Indotech Inward Privacy Policy

Effective 29 September 2026

Indotech Inward is an internal application for authorized Indotech personnel. Its current feature lets a user scan purchase bill pages and send them to Indotech for intake. An upload receipt confirms that the images arrived; it does not mean a bill was approved or entered into ERPNext.

Information handled

  • Purchase bill images selected or scanned by the user.
  • Employee sign-in identity, including an account identifier used to associate an upload with its owner.
  • Upload details such as the intake ID, page count, file sizes, checksums, status, and timestamps.
  • Authentication tokens needed to keep the user signed in; the app encrypts them in private device storage.

The app keeps a pending draft in private storage on the device until upload succeeds. Device backup for this app is disabled. It sends bill images and intake details over HTTPS to Indotech's AWS service in the Asia Pacific (Mumbai) region. Images are stored in a private, encrypted S3 bucket. Intake details are stored in DynamoDB.

Use and access

Indotech uses the information to receive and track purchase bill submissions and to support authorized internal processing. Sign-in is handled through Indotech's identity services and Amazon Cognito. Access to the upload API is limited to approved account identifiers. The app does not contain advertising or analytics features, and Indotech does not sell bill images or account information.

The scan feature uses Google ML Kit Document Scanner through Google Play services. Google says ML Kit can collect device and app information, device or installation identifiers, performance metrics, feature events, input and output sizes, and error codes for diagnostics and usage analytics. Google says this data is encrypted in transit and is not shared with third parties. The document scanning flow runs on the device. Indotech's upload service receives the scanned images only when the user chooses Upload.

Retention and deletion

Uploaded bill images are scheduled to expire 365 days after upload. Intake records are scheduled to expire 365 days after receipt, or after creation if an upload is never completed. AWS lifecycle and database expiry run asynchronously, so removal may occur after that date. Database recovery backups may retain recoverable records for up to 35 additional days. A user can remove an unfinished draft from the app.

Request deletion of uploaded data

To request earlier deletion of an Indotech Inward upload, email Contact@indotechmeter.com with the intake receipt ID and the account used to upload it. Indotech will verify the request and delete the matching bill images and intake record when permitted by its business and legal obligations. An employee account is managed by Indotech separately; this request does not automatically delete the employee account. Recovery backups may retain deleted intake records for up to 35 additional days.

Contact

For access, correction, or deletion requests, email Contact@indotechmeter.com. Indotech's general privacy policy is available at indotechworks.com/privacy.