QuikIT Platform

Privacy Policy — QuikInfra Mobile Application

Effective: 22 July 2026Last Updated: 22 July 2026

1. Introduction

This Privacy Policy describes how personal and business information is collected, used, stored, shared, and protected when you use QuikInfra, a construction enterprise resource planning (ERP) product within the QuikIT platform. QuikInfra helps organisations manage site operations, store and materials, procurement, project progress (including BOQ, DPR, and RAB), quality and safety workflows, and related construction management functions.

QuikInfra is offered as a multi-tenant software service. Access is typically granted by an organisation (your employer or contracting party) that has subscribed to or been provisioned for QuikInfra. Authentication is provided through the central QuikIT authentication service; QuikInfra itself does not operate a separate local username-and-password login endpoint.

By creating an account, accepting an invitation, signing in, or otherwise using QuikInfra (including the web application hosted at infra.quikit.ai / quikinfra.quikit.ai and any official QuikInfra mobile client that connects to the same services), you acknowledge the practices described in this Policy. If you do not agree, you should not use the Service.

2. Roles and Responsibilities

QuikInfra is a business-to-business (B2B) service. In most cases:

  • Your organisation (the employer, contractor, or entity that provisioned your account) is the data controller (or "data fiduciary" under applicable Indian law). It determines what data is entered into QuikInfra, who can access it, and how long it is retained.
  • QuikIT acts as the data processor, processing information on the organisation's behalf and in accordance with its instructions and our service agreements.

If you have questions about how your organisation uses QuikInfra, or wish to exercise rights over records controlled by your organisation, please contact your organisation's administrator first. We will support your organisation in responding to such requests.

3. Information We Collect

3.1 Account and Identity Information

When your account is created or provisioned through the QuikIT authentication service, we collect and maintain:

  • Full name, work email address, and mobile phone number
  • Employee ID, designation, department, and role (e.g., site engineer, site manager, store keeper, project manager)
  • Organisation and project/site assignments and permission levels
  • Profile photograph (if provided)
  • Authentication tokens and session identifiers issued by the QuikIT authentication service

Your mobile phone number and/or email address may be used to deliver one-time passwords (OTPs) and verification codes via SMS or email as part of the QuikIT authentication process. Standard carrier SMS charges may apply.

3.2 Operational and Business Data

In the course of using QuikInfra, you and your organisation may enter or generate:

  • Project data, including Bill of Quantities (BOQ), Daily Progress Reports (DPR), Rate Analysis / Running Account Bills (RAB), work orders, and measurement records
  • Store and materials data: stock entries, material receipts (GRN), issues, transfers, and consumption records
  • Procurement data: purchase requisitions, purchase orders, vendor details, quotations, and invoices
  • Quality and safety records: inspections, checklists, non-conformance reports, incident reports, and toolbox talk records
  • Attendance, labour, and workforce deployment records (where enabled by your organisation)
  • Comments, remarks, approvals, and audit trail entries attributed to your user account

This data may contain personal information about you or third parties (e.g., vendor contacts, labour records). Your organisation is responsible for ensuring it has the right to enter such information into the Service.

3.3 Photos, Videos, and Files

The mobile application allows you to capture or upload site photographs, videos, and documents (e.g., for DPRs, quality inspections, safety incidents, and material receipts). These files may include embedded metadata such as capture time and, where location tagging is enabled, GPS coordinates.

3.4 Location Data

With your permission, the mobile app may collect device location:

  • To geotag site photos and progress reports
  • To verify site check-in / attendance (where enabled by your organisation)
  • To associate records with the correct project site

Location is collected only while you use the relevant features (or as clearly disclosed in-app if background collection is ever enabled by your organisation). You can withdraw location permission at any time through your device settings, though some features may stop working.

3.5 Device and Technical Information

We automatically collect:

  • Device model, operating system and version, app version, and unique device identifiers
  • IP address, network type, and language/region settings
  • Crash logs, error reports, and diagnostic data
  • Usage data such as features accessed, screens viewed, and actions performed (used for audit trails, security, and product improvement)

3.6 Offline Data

The mobile app may cache data locally on your device so you can work at construction sites with poor or no connectivity. Cached data is synchronised with our servers when a connection is available. Locally stored data is protected as described in Section 8 and is removed when you sign out or uninstall the app, subject to pending synchronisation.

3.7 Communications

If you contact our support team, we collect the contents of your communication and related contact details.

4. Mobile Device Permissions

The QuikInfra mobile app may request the following permissions. Each is optional unless required for a feature you or your organisation choose to use:

PermissionPurpose
CameraCapturing site photos/videos for DPRs, inspections, GRNs, and incident reports
Photos / Media / StorageUploading existing images and documents; saving downloaded reports
Location (GPS)Geotagging records, site check-in, and site association
NotificationsAlerts for approvals, task assignments, stock thresholds, and safety notices
Network accessSynchronising data with QuikInfra servers
MicrophoneRecording audio as part of site videos or voice notes (only while capturing)
Biometrics (Face/Fingerprint)Optional app lock / quick sign-in (biometric data never leaves your device)

You can manage or revoke permissions at any time in your device settings.

5. How We Use Information

We use the information described above to:

  • Provide, operate, and maintain the QuikInfra service and mobile application
  • Authenticate you through the QuikIT authentication service and enforce role-based access controls
  • Enable core ERP workflows: site operations, stores, procurement, BOQ/DPR/RAB, quality, and safety
  • Synchronise data between your device and our servers, including offline usage
  • Maintain audit trails and record attribution required for construction project governance
  • Send service notifications and alerts relevant to your role and assignments
  • Provide customer support and respond to enquiries
  • Monitor, detect, and prevent fraud, abuse, security incidents, and unauthorised access
  • Analyse usage in aggregate to improve performance, reliability, and features
  • Comply with legal obligations and enforce our agreements

We do not use your personal information for third-party advertising, and we do not sell personal information.

6. Legal Bases for Processing

Where applicable law (such as the GDPR or India's Digital Personal Data Protection Act, 2023) requires a legal basis, we process personal data on the basis of:

  • Contract — to provide the Service under our agreement with your organisation
  • Legitimate interests — securing the Service, preventing misuse, improving the product, and maintaining audit records
  • Consent — for optional device permissions (e.g., camera, location) and any optional communications
  • Legal obligation — where retention or disclosure is required by law

7. How We Share Information

We share information only in the following circumstances:

  • Within your organisation: Data you create is visible to other authorised users of your organisation according to the roles and permissions configured by your organisation's administrators (e.g., project managers can view site engineers' DPRs).
  • Service providers (sub-processors): We use vetted third-party providers for cloud hosting, data storage, push notifications, crash reporting, and analytics. They are bound by contractual obligations to protect your data and use it only to provide services to us. These currently include:
    • Cloud hosting provider TO CONFIRM: AWS / Google Cloud / Azure — application hosting and data storage
    • Google Firebase (Cloud Messaging) — push notification delivery
    • Firebase Crashlytics — crash and error reporting
    • Google Maps Platform — map display and location services
    • SMS gateway provider (e.g., MSG91 / Twilio) — OTP and SMS delivery
    We will update this list as our sub-processors change; an up-to-date list is available on request.
  • Legal requirements: We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, safety, and property of QuikIT, our customers, or the public.
  • Business transfers: If we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this Policy's protections.

We do not share your personal information with advertisers or data brokers.

8. Data Security

We implement technical and organisational measures appropriate to the risk, including:

  • Encryption of data in transit (TLS/HTTPS) and at rest
  • Centralised authentication via the QuikIT authentication service with token-based sessions
  • Role-based access control and tenant-level data isolation in our multi-tenant architecture
  • Access logging and audit trails
  • Regular security reviews, patching, and vulnerability management
  • Restricted employee access to customer data on a need-to-know basis

No system is completely secure. You are responsible for keeping your credentials confidential, using device lock features, and promptly reporting suspected unauthorised access to your organisation's administrator or to us.

8.1 Security Incident and Breach Notification

If we become aware of a personal data breach affecting your information, we will:

  • Investigate and take reasonable steps to contain and remediate the incident
  • Notify the affected organisation(s) without undue delay so they can inform their users, and notify affected individuals directly where required by law
  • Report the breach to the relevant authorities (including the Data Protection Board of India and CERT-In, or other applicable regulators) within the timelines prescribed by applicable law
  • Provide reasonable information about the nature of the breach, the data involved, and the measures taken in response

9. Data Retention and Deletion

  • Operational and business records are retained for as long as your organisation's subscription remains active and thereafter as directed by your organisation or required by law (construction records are often subject to statutory retention periods).
  • Account information is retained while your account is active. When your organisation deactivates your account, your personal profile is disabled, though records you created (e.g., DPR entries, approvals) may be retained by your organisation for audit and legal purposes with your name attributed.
  • Diagnostic and log data is retained for limited periods consistent with security and troubleshooting needs.
  • Upon termination of an organisation's contract, tenant data is deleted or returned in accordance with our service agreement, subject to legal retention requirements.

To request deletion of your personal data, contact your organisation's administrator or reach us at the contact details in Section 15. In-app, you may also access account deletion options at https://www.quikit.ai/delete-account, consistent with app store requirements.

10. Your Rights and Choices

Depending on your jurisdiction, you may have rights to access, correct, update, delete, restrict, or port your personal data, and to object to certain processing or withdraw consent.

Because your organisation controls most data in QuikInfra, we may redirect requests to your organisation's administrator and will assist them in fulfilling your request. You may also:

  • Update your profile information in the app (where enabled)
  • Manage device permissions (camera, location, notifications) in device settings
  • Opt out of non-essential notifications in app settings

If you believe your rights have been infringed, you may lodge a complaint with your local data protection authority.

11. International Data Transfers

Your information may be stored and processed in the country where our hosting infrastructure is located, which may differ from your country of residence. Where required, we implement appropriate safeguards (such as contractual protections) for cross-border transfers in accordance with applicable law.

12. Children's Privacy

QuikInfra is a professional workplace tool intended for adult users. It is not directed at children under 18, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, please contact us so we can delete it.

13. Third-Party Services and Links

The Service may integrate with or link to third-party services (e.g., map providers, document viewers). Their handling of your data is governed by their own privacy policies, and we encourage you to review them. This Policy applies only to QuikInfra and QuikIT services.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the app, the web application, or your organisation's administrators. The "Last Updated" date at the top indicates the latest revision. Continued use of the Service after changes take effect constitutes acknowledgement of the updated Policy.

15. Contact Us

For questions, concerns, or requests regarding this Privacy Policy or our data practices:

QuikIT

Email: inquiry@quikit.ai

Phone: +91 95222 62841

India (Registered Office): B Zone Business Spaces, Indore, MP 452010

Grievance Officer / Data Protection Contact (as required under applicable Indian law):

Name: Hemant Patidar

Email: it@quikit.ai

Response time: We aim to acknowledge grievances within 7 business days and resolve them within the timelines prescribed by applicable laws.

If you access QuikInfra through your organisation, please also review any privacy notices or policies issued by your organisation, as they govern data your organisation controls.