Back to Nirikshan

Privacy Policy

Last updated: May 2026

Nirikshan is built for Indian government officers. This policy explains exactly what data we collect during inspections, how we protect it, and your rights under the Digital Personal Data Protection Act, 2023.

1.Who We Are

Nirikshan ("we", "our", "us") is an AI-assisted inspection management platform operated by an independent software provider based in India. We serve government officers across eight regulatory departments: FSSAI, FDCA (Drug Control), Labour, GPCB, PWD, Revenue, SMC Health, and Mining.

2.What Data We Collect

We collect only what is necessary to generate inspection reports. Data varies by department.

Data TypeWhat ExactlyStored Where
AccountName, email, designation, department, district, stateNeon DB (AWS Mumbai)
GPS LocationCoordinates + human-readable address at inspection siteNeon DB (AWS Mumbai)
Voice RecordingAudio for transcription; optional copy uploaded to Cloudinary when upload succeedsTranscript + provider metadata in Neon; audio URL may be stored when Cloudinary upload succeeds
PhotosPhotos taken at establishment during inspectionCloudinary
Inspection ReportsViolations, observations, AI-generated summary and PDF linkNeon DB (AWS Mumbai)
Senior Officer EmailReporting authority email for report deliveryNeon DB — used only to send reports
Device/IP DataIP address and browser type for securityAudit logs — 90 days

Department-specific data collected

FSSAI

FSSAI License No., food samples (if collected), hygiene observations

FDCA

Drug licence, Schedule H/H1/X records, pharmacist presence, expired stock

Labour

Factory registration, worker counts, safety checks, child labour checks

GPCB

Consent/CTO details, ETP status, stack measurements, records

PWD

Work order, contractor details, construction stage, measurement records

Revenue

Survey identifiers, village, land classification, boundary points

SMC Health

Municipal licence, water source, waste disposal, sanitation observations

Mining

Lease validity, mineral type, GPS boundary compliance, safety checks

3.How We Use Your Data

  1. Provide inspection management and report generation
  2. Transcribe voice recordings to text (Sarvam AI primary; OpenAI Whisper fallback)
  3. Generate structured AI inspection drafts from text context (Google Gemini API)
  4. Send completed reports to your senior officer (Resend)
  5. Generate GPS-stamped PDF reports
  6. Send service notifications (trial expiry, updates)
  7. Maintain audit trails for compliance and security

We will never:

  • Sell your data to any third party
  • Share inspection data with unauthorized persons
  • Use your data for advertising purposes
  • Share data with other departments without your request
  • Retain raw voice audio unless you have opted into workflows that store it (optional Cloudinary upload during transcription)

4.Legal Basis (DPDP Act 2023)

We process your data based on:

  • Your explicit consent given during account creation
  • Legitimate use in providing the inspection service
  • Compliance with Indian laws and regulations
Under the DPDP Act 2023, you are the "Data Principal". Nirikshan is the "Data Fiduciary".

5.Data Storage and Security

Location: Application data is stored in Neon PostgreSQL (region follows your Neon project — commonly AWS ap-south-1 Mumbai for India deployments). Voice is sent to Sarvam or, if needed, OpenAI Whisper for transcription only; the text transcript is saved in Neon. Optional voice files may be uploaded to Cloudinary when that step succeeds. AI report drafting uses Google Gemini; prompts contain inspection text and wizard context — handling is governed by Google's API terms (we do not use your data to train their models).

Nirikshan is currently serving government officers across India.

Security measures:

  • HTTPS/TLS encryption in transit
  • Database encrypted at rest
  • Access limited to you and your configured workflows
  • Audit logs for security actions
  • Rate limiting on API endpoints

6.How Long We Keep Your Data

DataRetentionReason
Inspection reports + photos7 yearsAudit compliance
Account dataUntil account deletedService provision
Voice audio filesOptional Cloudinary + URL in DB if upload succeedsOtherwise only transcript text retained
Audit logs7 yearsSecurity and compliance
Device/IP data90 daysSecurity only
Payment records7 yearsGST/tax compliance

7.Your Rights (DPDP Act 2023)

ACCESS Request a copy of all your personal data
CORRECTION Fix incorrect personal data anytime
ERASURE Delete your account (records may be retained for audit)
GRIEVANCE File a complaint — response within 7 days
WITHDRAW CONSENT Stop using the service anytime

Exercise your rights

privacy@nirikshan.in

Response within 7 days.

8.Data Breach Notification

If a breach affecting your data occurs:

  • We notify you within 72 hours
  • We notify the Data Protection Board of India (as applicable)
  • We provide details and mitigation steps

9.Third-Party Services

ServicePurposeData SentRetained?
NeonPostgreSQL database (hosted Postgres)Inspections, officers, auth/session tables, photos URLs, transcripts, audit logs, invite codes metadataRetained as per Nirikshan policy (typically up to 7 years for inspection records).
CloudinaryMedia hostingInspection photos; optional voice recording files when upload succeeds during transcriptionYes — files retained per your Cloudinary account; URLs/reference stored in Neon
Sarvam AISpeech-to-text (primary)Audio blob sent to api.sarvam.aiTranscript stored in Neon; retention/deletion of audio governed by Sarvam — see their policy
OpenAISpeech-to-text fallback only (Whisper API)Audio blob when Sarvam does not return a resultTranscript stored in Neon; audio handling per OpenAI API data policies (not used to train models by default)
Google (Gemini API)AI inspection draft / structured report generationText: transcription + establishment/wizard fields relevant to the reportGenerated output stored in Neon; request handling per Google AI API terms
ResendTransactional emailRecipient addresses, OTPs, invite codes, report HTML/PDF links, service noticesEmail pipeline provider — short-lived logs may apply; see Resend documentation
Vercel (typical deploy)Application hosting & CDNHTTP access logs, IPs, edge/request metadataPlatform logs are retained for a limited time (often weeks to ~90 days, depending on the hosting plan).

About AI processing

Voice is transcribed with Sarvam AI first; if that fails, OpenAI Whisper is used as a fallback. Structured inspection drafts are produced with Google Gemini. Sign-in OTPs, invitations, completed reports, and service notices are emailed via Resend. Each vendor applies its own subprocessors and retention rules — refer to their published privacy and data processing terms. Nirikshan uses these APIs only to deliver the features above, not for unrelated advertising.

10.Children's Data

Nirikshan is for adult government officers (18+) only. We do not knowingly collect data from minors.

11.Changes to This Policy

We will notify you by email at least 30 days before any material changes.

12.Contact & Grievance Officer

Grievance Officer (DPDP Act 2023)

Gujarat, India

© 2026 Nirikshan. All rights reserved.