01Who this policy covers, and an important note on how access is granted
Brikito is a business/workplace application. You don't sign up for it on your own the way you would a consumer app — your organization (the construction company, or a project you're contracted to) invites you, sets up your account, and assigns you a role (Site Engineer, Project Manager, Inventory Manager, Purchase Manager, Finance Manager, or another role your organization defines). This matters for how your data is handled:
- Your organization's Super Admin/Org Admin is the primary controller of the data generated on their projects — they decide who's invited, what role they hold, and which projects they can see. Brikito operates the platform on the organization's behalf.
- If you're an employee or site worker using Brikito as a condition of your role (e.g., your employer requires attendance check-in and daily reporting through the app), your use of certain features isn't a matter of individual opt-in the way a consumer app's would be — it's directed by your employer, similar to any other workplace system. Where a feature genuinely is optional (see Section 10 on face capture, for example), that's called out specifically.
- Vendors and Contractors who are given limited, scoped access (to see only their own purchase orders, deliveries, or work orders) are covered by this policy for the data Brikito itself collects from them, but their own separate dealings with the organization (contracts, commercial terms) are governed by their agreement with that organization, not by Brikito.
- Clients/Customers given read access to summary project information are covered by this policy for their own account data; project data they view belongs to the organization that granted them access.
02Information we collect
2.1 Account and identity information
- Full name, mobile phone number (used for OTP-based login), and role/designation
- Email address, where provided as a secondary contact
- A profile photo, if you add one
- A face photo captured during onboarding, used for identity verification at signup — see Section 10 for special handling of this, since it's treated as sensitive/biometric data
- Which organization, project(s), and chat group(s) you're part of
2.2 Location data
- GPS location, collected specifically when you check in or out of attendance, to confirm you're within the configured radius of the project site (geofencing). Brikito is not designed to track your location continuously or outside of the attendance check-in moment — see Section 11 for more detail on exactly when this is collected.
2.3 Photos and other media you submit
- Photos attached to confirm receipt of materials or tools, to a Daily Progress Report (DPR), to a repair/fault report, or to any other record where a photo is requested
- Documents and drawings you or your organization upload (architectural/structural drawings, contracts, BOQs, schedules)
2.4 Voice input
- If you use a voice-input feature (to fill an indent, DPR/DLR, or weekly plan form, or to talk to Brik AI), your spoken audio is processed to extract text and structured data. In the current prototype this is simulated for demonstration purposes and no real audio is captured; in the production app, real speech will need to be processed (very possibly by a third-party speech-to-text service — see Section 6) to deliver this feature, and we'll update this section with the specifics once that's finalized.
2.5 Messages and work content
- The content of messages, indents, purchase requests, inquiries, tasks, updates, and any other content you post inside your organization's project chat groups
- Files, quotations, invoices, and payment proofs attached to purchase and payment records
2.6 Work and attendance records
- Check-in/check-out timestamps, breaks, and attendance status
- Task assignments, completions, and remarks
- DPR/DLR entries (site progress, labour headcount, materials consumed)
2.7 Financial and commercial data
- Purchase requests, vendor quotations, purchase orders, invoices, and payment records related to project procurement. Some of this data (vendor contact details, pricing) may itself be personal data about individuals at your vendor organizations, not just business data about your company.
2.8 Usage and device information
- Standard technical information generated by using the app — device type, operating system, app version, and basic diagnostic/crash information, collected to keep the app working reliably. Brikito does not use this information for advertising, and does not run third-party advertising or ad-tracking code (see Section 6).
03How we use your information
- To operate the app's core functions — routing indents/PRs/inquiries/tasks to the right people, tracking approvals, generating status views, and keeping your organization's teams coordinated
- To verify your identity at signup and login
- To confirm attendance and location within the configured project geofence, at the moment of check-in/out only
- To generate reports, summaries, and dashboards for your organization's managers and leadership (Project Manager, CXO/Management-level views), scoped to what their role is permitted to see (see Section 5)
- To power Brikito's AI-assisted features — see Section 4, which explains this in more detail since it deserves a closer look
- To maintain security, investigate misuse, and keep an audit trail of who did what (Section 8)
- To communicate with you about your account, or about safety, schedule, or budget issues that Brikito or your organization's managers flag
We do not use your personal data to serve you ads, and we do not sell your personal data to third parties.
04AI processing of your data — how it works and what it doesn't do
Because Brikito is built around AI-assisted message understanding and a project-wide assistant ("Brik AI"), this deserves its own clear explanation rather than being folded into Section 3.
- When you type or speak a message, Brikito's AI reads that message to classify it (as an indent, inquiry, task, update, etc.) and extract structured details from it — item names, quantities, dates, and so on.
- The AI never commits an action on your behalf without you confirming it first. Every AI-drafted indent, task, or structured record is shown to you for review — with the option to edit any field — before it's actually created and sent to the rest of your team. This is a deliberate design principle, not an incidental one, carried through everything specified for this product.
- Brik AI, the project-wide assistant, can answer questions using your organization's live project data (indent counts, approval status, attendance, and — once implemented — uploaded schedules, budgets, and drawings) when a member of your organization asks it something. It answers using data your organization already has and that your role permits you to see; it does not have access to other organizations' data.
- AI processing described here happens as part of delivering the app's core functionality on behalf of your organization — it is not used to build an advertising profile about you, and outputs are not shared outside your organization.
05Who can see your information
Brikito is built around role-based access — what any given person can see depends on their role and which project(s) they're part of, not on a blanket "everyone sees everything" model. In broad terms:
- Your immediate work: people in the same chat group/project as you can see the messages, indents, and records you post there, consistent with how a work chat normally functions.
- Your managers: your Project Manager (and above, if your organization has a management/CXO tier) can see records relevant to approvals, progress, and reporting across the project.
- Your organization's Admin: has broad administrative access needed to manage users, projects, and settings.
- People outside your organization (a different company's project, or the general public) never have access to your data through Brikito.
- Vendors and Contractors only see the specific purchase orders, deliveries, or work assigned to them — never your organization's internal chats, other vendors' pricing, or unrelated project data.
The exact permission structure is detailed in Brikito's Roles & Permissions specification, which this policy is consistent with; your organization's Admin can tell you specifically what your role can see.
06Sharing with third parties
- We do not sell your personal data.
- Within your organization, data is shared according to the role-based access described in Section 5 — this is normal operation of the app, not third-party sharing.
- Service providers: to actually run the app, a small number of infrastructure providers process data on our behalf under contract — for example, cloud hosting/storage, the SMS/OTP gateway used for phone verification, and (if the production voice feature described in Section 2.4 is built as planned) a speech-to-text service. These providers are only permitted to use the data to provide their service to us, not for their own purposes. list the actual providers once selected, since this section currently describes the category of provider rather than naming specific vendors.
- Legal disclosure: we may disclose information if required by law, legal process, or to protect the rights, property, or safety of Brikito, your organization, or others.
- Business transfers: if Brikito (the company) were involved in a merger, acquisition, or sale of assets, data may be transferred as part of that transaction, subject to the same protections described here.
07Data retention
- We retain your data for as long as your account is active and you're part of an organization using Brikito, plus a reasonable period afterward for legitimate business, audit, and legal purposes.
- Some records — particularly attendance, payment, and procurement records — may be subject to statutory retention requirements under applicable Indian labour, tax, or company law, which can require retention for longer than the operational need alone would suggest. with counsel: specific retention periods per record type, since these depend on which statutory requirements apply to your organization's operations.
- If your account is deactivated (e.g., you leave the organization), your historical actions remain in the record for audit purposes (consistent with the audit-log approach in the Roles & Permissions specification), but your account itself moves to an inactive state rather than being immediately deleted.
08Data security
- Access to data is controlled by the role-based permission model described in Section 5 — enforced at the system level, not just hidden in the app's interface.
- Actions that create, edit, approve, or reject records are logged with who performed them and when, consistent with the audit-log approach specified for Brikito.
- Data in transit and at rest is protected using industry-standard encryption. once the production backend/infrastructure is built: specifics of encryption standards, hosting region, and any relevant certifications.
- No system is perfectly secure, and we can't guarantee absolute security — but security is treated as core infrastructure for this product, not an optional feature.
09Your rights
If you're in India, the Digital Personal Data Protection Act, 2023 gives you certain rights over your personal data, and we intend for Brikito to honor them:
- Right to access information about what personal data of yours is being processed and how
- Right to correction and erasure — you can ask us to correct inaccurate data, or delete data that's no longer needed for the purpose it was collected for (subject to legitimate retention needs described in Section 7)
- Right to withdraw consent, where our processing relies on your consent, at any time — as easily as you gave it
- Right to grievance redressal — you can raise a complaint about how your data is handled
- Right to nominate someone else to exercise these rights on your behalf in the event of your death or incapacity
To exercise any of these rights, contact Grievance Officer name / email / phone — required under Indian law once these provisions are in force.
If you're using Brikito through your employer, some requests (like correcting your role or removing you from a project) may need to go through your organization's Admin, since they control that operational data — we'll route you appropriately.
If you're outside India, you may have similar rights under the law that applies to you; contact us and we'll do our best to honor them even where not strictly required.
10Special note on biometric data — face capture at onboarding
The onboarding flow captures a photo of your face to verify your identity when your account is created. Because this is treated as sensitive biometric data:
- It is used only for identity verification at signup, not for ongoing facial recognition, surveillance, or tracking during your regular use of the app.
- is face capture mandatory for every user today, or is there (or should there be) an alternative verification method for someone who doesn't want to provide it? This affects both the product and what this policy needs to say — please confirm before this section is finalized.
11Special note on location data — attendance geofencing
- Location is collected only at the moment you check in or check out of attendance, to confirm you're within your project's configured radius — Brikito is not designed to track your location continuously, log your movements throughout the day, or track you outside of work hours.
- If your device's location services are off, you generally won't be able to check in until they're enabled, since the geofence check depends on it.
12Children's data
Brikito is a workplace tool intended for adult construction-industry professionals and is not directed at, or intended for use by, children. We do not knowingly collect personal data from anyone under 18. If you believe a minor has been given access to Brikito, please contact us so we can address it.
13International data transfer
where is production data hosted, and does any processing happen outside India? If Brikito is built and hosted entirely within India for an India-based customer base, this section can say so plainly; if any third-party service provider (Section 6) processes data outside India, that needs to be disclosed here specifically.
14Changes to this policy
We may update this Privacy Policy from time to time as the product evolves — for example, as AI features move from the current prototype into real production capability, or as new modules are added. We'll update the "Last updated" date above, and where a change is significant, we'll make a reasonable effort to notify your organization's Admin and/or notify you directly within the app.
A note on what's still open
A few things in this draft genuinely need your input, not just a legal read-through, because they're product decisions that can't be made for you:
- Face capture at onboarding (Section 10) — mandatory, or should there be an alternative?
- Third-party service providers (Section 6) — which cloud hosting, SMS/OTP gateway, and (if built) speech-to-text provider will actually be used? This also determines Section 13 (international transfer).
- Retention periods (Section 7) — these depend on which Indian statutory requirements apply to your organization's specific operations (labour law, tax law, company law) and should be confirmed with counsel rather than guessed at here.
- Grievance Officer / legal entity details (Sections 9, 15) — needed to make this a complete, publishable document rather than a template.