AlignHub Security, Privacy, and Accessibility Compliance

Last Updated: July 21, 2026
AlignHub is a B2B work management and business operations platform owned and operated by SpreadMe Digital Pvt. Ltd.. This page explains our current approach to privacy, security, data processing, accessibility, and responsible product use.
This page is a transparency statement, not a certification report or legal opinion. We claim a certification or formal attestation only where it is expressly identified and supported by current documentation.

1. Our Compliance Approach

We use a risk-based approach designed to support applicable legal, contractual, security, and accessibility requirements. Because obligations vary by customer, industry, data type, and country, customers remain responsible for evaluating whether AlignHub is appropriate for their own compliance needs.
Our policies and product controls are reviewed as the platform, applicable laws, technical standards, and customer requirements evolve.

2. Legal Entity and Product Scope

AlignHub is a product of SpreadMe Digital Pvt. Ltd.. The platform may provide credential management, task and project management, leave administration, payroll calculation and payslip generation, asset management, collaboration, reporting, integrations, and optional white-label configurations.
Core access may be offered without charge. Organizations may purchase optional white-label customization, custom domains, implementation, migration, enterprise support, and related professional services.
AlignHub does not transfer salaries, execute payroll payments, hold employee funds, or provide legal, accounting, tax, financial, or employment advice.

3. Privacy and Data Protection

3.1 Our roles

SpreadMe Digital Pvt. Ltd. generally acts as a Data Fiduciary or controller for information collected for account administration, website operations, sales, support, billing, security, and our own business purposes.
When a customer submits or generates personal data through its Workspace and we process that data on the customer’s instructions, the customer generally acts as the Data Fiduciary or controller and we act as the Data Processor or processor.

3.2 Applicable privacy framework

Our privacy program is designed to address applicable provisions of India’s Digital Personal Data Protection Act, 2023 and implementing rules as they take effect, and to support contractual obligations under other applicable privacy laws when AlignHub is used internationally.
Customers using AlignHub to process employee, contractor, client, supplier, payroll, credential, or other personal data are responsible for providing notices, establishing a lawful basis, limiting collection, managing access, and responding to individuals.

3.3 Privacy documentation

4. Security Controls

We use technical and organizational safeguards appropriate to the nature of the Services and the risks involved. Depending on the module and configuration, controls may include:

No cloud service can guarantee absolute security. Customers must use strong credentials, protect devices and networks, limit administrator access, review permissions, secure integrations, and promptly remove access that is no longer needed.

5. Credential Vault Security

The Credential Vault is intended for supported team credentials, access keys, tokens, and secure notes. Supported data is protected through encryption and access controls, including end-to-end encryption where the relevant feature supports it.
Customers are responsible for determining which users may access credentials, reviewing credential-use logs, rotating secrets where appropriate, and immediately removing access for users who no longer require it.
Customers must not use the Credential Vault or any other module to store prohibited payment-card authentication data such as CVV codes.

6. Payroll and Workforce Data

AlignHub provides administrative tools for payroll calculations, compensation records, statutory-deduction fields, and payslip generation. It does not transfer salaries or execute payroll payments.
Payroll, tax, leave, attendance, employment, and statutory outputs must be reviewed and approved by the customer and its qualified legal, tax, accounting, payroll, or employment advisers. The customer remains responsible for compliance with the laws that apply to its workforce and jurisdiction.

7. White-label and Customer-Controlled Environments

A customer may purchase approved white-label configuration, including branding, themes, custom domains, and implementation services. White-label customers generally control the purposes for which user data is processed in their environment and must publish appropriate privacy notices and terms for their users.
White-label configuration does not transfer ownership of the AlignHub technology, platform, source code, security architecture, or underlying intellectual property.

8. Data Hosting, Service Providers, and International Transfers

AlignHub is operated from India. Personal data may be processed in India and in other countries where approved service providers or customer-selected integrations operate.
Where applicable law restricts international transfers, we use or support appropriate contractual, organizational, and technical safeguards. Customers may contact us for information relevant to their use case and may request current Subprocessor information.

9. Accessibility

We are committed to improving access to the AlignHub public website and supported user interfaces for people with disabilities. Our ongoing goal is to align relevant web content with the Web Content Accessibility Guidelines (WCAG) 2.2, Level AA, where reasonably applicable.
Accessibility work may include:
Accessibility is an ongoing process, and a particular page, integration, third-party component, or newly released feature may not fully satisfy every WCAG success criterion at all times. We welcome reports so we can investigate and prioritize improvements.

10. Incident and Vulnerability Reporting

Customers and security researchers should report suspected unauthorized access, data incidents, or security vulnerabilities to info@spreadme.digital. Please provide enough detail to reproduce or investigate the issue, but do not include passwords, private keys, sensitive Customer Data, or exploit data that could create additional risk in an unsecured email.
Do not access data that does not belong to you, disrupt services, use social engineering, or publicly disclose an unresolved vulnerability. We will review good-faith reports and respond based on severity and available information.

11. Accessibility Feedback

If you encounter an accessibility barrier, email info@spreadme.digital and include the page URL, the task you were trying to complete, the browser or assistive technology used, and a description of the issue. We aim to acknowledge accessibility feedback promptly and investigate reasonable remediation options.

12. Certifications and Customer Assessments

We do not claim ISO, SOC, PCI DSS, HIPAA, or another third-party certification or attestation unless the certification is current and specifically displayed on the AlignHub website or provided through authorized compliance documentation.
Upon reasonable request from a business customer, we may provide appropriate security and privacy information, questionnaires, contractual documentation, or other materials that are available and suitable to share under confidentiality.

13. Customer Compliance Responsibilities

14. Contact Information

Product:

AlignHub

Owned and operated by:

SpreadMe Digital Pvt. Ltd.

Privacy and Grievance Contact:

Jigar Patel

Telephone:

Address:

Capitol Icon, 604, GIFT City Road, Sargasan, Gandhinagar, Gujarat 382419, India
For privacy rights requests, include your full name, account email, organization or Workspace name, the nature of your request, and enough information to identify the relevant records. We aim to acknowledge privacy requests promptly and respond within 30 days, subject to applicable law and reasonable identity verification.