Firmity provides cloud-based Computerized Maintenance Management System (CMMS), Human Resource Management System (HRMS), Facility Management, Asset Management, Inventory Management, Complaint Management, Payroll Management, Attendance Management, Visitor Management and related operational software services through its website, web platform, mobile applications, APIs and associated services (collectively referred to as the “Platform”).
Our Role
For most customer data processed through the Platform:
- The Customer organisation remains the Data Controller and owner of Customer Data.
- Firmity acts as a Data Processor and processes such information solely for providing Platform services.
- Customers are responsible for obtaining any necessary notices, permissions or consents from their employees, contractors, visitors or other users.
Information We Collect
A. Account Information
We may collect full name, email address, mobile number, company name, department, designation, user role, login credentials.
B. Employee Information
Depending on customer configuration: employee ID, employment records, attendance records, leave records, shift records, payroll records, salary details, bank account information, emergency contacts, employee documents, employment status information.
C. Facility and Operational Information
The Platform may process facility details, site information, buildings and locations, asset records, inventory records, vendor records, maintenance records, work orders, complaint records, inspection records, incident reports, budget and expense records.
D. Visitor Information
Where enabled by the customer: visitor name, contact information, entry and exit records, visit purpose, host details, visitor photographs.
E. Attendance and Location Information
Where enabled by the customer: check-in and check-out records, attendance logs, geolocation information, geo-fencing validation data, time and date stamps.
F. Biometric Information
Where enabled by the customer, Firmity may process biometric attendance information including facial recognition templates solely for attendance verification and workforce management purposes.
Firmity does not sell, market, profile, or commercially exploit biometric information. Biometric information is encrypted and protected using industry-standard security controls.
G. Complaint and Communication Data
The Platform may process information relating to complaints, service requests, incidents, feedback, and operational communications submitted by users or generated during the resolution process. Such information may include complaint descriptions, photographs and other supporting evidence, internal notes, communication records, status updates, resolution details, feedback, satisfaction ratings, and any related documentation. This information is processed solely for service delivery, quality assurance, reporting, compliance, audit, and continuous improvement purposes.
H. Technical Information
Firmity automatically collects certain technical, diagnostic, and usage information generated through the use of the Platform. This may include IP addresses, browser and device information, operating system details, network information, application logs, session identifiers, access records, performance metrics, crash reports, and user interaction analytics. Such information is used for system administration, security monitoring, authentication, performance optimisation, product improvement, compliance, and audit purposes.
How We Collect Information
Information processed by Firmity may be obtained directly from users, provided by customer organisations, or generated through the operation of the Platform. We may collect information through user registrations, web and mobile applications, attendance systems, QR code interactions, complaint submissions, asset and facility management activities, APIs, authorised third-party integrations, cookies, analytics technologies, and automated system logs. In certain cases, information may also be imported from external systems or supplied by customers to facilitate service delivery, operational management, reporting, security, compliance, and platform administration.
Purpose of Processing
Firmity processes information for legitimate business and operational purposes, including providing, maintaining, and improving the Platform and its services. Information may be used to manage maintenance operations, workforce administration, attendance and payroll processing, asset and inventory management, visitor management, complaint resolution, reporting and analytics, user authentication, customer support, workflow automation, system administration, fraud prevention, security monitoring, compliance management, and the fulfilment of contractual and legal obligations. We may also use information to enhance platform performance, develop new features, improve user experience, and ensure the reliability, integrity, and security of the Platform.
Location Data
Where enabled by a customer, Firmity may collect, process, and store location-related information to facilitate attendance validation, geo-fencing enforcement, site presence verification, authorised facility access, workforce management, operational monitoring, and other business workflows supported by the Platform. Location information is collected only in connection with authorised platform functions and only to the extent necessary for providing the relevant services. Such information is processed in accordance with applicable laws, customer instructions, and Firmity's security and privacy obligations, and is not used for advertising, profiling, or unrelated tracking purposes.
Camera Access
Where camera access is requested by the Firmity mobile application, users are informed of:
- Why camera permission is required.
- That access is user-initiated.
- That there is no background recording.
- How captured information is used.
AI-Powered Features
Firmity may develop, deploy, and enhance artificial intelligence (“AI”), machine learning, predictive analytics, and automation capabilities within the Platform to improve operational efficiency, user experience, reporting, workflow management, complaint handling, maintenance planning, resource allocation, and business insights. These features may analyse customer-provided and operational data to generate classifications, recommendations, forecasts, trends, alerts, summaries, or other informational outputs.
AI-generated content is provided on an “as-is” and advisory basis and may not always be accurate, complete, or suitable for a particular purpose. Such outputs are intended to assist users and must not be relied upon as the sole basis for operational, legal, employment, financial, regulatory, safety-related, or business decisions. Customer organisations and users remain solely responsible for reviewing, verifying, and evaluating all AI-generated outputs before taking any action based upon them.
Cookies and Analytics
Firmity uses cookies, web beacons, local storage, and similar technologies to operate, secure, and improve the Platform. These technologies help us maintain user sessions, authenticate users, remember preferences, analyse Platform usage, monitor performance, enhance security, detect fraudulent or unauthorised activity, and improve the overall user experience.
Some cookies may be essential for the proper functioning of the Platform and cannot be disabled without affecting certain features or services. Users may control or restrict cookies through their browser or device settings; however, doing so may impact the availability or functionality of certain Platform features. Firmity may publish and update a separate Cookie Policy from time to time, which shall form part of and be read together with this Privacy Policy.
Sharing of Information
Firmity may disclose information in connection with a merger, acquisition, corporate restructuring, financing transaction, sale of assets, or similar business transaction, provided that appropriate safeguards are implemented to protect the confidentiality and security of such information and the receiving party agrees to honour the obligations described in this Privacy Policy.
This Privacy Policy is suitable for:
- Website Privacy Policy
- Google Play Store submission
- Enterprise procurement reviews
- DPDP Act (India) compliance framework
- Future SOC 2 readiness initiatives
Data Security
Firmity maintains commercially reasonable technical, administrative, and organisational safeguards designed to protect information against unauthorised access, disclosure, alteration, loss, misuse, or destruction. These safeguards may include encryption of data in transit and at rest, role-based access controls, user authentication mechanisms, password protection measures, activity monitoring, audit logging, network security controls, vulnerability management practices, backup and recovery systems, disaster recovery procedures, and other security measures appropriate to the nature of the information processed.
Access to information is restricted to authorised personnel and service providers who require such access for legitimate business purposes and are subject to confidentiality obligations. While Firmity continuously reviews and enhances its security practices, no method of electronic transmission, storage, or processing can be guaranteed to be completely secure.
Security Incidents
Firmity will notify affected customers of confirmed security incidents involving customer data within a reasonable period after discovery.
Data Retention
Firmity retains personal, operational, and technical information only for as long as reasonably necessary to fulfil the purposes described in this Privacy Policy, provide Platform services, support customer operations, comply with contractual commitments, satisfy legal and regulatory obligations, maintain security and audit records, prevent fraud, resolve disputes, and protect the rights and legitimate interests of Firmity, its customers, and users.
Retention periods may vary depending on the nature of the information, customer requirements, applicable laws, and operational needs. Upon the expiration of applicable retention periods, information may be securely archived, anonymised, or permanently deleted in accordance with Firmity's data governance and retention policies. Notwithstanding any deletion request, Firmity may retain certain information where required by law, regulatory requirements, legal proceedings, audit obligations, security investigations, or legitimate business purposes.
User Rights
Depending on the applicable jurisdiction and nature of the information processed, individuals may have the right to access, review, update, correct, delete, restrict, object to, or request portability of their personal information, as well as withdraw consent where consent forms the legal basis for processing.
Where Firmity processes information on behalf of a customer organisation, such requests should ordinarily be directed to the relevant customer organisation, which remains responsible for determining how such requests are handled. Firmity may assist customer organisations in responding to such requests where required by law or contractual obligations. Requests submitted directly to Firmity will be reviewed and processed in accordance with applicable laws, customer instructions, legal obligations, security requirements, and Firmity's operational responsibilities.
Data Export and Deletion
Customers may request the export of their customer data, closure of their accounts, or deletion of information processed through the Platform, subject to applicable laws, contractual commitments, technical limitations, and verification requirements. Firmity will use commercially reasonable efforts to facilitate such requests in accordance with its obligations as a service provider and data processor.
Following account closure, service termination, or deletion requests, certain information may remain temporarily stored in backups, disaster recovery systems, archives, logs, and security records as part of normal business continuity and operational processes. Firmity may also retain information where necessary to comply with applicable legal, regulatory, tax, accounting, audit, security, fraud prevention, contractual, or dispute resolution requirements, or to establish, exercise, or defend legal claims.
Google Play Data Safety Disclosure
The Firmity mobile application may collect:
- User account information
- Attendance information
- Operational records
- Location data
- Device information
- Photographs
- Usage analytics
Data is used solely to provide Platform services, improve functionality, maintain security and comply with customer requirements. Data is encrypted during transmission and storage. Users may request deletion through their organisation administrator or by contacting Firmity.
Children's Privacy
Firmity is intended for business and organisational use and is not directed toward individuals under eighteen (18) years of age.
International Data Transfers
Firmity primarily stores and processes information within India. However, in connection with cloud hosting, infrastructure services, customer support, disaster recovery, security operations, authorised integrations, or other legitimate business purposes, information may be transferred to, stored in, or processed in jurisdictions outside India.
Where such cross-border transfers occur, Firmity will implement appropriate contractual, technical, organisational, and security safeguards designed to protect information in accordance with applicable laws, regulatory requirements, industry standards, and this Privacy Policy.
Changes to This Policy
We may revise this Privacy Policy from time to time. Updated versions will be published on the Firmity website and become effective upon publication unless otherwise stated.
Contact Information
Grievance Officer
Mr. Sanjeev Kumar
M: +91 9868999648
Registered Office
A-13/ S-1, Dilshad Garden,
Delhi – 110095