Legal
Privacy policy
What we collect, why we hold it, and who can reach it. Written to be read, not to be skimmed past.
In effect from 1 September 2026
01
Who we are
FieldNiq is a field-force management service operated by FieldNiq, a company registered in India with its registered office at [REGISTERED OFFICE ADDRESS] ("we", "us", "our").
This policy covers two different groups of people, and the difference matters:
- Visitors to this website, and people who sign up for a subscription.
- Employees of a subscribing organisation, whose activity is recorded through the mobile app.
Sections 2 to 4 explain why those two groups are treated differently under this policy.
02
Our role, and your employer's role
This is the most important section in this document.
When an organisation subscribes to FieldNiq and deploys the app to its employees, that organisation decides what to record, who to record it about, and how long to keep it. Under the Digital Personal Data Protection Act, 2023, the organisation is the Data Fiduciary. We act as a Data Processor on its instructions.
In practical terms: we do not decide to track anyone. Your employer does, using tools we provide. We process that data to deliver the service and for no independent purpose of our own.
If you are an employee and you want to know what is being recorded about you, why, or for how long, your employer is the correct first point of contact. If they do not respond, you may still write to us at soul@fieldniq.com and we will route your request to them and assist.
Where we handle data about our own customers — the person who signs up, billing records, support correspondence — we are the Data Fiduciary and answer for it directly.
03
What we collect
From visitors to this website:
- Nothing beyond standard server logs. We do not run analytics, advertising trackers or session recording on this site.
- If you email us, we keep that correspondence.
When an organisation signs up:
- Organisation name, and optionally GSTIN for invoicing.
- Administrator name, email address and phone number.
- Country and approximate team size.
- Chosen plan and billing cycle.
- Payment records — amount, date, order reference and invoice. Card and bank details are handled entirely by our payment gateway and never reach our servers.
From employees using the mobile app, on the instructions of their employer:
- Name, email address, phone number, role and reporting manager.
- Attendance events with GPS coordinates and timestamps for punch-in and punch-out.
- Customer visit records: coordinates and time of check-in and check-out, visit notes, photographs attached to the visit, and the next scheduled visit date.
- Location readings taken periodically during working hours, forming a route trail for the day.
- Orders booked, leads captured and follow-up notes.
- Leave applications and expense claims, including photographs of receipts.
- A device identifier, used to bind one employee account to one phone.
About your customers and outlets, entered by your team:
- Business name, address, contact person, phone number, email and GPS coordinates.
Your organisation is responsible for having a lawful basis to enter third-party contact details into the service.
04
Location data, specifically
Location is the most sensitive category of data this service handles, so it is worth stating plainly what happens.
- Coordinates are captured when an employee punches in or out, and when they check in or out of a customer outlet.
- The distance check that decides whether a punch or a visit is valid runs on our server, against coordinates the organisation registered in advance. The phone reports its position; it does not decide the outcome.
- Periodic location readings are taken during working hours to form the day's route trail. Collection is tied to the working day configured by the organisation.
- Location is not collected when an employee is punched out, on approved leave, or on a non-working day.
- Employees can see their own recorded attendance and visits in the app.
Employers: monitoring employees carries obligations under Indian labour and privacy law that fall on you, not on us. Before deploying the app you must inform your staff what is recorded and why, and obtain consent where it is required. Clause 7 of the Terms of Service makes this a contractual condition of using the service.
05
Why we process it
- To provide the service the organisation subscribed to — verifying attendance, recording visits, routing beat plans, booking orders.
- To take payment, issue GST invoices and manage subscriptions.
- To provide support when you contact us.
- To keep the service secure, investigate abuse, and diagnose faults.
- To meet legal, tax and accounting obligations in India.
We do not sell personal data. We do not share it with advertisers. We do not use employee location data to build any product or profile beyond the reports the subscribing organisation sees.
07
How long we keep it
- Operational records — attendance, visits, orders, expenses — are retained for as long as the organisation's subscription is active, because the organisation needs its own history.
- After a subscription ends, data is retained for 90 days so it can be exported or the account reinstated, and is then deleted.
- Invoices, payment records and tax documents are retained for eight years, as Indian tax law requires.
- Server logs are retained for 90 days.
- An organisation may request earlier deletion of its data at any time by writing to us.
08
How it is protected
- Every record is scoped by organisation at the database level. This is a property of how the data is queried, not a permission setting that can be misconfigured — a query cannot reach another organisation's rows.
- All traffic between the app, the website and our servers is encrypted in transit using TLS.
- Each employee account is bound to a single device. Moving to a new phone requires an administrator to release the binding, and that action is recorded.
- Access to production systems is limited to staff who need it, and is logged.
No system is perfectly secure. If a breach occurs that is likely to cause harm, we will notify the affected organisations and the Data Protection Board of India as required by law.
09
Your rights
Under the Digital Personal Data Protection Act, 2023 you have the right to:
- Access a summary of the personal data we hold about you and how it is processed.
- Have inaccurate or incomplete data corrected, and have data erased where there is no longer a lawful reason to keep it.
- Nominate another person to exercise these rights on your behalf in the event of death or incapacity.
- Have a grievance heard and answered.
If you are an employee of a subscribing organisation, exercise these rights through your employer, who controls the data — see section 2. We will support them in responding.
If you are our direct customer, write to soul@fieldniq.com. We will respond within 30 days.
10
Grievance officer
If you are not satisfied with how we have handled your data or your request, you can escalate to our grievance officer:
- [GRIEVANCE OFFICER NAME]
- soul@fieldniq.com
- [REGISTERED OFFICE ADDRESS]
We acknowledge grievances within 7 days and aim to resolve them within 30 days. If you remain dissatisfied, you may complain to the Data Protection Board of India.
12
Children
FieldNiq is a workplace tool sold to businesses. It is not directed at children and we do not knowingly collect data about anyone under 18. If you believe a child's data has reached us, write to us and we will delete it.
13
Changes to this policy
If we change this policy in a way that materially affects how personal data is handled, we will notify subscribing organisations by email at least 14 days before the change takes effect, and update the date at the top of this page.