Inno Source

Inno Source mobile app — Privacy Policy

What the app collects from your phone, why, how long it is kept, how to have it deleted, and how it is secured.

What the app collects from your phone, why, how long it is kept, how to have it deleted, and how it is secured.

Who this policy is for

This policy covers the Inno Source mobile app for staff (com.innosource.erp) and the data it handles on your phone.

The app is not a consumer product. It is issued to you by the company you work for, which subscribes to Inno Source and creates your account. That company decides what the app records about you and what you can see in it; in data-protection terms it is the CONTROLLER and Inno Source is the PROCESSOR acting on its instructions.

That split decides who ultimately answers a request about your data. It is not a reason to leave you without a route: whatever your employer does, you can write to us directly at the address in this policy and we will act on it as described under "How to have your data deleted".

What the app collects

Account and identity — your name, your employee number, and the email or phone your employer recorded for you. You do not create this account; your employer does.

Work records — the documents and transactions you open or create in the app: orders, invoices, stock movements, tasks, approvals and messages, according to the permissions your employer gave you.

Attendance — when you check in or out from the app, the time and the branch. Where your employer has switched on mobile attendance, this also includes the LOCATION of the check-in, and where your employer requires it, a PHOTO taken at that moment.

Barcode scans — the codes you scan, as part of the stock and sales work you are doing. Images from the camera are processed to read the code and are not stored.

Notifications — a device token issued by the operating system, used to deliver notifications to this device.

On-device copy — the app keeps a copy of the data you have already viewed in its own storage on the phone, so it works without a connection.

Diagnostics — technical error information used to fix faults.

The app does not collect your contacts, your photo library, your call or message history, or your browsing.

Permissions, and what each one is for

Location — used for one purpose only: recording where an attendance check-in happened, and only where your employer has switched mobile attendance on for your branch. The app asks the server first; where the branch has the feature off, the app does not request location permission at all and records no location. It does not track your location in the background and records nothing between check-ins.

Camera — used to scan barcodes, and to take the attendance photo where your employer requires one. It is not used at any other time.

Notifications — used to deliver work notifications: an approval waiting on you, a task assigned to you, a message addressed to you.

Storage — used to hold the offline copy described above.

Refusing a permission disables the feature that needs it and nothing else. You can change any of them in your phone settings at any time.

What we use it for

To provide the service your employer subscribed to: showing you your work, recording what you do, and keeping your employer's records accurate.

To operate, secure and support the app, including diagnosing faults.

To meet a legal obligation where one applies.

We do NOT use your data for advertising. We do NOT sell it. We do NOT build a profile of you, and we do not track you across other apps or websites.

We may use data in aggregated and anonymised form — a form that cannot be traced back to you, your employer or your figures — to analyse and improve the service.

Who we share it with

Your employer. The company that issued your account sees the work you do in the app; that is the purpose of the app, and that company decides who inside it may see what.

Hosting providers, who run the servers the data is stored on.

Push notification delivery. Notifications are delivered through the operating system's own push service — Firebase Cloud Messaging on Android — which receives the device token and the notification content in order to deliver it. Notifications carry the subject and never a monetary amount.

Messaging platforms, artificial-intelligence providers and payment gateways ONLY where your employer has configured them. An employer that configures none sends data to none of them.

A competent judicial or regulatory authority, where the law requires it.

We do not share your data with anyone else, and we do not sell it to anyone.

How long we keep it

On your phone: the offline copy stays on the device until you sign out or remove the app. Signing out clears it. Uninstalling the app removes it.

Work records and attendance: kept for as long as your employer keeps them, because they are your employer's business records. Your employer can delete an individual record at any time.

Attendance photographs and check-in locations: kept with the attendance record they belong to, under the same rule.

Notification device token: kept while the app is installed and signed in, and removed when you sign out or the token is replaced by the operating system.

Diagnostic error data: kept for up to ninety (90) days and then deleted.

After your employer's subscription ends: your employer has thirty (30) days to export its data, and we may permanently delete it from our infrastructure sixty (60) days after that end date.

Records the law requires us to keep — invoices and accounting records — are kept for the period the law sets, regardless of the above.

How to have your data deleted

You can ask for your data to be deleted, and here is exactly how.

STEP 1 — Send a request to the email address in the "How to reach us" section of this policy, with the subject "Data deletion request".

STEP 2 — Include your full name, the name of the company you work for (or worked for), and the email or phone number your account uses. We need these to find your record and to be sure the request is really yours; we will not act on a request we cannot verify.

STEP 3 — We acknowledge your request within seven (7) days and complete it within thirty (30) days.

WHAT HAPPENS. Because your employer is the controller of its own business records, we forward your request to that employer and act on their instruction, and we tell you that we have done so and who it went to. Where the data is ours to delete — your account, your device token, your diagnostic data — we delete it directly and confirm to you when it is done.

WHAT WE CANNOT DELETE, and why: records your employer must keep by law, such as payroll and accounting entries and attendance used to calculate pay, and anything a court or regulator requires us to retain. We will tell you specifically which of these applied to your request rather than refusing it in general terms.

DELETING THE APP. Removing the app from your phone deletes the copy held on the device. It does not delete your employer's records, which is why the request above exists.

You may also ask us for a copy of the data we hold about you, or to correct it, using the same address and the same timescales.

How we keep it safe

In transit: everything the app sends and receives travels over an encrypted HTTPS/TLS connection. The app does not send your data over an unencrypted connection.

Separation between companies: each subscribing company's data is held in its own separate database schema, logically isolated from every other company. One company cannot read another's data.

Access control enforced on the server: what you can see is decided by the permissions and branches your employer set on your account, and that check runs on the SERVER — a screen you are not allowed to see is not merely hidden, the data is never sent to your device. Financial figures are withheld at the server from accounts without the financial-data permission.

On your device: the offline copy is kept in the app's own private storage, which other apps cannot read. Signing out clears it.

Credentials: your session token is stored in the app's private storage and is cleared on sign-out. If you lose your phone, tell your employer — they can disable the account immediately, which stops that device reaching any data.

On our side: our staff reach customer data only where support or operation requires it and under a written confidentiality obligation, we take regular backups, and sensitive actions are recorded in an audit log that also records refused attempts.

No system is perfectly secure, and we do not claim otherwise. If a breach affects your data we notify your employer without undue delay so that they, as the controller, can notify you and the regulator.

Children

This app is a workplace tool for the staff of a subscribing company. It is not directed at children, it is not offered to children, and we do not knowingly collect data from anyone under 18.

Accounts are created by an employer for its own employees; there is no way for a member of the public to sign up.

Changes to this policy

We may amend this policy. The amended version is published at this address with its version number and effective date, and applies from that date.

Where an amendment materially changes what the app collects or who it is shared with, we notify subscribing companies through the approved channel before it takes effect, and the app asks you to accept the new version.

How to reach us

Inno Source

Address: Nasr City, Cairo 11371, EG

Email for notices: privacy@innovationsrc.com

Telephone: +201117330111

A notice sent to the address or email published here is effective from the date it is sent.

Language and the governing text

These terms were drafted in Arabic. The Arabic text is the authentic and governing version. The English version is provided as a convenience translation, and where the two differ in meaning the Arabic text alone applies.

All pages