This privacy policy applies to the processing of personal data by Yogiji Digi Limited, a company incorporated under the (Indian) Companies Act, having its registered office at PLOT NO-148, SECTOR -58, FARIDABAD, Haryana, India, 121004 (‘Yogiji Digi’, ‘we’ or ‘us’), in connection with the mobile application published as ‘YD - VEDA’ (the ‘App’).
YD - VEDA is a private business-to-business tool allowing an authorised engineer, supervisor or plant manager monitor a steel rolling mill and related equipment, review production history, generate and share reports, and put questions to a built-in assistant called ‘YOGI’. It is not a consumer application. It carries no advertising, no tracking and no in-app purchases, every screen requires a sign-in, and only a person whose work email address an administrator has approved in advance can register. Users are adults acting in a professional capacity; the App is not directed at children and we do not knowingly collect personal data from anyone under the age of eighteen (18).
By registering for or using the App, you confirm that you have the capacity to enter into a legally binding contract, and that you have read, understood and agreed to this policy.
Definitions
‘Personal data’ means any data about an individual who is identifiable by or in relation to such data.
‘Processing’ means any operation performed on personal data, whether or not by automated means, including its collection, storage, use, sharing, disclosure, erasure or destruction.
What we collect
Account data: your name; your work email address; the password you choose (held only as an irreversible hash, never in readable form); the organisation and production lines an administrator has permitted you to see; your access rights; the date you last signed in; and the session token that keeps you signed in.
Delivery details: where you ask for a report or an alert to be sent by WhatsApp, the mobile number you enter. Delivery by email uses the address already on your account. If the number you enter is a colleague’s, you confirm that you are entitled to give it to us for that purpose.
Questions you put to YOGI: the question you type or speak, the recent messages of the same conversation, the production line selected and your device’s date. Ordinary questions are not archived, but we would rather state two exceptions plainly: if you rate a reply with a thumbs-up or thumbs-down we keep that whole conversation together with your email address, and if a single question consumes an unusually large amount of processing our systems save it automatically, with your email address and organisation, for engineering diagnostics. Conversations saved either way can be read by our administrators.
Use of YOGI: counts of the messages, voice messages and processing capacity used, held against your email address for internal usage and cost monitoring.
Voice: if you speak to YOGI, a recording of up to fifteen (15) seconds per turn. It is deleted from your device immediately after upload, held on our systems in memory only and never written to disk, and transcribed by an outside speech-recognition provider – so your voice does leave our systems for that purpose. The transcript is then treated as a typed question, and the spoken reply is generated by an outside speech-synthesis provider and is not saved.
On your device: the session token, held in the iOS Keychain on that device alone and excluded from iCloud and backups; a session cookie, deleted when you sign out; the last screen you were on; and your chosen narration accent. The App keeps no local copy of production or personal data.
Technical data: your IP address, used momentarily with the email address entered to rate-limit sign-in and password-reset attempts, and held in memory for that window only. The App contains no analytics or crash-reporting software, and diagnostic logs written on your device stay on your device.
Production and machine data
Most of what the App displays i.e. gauge, force, speed and thickness readings, coil records, tonnage, energy consumption, roll-change history and furnace data is machine data belonging to the customer organisation. We treat it as commercially confidential, but it does not identify individuals. Records of which user viewed or scheduled what, and alert subscriptions holding a name, email address and mobile number, can be traced back to you, and those we treat as personal data.
Permissions, and what we do not collect
The App asks for one permission only, access to your microphone at the point you first speak to YOGI, and remains fully usable if you decline. No other permission is requested. The App uses no advertising identifiers and does not track you across other apps or websites; it reads no device identifier, model or operating-system version; it collects no location, photographs, contacts, calendar, health, fitness or biometric data, and Face ID and Touch ID are not used; it does not measure your screen views, taps or session lengths; and it collects no payment or financial information. We do not sell or rent personal data, and we do not share it for anyone else’s marketing.
Why we process personal data
To create and administer your account and verify who you are at sign-in; to show you the plant data you are authorised to see, and no more; to produce and deliver the reports and alerts you have asked for, and let you share them; to answer your questions through YOGI and to review and improve its answers where you have given feedback; to keep the App and our systems secure and investigate misuse; to monitor internal usage and cost; and to comply with law. This processing rests on the performance of our contract with your organisation and with you, on our legitimate interest in operating and securing the App, on your consent where the law requires it, and on compliance with our legal obligations.
Disclosure of personal data
We do not sell, rent or trade personal data. The App communicates only with our own servers, which in turn rely on a small number of carefully selected service providers, namely, cloud infrastructure and file storage, managed database hosting, an artificial-intelligence language-model provider that generates YOGI’s answers, a speech-recognition provider, speech-synthesis providers, an email delivery provider, and a WhatsApp message delivery provider. Each processes data only on our instructions, is bound to confidentiality and appropriate security measures, and may not use it for its own purposes; none is a data broker. We identify them by category because their identity is commercially confidential; a named list is available to customer organisations, regulators and individuals on request, on appropriate terms of confidentiality.
We may also disclose personal data where required by law, by a court or by a regulator, to our professional advisers under a duty of confidence, and to a successor in connection with a reorganisation or transfer of business. Apple distributes the App and holds its own account relationship with your device, governed by Apple’s privacy policy. Where a provider processes personal data outside India, we ensure the transfer is made in accordance with applicable law and on terms requiring an equivalent standard of protection.
Retention of personal data
We keep personal data only for as long as we need it, or for as long as the law requires:
- account data, for the life of your account;
- a report schedule or alert, and any mobile number given for it, until you cancel or delete it;
- a password-reset token only for fifteen (15) minutes; a session token, until you sign out, it expires, or you sign in from another device;
- voice recordings and spoken replies are not retained;
- conversations archived through feedback or diagnostics, and counts of your use of YOGI; and
- records which the law requires us to keep only for the statutory period.
Security
All communication between the App and our servers is encrypted. Passwords are stored only as an irreversible bcrypt hash. The session token sits in the hardware-backed iOS Keychain, sandboxed to the App, and never leaves the device. Only one (1) session per account is permitted, so signing in on a new device signs the previous one out. Every request requires a valid session, sign-in and password-reset requests are rate-limited, access is scoped to the organisations and production lines granted to you, voice recordings are never written to disk, and credentials are deliberately kept out of diagnostic logs. Since no system can be guaranteed to be completely secure we request you to please keep your password confidential and tell us immediately if you believe your account has been used by someone else.
Your rights
Subject to applicable law, you may ask for access to the personal data we hold about you, ask us to correct or erase it, ask us to restrict its use, withdraw a consent you have given (microphone access can be switched off in your device settings at any time), nominate another person to exercise these rights in the event of your death or incapacity, and have a grievance considered and answered by us.
You can delete your account and the data associated with it at any time from within the App, or by writing to us. Records we are required by tax, company or other law to keep will survive that deletion, and will be kept for the statutory period and used for no other purpose. Because your access is granted through your organisation, its administrator may also remove or vary it.
Payments
The App takes no payments. It has no purchase flow, no pricing and no subscription feature, and simply reflects the access your organisation has already arranged. Nothing in the remainder of this section applies to the App.
Where you choose to pay for a subscription or service on our website, your card, UPI and net-banking credentials are entered directly into the payment gateway’s own hosted checkout and are never seen or stored by us; where a card is saved, we hold only the network-issued token, the last four (4) digits and the card network. We do hold the payer’s name, billing email address, telephone number and address, any GST registration number needed for a compliant tax invoice, records of the transaction, and the state of your subscription. The gateway is PCI-DSS certified and stores payment data relating to Indian transactions within India, as the Reserve Bank of India requires; it acts partly on its own account for fraud prevention, anti-money-laundering and regulatory reporting, so its own privacy policy applies alongside this one. We process payment data to perform our contract with you and to comply with tax and accounting law, which requires books of account to be kept for eight (8) financial years and goods and services tax records for seventy-two (72) months; those records survive the closure of an account and any deletion request.
Changes to this policy
This policy may be updated or amended from time to time in writing. The current version, with its version number and effective date, is always published at https://ydagchmi.com/privacy, and we will take reasonable steps to bring material changes to your attention.
Grievance officer and contact information
If you have a question about this policy, wish to exercise any of the rights above, or wish to make a complaint, please contact –
Lakshya Sharma, Grievance Officer
Yogiji Digi Limited
147, Sector 58, Faridabad, HR – 121004
Telephone: 129-4295200
Email: softwareteam@ydgroup.com
We will acknowledge your request and respond within the period allowed by applicable law. If you are not satisfied with our response, you may escalate the matter to the competent data protection authority.