1. Information We Collect
Depending on your role and use of the application, we may collect the following information.
Account and Employee Information
- Employee name
- Employee ID
- Mobile number
- Email address
- Department and designation
- User role and approval authority
- Assigned centre or business unit
- Authentication and login information
Payment and Voucher Information
- Expense and voucher identification numbers
- Expense category and subcategory
- Payment mode
- Gross amount, deductions, TDS, and net payable amount
- Beneficiary or vendor information
- Bank name, account details, and IFSC information
- Payment reference and transaction details
- Voucher status and approval decisions
- Rejection reasons and approval remarks
- Payment denomination and cheque details, where applicable
Attachments and Uploaded Files
Users may upload documents related to expenses, payments, vouchers, and approvals, including:
- Invoices
- Bills
- Receipts
- Payment proof
- Bank documents
- Challans
- Cheque images
- Supporting expense documents
- Files attached to comments or queries
Comments and Approval Activity
- Queries raised against expenses or vouchers
- Employee replies
- Approval and rejection comments
- Query-resolution status
- Dates and times of actions
- Approver identity and approval level
Device and Technical Information
- Device model
- Operating system and version
- Application version
- Device identifiers where required
- Push-notification device token
- Application logs and diagnostic information
- Network and technical error information
2. Camera Permission
NHCPL Payments may request access to the device camera so users can:
- Capture bills and invoices
- Capture receipts and payment proof
- Capture cheque or challan documents
- Attach supporting documents to a voucher
- Attach files to a payment query or reply
The camera is accessed only when the user chooses to capture a document or image using an application feature.
3. Photos, Files, and Media Access
The application may allow users to select documents or images stored on their device for upload.
This may include:
- Invoices and receipts
- Payment supporting documents
- Voucher attachments
- Cheque or challan images
- Files submitted with queries and replies
Where the Android system file picker or photo picker is used, the application accesses only files selected by the user.
NHCPL Payments does not use uploaded files for advertising or unrelated commercial purposes.
4. Notifications
NHCPL Payments may use Firebase Cloud Messaging or similar notification services to send:
- New voucher notifications
- Approval requests
- Approval or rejection updates
- Payment status updates
- Query and reply notifications
- Important operational alerts
Push-notification tokens are used only to deliver application-related notifications.
5. How We Use Information
We may use information collected through NHCPL Payments to:
- Authenticate authorized users
- Display expenses and vouchers assigned to a user
- Create and manage payment records
- Process payment approvals and rejections
- Validate mandatory voucher attachments
- Maintain approval workflows and timelines
- Allow employees and approvers to raise and respond to queries
- Provide payment and approval notifications
- Generate financial and operational reports
- Maintain audit and compliance records
- Prevent unauthorized use, fraud, and misuse
- Diagnose errors and improve application performance
- Provide technical and administrative support
- Meet legal, accounting, taxation, and regulatory obligations
6. Legal and Operational Basis
Information is processed for legitimate organizational, employment, contractual, accounting, security, and legal purposes.
NHCPL Payments is an internal business application. Access may be provided based on a user's employment, contractual relationship, job role, or authorization from Nirnayan Health Care Private Limited.
7. Information Sharing
We do not sell or rent personal, financial, voucher, or payment information.
Information may be shared only when required for legitimate business or legal purposes, including:
- With authorized employees, approvers, directors, administrators, and finance or accounts personnel
- With internal departments and authorized centres of Nirnayan Health Care Private Limited
- With vendors, banks, or payment service providers where required to complete an authorized business payment
- With hosting, cloud, notification, security, and technical service providers supporting the application
- With auditors, legal advisers, or regulatory authorities where required
- When required by law, court order, government request, or legal process
- To detect fraud, security incidents, unauthorized activity, or policy violations
8. Third-Party Services
NHCPL Payments may use trusted third-party services necessary to operate the application, including:
- Google Play Services
- Firebase Cloud Messaging
- Cloud hosting and server infrastructure
- Secure file-storage services
- Application monitoring and diagnostic services, where enabled
These service providers may process limited technical or operational data according to their own privacy policies and contractual obligations.
9. Data Storage and Retention
We retain data only for as long as reasonably necessary for:
- Payment and voucher processing
- Accounting and financial recordkeeping
- Approval and audit history
- Taxation and regulatory compliance
- Fraud prevention and security
- Dispute resolution
- Employment and operational requirements
- Legal and contractual obligations
Financial and accounting records may be retained for the period required by applicable law and company retention policies.
When information is no longer required, it may be securely deleted, anonymized, or archived.
10. Data Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information, including:
- Authenticated user access
- Role-based authorization
- Approval-level access controls
- Secure HTTPS communication
- Restricted administrative access
- Protected server and database infrastructure
- Logging and audit controls
- Secure document handling procedures
- Monitoring for unauthorized activity
No electronic storage or transmission method is completely secure. Therefore, absolute security cannot be guaranteed.
11. User Responsibilities
Authorized users must:
- Keep login credentials confidential
- Use the application only for authorized business activities
- Upload only legitimate and relevant documents
- Avoid sharing confidential payment information with unauthorized persons
- Immediately report suspected unauthorized access or misuse
12. User Rights and Choices
Subject to applicable law and company requirements, users may request to:
- Access their personal information
- Correct inaccurate employee or account information
- Request deletion of eligible personal information
- Withdraw optional device permissions
- Ask questions about how their information is used
- Raise a privacy or security complaint
Some payment, accounting, approval, audit, employment, or legal records may need to be retained even after an account is disabled.
13. Account and Data Deletion Requests
Users may request account deactivation or deletion of eligible personal information by contacting Nirnayan Health Care Private Limited.
Before processing a request, we may need to verify the user's identity and authority.
Information may not be deleted where retention is required for financial, accounting, audit, fraud prevention, employment, contractual, taxation, or legal purposes.
14. Permission Management
Users can manage application permissions from their Android device:
Disabling camera, files, photos, or notification permissions may prevent certain features from working correctly.
15. Location Data
NHCPL Payments does not require background location tracking for its primary payment and voucher functionality.
The application should not collect precise or background location unless a future feature specifically requires it and the user is provided with the required disclosure and consent.
16. Children's Privacy
NHCPL Payments is intended only for authorized employees, contractors, approvers, and business users.
It is not intended for children under the age of 13, and we do not knowingly collect personal information from children.
17. Changes to This Privacy Policy
We may update this Privacy Policy when application functionality, data practices, legal requirements, or business operations change.
The updated policy will be published on this page with a revised effective date.
18. Contact Us
For privacy questions, security concerns, correction requests, or data deletion requests, please contact: