Privacy Policy
Last updated: 2 September 2026 · Applies to oemup.app, app.oemup.app and the OEMup mobile app for Android and iOS
OEMup ("we", "our", "us") is a product of Kira Intrilogy, a sole proprietorship based in Ahmedabad, Gujarat, India. This policy explains what information we collect, why, who we share it with, how long we keep it, and the choices you have — whether you are visiting our website, using the web application, or using the OEMup mobile app (Android package and iOS bundle app.oemup.mobile).
- We never sell personal or business data, and the app contains no advertising or tracking SDKs.
- The mobile app asks for location only when you tap check-in or check-out on a client visit, and for file access only when you attach a document. Nothing runs in the background.
- Your company owns the business data it enters. We process it to run the service and share it only with the processors listed in section 6 or when the law requires.
- You can ask for your data, correct it, export it, or delete your account at any time.
- Who we are and what this covers
- Your company's data and our role
- Information we collect
- How we use information
- Legal basis
- Who we share information with
- Security
- How long we keep data
- Your rights and choices
- Deleting your account
- Children
- Where data is stored
- Cookies and similar technologies
- Changes to this policy
- Contact and grievance officer
1. Who We Are and What This Covers
The data controller (in the language of India's Digital Personal Data Protection Act, 2023, the "data fiduciary") for the website and for your account with us is Kira Intrilogy, proprietor Komal Sanket Sonara, Ahmedabad, Gujarat, India. This policy covers:
- the marketing website at oemup.app;
- the OEMup web application at app.oemup.app;
- the OEMup mobile app distributed through Google Play and the Apple App Store; and
- emails, WhatsApp messages and support tickets exchanged with us.
It does not cover third-party websites we link to, or the practices of your employer.
2. Your Company's Data and Our Role
OEMup is business software. A company registers a workspace, and its administrators add staff as users. Two roles follow from that:
- For your account and for website visitors, we are the controller. We decide how login details, support conversations and website analytics are handled, as described here.
- For data your company enters into OEMup, your company is the controller and we are its processor. That includes customer and vendor records, invoices, employee HR records (attendance, leave, salary set-up), documents, and GPS check-ins recorded by field staff. We process this data only on the company's instructions, to provide the service. Questions about why your employer collects something — for example, why a client visit needs a GPS check-in — should go to your employer first; we will help them answer.
3. Information We Collect
a. Information you or your company provide
- Account details: name, work email, mobile number, password (stored only as a salted hash), designation, department, employee code and, if your company sets one, a profile photo.
- Company registration details: company name, contact person, email, mobile numbers, GSTIN, PAN, address and industry.
- Business data entered into the ERP: customers, vendors, items, orders, invoices, purchase records, stock movements, production plans, tasks, notes and attachments.
- Employee data entered by your company's HR or administrators: joining date, date of birth, gender, blood group, bank details for salary, attendance and leave records.
- Support and contact messages: demo requests, enquiries, support tickets and anything you attach to them.
- Payment information for subscriptions is processed by a PCI-DSS-compliant payment gateway; we do not store card numbers.
b. Information collected automatically
- Log data: IP address, browser or app version, operating system, pages or screens used, timestamps, and error reports.
- Audit trail: who created, changed or approved a record and when. This is a core ERP feature and is visible to your company's administrators.
- Session records for the mobile app: platform (Android/iOS), OS version, app version, device model and a device identifier, used to secure sessions and diagnose problems.
c. Data the OEMup mobile app collects, and the permissions it asks for
This table is the same information we declare in Google Play's Data safety section and Apple's App Privacy details.
| Data | When it is collected | Why, and who sees it |
|---|---|---|
| Name, email, mobile number | When you sign in or register a company | To identify you and secure your account. Visible to your company's administrators. Not shared with third parties except the processors in section 6. |
| Precise location (GPS) | Only at the moment you tap check-in or check-out on a client visit (HRMS → Visits). Requested as "while using the app"; never collected in the background. | Stored on that visit record, with the timestamp and accuracy, in your company's workspace so the visit can be verified. Not used for advertising and not shared with third parties. You may deny the permission; other features keep working. |
| Files and photos you choose | When you tap Attach or Upload and pick a file from the system file or photo picker | Stored as an attachment on the record (customer, vendor, purchase order, support ticket, or your profile photo). The app reads only the files you select and does not scan your library. It does not request camera permission. |
| Device and app information (platform, OS version, app version, device model, device identifier, IP address) | While you use the app | Session security, fraud prevention, crash diagnosis and knowing which app versions to support. |
| App activity (records you view, create, approve; tasks assigned to you) | While you use the app | To run the ERP and its audit trail; to show you live in-app alerts when a task is assigned. The app keeps a real-time connection to our servers while you are signed in for this purpose. |
| Support tickets and messages | When you raise a ticket from the Help Center | To respond to you. Visible to our support team and your company's administrators. |
| Sign-in token | After sign-in, on your device only | Kept in the phone's secure storage (Android Keystore / iOS Keychain) so you stay signed in; deleted when you sign out. |
The app does not collect: contacts, calendar, call or SMS logs, microphone or camera input, health data, background or continuous location, or an advertising identifier. It does not send push notifications in the current version; if we add them, the app will ask for permission first and this policy will be updated.
d. Website visitors
- Forms (demo, trial, newsletter, contact, account deletion) are delivered to our inbox through Web3Forms. Lead forms are also logged to a private Google Sheet we use as a simple CRM.
- When you submit a lead form, we look up your IP address with ipinfo.io to learn the approximate city and the organisation that owns the network. This helps us recognise which company is enquiring. We do not do this on the account-deletion form.
- Google Analytics 4 measures page views and traffic sources, subject to your choice in the cookie banner. See the Cookie Policy.
- The WhatsApp chat button opens WhatsApp on your device; anything you send there is also subject to WhatsApp's (Meta's) terms.
4. How We Use Information
- To provide, secure and maintain the OEMup service on the web and in the mobile app, including sign-in, permissions and the audit trail;
- To generate the documents your company asks for — invoices, e-invoices, e-way bills, purchase orders, payslips — and to file with government portals when your company uses those features;
- To respond to demo requests, enquiries and support tickets;
- To send service notices (security alerts, maintenance, changes to terms) and, if you opt in, product updates and marketing emails you can unsubscribe from at any time;
- To understand how the product is used and improve it, using aggregated or de-identified data wherever possible;
- To detect and prevent fraud, abuse and security incidents;
- To comply with Indian law, including GST, income-tax and labour-law record-keeping.
We do not use your data to train third-party AI models, and we do not profile individuals for advertising.
5. Legal Basis
We process personal data under the Information Technology Act, 2000 and its Sensitive Personal Data rules, and the Digital Personal Data Protection Act, 2023 as its rules take effect. Depending on the data, we rely on: performance of our contract with your company; your consent (for example, when you grant the location permission or opt in to marketing) which you can withdraw at any time; legal obligations (tax and labour records); and our legitimate interest in keeping the service secure and improving it. For customers outside India we apply the same principles, consistent with the GDPR and UK GDPR.
6. Who We Share Information With
We do not sell personal or business data. We share it only with the following categories of recipients, each bound by contract or by law to use it only for the stated purpose:
| Recipient | What they receive | Why |
|---|---|---|
| Cloud hosting and storage provider (infrastructure located in India) | All service data, encrypted | To run the servers, database, file storage and backups. |
| Transactional email provider | Email address and message content | To send sign-in, password, approval and notification emails. |
| GST e-invoice / e-way bill partner (ClearTax) and the Government of India's Invoice Registration Portal and e-way bill system | Invoice and consignment data the law requires | Only when your company generates an e-invoice or e-way bill from OEMup. |
| Payment gateway (PCI-DSS compliant) | Billing name, email and payment details | To collect subscription payments. Card numbers never reach our servers. |
| AI document reading (Google Gemini API) | Only a document you explicitly choose to import (for example, a supplier's purchase order or invoice PDF) | To turn the document's line items into a draft record you then review. Not used for advertising. |
| Website tools: Google Analytics, Web3Forms, ipinfo.io, Google Sheets | Usage data (with consent) and website form fields | Website analytics and delivering your form submissions to us. See section 3(d). |
| App stores (Google Play, Apple App Store) | Crash and install statistics generated by the store platform itself | Distribution of the mobile app. Governed by Google's and Apple's own privacy policies. |
| Government authorities, courts, regulators | What is required by the order or law | Only when legally compelled (for example, a GST audit, income-tax notice or court order). |
| Your company's administrators | Your account, activity and the records you create | They manage the workspace you belong to. |
If Kira Intrilogy is ever reorganised or the OEMup business is transferred, data would move to the successor under the same commitments, and you would be notified.
7. Security
- All traffic between your browser or the mobile app and our servers is encrypted in transit (TLS 1.2 or higher); API payloads carry an additional application-level encryption layer.
- Data at rest, including backups, is encrypted (AES-256).
- Passwords are stored as salted PBKDF2 hashes and are never visible to us.
- Access is role-based and logged; production access is limited to named staff.
- The mobile app stores its sign-in token in the device's secure storage and clears it on sign-out.
- We keep daily automated backups and follow ISO 27001-aligned practices. No system is perfectly secure; if we learn of a breach affecting your data we will notify you and the authorities as the law requires.
Found a vulnerability? Please email security@kiraintrilogy.com (see our security.txt).
8. How Long We Keep Data
| Data | Retention |
|---|---|
| Account and workspace data | For as long as the subscription or trial is active, then 90 days for recovery, then deleted. |
| Tax and statutory records (invoices, e-invoices, e-way bills, GST returns, payroll registers) | Up to 8 years from the end of the relevant financial year, as Indian tax and labour law require, even if the workspace is closed. |
| Client-visit GPS check-ins | With the visit record, under your company's retention; deleted or unlinked when your user account is deleted. |
| Server logs and mobile session records | Up to 12 months. |
| Website lead-form submissions | Up to 24 months after the last contact, unless you become a customer. |
| Backups | Rotated on a 90-day cycle; deleted data drops out of backups within that period. |
| Deletion-request log | Email, date and request type kept for 12 months to evidence the deletion. |
9. Your Rights and Choices
You can, at any time:
- Access the personal data we hold about you and get a copy;
- Correct inaccurate or incomplete data (most profile fields can be edited by you or your administrator);
- Export your company's data using the built-in export tools;
- Delete your account — see section 10;
- Withdraw consent — turn off the location permission in your phone's settings, decline file access, or unsubscribe from marketing emails using the link in every email;
- Nominate another person to exercise these rights on your behalf, as provided under the DPDP Act;
- Complain to our grievance officer (section 15) and, if unresolved, to the Data Protection Board of India or the supervisory authority in your country.
Write to info@kiraintrilogy.com from your registered email address. We respond within 30 days. Where the data belongs to your company's workspace, we may need to route the request through your administrator.
10. Deleting Your Account
You can request deletion of your user account, or of your company's entire workspace, from the account deletion page or by emailing us. We verify the request within 2 business days, disable the account immediately on verification, delete personal data within 30 days and purge backups within 90 days. Statutory records your company issued are retained as described in section 8, with your personal details removed where the law allows. Uninstalling the mobile app does not delete your account.
11. Children
OEMup is a business tool for adults at work. We do not knowingly collect data from anyone under 18, and the service and the mobile app are not directed at children. If you believe a minor has provided data to us, contact us and we will delete it.
12. Where Data Is Stored
OEMup data is hosted on cloud infrastructure located in India. If your company is outside India, your data is still stored in India and transferred only to the processors listed in section 6 to the extent needed to provide the service. We do not transfer data to countries restricted by the Indian government.
13. Cookies and Similar Technologies
The website uses essential cookies and, with your consent, analytics cookies; the web app uses essential cookies for authentication. The mobile app does not use cookies; it stores a sign-in token in secure device storage. Details are in our Cookie Policy.
14. Changes to This Policy
We may update this policy as the product or the law changes. The date at the top shows the latest revision. For material changes we will notify you by email, by an in-app notice, or on this page at least 30 days before they take effect where practical.
15. Contact and Grievance Officer
For privacy questions, requests or complaints, contact our grievance officer (designated under the Information Technology Rules and the DPDP Act):
Komal Sonara, Proprietor — Kira Intrilogy
Ahmedabad, Gujarat, India
Email: info@kiraintrilogy.com · Security: security@kiraintrilogy.com
Phone / WhatsApp: +91 63582 51676 (Mon–Sat, 10am–7pm IST)
Related: Terms of Service · Cookie Policy · Refund & Cancellation Policy · Delete your account · OEMup mobile app · Support