Skip to content
EmbrolinkSign in

Embrolink Privacy Notice

Draft — lawyer review (needs user). Written by the compliance agent from the real data flows (docs/CONTRACT.md §3 and §8, packages/contract/src/resources/*.ts, the SDK audit in docs/COMPLIANCE.md, docs/PERMISSIONS.md). It is not legal advice. Values in [SQUARE BRACKETS] come from the user and are rendered from configuration (COMPANY_LEGAL_NAME, COMPANY_ADDRESS, SUPPORT_EMAIL, SUPPORT_PHONE, GRIEVANCE_OFFICER_NAME, GRIEVANCE_OFFICER_EMAIL). Statements marked ⚙ describe behaviour that must be built and verified before this notice is published (see "Implementation dependencies" at the end).

Version: 2026-10-01 (must equal PRIVACY_VERSION) · Effective: [EFFECTIVE DATE] Applies to: the Embrolink website and web app, the Embrolink Android and iOS apps, and the public account-deletion page.

Summary

  • Embrolink is software that factories use to run their work: job cards, machines, stock, quality, wages and bills.
  • For your own account (name, mobile number, password, sign-ins) Embrolink decides how the data is used. We are the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). Part A explains this.
  • For the records a company keeps in Embrolink (its employees, customers, suppliers, contractors, documents) the company decides. The company is the Data Fiduciary and we are its Data Processor. Part B explains this.
  • We do not sell personal data. We show no ads. We use no analytics, advertising or tracking tools in the website or the apps. We do not use your data or your company's data to train AI models.
  • You can download your data, correct it, withdraw optional consent and delete your account, in the app or on the web, without calling anyone.
  • Embrolink is for adults. You must be 18 or older to have an account.

1. Who we are

[COMPANY LEGAL NAME] ("Embrolink", "we", "us"), [REGISTERED ADDRESS]. Contact: [SUPPORT E-MAIL], [SUPPORT PHONE]. Grievance Officer: [GRIEVANCE OFFICER] (section 5).

We play two roles:

Whose dataExamplesWho decides how it is usedOur role
People who have an Embrolink loginOwners, managers, supervisors, operators, accounts and HR staff who sign inEmbrolinkData Fiduciary (Part A)
People a company records in its workspaceEmployees and workers, party contacts, drivers, anyone named in a documentThe company that owns the workspaceData Processor (Part B)

If you are both (for example an employee who also signs in), both parts apply to you.


A1. What we collect, why, and on what basis

We collect only what each feature needs. "Required" means the feature cannot work without it.

FeaturePersonal dataRequired?Why we need itBasis (DPDP Act) (needs user: lawyer to confirm each row)
Sign up (create a workspace)Your name; mobile number; e-mail (optional); company name; type of business; city and state; number of machines (optional band, e.g. "6-20"); passwordName, mobile, company, business type, city, state and password are requiredTo verify your mobile number, create your login and set up your company's workspaceYou give it to us for this purpose (s.7(a))
Sign-up choicesYour "I am 18 or older" confirmation; acceptance of the Terms and this notice (with version); your product-update e-mail choice; date and time; the platform you used (web, Android, iOS); IP address; for the Terms acceptance, your browser or app description (user agent)Yes, except the product-update choiceTo prove what you agreed to and when, and that you confirmed your ages.7(a); proof of consent (s.6(10))
One-time codes (OTP)Mobile number; purpose of the code (sign up, sign in, accepting an invitation, password reset, account deletion); a one-way hash of the code (never the code itself); whether it went by SMS or WhatsApp; attempts; timesYes, when you use a codeTo check that you control the mobile numbers.7(a)
Sign in and sessionsMobile number or e-mail; password check; failed sign-in count and temporary lock (5 wrong passwords lock the account for 15 minutes); a session record (a one-way hash of the session token, platform, app version, device name if your device sends one, IP address, browser or app description, created / last seen / expiry / sign-out times)YesTo sign you in, keep you signed in, show you your signed-in devices, sign out devices, and stop password guessings.7(a); security safeguards (s.8(5))
Abuse limitsShort-lived counters in our own cache: sign-in attempts per account (keyed by a one-way hash of the mobile or e-mail, 1 minute), code requests per mobile number and purpose (15 minutes), and requests per network address (IP address, or its /64 block for IPv6; up to 1 hour). No outside service is involvedYes (automatic)To stop password guessing, code flooding and SMS spamSecurity safeguards (s.8(5))
PasswordYour password, stored only as an Argon2id hash. Nobody, including us, can read it. When you choose a password we check it against a short list of common passwords kept in our own software; the password is never sent to any outside serviceYes, for password sign-in (an invited person without a password signs in with codes)Sign in; refuse easily guessed passwordss.7(a); security safeguards (s.8(5))
ProfileName; e-mail; language; profile photo (optional)Name yes, others optionalTo show who you are to your colleagues and in records you creates.7(a)
Workspace membershipWhich companies you belong to; your roles; which factories you can see; status; owner or not; last active timeYesTo give you the right accesss.7(a)
InvitationsWhen a company admin invites you: your name, mobile number, e-mail (optional), the roles and factories offered. We send the invitation link to that mobile by SMS (and to the e-mail, if the admin gave one). To accept, you enter a one-time code we send to the invited mobile, which proves the number is yours. The e-mail the admin typed is not copied onto your account — you can add your own e-mail in Settings. If you already have an Embrolink account, you keep your own password and nobody can test it through the invitation. When you accept: the same consent record as at sign-up. The invitation's name, mobile and e-mail are erased 90 days after it is accepted, withdrawn or expiresYesTo let you join the company's workspaceThe admin gives it to us for this purpose; you then accept (s.7(a))
Activity record (audit log)Your user ID and name, what you created, changed, posted, cancelled or revealed, when, the reason you gave, your device description and IP addressYes (automatic)Your company needs a tamper-proof record of who changed what; we need it to investigate misuseCompany's legitimate business record (Part B); security safeguards (s.8(5), Rule 6(1)(e))
In-app notifications and alertsNotices addressed to you (for example "Machine M-04 is down") and whether you read them. If your company turns on SMS, WhatsApp or e-mail alerts: your mobile number or e-mail and the alert textOnly if your company uses themTo tell you about work events your company choses.7(a); your company's instruction
Download my dataAn Excel file and a JSON file with your profile, your sign-ins, your consent records and the actions you tookOnly when you askYour right of access (s.11)Legal obligation
Account deletionYour deletion request (date, source, scheduled date) and, after deletion, a restricted retention record (section A8)Only when you askTo carry out your request and meet the one-year log retention in DPDP Rules, Rule 8(3)Legal obligation
Support accessIf Embrolink support asks to view your workspace: the staff member, the reason, the access level, the time window and your owner's decisionOnly if your owner approvesTo help your company, and to record every support actionYour owner's approval; s.7(a)
Product-update e-mailsYour e-mail address and your choiceNo, optional and off by defaultAbout one e-mail a month about new featuresYour consent (s.6), which you can withdraw at any time
Security and server logsIP address; date and time; the page or API route called (search text, filters and secret links such as invitation tokens are removed before anything is written); response status; request ID; your user ID if signed inYes (automatic)To keep the service secure and working, detect abuse, and meet legal log-keeping dutiesSecurity safeguards (s.8(5), Rule 6(1)(e)); CERT-In Directions of 28 April 2022
Contacting us or the Grievance OfficerWhat you write to us, your contact details, our replyOnly if you contact usTo answer you and keep a record of complaintss.7(a); IT Rules 2021 r.3(2)

A2. What we never collect

  • Your location. No GPS, no location from Wi-Fi or cell towers. Attendance punches record only the time and "in" or "out".
  • Your phone's contacts, SMS, call log, calendar, microphone recordings, or list of installed apps.
  • Advertising IDs. The Android advertising ID permission is removed from the app.
  • Full Aadhaar numbers. The app accepts only the last 4 digits (Part B).
  • Payment card or UPI details. Nothing is sold inside the apps.
  • Anything from other apps or websites. We do not track you across apps or websites.

A3. Messages we send you

ChannelWhatProvider
SMSOne-time codes; alerts your company turned onMSG91 ([MSG91 LEGAL ENTITY — confirm]) (needs user)
WhatsAppOne-time codes if you choose WhatsApp; alerts your company turned onMeta Platforms (WhatsApp Business Platform), directly or through MSG91 (needs user)
E-mailInvitations, export-ready notices, account notices; product updates only if you opted in[E-MAIL PROVIDER, e.g. Amazon SES, Mumbai region] (needs user)

Codes and alerts contain no advertising. Account notices (for example "your account will be deleted on …" and "your account has been deleted") are sent even if you did not opt in to product updates, because they are about your account. Every product-update e-mail has an unsubscribe link and our postal address, and supports one-click unsubscribe in your mail app; it stops at once and we record your choice.

A4. The mobile app

  • Camera. Used only after you tap "Scan" or "Take photo", and only after a screen that explains why. QR codes are read on your phone by the open-source ZXing decoder; neither the camera picture nor the scanned code is sent anywhere. A photo is uploaded only when you attach it to a record (for example a party challan, a defect or a proof of delivery). If you say no, everything else still works and you can type the job number.
  • Photos you choose. When you pick a photo from your gallery, the system photo picker gives the app only that photo. The app cannot see your other photos.
  • Photos are cleaned. When a photo is uploaded, its hidden details (EXIF, XMP and text metadata, which can include the location, time and camera serial number) are removed; only the orientation flag is kept so the picture shows the right way up.
  • Stored on your phone. Your session token is kept in the phone's secure storage (Keychain on iOS, Keystore on Android). Entries you make while offline (production, quality checks, attendance, job inward drafts) wait in a local database on the phone until they are sent, and are removed from the phone when you sign out or delete your account, together with the photos you took or picked. On a shared phone, other people's unsent entries stay until they send them; the app tells you how many of your own entries are still waiting before you sign out. The session token is locked to this phone, and the app's data is kept out of iCloud and computer backups (iOS) and out of cloud backup and device-to-device transfer (Android).
  • No push notifications. The apps show live updates only while they are open; they do not register for push notifications.

A5. The website

We use only essential cookies and browser storage: the sign-in cookie el_session, the sidebar preference sidebar_state, the factory you picked (el.factory) and your light/dark choice (theme). No analytics, advertising or third-party scripts; fonts are served from our own domain. Details: the Cookie Policy at [WEBSITE URL]/legal/cookies.

A6. Who receives your data

We never sell or rent personal data, never share it for advertising, and never let a third party use it for its own marketing.

RecipientWhat they getWhy
People in your company's workspaceYour name, and what you did in the workspace, according to their roles. Your full mobile number is shown only where needed; elsewhere it is masked (98250•••••)So colleagues can work together
Hosting provider [HOSTING PROVIDER, India region] (needs user)Everything stored in Embrolink, encrypted in transitRuns our servers, database, file storage and backups under contract
SMS and WhatsApp providers (section A3)Mobile number and message textTo deliver codes and alerts
E-mail provider (section A3)E-mail address and messageTo deliver e-mails
Government, courts, CERT-In, the Data Protection BoardOnly what the law requires, after we check the request is lawfulLegal obligation

Our service providers act on our instructions under written contracts. The current list is in the Terms, Annex C. We tell workspace owners before we add a new provider that handles company data.

A7. Where your data is stored

In data centres in India ([HOSTING REGION]) (needs user). WhatsApp messages pass through Meta's systems, which may be outside India. The DPDP Act allows transfers outside India except to countries the Government restricts; we will follow any such restriction.

A8. How long we keep it

DataHow long
Account profile (name, mobile, e-mail, photo, language)While your account exists. After you delete your account: removed at the end of the 14-day cancellation period (section A11)
After deletion: restricted retention recordA keyed hash of your mobile number (not the number itself), the deletion date and the reason, kept for 1 year in a table only our security team can read, then erased. DPDP Rules, Rule 8(3), require us to keep personal data, traffic data and logs for at least one year
Unfinished sign-up (details you entered before the code was verified)Deleted 7 days after it expires or completes (the sign-up itself expires after 30 minutes)
One-time code recordsThe code is a one-way hash and stops working after 10 minutes. The record (mobile number, purpose, time, channel) is kept for 1 year as a security log, then deleted
Session recordsActive up to 30 days (web) or 90 days (app) after your last use; the record is kept for 1 year after it ends, then deleted
Consent records (Terms, this notice, 18+, product updates)While your account exists and 3 years after, as proof of what you agreed to (needs user: lawyer to confirm period)
InvitationsName, mobile and e-mail erased 90 days after the invitation is accepted, withdrawn or expires
Abuse-limit counters1 minute to 1 hour, then they expire on their own
Security and server logsAt least 180 days in India (CERT-In) and 1 year in total (DPDP Rule 6(1)(e) and 8(3)), then deleted (needs user: log store)
Activity record (audit log) in a workspaceAs long as the company keeps its workspace (company data, Part B). After you delete your account, your name in it is replaced with "Former user"
Data export filesAvailable to download for 7 days, then deleted
Grievance and rights requests3 years after closing (needs user: lawyer to confirm)
Product-update e-mail choiceUntil you change it; the change itself is kept as a consent record

Backups are encrypted and overwritten on a [BACKUP RETENTION, e.g. 35-day] cycle (needs user), so deleted data leaves backups within that time.

A9. How we protect it

  • Encryption in transit (HTTPS/TLS) for every connection. The Android and iOS apps refuse unencrypted connections in production.
  • Passwords hashed with Argon2id and checked against a list of common passwords; session tokens and one-time codes stored only as hashes; invitation and unsubscribe links are never written to our API logs.
  • Each company's data is separated inside the database by row-level security, and an automated test checks that one company cannot read another's data.
  • Bank account numbers, PF UAN and ESIC numbers are encrypted in the database (AES-256-GCM), shown masked (last 4 digits), and every "show full number" is recorded in the activity log.
  • Role-based access; lock after 5 wrong passwords; limits on sign-in attempts and code requests per account, per mobile number and per network, all enforced inside our own systems.
  • Our staff see a company's records only in a support session the owner approved, with a banner on screen and every action logged.

No system is perfectly secure. If a breach affects your personal data, we will tell you and the authorities as the law requires.

A10. Your rights and how to use them

Right (DPDP Act)How
Know what we hold (s.11)Settings → Account & privacy → Download my data. You get a machine-readable file (JSON) with your profile, sign-ins, consent records and the actions you took in each workspace. The link works for 7 days. You can also ask the Grievance Officer for a summary, including the list of our service providers
Correct or update (s.12)Edit your name, e-mail, language and photo in Settings → Account. To change your mobile number, or data your company holds about you, ask your company's admin or write to us
Erase — delete your account (s.12)In the app: Settings → Account & privacy → Delete account. Without the app: [WEBSITE URL]/delete-account — enter your mobile number and the code we send. See section A11
Withdraw consent (s.6(4))Product-update e-mails: Settings → Account & privacy, or the unsubscribe link in any such e-mail. Withdrawing is as easy as giving it and takes effect at once
Nominate someone (s.14)E-mail the Grievance Officer with the name and contact details of the person who may use your rights if you die or cannot act
Complain (s.13)Grievance Officer (section 5). If you are not satisfied with our answer, you can complain to the Data Protection Board of India (https://www.dpb.gov.in [confirm URL]) (needs user)

To protect you, we confirm it is you before acting: a code sent to your registered mobile, or your signed-in session. We answer rights requests within [30] days and never later than 90 days (DPDP Rules, Rule 14(3)) (needs user: confirm the internal target).

Please do not file false or frivolous complaints or impersonate someone else; the DPDP Act (s.15) places these duties on you too.

A11. Deleting your account — what happens

  1. At once: you are signed out on every device and any product-update e-mail consent is withdrawn. We send an SMS (and an e-mail if you gave one) with the date the deletion will happen.
  2. For 14 days you can change your mind. You can still sign in (with your password or a code); the app and the website then show "Your account will be deleted on …" with Cancel deletion. If you asked on the public deletion page, you can also cancel there with a new code. (If you are the only owner of a workspace, you cannot start a deletion until you make someone else owner or delete the whole workspace.)
  3. After 14 days: your name becomes "Former user"; your mobile number, e-mail, password and profile photo are erased; you are removed from every workspace, and your name in activity records becomes "Former user". Just before we erase your contact details, we send an SMS (and an e-mail if you gave one) saying the deletion is done.
  4. What stays with your company: job cards, entries, bills and other business records you created belong to your company. They stay, showing "Former user".
  5. What we keep for 1 year: the restricted retention record in section A8, security logs and consent records, as the law requires. Then they are erased.

Deleting your Embrolink login does not delete your employee record (if your company keeps one). That is your company's data; ask your company (Part B).

A12. Age

Embrolink is for adults. Sign-up and invitation acceptance require you to confirm that you are 18 or older. We do not knowingly create accounts for anyone under 18. If we learn that an account belongs to someone under 18, we close it and delete its personal data (except what the law requires us to keep). The app stores list Embrolink as 18+.


B1. Who is responsible

A company (for example an embroidery factory) that subscribes to Embrolink decides what to record about its people and business partners and why. That company is the Data Fiduciary. We store and process that data only to provide Embrolink to the company, following its instructions and our contract with it (Terms, Annex A — Data Processing Agreement).

B2. What companies record

Depending on the modules a company uses:

PeopleData a company may record
Employees and workersEmployee number, name, mobile and alternate mobile, e-mail, gender (with "prefer not to say"), date joined and left, type, department, unit, designation, shift, skills, machines, pay type, monthly salary or daily wage, salary structure, bank name, account number, IFSC, PF UAN, ESIC number, last 4 digits of Aadhaar only, address, emergency contact name and phone, photo; attendance and punch times (no location), leave, holidays, payroll, payslips, incentives, advances, loans, deductions, the employee ledger; production entries and quality checks they did
Customers, suppliers, contractors, transporters, brokers ("parties")Name, GSTIN, PAN, mobile, e-mail, addresses, bank details, credit terms, rates, contacts (name, designation, mobile, e-mail, whether they agreed to WhatsApp messages), ledgers, invoices, bills, payments
DriversName and phone on vehicles and trips
AnyoneNames in documents; photos and PDFs attached to records (challans, defect photos, proof of delivery, design images); remarks and notes

We designed Embrolink to hold less: it has no date-of-birth field, never accepts a full Aadhaar number, never collects location, and hides bank and statutory numbers unless a permitted person asks to see them (and that is logged).

B3. How we handle it

  • Only to provide Embrolink to that company, on its instructions. We do not sell it, use it for advertising, combine it with other companies' data, or use it to train AI models.
  • Each company's data is isolated from every other company's.
  • Our staff do not look at it, except in a support session the company's owner approved, which is time-limited, shown on screen and logged.
  • The same service providers as in section A6 host and deliver it.
  • If a breach affects it, we tell the company within 24 hours of confirming it, so the company can inform the people affected and the Data Protection Board.

Please send requests about your data (access, correction, erasure, grievance) to that company first; it decides and can act in Embrolink directly. If you contact us, we pass your request to the company within [5] business days and tell you we did (needs user: confirm). We cannot change a company's records without its instruction, except where the law requires us to.

Companies must tell their employees how their data is used. Processing for employment purposes is a "legitimate use" under s.7(i) of the DPDP Act, so the company may not need your consent for core HR records, but optional uses (for example WhatsApp messages) need your agreement.

B5. How long company data is kept

The company decides, within the law (for example wage and tax records that labour and GST laws require it to keep). When a company deletes a record, it is removed from the live system; posted documents cannot be deleted, only cancelled, because accounting and tax law require an unbroken record. When a company leaves Embrolink or its trial ends: the workspace becomes read-only for 30 days (the company can still export everything), is then soft-deleted and recoverable for 90 days, and is then erased, including from backups within the backup cycle in section A8.


4. Changes to this notice

Each version has a date. If we change what we collect or why, we show the new version in the app and on the website at least [15] days before it applies (needs user) and ask you to accept it again where the law or our Terms require. Your acceptance is recorded with the version and time.

5. Contact and Grievance Officer

Grievance Officer: [GRIEVANCE OFFICER] · [DESIGNATION] · [GRIEVANCE E-MAIL] · [SUPPORT PHONE] · [REGISTERED ADDRESS]. We acknowledge complaints within 24 hours and resolve them within 15 days (IT Rules 2021, r.3(2)). Details and how to write to us: [WEBSITE URL]/legal/grievance.

General questions: [SUPPORT E-MAIL].