01About this policy
This Privacy Policy explains how Vividia Infosys (“Vividia”, “we”, “us”) handles personal information when you use:
- The Vividia Suite mobile app for iPhone, iPad and Android (bundle and package ID
com.vividiainfosys.erp), available on the App Store and Google Play. - The Vividia Suite web applications, including Vividia Workspace and the ABMS, HRM, EMIS, LMS, HMS, Clinic, RMS, IMS, Manufacturing and Viana AI applications (together, the “Services”).
- This website, vividiasuite.com, including its contact and demo request forms.
It describes what we collect, why, who we share it with, how long we keep it, how we protect it and the choices and rights you have. Please read it together with our Terms and Conditions.
Vividia Suite is business software. You can only sign in to the app with an account created by an organization that subscribes to Vividia Suite, such as your employer, school, clinic, hotel or restaurant. There is no public sign-up, no advertising and no in-app purchases.
02Who is responsible for your information
Our role depends on the information involved:
- Organization data. Records that an organization and its users enter into the Services—employee, student, patient, guest, customer, supplier, financial and operational records—belong to that organization. The organization decides what is collected and why, and is the controller of that data. Vividia processes it on the organization’s behalf and under its instructions, as set out in the customer agreement.
- Account, device and diagnostic data. For information needed to run, secure, support and improve the app and Services (for example sign-in, crash reports and push notification tokens), Vividia acts as controller.
- Website and enquiry data. For information you submit through this website, Vividia acts as controller.
If your organization gave you access to Vividia Suite, questions about how it uses your records (for example your payroll, attendance or student data) should first go to your organization’s administrator. We will help them respond.
03Information we collect
Account and sign-in information
- Workspace code, email address and password (passwords are sent over encrypted connections and are not visible to Vividia staff).
- Your name, role, assigned applications and permissions, as set by your organization’s administrator.
- One-time passcodes used to reset a forgotten password.
- Session tokens that keep you signed in.
Information entered in the applications
Depending on which applications your organization uses and what your role allows, the Services may contain:
| Application | Examples of information |
|---|
| HRM | Employee profile and contact details, attendance and check-in times, leave, payroll and payslips, tax certificates, expense claims and receipts, travel and cash advances, tasks and timesheets, performance reviews, grievances, recruitment and onboarding records. |
| ABMS (accounting) | Invoices, payments, vouchers, customer and supplier details, bank accounts and statements, cheques, budgets and tax (IRD, TDS) records. |
| IMS (inventory) | Products, stock, sales and purchase orders, point-of-sale transactions, customer and vendor records, vendor bills and instalment (EMI) documents. |
| Manufacturing | Production and work orders, quality inspections and photos, maintenance, traceability, visitor check-ins and safety incident records. |
| Clinic | Patient registration details, appointments and queue tokens, visit and consultation records, diagnoses, allergies, prescriptions, lab reports, billing and insurance claims. This is health information and is handled with additional care. |
| RMS (restaurant) | Orders, tables and reservations, menus, invoices, refunds, tips and customer details. |
| EMIS (school) | Student records such as name, date of birth, guardian and parent names, blood group, attendance, marks and results; staff records; notices and library records. |
| LMS (learning) | Courses, learner enrolments, instructors, payments, invoices and refunds. |
| HMS (hotel) | Reservations, room status, guest details, folios and guest requests. |
| Viana AI | The questions you type or speak (converted to text), the answers returned and your saved conversations. |
| Workspace | Organization profile, users and roles, subscriptions, support tickets, backups, bulk SMS and integration settings. |
Information collected through device features (only when you use them)
| Permission | What it is used for | When |
|---|
| Location (precise) | Recording where you are when you check in or out for attendance, checking whether you are inside a work location set by your organization, and logging HRM field visits. A map of the check-in location may be shown. | Only at the moment you perform these actions, while the app is open. The app does not track location in the background. |
| Camera | Scanning product, serial, library and appointment barcodes and QR codes; taking photos of receipts, bills, bank statements, quality checks, field visits, patient documents and support issues. | Only when you open the scanner or choose to take a photo. |
| Photos and files | Attaching existing images or documents to claims, tickets, messages, notices and records. | Only when you choose a file. |
| Microphone and speech recognition | Asking Viana a question by voice. | Only while voice input is active. Speech is converted to text by your device’s speech service; only the resulting text is sent to Viana. |
| Face ID, Touch ID or fingerprint | Unlocking the app with biometric sign-in, if you turn it on. | Matching is performed by your device’s operating system. Vividia never receives your face or fingerprint data. |
| Bluetooth and local network | Connecting to thermal receipt and label printers, barcode scanners and similar peripherals. | Only when you connect or print. |
| Notifications | Showing approvals, reminders and updates from your organization’s applications. | After you allow notifications. |
You can refuse or later withdraw any of these permissions in your device settings. The rest of the app keeps working, but the related feature will not.
Device, diagnostic and technical information
- Push notification token and basic device registration details, so notifications reach the right device.
- Crash and error reports, including device model, operating system version, app version and the technical state of the app when the problem occurred.
- Limited automatic app events and device information collected by the Firebase SDK used in the app, such as app opens and sessions. We do not use this for advertising.
- Network information needed to deliver the Services, such as IP address, request times and error logs on our servers.
Website information
- Contact and demo request details you submit: name, phone number, email, organization, applications of interest, preferred meeting details and your message.
- Website usage information collected by Microsoft Clarity when it is enabled, such as pages viewed, clicks, scrolling and device and browser type. Clarity uses cookies and similar technologies.
04How we use information
- To provide the Services: sign you in, show the applications and records your role allows, save your work and sync it across web and mobile.
- To carry out the specific features you use, such as location-verified attendance, barcode scanning, printing, offline queues and Viana AI answers.
- To send notifications that your organization’s applications generate.
- To keep the Services secure: authenticate users, detect and prevent misuse, fraud and unauthorized access, and keep audit records.
- To diagnose crashes and errors and improve the reliability and performance of the app.
- To provide customer support and respond to requests from your organization or from you.
- To respond to website enquiries and arrange demonstrations.
- To meet legal, tax, accounting and regulatory obligations and to establish or defend legal claims.
We do not sell personal information, use it for advertising, build advertising profiles, or share it with data brokers. We do not use organization data for any purpose other than providing the Services to that organization, unless the organization instructs us or the law requires it.
05Legal bases for processing
Where the law requires a legal basis, we rely on:
- Contract—to provide the Services under our agreement with your organization and these terms.
- Legitimate interests—to secure, maintain and improve the Services and respond to enquiries, balanced against your rights.
- Consent—for device permissions, biometric sign-in, notifications and website analytics cookies where required. You can withdraw consent at any time.
- Legal obligation—to comply with applicable laws, including the Individual Privacy Act, 2075 (2018) of Nepal.
- For organization data, the organization is responsible for having its own lawful basis, including any consent required for sensitive information such as health or children’s records.
06Viana AI assistant
- Viana answers questions using information from the Vividia applications your organization has enabled, limited to what your role is permitted to see.
- Your questions are sent as text to Vividia’s Viana service. Voice questions are first converted to text by your device’s speech recognition, which may be processed by Apple or Google as described in their privacy policies. Spoken replies are generated on your device.
- Viana may use third-party AI model providers acting as our service providers to generate answers. They receive only what is needed to answer the request and are bound by contractual confidentiality and data protection obligations.
- Conversations are saved so you can return to them. You can delete a conversation in the app at any time.
- AI-generated answers can be incomplete or wrong. Check important figures in the source application before acting on them.
07How information is shared
We share personal information only in these circumstances:
- Within your organization. Other users in your organization can see records according to the roles and permissions its administrators assign. For example, a manager may see your leave and attendance.
- Service providers. Companies that host, secure, monitor or support the Services on our behalf, under contracts that limit their use of the data.
- Integrations your organization enables. Such as email, SMS or payment services connected in Workspace.
- Legal and safety reasons. Where required by law, court order or a government authority, or where necessary to protect the rights, property or safety of Vividia, our customers or others.
- Business transfers. If Vividia is involved in a merger, acquisition or sale of assets, subject to this policy continuing to protect the information.
The third-party services built into the mobile app are:
| Provider | Purpose | Information involved |
|---|
| Google Firebase | Push notifications (Cloud Messaging), crash reporting (Crashlytics) and basic app analytics | Notification token, crash and error details, device and app information, limited app events |
| Google Maps | Displaying map tiles around attendance locations | Map area requested and IP address |
| Apple / Google speech services | Converting Viana voice questions to text | Audio of your spoken question, processed by the device platform |
| Apple App Store / Google Play | Checking whether a newer app version is available | App identifier and version |
| Google ML Kit (on device) | Reading barcodes and QR codes | Camera frames are processed on the device |
Website analytics are provided by Microsoft Clarity, subject to the Microsoft Privacy Statement.
08Storage on your device
- Session tokens are stored in encrypted storage protected by the iOS Keychain or Android Keystore.
- If you enable biometric sign-in, the credentials needed to sign you in are kept in the device’s secure storage (iOS Keychain or Android encrypted storage). Turning biometric sign-in off removes them.
- Some data is cached on the device so the app is fast and works with a weak connection, including settings, workspace details, permissions and recently viewed information.
- Offline features keep a queue of actions until they can be synced: restaurant POS orders, warehouse picking, packing and shipping, manufacturing shop-floor actions and school attendance drafts.
- Signing out removes your session and most cached organization data. Unsynced offline drafts and app settings can remain on the device until they are synced, biometric sign-in is turned off, or the app is deleted. Deleting the app removes all data it stored on the device.
- The app does not include its data in Android device backups.
09How we protect information
- All communication between the app and Vividia servers uses HTTPS encryption in transit.
- Access is controlled by organization, application, role and route-level permissions.
- Sign-in tokens are stored encrypted on the device, and biometric matching never leaves the device.
- Access to production systems is limited to authorized personnel who need it for their work.
- We keep backups and operational logs to recover from incidents and investigate misuse.
No system is completely secure. If we become aware of a security incident affecting personal information, we will notify the affected organization and, where required, authorities and individuals, without undue delay.
10How long we keep information
- Organization data is kept for as long as the organization’s subscription is active, and afterwards for the period set in the customer agreement so the organization can export it. It is then deleted or anonymized, apart from copies that expire through our normal backup cycle.
- User accounts remain until the organization’s administrator removes them or the organization’s subscription ends. Records you created may be retained by the organization for its own legal or business purposes.
- Crash reports and diagnostic data are kept only as long as needed to resolve issues, under the retention settings of the service provider.
- Website enquiries are kept for as long as needed to respond and follow up, and then deleted or kept only where needed for legitimate business records.
- Some information must be kept longer where the law requires it, for example tax and accounting records.
11Deleting your account and data
Because accounts are provided by organizations, there are two routes to deletion:
- Ask your organization’s administrator. Administrators can deactivate or remove users and delete records in Vividia Workspace and the relevant applications.
- Ask Vividia directly. Email [email protected] from the email address linked to your account, with the subject “Account deletion request”, and include your workspace code. You can also use our contact page. You do not need the app installed to make a request.
We will confirm your identity, inform your organization, and delete your account and the personal information associated with it within 30 days, unless your organization or the law requires certain records to be kept (for example payroll, tax, attendance, medical or academic records). In that case we will tell you what is retained and why. Removing the app from your phone does not delete your account.
You can delete individual Viana conversations in the app at any time.
12Your rights and choices
Subject to applicable law, you may have the right to:
- Access the personal information held about you and receive a copy.
- Correct inaccurate or incomplete information.
- Delete information, or restrict or object to certain processing.
- Withdraw consent you have given, without affecting earlier processing.
- Receive your information in a portable format.
- Complain to a data protection or privacy authority.
For organization data, we will pass your request to the organization that controls it and support them in responding. For other requests, contact [email protected]. We respond within 30 days.
Other choices: switch off location, camera, microphone, Bluetooth or notification access in your device settings; turn biometric sign-in on or off in the app; and block or clear cookies in your browser for this website.
13Children’s information
The Vividia Suite app and Services are intended for staff and administrators of organizations and are not directed at children. We do not knowingly allow children to create accounts or sign in, and the app has no student or parent login.
Schools, colleges, learning providers and clinics may store information about minors, such as student and patient records, in the Services. That information is entered and controlled by the organization, which is responsible for obtaining any consent required from parents or guardians. Vividia processes it only to provide the Services to that organization.
14International processing
Vividia is based in Nepal. Information may be processed in Nepal and in other countries where our hosting and service providers, including Google, operate. Where information is transferred across borders, we take steps so that it continues to receive a level of protection consistent with this policy and applicable law.
15Changes to this policy
We may update this policy as the Services, the app or the law change. We will change the “Last updated” date above and, for material changes, notify organization administrators or show a notice in the app or on this website before the change takes effect.
16Contact us
For privacy questions, requests or complaints: