifically displayed on the AlignHub website or provided through authorized
compliance documentation.
Upon reasonable request from a business customer, we may provide appropriate security and privacy
information, questionnaires, contractual documentation, or other materials that are available and suitable
to share under confidentiality.
13. Customer Compliance Responsibilities
- Determine whether AlignHub is suitable for the customer's legal, regulatory, contractual, and industry requirements;
- Configure roles, permissions, modules, retention, and integrations appropriately;
- Collect only necessary personal data and maintain a valid legal basis;
- Provide required employee, user, and customer notices;
- Review payroll, tax, leave, HR, and operational outputs before relying on them;
- Maintain source records and backups where appropriate;
- Protect user accounts, administrator access, devices, networks, and connected systems;
- Manage requests from individuals and cooperate with regulators; and
- Use White-label Services in accordance with the applicable Order and customer-facing legal obligations.
14. Contact Information
Product:
AlignHub
Owned and operated by:
SpreadMe Digital Pvt. Ltd.
Privacy and Grievance Contact:
Jigar Patel
Email:
Telephone:
Address:
Capitol Icon, 604, GIFT City Road, Sargasan,
Gandhinagar, Gujarat 382419, India
Website:
For privacy rights requests, include your full name, account email, organization or Workspace name, the
nature of your request, and enough information to identify the relevant records. We aim to acknowledge
privacy requests promptly and respond within 30 days, subject to applicable law and reasonable identity
verification.