People Connect (“the App”) is an internal leave and outdoor-duty management application provided by Gujarat Industries Power Company Limited (GIPCL) to its employees, and developed and operated on GIPCL’s behalf by AeonX Digital. This policy explains what personal data the App processes, why, and how it is protected. The App is intended solely for authorised GIPCL personnel and is not available to the general public.
| Category | Examples | Purpose |
|---|---|---|
| Identity & employment | Name, employee ID, role, department, reporting manager | Authentication, routing approvals |
| Leave & outdoor-duty records | Leave type, dates, reason, OD location & purpose, approval status | Core leave/OD management, SAP HCM posting |
| Approximate & precise location | GPS coordinates captured only when you check in for an outdoor duty | To verify on-site attendance for OD |
| Contact (optional) | WhatsApp number, where you opt in to WhatsApp approvals | To deliver approval messages you opted into |
| Device & technical | App version, device model, OS, diagnostic logs | Security, reliability, support |
| Biometric (on-device only) | Fingerprint / Face unlock state | Optional app lock — handled by your device’s secure hardware and never transmitted to us |
We process the data above only to operate the App: to authenticate you, create and route leave and outdoor-duty requests, record approvals, synchronise records with GIPCL’s SAP HCM system, send you notifications you have enabled, and to secure and support the service. We do not use your data for advertising, and we do not sell personal data.
Your data is shared only with: (a) authorised GIPCL personnel within your approval chain and HR; (b) GIPCL’s SAP HCM system; and (c) where you opt in to WhatsApp approvals, Meta Platforms’ WhatsApp Business API to deliver those specific messages. We do not share personal data with any other third party except where required by applicable law.
All personal data is stored and processed within India (AWS Asia Pacific — Mumbai, ap-south-1). Data is encrypted in transit (TLS) and at rest (AES-256). Access is restricted by role-based controls and authentication, and platform activity is recorded in an immutable audit trail. We apply the protection principles of the Digital Personal Data Protection Act, 2023 and align operations with ISO/IEC 27001 practices.
Personal data is retained in line with GIPCL’s HR record-keeping policies and applicable law, then deleted or anonymised. As a GIPCL employee you may request access to, correction of, or deletion of your personal data, subject to legal and HR record-keeping obligations, by contacting GIPCL HR or the address below.
The App is an employee tool and is not directed to or intended for use by anyone under 18.
We may update this policy from time to time. Material changes will be notified through the App or by GIPCL HR, and the effective date above will be revised.
For privacy questions or data requests: privacy@aeonx.digital (AeonX Digital, processor) or your GIPCL HR department (data controller).