Enterprise Asset Intelligence

Privacy Policy

What information we collect, why we hold it, where it is stored, and what we will never do with it.

Published by the legal and compliance team.
Last Updated: June 2026

1. Introduction

ASTITVAAMS Enterprise Intelligence is committed to maintaining the highest standards of data protection and privacy for our government ministries, public sector undertakings (PSUs), and enterprise clients. This Privacy Policy describes how we handle the sensitive physical asset data entrusted to our intelligence platform.

We hold records about your organisation's assets and the staff responsible for them. Some of our customers are government bodies with statutory reporting duties, so we treat that data carefully by default rather than as an afterthought.

2. Information Collection

Two different things are covered here: what you tell us through this website, and what the platform records once you are a customer.

What You Send Us Through This Website

When you submit a form on this site we receive your name, work email address, organisation, mobile number and whatever you wrote to us. We use it to answer you and nothing else - no advertising, and we do not sell or share it.

If our email system is down when you submit, your enquiry is written to a private file on our server so it is not lost, and removed once we have replied. Ask for a copy or deletion at any time using the contact details at the end of this page.

Technical Asset Telemetry

RFID/QR scan coordinates, IoT telemetry, equipment calibration logs, maintenance cost invoices, and hardware health metrics.

Personnel & Custody Identity

Sign-in records, confirmations when someone accepts custody of an asset, and the permissions each user holds.

3. Data Usage

  • Intelligence & Reconciliation: Aggregated data is processed to generate predictive maintenance schedules, detect unrecorded ghost assets, and verify Form GFR 22 balances.
  • Statutory Audit Trails: Maintaining immutable cryptographic logs for CAG audit readiness and internal departmental security inspections.
  • System Optimization: Using anonymized metadata to enhance the accuracy of our AI-driven procurement surplus algorithms without exposing client identifiers.
Secure Data Server Room
Zero-Trust Architecture

Your Data Stays Separate

Every data packet is verified, encrypted at rest with AES-256, and isolated within domestic Indian cloud instances.

4. Cookies & Tracking

Our platform uses essential session tokens, CSRF protection headers, and strict authentication cookies. We do not use third-party advertising cookies or cross-site behavioral tracking mechanisms within our enterprise or government environment.

5. Security Architecture

Data security is the absolute foundation of ASTITVAAMS. Our infrastructure employs:

Encrypted at rest: Asset records, tag data and signatures are all encrypted where they are stored.
TLS 1.3 Transport Security: Mandatory end-to-end encryption for field mobile scanner syncs and API requests.
Held in India: Your data stays in Indian data centres and is not copied outside the country.

6. DPDP Act 2023 Compliance

We follow India's Digital Personal Data Protection Act 2023. Your organisation is the one that decides what happens to your data. We only process it on your instructions, to run the service you are paying for.

7. Mobile App

The ASTITVAAMS mobile app is used by employees and authorised personnel of our Client Organisations to manage assets, inventory, and tickets on the move. This section explains what the app specifically collects on your device, in addition to the practices described above.

Account & Profile Information

When your organisation creates your account, we collect your name, email address, phone number, role/department, and organisation identifiers linking you to your Client Organisation.

Location

Precise and approximate location is requested only when you geo-tag a photo attached to an asset/document record, or perform an asset verification scan. We do not track location in the background, and you can withdraw this permission any time from your device settings.

Photos, Documents & Files

You can capture photos, pick images from your library, and upload documents (PDFs, images, etc.) linked to assets, tickets, or inventory records. These are transmitted and stored as part of your organisation's asset records.

Operational Data

As you use the app, we collect the data generated by your work — asset records, custody assignments and transfers, inventory transactions, support tickets, and QR/barcode scan history.

Device & Diagnostic Information

Limited technical data — app version, network status, and basic device-integrity signals (e.g. detecting rooted/jailbroken/emulator environments) — is collected purely for security and troubleshooting.

Stored Locally On Your Device

Your session/authentication token (via secure platform storage), and an offline action queue that syncs once your device reconnects.

App Permissions

PermissionPurpose
CameraCapture photos for asset/document records and QR/barcode scanning
Photo library / filesAttach existing images and documents to records
Precise & approximate locationGeo-tag photos and asset verification scans
NotificationsAlerts for tickets, approvals, and asset assignments
Internet/network stateCore connectivity and offline-sync detection

We do not use app data for advertising and do not sell your personal information to third parties.

8. Your Privacy Rights

Your data belongs to you, not to us. You can ask for a full export at any time, ask us to show you the audit log, or ask us to delete everything once your contract ends. We will confirm in writing when it is done.

Data Protection Office (DPO)

Have specific compliance questions or need to exercise statutory privacy rights?