Privacy Policy

Asthra ERP mobile application · Last updated: 28 May 2026

This Privacy Policy describes how the Asthra ERP mobile application (the “App”), published by Assetbot, behaves with respect to your personal information. The App is provided to authorised users of organisations that operate their own deployment of the Asthra ERP, for tasks such as managing cost sheets, bookings, site visits, and approvals.

1. About Assetbot’s role

Assetbot is the publisher of the App. Assetbot does not operate the server that holds your records, does not receive a copy of any data you enter into the App, and has no access to information stored in your organisation’s ERP backend.

When you sign in, you enter the URL of your organisation’s ERP backend (or it is pre-configured by your administrator). From that point on, the App communicates directly with that backend over HTTPS. Your organisation is the entity that collects, stores, and controls your personal information — not Assetbot.

2. Information the App accesses on your device

The App requests only the permissions it needs to deliver specific features. You may grant or revoke each permission at any time from your device’s system settings.

Permission Why it is requested Where the data goes
Account information (username, password, name, email, phone, role) To sign you in, identify you to your organisation’s ERP, and personalise the App (display your name, surface approvals assigned to you, etc.). Your username and password are sent over HTTPS to your organisation’s Asthra ERP backend for verification. Your password is never stored on the device. Your name, email, phone and role are returned by the backend and held in the App’s local secure storage so you stay signed in.
Location (while in use) To record the location of site visits when you explicitly choose to capture one inside the App. Sent to your organisation’s Asthra ERP backend along with the related site-visit record. Not shared with third parties.
Contacts To let you select a contact when adding customer or lead information, so you do not have to re-type it. Only the contact entry you explicitly pick is sent to your organisation’s Asthra ERP backend. The App does not upload or scan your full address book.
Notifications To alert you about approvals awaiting your action, status changes on your bookings or cost sheets, and other ERP updates relevant to you. Notification content is generated by your organisation’s Asthra ERP backend. Delivery may transit through Apple’s and Google’s standard push-notification services, as required by the operating system.
Biometric authentication (Face ID, Touch ID, fingerprint) To unlock the App and confirm sensitive actions without typing your password each time. Biometric data is handled entirely by your device’s operating system. The App never receives, stores, or transmits your biometric data.
Files and documents To let you attach files (e.g. cost-sheet supporting documents) and to save reports you download. Files you select are uploaded to your organisation’s Asthra ERP backend. Downloaded reports are stored locally on your device until you delete them.
Camera To let you capture photos of supporting documents — KYC proofs (PAN, Aadhar, ID), signed booking forms, and payment receipts — directly inside the App when you tap “Take photo”. The captured image is uploaded to your organisation’s Asthra ERP backend and attached to the related record. The App accesses the camera only while you have it open, does not record video or audio, and does not operate the camera in the background.
Photos To let you attach images already on your device — for the same KYC, booking and receipt records — when you tap “Choose from gallery”. Only the images you explicitly select are uploaded to your organisation’s Asthra ERP backend. The App does not scan, index, or read any other photos on your device.
Internet access To communicate with your organisation’s Asthra ERP backend. All requests go directly to the ERP API endpoint configured for your organisation. No third-party servers are involved.

3. Information stored on your device

To keep you signed in and to make the App fast offline, the App stores the following on your device only:

All of this is removed when you sign out of the App or uninstall it. None of it is transmitted to Assetbot.

4. Information sent off your device

When you take actions inside the App (creating a cost sheet, recording a booking, submitting an approval, uploading a document, capturing a site visit), the App sends the relevant information over HTTPS to the ERP backend URL configured for your organisation.

That backend is operated by your organisation, not by Assetbot. Assetbot does not intercept, copy, or store any of this information. The App does not transmit any data to Assetbot’s own systems and does not contact any third-party service operated by Assetbot.

5. Things this App does not do

6. Children

The App is a business tool intended for authorised employees and partners of the organisations that use the Asthra ERP. It is not directed at children, and is not designed to be used by anyone under 18.

7. Security

Communication between the App and your organisation’s ERP backend uses HTTPS. Authentication tokens are stored in the platform’s dedicated secure storage (Keychain on iOS, Keystore on Android). Your password is sent only to your organisation’s ERP backend for verification and is never stored on the device. Access to records inside the ERP backend is controlled by your organisation’s administrator.

8. Your data rights and account deletion

Because your personal information lives inside your organisation’s ERP backend (and not with Assetbot), all data-rights requests — access, correction, deletion, export — are handled by your organisation. To request that your account or your records be deleted, contact your organisation’s administrator. They can deactivate or remove your user record from the ERP, after which your sign-in will stop working.

You can also withdraw consent for any device permission at any time from your device’s system settings, or uninstall the App entirely. Uninstalling the App removes the authentication token and all locally cached data.

9. Changes to this policy

Assetbot may update this Privacy Policy from time to time. When that happens, the “Last updated” date at the top of this page will change. Continued use of the App after an update means you accept the updated policy.

10. Contact

For questions about the App itself — permissions it requests, on-device behaviour, security of the App code — contact Assetbot at adithyan@assetbot.org.

For anything concerning the records held inside your organisation’s ERP backend — access, correction, deletion, export, retention — please contact your organisation’s administrator. Assetbot is not able to action those requests because Assetbot does not have access to your organisation’s ERP data.