Official Policy

Privacy Policy

GPIL ESS & Access Control • Last Updated: July 14, 2026

Introduction

This Privacy Policy explains how the GPIL ESS & Access Control mobile application ("Application", package name: in.gpil.ess) collects, uses, protects, and handles user data. We are committed to ensuring that your personal and workplace data remains secure and private.

By using the Application, you agree to the collection and use of information in accordance with this policy. The application is designed primarily for employees, contractors, visitors, and administrative staff associated with GPIL (a subsidiary of the HIRA Group).

Information We Collect

To provide access control, secure authentication, and employee self-service features, the Application collects the following types of information:

How We Use Your Information

The collected information is used to facilitate day-to-day workplace access operations and ensure platform security:

Data Protection & Security Controls

We implement a robust suite of industry-standard security measures to safeguard your information from unauthorized access, alteration, or disclosure:

Broken Object Authorization (BOLA) Shields

Strict server-side validation checks ensure that you can only view and manage your own personal data. Cross-user data access is barred.

MFA Rate-Limiting

To prevent brute-force entry, verification endpoints (such as OTP inputs and login checks) are rate-limited, automatically blocking repeated incorrect attempts.

PII Data Masking

Personally Identifiable Information (such as phone numbers and email addresses) is masked at the API boundary, ensuring it remains hidden from non-admin viewers.

Injection Defenses

Notice board inputs are automatically sanitized to strip executable scripts. Excel/CSV exports use formula sanitization to block CSV injection exploits.


Additionally, the Application uses SSL/TLS encryption for all data in transit, standard cross-site request forgery (CSRF) token checks, and follows Web Application Penetration Testing (WAPT) compliance protocols.

Third-Party Data Sharing

We value your privacy. The Application **does not share, sell, lease, or monetize** your personal data with any third-party advertisers or external entities.

Data sharing is strictly limited to infrastructure requirements, specifically with Google Firebase Cloud Messaging (FCM) to safely route push notifications directly to your Android device.

User Rights and Control

As an authorized user of the GPIL ESS & Access Control platform, you hold the following rights regarding your data:

Contact Us

If you have any questions, feedback, or concerns regarding this Privacy Policy, please contact the GPIL IT Support Desk:

GPIL IT Department
Email: it.support@gpil.in
Website Support: https://support.gpil.in