Privacy Policy
[LEGAL ENTITY NAME] ("we") operates oneeye.in. This policy explains what personal data we handle, why, and what rights you have. We handle personal data under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.
Our two roles
As Data Fiduciary, for our own customers: your name, business name, email, phone, billing details, and how you use the product.
As Data Processor, for site media: photographs uploaded by or on behalf of a customer may incidentally contain images of people. We process this only on the customer's instructions, for the sole purpose of assessing physical work. The customer is the Data Fiduciary for that media and is responsible for notifying people at the site. See /dpa.
What we collect
| Category | Examples | Purpose | Basis |
|---|---|---|---|
| Account | Name, email, phone, company | Provide and support the service | Contract performance |
| Billing | GSTIN, invoice details, payment reference | Charge, invoice, comply with tax law | Legal obligation |
| Project | Drawings, BOQ, specifications, work items | Generate the progress record | Contract performance |
| Site media | Photographs of the worksite | Assess physical progress and defects | Customer instruction |
| Technical | IP address, device, log data | Security, abuse prevention, debugging | Legitimate use |
We do not collect biometric data. We do not build person profiles. We do not run advertising and we do not sell or share personal data with advertisers or data brokers.
Faces in site photographs
Photographs taken on an active site will sometimes contain workers or residents. On upload, before any analysis, we detect and irreversibly blur faces. The unblurred frame is discarded and never written to durable storage. We do not generate, store, or match any biometric identifier. Our models are trained to assess surfaces, materials, and assemblies — not people.
Retention
- Site media: deleted 90 days after project closure, or on request, whichever is earlier.
- Derived records (progress percentages, snag lists): retained for the period the customer selects, default 3 years, so a handover dossier remains available.
- Account and billing records: retained 8 years as required by Indian tax law.
- Access logs: 12 months.
Storage and transfer
All project media and derived data are stored and processed in India. We do not transfer site media outside India. Limited account and billing metadata may be processed by international sub-processors listed at /sub-processors.
Your rights
You may request access to a summary of your data, correction, completion, updating, erasure, nomination of a person to exercise your rights, and grievance redressal. Write to privacy@oneeye.in. We respond within 30 days. If unsatisfied, you may escalate to the Data Protection Board of India.
Grievance Officer
[NAME], [TITLE] grievance@oneeye.in [FULL POSTAL ADDRESS]
Breach notification
We notify the Data Protection Board and affected data principals within 72 hours of confirming a personal data breach.
Children
The service is for business use and not directed at anyone under 18. We do not knowingly process children's data.
Changes
Material changes are notified by email at least 30 days before taking effect.
Contact: privacy@oneeye.in