This Privacy Policy describes how Pinnacle Infratech & Service Pvt. Ltd., a company incorporated in India and operating under the trade name neaurabuild ("Pinnacle", "neaurabuild", "we", "us", "our"), collects, uses, shares, and protects your personal data when you use the Beat — Field Force CRM mobile application, web application, and related services (collectively, "Beat" or the "Service").
Beat is a business-to-business (B2B) customer relationship management platform used by organisations in the cement and building-materials distribution sector in India. If you are using Beat as part of your job at one of our customer organisations (a "Tenant"), the Tenant determines what data is collected about you within their account. We process that data as a "Data Processor" on the Tenant's instructions. For matters relating to your data inside the Tenant's account (correction, deletion, etc.), please contact the Tenant first. For privacy practices that apply across Beat itself, this policy applies.
This policy applies to:
It does NOT cover third-party websites or services that may be linked from within Beat (for example, Google Maps when you tap a customer address). Their own privacy policies apply to those.
We collect the following categories of personal data:
| Data | Purpose | Source |
|---|---|---|
| Full name | Identify you within your organisation | You / Tenant admin |
| Email address | Login, password reset, 2FA, support | You / Tenant admin |
| Phone number | Account recovery, two-factor authentication | You / Tenant admin |
| Role within Tenant | Permissions and visibility | Tenant admin |
| Reporting manager | Hierarchy-based data visibility | Tenant admin |
| Assigned states / districts | Geographic scope of your work | Tenant admin |
| Preferred language | Show the UI in English / Hindi / Hinglish | You |
| Password (hashed) | Authentication. We never see the plain text. | You |
| Data | Purpose | When captured |
|---|---|---|
| Precise GPS (latitude, longitude, accuracy) | Verify check-in/check-out happened at the customer site | When you tap check-in or check-out on a visit; when you start/end your work day |
| Background GPS pings (every ~5 min, only while you've started your work day) | Build a travel log so the office can verify your route | Only between start-of-day and end-of-day. Stops when you tap "End day". You can deny background location and still use Beat — only the live route trace is unavailable. |
| Reverse-geocoded place name (city, state, district, locality, PIN code) | Show a readable address next to the lat/long | Derived from the GPS reading above |
| Data | Purpose | When captured |
|---|---|---|
| Photos you take in-app | Visit-site photos, odometer photos for travel logs, document photos (GST certificate, cancelled cheque) | When you tap the camera button on a form |
| Photos you pick from your gallery | Same as above, when you choose existing photos instead of capturing new ones | When you tap "Choose from gallery" |
When you tap the microphone button next to a text field, Beat records audio from your device's microphone while you speak. The audio is uploaded to our backend, forwarded to a cloud speech-to-text provider (currently Groq, Inc. with OpenAI, Inc. as failover), transcribed into text, and the text is returned to your device. The audio file is never persisted on our servers — it is processed in memory and discarded as soon as transcription completes. The text transcript becomes part of your visit note, lead remark, or quote comment as if you had typed it.
When you use Beat to do your job, you create records inside your Tenant's account:
These records belong to the Tenant, not to us. Other authorised users within the same Tenant can see them based on the Tenant's permission rules.
| Data | Purpose |
|---|---|
| Device model, OS version | Troubleshooting, deciding which mobile builds to support |
| App version, build number | Troubleshooting, rolling out updates |
| IP address | Server logs for security and rate limiting |
Stable device identifier (device_hint) | Trusted-device recognition for 2FA. Not a Google Advertising ID; cannot be used to track you across other apps. |
| Login timestamp and method | Security audit log |
| App crash reports (if our error tracker is enabled by the Tenant) | Find and fix bugs |
We use the data described in Section 3 to:
Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), we process your personal data under the following grounds:
We will not use your personal data for any purpose other than what is listed in Section 4 without obtaining a fresh, specific consent from you.
We share personal data only with the following categories of recipients:
Everything you do inside Beat is visible (subject to the Tenant's permission rules) to other authorised users in your Tenant — typically your reporting manager, their manager, and the Tenant's admin.
| Provider | Data shared | Purpose | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | All Beat data — encrypted at rest | Compute, storage, networking | India (Mumbai region) |
| MongoDB Atlas | All Beat application data | Managed database | India (Mumbai region) |
| Groq, Inc. (primary) | Voice recording sent for transcription, discarded after transcription. Not stored. | Speech-to-text (Whisper model) | United States |
| OpenAI, Inc. (failover) | Same as Groq, used only when Groq is unavailable | Speech-to-text (Whisper model) | United States |
| Anthropic, PBC | Field labels (typically generic strings like "Customer name"). No personal data. | Translation of admin-defined form labels to Hindi / Hinglish (admin tool only) | United States |
| Microsoft (Microsoft Graph) | Quote PDF, customer email address, sender (Tenant's outbound mailbox) | Sending quote-share emails on behalf of your Tenant | Tenant's tenant region (typically India) |
| Google Maps Platform | Latitude/longitude pairs from your GPS readings | Reverse geocoding into readable place names | United States |
| Expo Application Services, Inc. | App version metadata and over-the-air (OTA) update fingerprints | Deliver JavaScript-only app updates without re-installing | United States |
| Google Play / Apple App Store | Install / update events, crash reports if you opted in | Store delivery, official update channel | Per the store's own policies |
Each sub-processor is bound by a written data-processing agreement. They may only process your data on our instructions, must protect it with industry-standard security, and must not use it for their own purposes.
We may disclose your data when compelled by a valid order of an Indian court, an authorised regulator, or law enforcement; or when necessary to investigate suspected fraud, security breaches, or violations of our Terms of Service.
| Data | Retention |
|---|---|
| Active user account | For as long as the Tenant maintains its Beat subscription and keeps your account active |
| Deactivated user account | Kept (in deactivated state, with no login access) for 90 days, then anonymised |
| Business records (visits, leads, customers, quotes) | Belong to the Tenant. Retained as long as the Tenant requires; default is 7 years (Indian tax law). |
| GPS location pings (background travel trace) | 1 year, then aggregated and personal location detail discarded |
| Voice recordings | Not stored. Discarded within seconds of transcription. |
| Server logs (IP, request paths) | 30 days |
| Security audit log (logins, permission changes) | 2 years |
| Email communications with support | 3 years from last interaction |
When the Tenant terminates its Beat subscription, all Tenant data is retained for 30 days (for accidental termination recovery) then permanently deleted. The Tenant can request an export of its data at any point during that 30-day window.
Under the DPDP Act, you have the following rights regarding your personal data:
Where you exercise these rights in respect of data held by your Tenant (business records you created in their account), please raise the request with the Tenant admin first.
Beat is a B2B workforce tool for adults employed by our Tenants. It is not directed at children. We do not knowingly collect personal data from anyone under 18 years of age. If a parent or guardian believes their child has used Beat, please contact us at the address in Section 14 and we will delete the data.
The application data (your account, visits, leads, customers, quotes) is hosted in India (AWS Mumbai region) and does not leave India for routine operations. Certain sub-processors listed in Section 6.2 process specific data in the United States — namely voice transcription (Groq / OpenAI) and reverse geocoding (Google Maps Platform). Where data is transferred outside India, we rely on the contractual safeguards required by the DPDP Act and the receiving country's data protection regime.
If the Government of India designates any of the above countries as a "restricted country" under Section 16 of the DPDP Act, we will move the affected processing to a permitted jurisdiction or to India before the restriction takes effect.
Beat may show links that open external services — for example, tapping a customer address may open Google Maps, tapping a customer's phone number may open the system dialler. Those services have their own privacy policies and we do not control them.
We may update this Privacy Policy from time to time to reflect changes in our practices, new features, or new legal requirements. When we make a material change, we will notify affected users by:
The "Last updated" date at the top of this policy reflects the most recent revision. Continued use of Beat after a change means you accept the revised policy.
We respond to privacy requests within 7 business days.
For unresolved grievances, you may also approach the Data Protection Board of India once it is operational.
This document is published at https://app.beat.neaurabuild.com/privacy
and is the canonical privacy policy for the Beat mobile application (Google Play Store package beat.prod;
Apple App Store bundle ID com.neurabuild.beat) and the Beat web application.