Infilect Technologies Private Limited
Applies to the Infilect mobile applications listed in Section 1
1. Introduction and Applications Covered
This Privacy Policy applies to the mobile applications published by Infilect Technologies Private Limited (“Infilect”, “we”, “us”, “our”) and its affiliates as well as subsidiaries and made available through the Google Play Store and the Apple App Store, namely:
| Application | Package / bundle identifier | Purpose |
|---|---|---|
InfiViz Shots | infilect.infiviz | Capture of photographs and video of retail shelves, displays and packaging by field users, for automated visual inspection and audit |
InfiViz Shots — UAT | infilect.infiviz.uat | Pre-production test build of InfiViz Shots, used for customer acceptance testing |
InfiViz Pulse | com.infilect.infivizpulse | Mobile viewing of embedded analytics dashboards by authorised business users |
These applications are enterprise tools. They are not intended for consumer use, and they are made available to individuals by the organisation that has licensed the InfiViz platform. Our corporate website is covered by our separate Website Privacy Policy.
2. Our Role and Your Employer’s Role
If you use one of these applications because your employer, principal, or the agency that engages you has deployed InfiViz, that organisation is the data fiduciary or controller in respect of your use of the application and of the images and data you capture. It decides which users are enrolled, what tasks are assigned, what is photographed, and how long the resulting data is kept. Infilect acts as that organisation’s data processor and processes personal data only on its documented instructions and in accordance with the agreement between us.
This means that where you wish to exercise a right in respect of your personal data, you should ordinarily contact that organisation in the first instance. We will assist it in responding to you.
Infilect acts as a controller in its own right only in respect of application diagnostics, crash reporting, and the account provisioning necessary for us to operate and secure the service.
3. Data the Applications Collect
| Category | Examples | Why |
|---|---|---|
Account and identity data | User identifier issued by the deploying organisation, work email address, display name, assigned territory or route, and authentication tokens (including where enterprise single sign-on is used) | To authenticate you and to associate captured data with the correct task and organisation |
Location data | Photographs and video of retail shelves, displays, price labels and packaging, together with the capture timestamp and the task or store to which they relate | The core function of the application |
Device and technical data | Approximate or precise device location at the time of capture, where the deploying organisation has enabled this setting | To verify that a store visit occurred at the assigned outlet |
Diagnostic data | Device model, operating system version, application version, network type and connectivity state, storage availability, language and region | To operate the application, apply configuration, and support the device |
Full Name | Crash reports, error logs, performance traces and synchronisation logs | To detect and fix defects and to secure the service |
Without permission, the applications do not perform facial recognition or biometric identification and are not designed to identify individuals. Individuals may occasionally appear incidentally in the background of a shelf photograph. Deploying organisations are instructed to direct field users to avoid capturing individuals, and masking and deletion controls are available on request.Without permission, the applications do not collect contacts, calendar entries, call logs, SMS messages or health data, and they do not use advertising identifiers.
4. Device Permissions
| Permission | Why it is requested |
|---|---|
Camera | Required for InfiViz Shots to capture photographs and video. Capture occurs only when you initiate it. |
Photos and media / storage | Required to store captured media on the device until it has been synchronised, and to attach existing images to a task where the deploying organisation permits this. |
Location | Optional, and controlled by the deploying organisation. Where enabled, location is recorded at the point of capture only, not continuously in the background. |
Network and Wi-Fi state | Required to apply your synchronisation preferences (for example, upload over Wi-Fi only) and to manage retries. |
Notifications | Optional. Used to notify you of task assignments, synchronisation status and required application updates. |
You may withdraw any permission through your device settings. Withdrawing the camera or storage permission will prevent the capture functions of InfiViz Shots from operating.
5. How Data Is Used
We use the data collected through the applications:
- To authenticate you and provision your access to the tasks assigned to you by the deploying organisation;
- To capture, store, compress and transmit media and the associated task metadata to the InfiViz cloud platform;
- To run on-device quality checks so that unusable images are identified before upload;
- To generate the retail execution analytics that the deploying organisation has contracted for;
- To operate, secure, troubleshoot and improve the applications and the platform; and
- To comply with legal obligations and to establish, exercise or defend legal claims.
We do not use the data collected through these applications for advertising, and we do not sell it or share it for cross-context behavioural advertising. Media and derived data belonging to one deploying organisation are logically segregated from those of every other organisation, and are not used to train models for any other organisation except where that organisation has expressly agreed in writing.
6. On-Device Processing and Synchronisation
The applications run on-device intelligence to capture and store media in an appropriate form, format and size. Captured media is held in the application’s protected storage area on the device until it is synchronised with the InfiViz cloud platform. Synchronisation follows the network preference configured by you or by the deploying organisation, including the option to upload only over Wi-Fi. Once synchronisation is confirmed, local copies are cleared in accordance with the configuration set by the deploying organisation.
7. Disclosure and Sharing
We disclose data collected through the applications:
- To the deploying organisation, which is the controller of that data;
- To sub-processors engaged under written contract to host and support the platform, principally Google Cloud Platform;
- To our affiliates within the Infilect group, for support and operations;
- To professional advisers, under confidentiality obligations;
- To a purchaser or prospective purchaser, and to their advisers, in connection with a merger, acquisition, investment or other corporate transaction, subject to appropriate protections, and to any successor entity following completion; and
- To a court, regulator or law enforcement authority, where required by applicable law.
Google and Apple receive limited information about application installation and crash events in their capacity as platform operators, under their own privacy policies.
8. International Transfers
Data collected through the applications is hosted on Google Cloud Platform, principally in the asia-southeast1 (Singapore) and us-central1 (United States) regions, with backups stored multi-regionally. The hosting region applicable to a given deploying organisation is set out in its agreement with us.
Where personal data originating in the European Economic Area or the United Kingdom is transferred to a country without an adequacy decision, we rely on the European Commission Standard Contractual Clauses or the UK International Data Transfer Addendum, together with appropriate supplementary measures.
9. Retention and Deletion
Captured media and derived data are retained for the period agreed with the deploying organisation in its contract, and are deleted or irreversibly anonymised at the end of that period or on that organisation’s instruction.
Account and authentication data are retained while your access remains active, and are removed following deprovisioning by the deploying organisation. Diagnostic data is retained for up to 12 months.
Deletion is carried out in accordance with our information deletion procedures, including deletion from backups within the applicable backup cycle.
10. Security
The applications and the platform that supports them are operated within an Information Security Management System certified to ISO/IEC 27001 and subject to independent SOC 2 examination. Controls include encryption of data in transit using TLS and of data at rest, authenticated and authorised access with support for enterprise single sign-on, protected on-device storage, role-based access control and privileged access management, logging and monitoring, secure coding and security testing in the development lifecycle, vulnerability assessment and penetration testing, and documented incident response, backup and disaster recovery procedures.
11. Your Rights
Subject to the law applicable to you, you may have the right to access, correct, erase, restrict, object to the processing of, or receive a portable copy of your personal data, to withdraw consent, and to nominate another individual to exercise your rights.
Because Infilect acts as processor for the deploying organisation, requests relating to your use of the application and the data you capture should be made to that organisation, which we will assist.
Requests relating to data for which Infilect is the controller, or complaints about our handling of a request, may be sent to support@infilect.com or to our Grievance Officer at support@infilect.com. We acknowledge grievances within 72 hours and respond within 30 days. You may complain to your supervisory authority or, in India, to the Data Protection Board of India.
12. Children
The applications are enterprise tools intended for use by adults in the course of their work. They are not directed at children, and we do not knowingly collect personal data from children.
13. App Store Disclosures
The data collection and sharing disclosures we make in the Google Play Data Safety section and in the Apple App Store privacy details are derived from this Policy. Where you identify an inconsistency between a store disclosure and this Policy, please tell us at support@infilect.com so that we can correct it. This Policy prevails.
14. Changes and Contact
We may update this Policy. The version in force is the one published at www.infilect.com/app-privacy-policy and linked from the store listings, with the effective date shown at the top. Material changes will be notified in the application or by the deploying organisation.
Entity | Infilect Technologies Private Limited |
Address | Indiqube Ascent, No. 420, Mahakavi Vemana Road, KHB Block, Koramangala 4-B, 5th Block, Bengaluru, Karnataka 560034, India |
Privacy contact | support@infilect.com |
Grievance Officer (India) | Anand Prabhu Subramanian — support@infilect.com |