Embrolink Privacy Notice
Draft — lawyer review (needs user). Written by the compliance agent from the real data flows (docs/CONTRACT.md §3 and §8,
packages/contract/src/resources/*.ts, the SDK audit in docs/COMPLIANCE.md, docs/PERMISSIONS.md). It is not legal advice. Values in[SQUARE BRACKETS]come from the user and are rendered from configuration (COMPANY_LEGAL_NAME,COMPANY_ADDRESS,SUPPORT_EMAIL,SUPPORT_PHONE,GRIEVANCE_OFFICER_NAME,GRIEVANCE_OFFICER_EMAIL). Statements marked ⚙ describe behaviour that must be built and verified before this notice is published (see "Implementation dependencies" at the end).
Version: 2026-10-01 (must equal PRIVACY_VERSION) · Effective: [EFFECTIVE DATE] Applies to: the Embrolink website and web app, the Embrolink Android and iOS apps, and the public account-deletion page.
Summary
- Embrolink is software that factories use to run their work: job cards, machines, stock, quality, wages and bills.
- For your own account (name, mobile number, password, sign-ins) Embrolink decides how the data is used. We are the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). Part A explains this.
- For the records a company keeps in Embrolink (its employees, customers, suppliers, contractors, documents) the company decides. The company is the Data Fiduciary and we are its Data Processor. Part B explains this.
- We do not sell personal data. We show no ads. We use no analytics, advertising or tracking tools in the website or the apps. We do not use your data or your company's data to train AI models.
- You can download your data, correct it, withdraw optional consent and delete your account, in the app or on the web, without calling anyone.
- Embrolink is for adults. You must be 18 or older to have an account.
1. Who we are
[COMPANY LEGAL NAME] ("Embrolink", "we", "us"), [REGISTERED ADDRESS]. Contact: [SUPPORT E-MAIL], [SUPPORT PHONE]. Grievance Officer: [GRIEVANCE OFFICER] (section 5).
We play two roles:
| Whose data | Examples | Who decides how it is used | Our role |
|---|---|---|---|
| People who have an Embrolink login | Owners, managers, supervisors, operators, accounts and HR staff who sign in | Embrolink | Data Fiduciary (Part A) |
| People a company records in its workspace | Employees and workers, party contacts, drivers, anyone named in a document | The company that owns the workspace | Data Processor (Part B) |
If you are both (for example an employee who also signs in), both parts apply to you.
Part A — Your Embrolink account (Embrolink is the Data Fiduciary)
A1. What we collect, why, and on what basis
We collect only what each feature needs. "Required" means the feature cannot work without it.
| Feature | Personal data | Required? | Why we need it | Basis (DPDP Act) (needs user: lawyer to confirm each row) |
|---|---|---|---|---|
| Sign up (create a workspace) | Your name; mobile number; e-mail (optional); company name; type of business; city and state; number of machines (optional band, e.g. "6-20"); password | Name, mobile, company, business type, city, state and password are required | To verify your mobile number, create your login and set up your company's workspace | You give it to us for this purpose (s.7(a)) |
| Sign-up choices | Your "I am 18 or older" confirmation; acceptance of the Terms and this notice (with version); your product-update e-mail choice; date and time; the platform you used (web, Android, iOS); IP address; for the Terms acceptance, your browser or app description (user agent) | Yes, except the product-update choice | To prove what you agreed to and when, and that you confirmed your age | s.7(a); proof of consent (s.6(10)) |
| One-time codes (OTP) | Mobile number; purpose of the code (sign up, sign in, accepting an invitation, password reset, account deletion); a one-way hash of the code (never the code itself); whether it went by SMS or WhatsApp; attempts; times | Yes, when you use a code | To check that you control the mobile number | s.7(a) |
| Sign in and sessions | Mobile number or e-mail; password check; failed sign-in count and temporary lock (5 wrong passwords lock the account for 15 minutes); a session record (a one-way hash of the session token, platform, app version, device name if your device sends one, IP address, browser or app description, created / last seen / expiry / sign-out times) | Yes | To sign you in, keep you signed in, show you your signed-in devices, sign out devices, and stop password guessing | s.7(a); security safeguards (s.8(5)) |
| Abuse limits | Short-lived counters in our own cache: sign-in attempts per account (keyed by a one-way hash of the mobile or e-mail, 1 minute), code requests per mobile number and purpose (15 minutes), and requests per network address (IP address, or its /64 block for IPv6; up to 1 hour). No outside service is involved | Yes (automatic) | To stop password guessing, code flooding and SMS spam | Security safeguards (s.8(5)) |
| Password | Your password, stored only as an Argon2id hash. Nobody, including us, can read it. When you choose a password we check it against a short list of common passwords kept in our own software; the password is never sent to any outside service | Yes, for password sign-in (an invited person without a password signs in with codes) | Sign in; refuse easily guessed passwords | s.7(a); security safeguards (s.8(5)) |
| Profile | Name; e-mail; language; profile photo (optional) | Name yes, others optional | To show who you are to your colleagues and in records you create | s.7(a) |
| Workspace membership | Which companies you belong to; your roles; which factories you can see; status; owner or not; last active time | Yes | To give you the right access | s.7(a) |
| Invitations | When a company admin invites you: your name, mobile number, e-mail (optional), the roles and factories offered. We send the invitation link to that mobile by SMS (and to the e-mail, if the admin gave one). To accept, you enter a one-time code we send to the invited mobile, which proves the number is yours. The e-mail the admin typed is not copied onto your account — you can add your own e-mail in Settings. If you already have an Embrolink account, you keep your own password and nobody can test it through the invitation. When you accept: the same consent record as at sign-up. The invitation's name, mobile and e-mail are erased 90 days after it is accepted, withdrawn or expires | Yes | To let you join the company's workspace | The admin gives it to us for this purpose; you then accept (s.7(a)) |
| Activity record (audit log) | Your user ID and name, what you created, changed, posted, cancelled or revealed, when, the reason you gave, your device description and IP address | Yes (automatic) | Your company needs a tamper-proof record of who changed what; we need it to investigate misuse | Company's legitimate business record (Part B); security safeguards (s.8(5), Rule 6(1)(e)) |
| In-app notifications and alerts | Notices addressed to you (for example "Machine M-04 is down") and whether you read them. If your company turns on SMS, WhatsApp or e-mail alerts: your mobile number or e-mail and the alert text | Only if your company uses them | To tell you about work events your company chose | s.7(a); your company's instruction |
| Download my data | An Excel file and a JSON file with your profile, your sign-ins, your consent records and the actions you took | Only when you ask | Your right of access (s.11) | Legal obligation |
| Account deletion | Your deletion request (date, source, scheduled date) and, after deletion, a restricted retention record (section A8) | Only when you ask | To carry out your request and meet the one-year log retention in DPDP Rules, Rule 8(3) | Legal obligation |
| Support access | If Embrolink support asks to view your workspace: the staff member, the reason, the access level, the time window and your owner's decision | Only if your owner approves | To help your company, and to record every support action | Your owner's approval; s.7(a) |
| Product-update e-mails | Your e-mail address and your choice | No, optional and off by default | About one e-mail a month about new features | Your consent (s.6), which you can withdraw at any time |
| Security and server logs | IP address; date and time; the page or API route called (search text, filters and secret links such as invitation tokens are removed before anything is written); response status; request ID; your user ID if signed in | Yes (automatic) | To keep the service secure and working, detect abuse, and meet legal log-keeping duties | Security safeguards (s.8(5), Rule 6(1)(e)); CERT-In Directions of 28 April 2022 |
| Contacting us or the Grievance Officer | What you write to us, your contact details, our reply | Only if you contact us | To answer you and keep a record of complaints | s.7(a); IT Rules 2021 r.3(2) |
A2. What we never collect
- Your location. No GPS, no location from Wi-Fi or cell towers. Attendance punches record only the time and "in" or "out".
- Your phone's contacts, SMS, call log, calendar, microphone recordings, or list of installed apps.
- Advertising IDs. The Android advertising ID permission is removed from the app.
- Full Aadhaar numbers. The app accepts only the last 4 digits (Part B).
- Payment card or UPI details. Nothing is sold inside the apps.
- Anything from other apps or websites. We do not track you across apps or websites.
A3. Messages we send you
| Channel | What | Provider |
|---|---|---|
| SMS | One-time codes; alerts your company turned on | MSG91 ([MSG91 LEGAL ENTITY — confirm]) (needs user) |
| One-time codes if you choose WhatsApp; alerts your company turned on | Meta Platforms (WhatsApp Business Platform), directly or through MSG91 (needs user) | |
| Invitations, export-ready notices, account notices; product updates only if you opted in | [E-MAIL PROVIDER, e.g. Amazon SES, Mumbai region] (needs user) |
Codes and alerts contain no advertising. Account notices (for example "your account will be deleted on …" and "your account has been deleted") are sent even if you did not opt in to product updates, because they are about your account. Every product-update e-mail has an unsubscribe link and our postal address, and supports one-click unsubscribe in your mail app; it stops at once and we record your choice.
A4. The mobile app
- Camera. Used only after you tap "Scan" or "Take photo", and only after a screen that explains why. QR codes are read on your phone by the open-source ZXing decoder; neither the camera picture nor the scanned code is sent anywhere. A photo is uploaded only when you attach it to a record (for example a party challan, a defect or a proof of delivery). If you say no, everything else still works and you can type the job number.
- Photos you choose. When you pick a photo from your gallery, the system photo picker gives the app only that photo. The app cannot see your other photos.
- Photos are cleaned. When a photo is uploaded, its hidden details (EXIF, XMP and text metadata, which can include the location, time and camera serial number) are removed; only the orientation flag is kept so the picture shows the right way up.
- Stored on your phone. Your session token is kept in the phone's secure storage (Keychain on iOS, Keystore on Android). Entries you make while offline (production, quality checks, attendance, job inward drafts) wait in a local database on the phone until they are sent, and are removed from the phone when you sign out or delete your account, together with the photos you took or picked. On a shared phone, other people's unsent entries stay until they send them; the app tells you how many of your own entries are still waiting before you sign out. The session token is locked to this phone, and the app's data is kept out of iCloud and computer backups (iOS) and out of cloud backup and device-to-device transfer (Android).
- No push notifications. The apps show live updates only while they are open; they do not register for push notifications.
A5. The website
We use only essential cookies and browser storage: the sign-in cookie el_session, the sidebar preference sidebar_state, the factory you picked (el.factory) and your light/dark choice (theme). No analytics, advertising or third-party scripts; fonts are served from our own domain. Details: the Cookie Policy at [WEBSITE URL]/legal/cookies.
A6. Who receives your data
We never sell or rent personal data, never share it for advertising, and never let a third party use it for its own marketing.
| Recipient | What they get | Why |
|---|---|---|
| People in your company's workspace | Your name, and what you did in the workspace, according to their roles. Your full mobile number is shown only where needed; elsewhere it is masked (98250•••••) | So colleagues can work together |
| Hosting provider [HOSTING PROVIDER, India region] (needs user) | Everything stored in Embrolink, encrypted in transit | Runs our servers, database, file storage and backups under contract |
| SMS and WhatsApp providers (section A3) | Mobile number and message text | To deliver codes and alerts |
| E-mail provider (section A3) | E-mail address and message | To deliver e-mails |
| Government, courts, CERT-In, the Data Protection Board | Only what the law requires, after we check the request is lawful | Legal obligation |
Our service providers act on our instructions under written contracts. The current list is in the Terms, Annex C. We tell workspace owners before we add a new provider that handles company data.
A7. Where your data is stored
In data centres in India ([HOSTING REGION]) (needs user). WhatsApp messages pass through Meta's systems, which may be outside India. The DPDP Act allows transfers outside India except to countries the Government restricts; we will follow any such restriction.
A8. How long we keep it
| Data | How long |
|---|---|
| Account profile (name, mobile, e-mail, photo, language) | While your account exists. After you delete your account: removed at the end of the 14-day cancellation period (section A11) |
| After deletion: restricted retention record | A keyed hash of your mobile number (not the number itself), the deletion date and the reason, kept for 1 year in a table only our security team can read, then erased. DPDP Rules, Rule 8(3), require us to keep personal data, traffic data and logs for at least one year |
| Unfinished sign-up (details you entered before the code was verified) | Deleted 7 days after it expires or completes (the sign-up itself expires after 30 minutes) |
| One-time code records | The code is a one-way hash and stops working after 10 minutes. The record (mobile number, purpose, time, channel) is kept for 1 year as a security log, then deleted |
| Session records | Active up to 30 days (web) or 90 days (app) after your last use; the record is kept for 1 year after it ends, then deleted |
| Consent records (Terms, this notice, 18+, product updates) | While your account exists and 3 years after, as proof of what you agreed to (needs user: lawyer to confirm period) |
| Invitations | Name, mobile and e-mail erased 90 days after the invitation is accepted, withdrawn or expires |
| Abuse-limit counters | 1 minute to 1 hour, then they expire on their own |
| Security and server logs | At least 180 days in India (CERT-In) and 1 year in total (DPDP Rule 6(1)(e) and 8(3)), then deleted (needs user: log store) |
| Activity record (audit log) in a workspace | As long as the company keeps its workspace (company data, Part B). After you delete your account, your name in it is replaced with "Former user" |
| Data export files | Available to download for 7 days, then deleted |
| Grievance and rights requests | 3 years after closing (needs user: lawyer to confirm) |
| Product-update e-mail choice | Until you change it; the change itself is kept as a consent record |
Backups are encrypted and overwritten on a [BACKUP RETENTION, e.g. 35-day] cycle (needs user), so deleted data leaves backups within that time.
A9. How we protect it
- Encryption in transit (HTTPS/TLS) for every connection. The Android and iOS apps refuse unencrypted connections in production.
- Passwords hashed with Argon2id and checked against a list of common passwords; session tokens and one-time codes stored only as hashes; invitation and unsubscribe links are never written to our API logs.
- Each company's data is separated inside the database by row-level security, and an automated test checks that one company cannot read another's data.
- Bank account numbers, PF UAN and ESIC numbers are encrypted in the database (AES-256-GCM), shown masked (last 4 digits), and every "show full number" is recorded in the activity log.
- Role-based access; lock after 5 wrong passwords; limits on sign-in attempts and code requests per account, per mobile number and per network, all enforced inside our own systems.
- Our staff see a company's records only in a support session the owner approved, with a banner on screen and every action logged.
No system is perfectly secure. If a breach affects your personal data, we will tell you and the authorities as the law requires.
A10. Your rights and how to use them
| Right (DPDP Act) | How |
|---|---|
| Know what we hold (s.11) | Settings → Account & privacy → Download my data. You get a machine-readable file (JSON) with your profile, sign-ins, consent records and the actions you took in each workspace. The link works for 7 days. You can also ask the Grievance Officer for a summary, including the list of our service providers |
| Correct or update (s.12) | Edit your name, e-mail, language and photo in Settings → Account. To change your mobile number, or data your company holds about you, ask your company's admin or write to us |
| Erase — delete your account (s.12) | In the app: Settings → Account & privacy → Delete account. Without the app: [WEBSITE URL]/delete-account — enter your mobile number and the code we send. See section A11 |
| Withdraw consent (s.6(4)) | Product-update e-mails: Settings → Account & privacy, or the unsubscribe link in any such e-mail. Withdrawing is as easy as giving it and takes effect at once |
| Nominate someone (s.14) | E-mail the Grievance Officer with the name and contact details of the person who may use your rights if you die or cannot act |
| Complain (s.13) | Grievance Officer (section 5). If you are not satisfied with our answer, you can complain to the Data Protection Board of India (https://www.dpb.gov.in [confirm URL]) (needs user) |
To protect you, we confirm it is you before acting: a code sent to your registered mobile, or your signed-in session. We answer rights requests within [30] days and never later than 90 days (DPDP Rules, Rule 14(3)) (needs user: confirm the internal target).
Please do not file false or frivolous complaints or impersonate someone else; the DPDP Act (s.15) places these duties on you too.
A11. Deleting your account — what happens
- At once: you are signed out on every device and any product-update e-mail consent is withdrawn. We send an SMS (and an e-mail if you gave one) with the date the deletion will happen.
- For 14 days you can change your mind. You can still sign in (with your password or a code); the app and the website then show "Your account will be deleted on …" with Cancel deletion. If you asked on the public deletion page, you can also cancel there with a new code. (If you are the only owner of a workspace, you cannot start a deletion until you make someone else owner or delete the whole workspace.)
- After 14 days: your name becomes "Former user"; your mobile number, e-mail, password and profile photo are erased; you are removed from every workspace, and your name in activity records becomes "Former user". Just before we erase your contact details, we send an SMS (and an e-mail if you gave one) saying the deletion is done.
- What stays with your company: job cards, entries, bills and other business records you created belong to your company. They stay, showing "Former user".
- What we keep for 1 year: the restricted retention record in section A8, security logs and consent records, as the law requires. Then they are erased.
Deleting your Embrolink login does not delete your employee record (if your company keeps one). That is your company's data; ask your company (Part B).
A12. Age
Embrolink is for adults. Sign-up and invitation acceptance require you to confirm that you are 18 or older. We do not knowingly create accounts for anyone under 18. If we learn that an account belongs to someone under 18, we close it and delete its personal data (except what the law requires us to keep). The app stores list Embrolink as 18+.
Part B — Data your company keeps in Embrolink (Embrolink is the Data Processor)
B1. Who is responsible
A company (for example an embroidery factory) that subscribes to Embrolink decides what to record about its people and business partners and why. That company is the Data Fiduciary. We store and process that data only to provide Embrolink to the company, following its instructions and our contract with it (Terms, Annex A — Data Processing Agreement).
B2. What companies record
Depending on the modules a company uses:
| People | Data a company may record |
|---|---|
| Employees and workers | Employee number, name, mobile and alternate mobile, e-mail, gender (with "prefer not to say"), date joined and left, type, department, unit, designation, shift, skills, machines, pay type, monthly salary or daily wage, salary structure, bank name, account number, IFSC, PF UAN, ESIC number, last 4 digits of Aadhaar only, address, emergency contact name and phone, photo; attendance and punch times (no location), leave, holidays, payroll, payslips, incentives, advances, loans, deductions, the employee ledger; production entries and quality checks they did |
| Customers, suppliers, contractors, transporters, brokers ("parties") | Name, GSTIN, PAN, mobile, e-mail, addresses, bank details, credit terms, rates, contacts (name, designation, mobile, e-mail, whether they agreed to WhatsApp messages), ledgers, invoices, bills, payments |
| Drivers | Name and phone on vehicles and trips |
| Anyone | Names in documents; photos and PDFs attached to records (challans, defect photos, proof of delivery, design images); remarks and notes |
We designed Embrolink to hold less: it has no date-of-birth field, never accepts a full Aadhaar number, never collects location, and hides bank and statutory numbers unless a permitted person asks to see them (and that is logged).
B3. How we handle it
- Only to provide Embrolink to that company, on its instructions. We do not sell it, use it for advertising, combine it with other companies' data, or use it to train AI models.
- Each company's data is isolated from every other company's.
- Our staff do not look at it, except in a support session the company's owner approved, which is time-limited, shown on screen and logged.
- The same service providers as in section A6 host and deliver it.
- If a breach affects it, we tell the company within 24 hours of confirming it, so the company can inform the people affected and the Data Protection Board.
B4. If you are an employee or contact of a company that uses Embrolink
Please send requests about your data (access, correction, erasure, grievance) to that company first; it decides and can act in Embrolink directly. If you contact us, we pass your request to the company within [5] business days and tell you we did (needs user: confirm). We cannot change a company's records without its instruction, except where the law requires us to.
Companies must tell their employees how their data is used. Processing for employment purposes is a "legitimate use" under s.7(i) of the DPDP Act, so the company may not need your consent for core HR records, but optional uses (for example WhatsApp messages) need your agreement.
B5. How long company data is kept
The company decides, within the law (for example wage and tax records that labour and GST laws require it to keep). When a company deletes a record, it is removed from the live system; posted documents cannot be deleted, only cancelled, because accounting and tax law require an unbroken record. When a company leaves Embrolink or its trial ends: the workspace becomes read-only for 30 days (the company can still export everything), is then soft-deleted and recoverable for 90 days, and is then erased, including from backups within the backup cycle in section A8.
4. Changes to this notice
Each version has a date. If we change what we collect or why, we show the new version in the app and on the website at least [15] days before it applies (needs user) and ask you to accept it again where the law or our Terms require. Your acceptance is recorded with the version and time.
5. Contact and Grievance Officer
Grievance Officer: [GRIEVANCE OFFICER] · [DESIGNATION] · [GRIEVANCE E-MAIL] · [SUPPORT PHONE] · [REGISTERED ADDRESS]. We acknowledge complaints within 24 hours and resolve them within 15 days (IT Rules 2021, r.3(2)). Details and how to write to us: [WEBSITE URL]/legal/grievance.
General questions: [SUPPORT E-MAIL].