Privacy Policy

BackOffice Employee Management Portal

Last Updated: February 2026 | Effective Date: February 2026

1. Introduction

BackOffice is TechSimba's internal employee management application. This Privacy Policy explains how we collect, use, disclose, and safeguard information when TechSimba employees use the BackOffice mobile application and related services (collectively, the "Service").

This app is exclusively for TechSimba employees. By using BackOffice, you acknowledge that you are a TechSimba employee and consent to the collection and use of your information as described in this policy.

2. Information We Collect

2.1 Information Provided During Account Setup

As a TechSimba employee, when your account is created in the BackOffice system, we collect the following information:

Authentication Information

  • Email address (company email)
  • Password (encrypted and securely stored)
  • Authentication tokens and session data

Personal Information

  • Full name (first and last name)
  • Date of birth
  • Gender
  • Marital status
  • Nationality
  • Blood group
  • Phone number
  • Personal email address
  • Profile photograph

Professional Information

  • Employee code/ID
  • Official email address
  • Department
  • Designation/Job title
  • Employment type
  • Work location
  • Joining date
  • Salary information
  • Probation period
  • Reporting manager information

Address Information

  • Permanent address (street, city, state, postal code)
  • Current address (street, city, state, postal code)

Financial Information

  • Bank name
  • Account number
  • IFSC code
  • Branch name
  • Salary slips and financial documents

2.2 Information Collected Automatically

  • Leave & Attendance Data: Leave applications, history, status, dates, and approver information
  • Communication Data: Real-time chat messages, timestamps, and participant information
  • Device & Technical Information: Firebase Cloud Messaging (FCM) token, device platform, OS version, app version, IP address, and device identifiers
  • Usage Information: Features accessed, time spent in app, navigation patterns, error logs, and performance metrics

2.3 Information from TechSimba Systems

We collect information from TechSimba's internal systems:

  • HR management systems
  • Employee database
  • Payroll systems
  • Firebase services (for messaging and notifications)
  • Device operating system (for permissions)

3. How We Use Your Information

We use the collected information for the following purposes:

3.1 Service Delivery

  • Creating and maintaining your account
  • Processing leave requests and approvals
  • Displaying salary slips and financial information
  • Facilitating real-time messaging
  • Delivering announcements and policies
  • Providing employee directory services

3.2 Authentication & Security

  • Verifying your identity
  • Preventing fraud and unauthorized access
  • Maintaining account security
  • Implementing biometric authentication
  • Managing session tokens and authentication

3.3 Communication

  • Sending push notifications for leave approvals
  • Notifying you of messages and announcements
  • Sending important updates and reminders
  • Responding to your inquiries

3.4 Service Improvement

  • Analyzing app usage patterns
  • Identifying technical issues
  • Improving user experience
  • Developing new features
  • Troubleshooting errors

4. Data Storage & Backend Infrastructure

4.1 Backend Server

  • Primary backend: https://bo.techsimba.co/Backend/api
  • Location: India
  • Data stored on secure servers with encryption
  • Regular backups and disaster recovery measures

4.2 Firebase Services

  • Firebase Realtime Database: Stores real-time chat messages
  • Firebase Cloud Messaging: Delivers push notifications
  • Firebase Firestore: Optional document storage
  • All Firebase data encrypted in transit and at rest

4.3 Local Storage

  • Sensitive data stored using React Native Keychain
  • Authentication tokens encrypted locally
  • AsyncStorage for non-sensitive cached data
  • Automatic cleanup on logout

5. Data Security

5.1 Security Measures

  • HTTPS/SSL encryption for all API communications
  • JWT Bearer token authentication
  • Secure token storage using device keychain
  • Automatic token refresh and expiration
  • Session timeout on inactivity
  • Biometric authentication support
  • Network error handling and retry logic

5.2 Access Control

  • Role-based access control (RBAC)
  • Employee can only access their own data
  • Managers can access subordinate leave requests
  • HR can access company-wide information
  • Admin access for system management

5.3 Data Encryption

  • Passwords encrypted using industry-standard algorithms
  • API communications encrypted with HTTPS
  • Sensitive data encrypted at rest
  • Firebase data encrypted in transit and at rest

6. Data Sharing & Disclosure

6.1 We Do NOT Share Your Data With

  • Third-party advertisers
  • Marketing companies
  • Data brokers
  • Social media platforms
  • External analytics services
  • Any external organizations outside TechSimba

6.2 Data Sharing Within TechSimba

  • HR department (for employee management and compliance)
  • Your reporting manager (for leave approvals and performance management)
  • Finance/Payroll team (for salary and financial processing)
  • System administrators (for technical support and maintenance)
  • Senior management (for organizational reporting, as needed)

6.3 Data Sharing Limitations

  • Data shared only for legitimate business purposes within TechSimba
  • Sharing limited to minimum necessary information
  • All recipients bound by confidentiality agreements
  • No data sold or monetized
  • Data remains within TechSimba systems

7. Your Rights & Choices

7.1 Access & Correction

  • You can view and update your profile information
  • You can correct inaccurate personal data
  • You can download your data in standard format

7.2 Data Deletion

  • You can request deletion of your account
  • Upon deletion, personal data removed from active systems
  • Some data retained for legal/compliance purposes
  • Backup data deleted according to retention policy

7.3 Communication Preferences

  • You can manage notification preferences
  • You can opt-out of non-essential communications
  • You can control biometric authentication settings

7.4 GDPR Rights (if applicable)

  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to lodge a complaint with supervisory authority

8. Data Retention

8.1 Retention Periods

Data Type Retention Period Reason
Active account data While employed Operational necessity
Leave records 7 years Legal requirement (India)
Salary slips 7 years Legal requirement (India)
Chat messages 2 years Business necessity
Profile data 1 year after termination Legal compliance
Backup data 90 days after deletion Disaster recovery

8.2 Deletion Process

  • Data deleted from active systems immediately upon request
  • Backup systems purged according to retention schedule
  • Encrypted data securely destroyed
  • Deletion confirmed in writing upon request

9. Third-Party Services

9.1 Firebase Services

  • Google Firebase provides real-time database and messaging
  • Firebase Privacy Policy: https://firebase.google.com/support/privacy
  • Data processed according to Firebase terms
  • Firebase data centers may be located outside India

9.2 Image Processing

  • Image cropping and compression performed locally
  • No images sent to third-party services
  • Images stored on company servers only

9.3 No Third-Party Analytics

  • We do not use Google Analytics or similar services
  • We do not track users across other apps
  • We do not share data with ad networks

10. Contact Information

For privacy-related inquiries, data access requests, or to exercise your rights:

Get in Touch

Email: hr@techsimba.in
Response Time: 30 days for standard inquiries
Urgent Matters: 5 business days
Breach Notifications: 72 hours

Compliance Statements

Legal Compliance

This app complies with applicable data protection laws:

  • Indian Information Technology Act, 2000
  • GDPR (for EU residents)
  • CCPA (for California residents, if applicable)

Employee Consent

  • Users acknowledge they are TechSimba employees
  • Users consent to data collection for HR and operational purposes
  • Users understand data sharing with HR, management, and finance teams
  • Users accept these terms as a condition of employment at TechSimba

By using BackOffice, you acknowledge that you have read and understood this Privacy Policy and agree to its terms and conditions as a TechSimba employee.