Privacy Policy
How the InomERP Chat Android app and the InomERP website handle your information.
In short: InomERP Chat is a client for an Odoo server that you or your employer operate. Your messages, files and account records are sent to that server and stored there — not on any InomERP server. We do not sell your data, we do not use it for advertising, and we do not build advertising profiles. The app collects a small amount of technical data needed to deliver notifications and diagnose crashes.
On this page
- Who we are
- What this policy covers
- Data the app collects
- Permissions and why
- How the data is used
- Where your data goes
- Sharing and disclosure
- Retention
- Deleting your account and data
- Security
- Children
- Your rights
- Third-party services
- International transfers
- Changes to this policy
- Contact and grievances
1. Who we are
This app and this website are published by InomERP Pvt Ltd, H-110 Sector-63, 301 1st floor, Noida, Uttar Pradesh 201301, India.
For data you enter into an Odoo server operated by you or your employer, that organisation is the data controller (the "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023) and their own privacy policy applies to that data. InomERP acts as a data processor only where we are separately engaged to host or support that server under a written agreement. For the limited technical data described in section 3 that the app sends to us directly, InomERP is the controller.
2. What this policy covers
This policy covers the InomERP Chat Android application distributed on Google Play under the package name in.inomerp.chat, and the InomERP website at inomerp.in. It does not cover:
- The Odoo server you connect the app to. That system is governed by the privacy policy of whoever operates it.
- Third-party websites or services you reach through links in the app.
- Other InomERP products, which have their own policies where required.
3. Data the app collects
The app collects only what it needs to function. Nothing below is used for advertising.
| Category | What it is | Why | Sent to |
|---|---|---|---|
| Account and server details | The server URL, database name, and the login, password or API key you enter. | To authenticate you to the server you chose. | Your Odoo server only. Credentials are held in the device's encrypted storage and are never transmitted to InomERP. |
| Profile information | Name, email address, profile photo, and (if you provide it) phone number. | To display who you are to other users in your workspace. | Your Odoo server. |
| Messages and content | Messages, attachments, images and any files you choose to send or receive. | To deliver the conversation. | Your Odoo server. |
| Push notification token | A device token issued by Google Firebase Cloud Messaging. | To deliver notifications for new messages. | Google FCM and your Odoo server. |
| Diagnostics | Crash reports: device model, OS version, app version, and an anonymous installation identifier. No message content. | To find and fix crashes. | InomERP, via the crash reporting service named in section 13. |
| App settings | Theme, notification preferences, last-opened conversation. | To remember your choices. | Stored on your device only. |
The app does not collect your precise or approximate location, your contacts, your browsing history, your installed apps, or any advertising identifier.
4. Permissions and why
Android asks for each of these at the moment it is first needed. You can decline any of them; only the feature that needs it stops working.
| Permission | Used for |
|---|---|
| Internet / Network state | Connecting to the Odoo server you configure. Required. |
| Notifications | Showing alerts for new messages. |
| Camera | Taking a photo to send in a conversation, or setting a profile picture. Only when you tap the camera. |
| Microphone | Recording a voice message. Only while you hold the record button. |
| Photos and media | Attaching a file or image you select, and saving files you download. |
| Foreground service | Keeping an active call or upload running while the app is in the background. |
The app does not access the camera, microphone, or your files in the background, and does not record anything you have not explicitly started.
5. How the data is used
- To provide the service: authenticate you, deliver and display messages, and sync your workspace.
- To notify you: send push notifications for activity directed at you.
- To keep it working: diagnose crashes and fix defects.
- To meet legal obligations: respond to lawful requests and enforce our terms.
Where the GDPR applies, our legal bases are performance of a contract (providing the app), legitimate interests (security and crash diagnostics), consent (notifications, camera, microphone, and file access), and legal obligation. You can withdraw consent at any time in Android's app permission settings.
We do not use your data for advertising, we do not sell or rent it, and we do not use your message content to train machine learning models.
6. Where your data goes
To your Odoo server only. Content you create in the app is transmitted over HTTPS to the server address you enter, and stored there under that organisation's control and retention rules. InomERP does not receive a copy.
To Google. The push notification token, and the notification payload (sender name and a message preview, unless you turn previews off), pass through Google Firebase Cloud Messaging in order to reach your device.
To InomERP. Only the crash diagnostics described in section 3.
Nowhere else. There are no analytics SDKs, advertising SDKs, data brokers, or third-party trackers in the app.
7. Sharing and disclosure
We share personal data only in these situations:
- Within your workspace: your name, photo and messages are visible to the other users of the Odoo server you connect to, as configured by its administrator.
- Service providers: the infrastructure and crash reporting providers listed in section 13, acting on our instructions under contract.
- Legal: where required by law, court order or a valid request from a public authority, or to establish or defend legal claims.
- Business transfer: if InomERP is involved in a merger, acquisition or asset sale, we will give notice before your data becomes subject to a different policy.
8. Retention
- Messages, files and profile data are retained by the Odoo server you connect to, for as long as its operator decides. We cannot delete them on your behalf unless we are contractually the operator of that server.
- Credentials and settings on your device are removed when you sign out or uninstall the app.
- Push tokens are invalidated on sign-out and expire automatically when the app is uninstalled.
- Crash reports are retained for up to 90 days and then deleted.
9. Deleting your account and data
You can request deletion of your account and the personal data associated with it at any time.
From inside the app
Open Settings → Account → Delete account, confirm, and the request is submitted to the server administrator. Signing out alone removes the local copy but not the server record.
By email
Send a request to info@inomerp.in from the email address on the account, with the subject "Account deletion request" and the name of the server you use. We acknowledge within 7 days and complete or forward the request within 30 days.
What is deleted, and what is kept
- Deleted: your user record, profile details, push tokens, and app settings.
- Kept where required: messages you sent to shared conversations may remain visible to other participants, because they form part of another person's record. Where the server operator's policy allows, these are anonymised instead of removed.
- Kept where the law requires: records we must retain for accounting, tax or dispute-resolution purposes, for the period the law specifies.
If your account lives on an Odoo server operated by your employer or another organisation, we will forward your request to that organisation, which is the only party able to action it.
10. Security
- All traffic between the app and your server uses HTTPS/TLS.
- Credentials and session tokens are stored in Android's encrypted keystore, not in plain files.
- Access to any InomERP-side systems is restricted to staff who need it, and is logged.
- We review dependencies and ship security fixes through Google Play updates.
No system is completely secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority as required by applicable law.
11. Children
This app is a business tool. It is not directed at children, and it is not designed for or targeted to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, to withdraw consent, and to complain to a supervisory authority.
- India (DPDP Act, 2023): you may access and correct your data, request erasure, nominate another person to exercise your rights, and raise a grievance with our Grievance Officer in section 16 before approaching the Data Protection Board of India.
- European Economic Area / UK (GDPR): the rights in Articles 15–22, including data portability, and the right to lodge a complaint with your local supervisory authority.
To exercise any of these, email info@inomerp.in. We may need to verify your identity. If your data sits on a server operated by another organisation, we will tell you who to contact.
13. Third-party services
The app includes these third-party components. Each has its own privacy policy:
| Service | Purpose | Data it receives |
|---|---|---|
| Google Firebase Cloud Messaging | Push notification delivery | Device push token, notification payload |
| Google Play Services | App distribution, updates, integrity checks | Handled by Google under its own policy |
| Sentry (replace or remove if you use a different crash reporter, or none) | Crash and error reporting | Device model, OS and app version, stack traces, anonymous install ID |
14. International transfers
InomERP is based in India, and our support and diagnostic systems are operated from India. Google's notification infrastructure operates globally. Where personal data of individuals in the EEA or UK is transferred outside those regions, we rely on Standard Contractual Clauses or another transfer mechanism permitted under applicable law. The location of your message data is determined by wherever your Odoo server is hosted.
15. Changes to this policy
We update this policy when the app changes. The "Last updated" date at the top always reflects the current version. For changes that materially affect how we handle your data, we will give notice in the app or by email before the change takes effect. Continuing to use the app after that date means you accept the updated policy.
16. Contact and grievances
InomERP Pvt Ltd
H-110 Sector-63, 301 1st floor, Noida, Uttar Pradesh 201301, India
Email: info@inomerp.in
Phone: +91 93102 41710
Grievance Officer (India, DPDP Act 2023): Sachin Prajapati, reachable at info@inomerp.in with the subject "Grievance". We acknowledge grievances within 7 days and respond within 30 days.