Privacy Policy
How personal data is handled in the Yantra Paalan iOS application and its backend services.
1. Who we are
Yantra Paalan ("Yantra Paalan", "we", "us") provides a maintenance management system (CMMS) for process plants, delivered as an iOS application together with a hosted backend. We license the system to industrial organisations — the plants and companies that are our customers — under a signed annual contract.
You will normally be using Yantra Paalan because your employer has adopted it. Your employer decides who gets an account, what role that account has, and what information is recorded in the system.
About the provider: Yantra Paalan is presently operated by an individual developer, not a registered company — there is no CIN or registered office address to publish. If a company is incorporated in future, its registration details will be added here. For all privacy queries, including requests under the DPDP Act, contact support@yantrapaalan.in.
2. Controller and processor
Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"):
- Your employer is the Data Fiduciary (the controller). They determine why and how your personal data is processed in Yantra Paalan. Their own internal privacy and IT policies apply to you as an employee.
- We are the Data Processor, acting on your employer's documented instructions under our contract with them. We do not decide, on our own account, what to do with the personal data held in a customer's workspace.
- You are the Data Principal — the individual the data relates to.
This matters in practice: if you want your data corrected or your account removed, the fastest and usually the only complete route is through your employer's administrator. We will act on such requests when they come from your employer, and we will help if you come to us directly — see Your rights and Account & Data Deletion.
3. Data we collect
We collect only what the maintenance workflow needs. Your employer supplies most of it when your account is created; the rest is generated as you use the app.
| Data | Source | Purpose |
|---|---|---|
| Full name | Entered by your employer's administrator | Identifying who raised, was assigned or closed a job |
| Email address | Employer's administrator | Sign-in, account recovery, service notices |
| Phone number | Employer's administrator | Contacting you about work assigned to you |
| Employee ID | Employer's administrator | Matching your app account to your employer's records |
| Role (admin, HOD, manager, supervisor, technician) | Employer's administrator | Deciding what you can see and do in the app |
| Photos taken in the app with the camera | Captured by you during a job | Evidence attached to work orders and inspections |
| Work-order and maintenance records — job details, readings, log-sheet entries, spare-part issues, timestamps, status changes | Generated as you use the app | The core maintenance record your employer keeps |
| Device push notification token | Issued by Apple to your device | Delivering job assignment and escalation alerts |
We do not ask for and do not want Aadhaar numbers, PAN, bank or payment details, biometric data, health data or precise location tracking. Please do not enter such information into free-text fields or capture it in photographs.
4. Why we use it
We process the data above in order to:
- authenticate you and enforce the access rules attached to your role;
- create, assign, track and close work orders and preventive-maintenance tasks;
- record log sheets, shift rosters and spare-part movements;
- produce the KPI and compliance reporting your employer relies on;
- send operational push notifications about work that concerns you;
- keep the service secure, diagnose faults and prevent misuse; and
- meet our legal obligations and those of our customer.
We do not use your personal data to train models, build profiles for marketing, or for any purpose unrelated to running the maintenance system for your employer.
5. Camera and photos
Yantra Paalan asks for camera permission so that you can attach photographic evidence to a job. Photos are taken inside the app and uploaded to your employer's workspace, where anyone with the appropriate role can see them as part of the work record.
- We access the camera only while you are actively attaching a photo.
- Photos captured in the app are stored with the work order they belong to.
- Photos are visible to authorised users in your organisation, not to the public.
- You can decline camera permission in iOS Settings; you will then not be able to attach photo evidence, but the rest of the app continues to work.
Please photograph the equipment and the work — not colleagues, documents containing personal details, or anything unrelated to the job.
6. Push notifications
If you allow notifications, Apple issues a push token that identifies your device installation. We store that token and use it only to deliver operational alerts — a job assigned to you, an escalation, a PM falling due. We do not send marketing push notifications. Turning notifications off in iOS Settings stops the alerts; the stored token is removed when it becomes invalid or when your account is deleted.
7. Where data is stored
Application data is stored on Supabase, which acts as our sub-processor for database, authentication and file storage. Our customers' workspaces are hosted on Supabase infrastructure, and Supabase processes the data only to provide that hosting to us.
- Encrypted in transit — all traffic between the app and the backend uses TLS.
- Encrypted at rest — stored data and uploaded files are encrypted on disk by the platform.
- Row-level security — access rules are enforced in the database itself, so a user's role and organisation are checked on every read and write, not merely hidden in the interface.
Because the app is offline-first, entries and photos you create without a signal are held on your device until they sync. That local copy is protected by your device's own security — please use a passcode and keep iOS updated.
Data location: our backend is hosted on Supabase infrastructure in Mumbai, India. Your data is stored and processed within India, and we do not host customer data in facilities outside the country.
8. Security
- Access is role-based and enforced server-side through row-level security.
- Accounts are created and revoked only by your employer's administrator.
- Our staff do not browse customer data; access for support is limited, granted only when needed to resolve a reported issue, and logged.
- We keep credentials and service keys out of the mobile app and rotate them when staff or systems change.
No system is perfectly secure. If a personal data breach occurs, we will notify the affected customer without undue delay so they, as Data Fiduciary, can notify the Data Protection Board of India and affected individuals as the DPDP Act requires, and we will support that notification with the facts we hold.
9. Who we share with
We share personal data only with:
- Your employer — the organisation that owns the workspace and the maintenance records in it;
- Supabase — our hosting and database sub-processor;
- Apple Push Notification service — to deliver notifications to your device;
- Authorities — where we are legally required to disclose, in which case we will tell the customer unless the law forbids it.
We do not sell personal data. We do not share it with advertisers, data brokers or analytics companies. We do not transfer it to any other third party without the customer's instruction.
10. No ads, no tracking
- The app contains no advertising.
- The app contains no third-party analytics or attribution SDKs.
- We do not track you across other apps or websites, and we do not use the iOS advertising identifier.
- We do not sell or rent personal data to anyone, for any purpose.
- This website sets no cookies at all — which is why you were not shown a cookie banner.
11. Retention and deletion
We retain personal data for the duration of your employer's contract with us. Maintenance records are business records your employer relies on for audits, statutory inspections and equipment history, so they stay in the system while the contract is live.
- When your employer's contract ends, we delete or return the workspace data according to the terms of that contract, within the period agreed there.
- When your individual account is deleted, we act on the request within 30 days. See Account & Data Deletion.
- Some records must be kept in a limited form where law requires it, or where a record has to remain attributable for safety or audit reasons. Your employer decides this, as Data Fiduciary.
- Routine backups are retained for a short, fixed window and then overwritten; deleted data disappears from backups as that window rolls over.
12. Your rights under the DPDP Act
As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the right to:
- Access — obtain a summary of the personal data being processed about you and the processing activities undertaken;
- Correction and completion — have inaccurate or incomplete data corrected, completed or updated;
- Erasure — have your personal data deleted, unless retention is required for a legal purpose;
- Grievance redressal — a readily available means of raising a complaint about how your data is handled;
- Nominate — nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
You also have duties under the Act, including not raising false or frivolous complaints and providing authentic information when you exercise a right to correction.
How to exercise them
Because your employer is the Data Fiduciary, please contact your plant administrator or your employer's HR/IT team first. They can act on most requests directly inside the app and they hold the records that sit outside it.
If you cannot reach them, or your request concerns something only we can do, write to support@yantrapaalan.in with your name, your employer's name and what you are asking for. We will acknowledge your request, verify it with your employer where we must, and respond within 30 days.
If you are not satisfied with the outcome, you may complain to the Data Protection Board of India as provided under the DPDP Act.
13. Children
Yantra Paalan is a workplace tool intended for employees and contractors of our customers. It is not directed at children, and accounts are not issued to anyone under 18. We do not knowingly process the personal data of a child. If you believe a child's data has been entered into the system, tell us and we will work with the customer to remove it.
14. This website
yantrapaalan.in is a static site. It sets no cookies, runs no analytics, embeds no third-party trackers and has no contact form. The only way it collects anything is if you choose to email us. Our hosting provider may keep standard server logs (including IP address) for a short period for security and abuse prevention; we do not use those logs to identify visitors.
If you email us, we keep your message and address for as long as needed to deal with your enquiry and to keep a record of it.
15. Changes to this policy
We will update this policy when the app or our practices change. The effective date at the top shows the current version. Material changes affecting a customer's workspace will also be communicated to that customer under our contract with them.
16. Contact
Privacy requests and questions
For faster resolution of anything about your own account — including correction and deletion — contact your plant administrator first. See Support and Account & Data Deletion.