Privacy Policy
Effective Date: July 17, 2026 Last Updated: September 1, 2026 Version: 2.4
Our Commitment to Your Privacy
At Commando 360, we believe that trust is built through transparency. This Privacy Policy explains what personal data we collect, why we collect it, how we protect it, and what rights you have over your information.
We are committed to the following principles:
We limit collection. We design the Service to collect personal data reasonably necessary for the configured workforce, field-operations, safety, support, and administration features. We do not sell your personal data to third parties.
We apply safeguards based on risk. Biometric data and location information are subject to additional access, storage, and retention controls where appropriate. Employee location sharing is limited by server-authorized work windows and user controls.
We give you control. You can access, correct, or request deletion of your personal data. Where we rely on consent, you can withdraw it at any time.
We address applicable law. We operate the Service with the intent to meet privacy and biometric requirements that apply to a particular processing activity, customer, and jurisdiction as those requirements come into effect.
For questions about this policy or to exercise your rights, contact us at support@commando360.ai or reach our Grievance Officer, Nidhi Singh, at the same address.
1. Introduction
This Privacy Policy explains how Commando360.ai Private Limited ("Company," "we," "us," or "our") collects, uses, discloses, and protects your personal data when you use the Commando 360 platform, including our Admin Portal, Client Portal, Mobile Application, and related services (collectively, the "Service").
We are committed to protecting your privacy and complying with applicable data protection laws, including:
- India: Digital Personal Data Protection Act, 2023 (DPDP Act)
- United Arab Emirates: Federal Decree-Law No. 45 of 2021 (UAE PDPL)
- United States: California Consumer Privacy Act (CCPA/CPRA) and state biometric laws
This Privacy Policy is a notice, not a blanket consent. Where consent is required, we request it separately through the relevant feature or another legally valid process.
2. Our Role and Your Organization's Role
For workforce, attendance, biometric, location, visitor, and employment records, the customer organization generally decides why the data is processed, which features are enabled, who may access the data, and how long customer-controlled records are retained. In that context, the customer generally acts as the data controller or data fiduciary, and Commando 360 generally acts as its processor or service provider.
Commando360.ai Private Limited may act as an independent controller or data fiduciary for its own account security, billing, support, fraud prevention, product security, legal compliance, and corporate operations.
The exact allocation may vary by contract, feature, and applicable law. Questions about an employer's workplace policy should normally be directed to that organization. Questions about Commando 360's own processing may be directed to us below.
Commando360.ai Private Limited
PNO 4, H.no 3-1-2(1-D), A-2, Trimulgherry Village
Thirumalgherry X Roads, Secunderabad
Hyderabad, Telangana 500015, India
Contact Information:
- Email: support@commando360.ai
- Phone: +91 95020 56901
Grievance Officer (India DPDP Act):
- Name: Nidhi Singh
- Email: support@commando360.ai
- Phone: +91 95020 56901
- Address: Same as above
3. Categories of Personal Data We Collect
We collect different categories of personal data depending on how you interact with our Service:
3.1 Identity Data
| Data Element | Purpose | Legal Basis |
|---|---|---|
| Full name (first, last) | Account identification, communication | Contract performance |
| Date of birth | Age verification, identity confirmation | Contract performance |
| Gender | Profile information | Contract performance |
| Employee ID | Unique identification | Contract performance |
| Profile photograph | Visual identification | Contract performance / Consent |
3.2 Contact Data
| Data Element | Purpose | Legal Basis |
|---|---|---|
| Email address | Account access, notifications | Contract performance |
| Phone number (primary, secondary) | Communication, OTP verification | Contract performance |
| Current address | Employment records | Contract performance |
| Permanent address | Employment records | Contract performance |
3.3 Employment Data
| Data Element | Purpose | Legal Basis |
|---|---|---|
| Designation/role | Access control, reporting | Contract performance |
| Employment status | Service eligibility | Contract performance |
| Military service history | Background verification | Consent / Legal compliance |
| Education level and field | Background verification | Contract performance |
| Language proficiency | Service assignment | Contract performance |
3.4 Financial Data
| Data Element | Purpose | Legal Basis |
|---|---|---|
| Bank account number | Payroll processing | Contract performance |
| Bank name and branch | Payroll processing | Contract performance |
| IFSC code / Routing number | Payroll processing | Contract performance |
| Account type | Payroll processing | Contract performance |
3.5 Government Identification Data
| Data Element | Purpose | Legal Basis |
|---|---|---|
| Aadhaar number (India) | Identity verification, legal compliance | Legal obligation |
| PAN number (India) | Tax compliance | Legal obligation |
| Passport number | Identity verification | Contract performance |
| Driving license number | Identity verification | Contract performance |
| Voter ID (India) | Identity verification | Contract performance |
| SSN (USA) | Tax compliance (if applicable) | Legal obligation |
| Emirates ID (UAE) | Identity verification (if applicable) | Legal obligation |
3.6 Optional AI Assistant Data
When a signed-in Client-app user chooses to enable Mr Commando, an AI request may include:
- The question the user types.
- Up to 40 recent messages from that user's Mr Commando conversation.
- Account identifiers such as user ID and name.
- Organization-scope identifiers needed to authorize and answer the request, such as client, region, operations-zone, site, or post identifiers and the user's scope type.
- App context such as the source screen and guided-assistant state.
- The current mobile AI data-sharing permission version.
The Client app stores a per-user permission record on the device. It does not send an AI request until the user affirmatively selects I Agree — Enable Mr Commando. Selecting Not Now leaves the rest of the app available. The user can withdraw permission from the assistant's shield control; withdrawal blocks future requests and clears the conversation held in the app. Withdrawal does not automatically delete information already processed for an earlier request. A user may submit a deletion request under Section 14.2.
Depending on the configured feature, Commando 360 may process the request using Anthropic, OpenAI, Google, or a Commando360-hosted model. The data is used to provide the requested response, not for third-party advertising or cross-app tracking. Provider retention, deletion, processing location, and model-training restrictions depend on the provider and the applicable service configuration and contract; contact support@commando360.ai for the current provider details applicable to your organization.
4. Facial Data and Biometric Information
⚠️ IMPORTANT NOTICE: BIOMETRIC INFORMATION
We collect and process biometric data. Please read this section carefully.
Illinois Residents: Please also review our Illinois Biometric Information Privacy Act Notice for additional state-specific disclosures.
4.1 What Biometric Data We Collect
| Biometric Type | Description | Storage Format |
|---|---|---|
| Facial geometry descriptors | Mathematical representation of facial features | Numerical template or descriptor |
| Facial photographs | Photos taken during enrollment and configured verification events | JPEG/PNG images |
| Face-match and liveness results | Comparison results and analysis used to verify identity and prevent spoofing | Confidence scores, status values, and flags |
| Limited verification metadata | Event time and type, result status, and technical identifiers needed to secure, diagnose, and audit verification | Structured database records |
4.2 Purpose of Biometric Collection
We collect biometric data solely for the following purposes:
- Identity Verification: To verify identity during enrollment, shift check-in and check-out, and configured periodic attendance, manager spot-check, or patrol-route checkpoints
- Fraud Prevention: To prevent time theft, buddy punching, and unauthorized access
- Security: To maintain secure access to protected sites
We do not use facial data for advertising, marketing, cross-app tracking, or unrelated profiling.
4.3 How Biometric Data Is Collected
- Initial Enrollment: During your first use of the Mobile Application, you will be asked to scan your face to create a baseline biometric template
- Check-In/Check-Out: Each time you check in or out, a photo is captured and compared against your stored template
- Periodic Verification: Depending on site policy, periodic verification photos may be required during shifts
- Manager Verification: When configured by the organization, manager spot check-ins and patrol-route checkpoints may require a face-evidence photo
4.4 Biometric Data Storage and Security
- Storage location: The production biometric database and private object storage are hosted through Supabase in the ap-south-1 (Mumbai, India) region. A provider may process limited request, security, or support data from other locations as described in this policy and its applicable service terms.
- Transport and storage safeguards: Facial data is protected in transit using HTTPS/TLS and at rest using Supabase's provider-managed storage protections. Database and object-storage systems are private and access controlled.
- Organizational access: Authorized organizational security or compliance personnel may access verification photographs, match or liveness results, and limited verification metadata only within their permitted organizational scope. Customer organizations do not receive direct access to facial geometry templates.
- Commando 360 access: Authorized Commando 360 support or security staff may access facial data only as needed to provide, secure, support, investigate, or legally administer the Service.
- Infrastructure processing: Supabase stores and processes facial data solely as Commando 360's contracted database and object-storage infrastructure provider.
- No sale or profit: We do not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information.
4.5 Biometric Data Retention
| Data Type | Retention Period |
|---|---|
| Face descriptors and enrollment images | Duration of employment or engagement + 90 days |
| Verification and face-evidence photos, including associated match and liveness results | 3 years (standard) or a documented customer or legal period |
| Transient face-verification job metadata | 90 days after completion or failure |
At the end of the applicable period, biometric data is scheduled for deletion or de-identification, subject to legal holds, customer instructions, and limited residual copies in protected backups or provider lifecycle systems where permitted by law.
4.6 Consent for Biometric Data
Explicit consent is required before any biometric data collection.
- Commando Employees: Biometric enrollment is required for your role. You will be presented with a consent form during onboarding.
- Client Employees: Biometric enrollment may be mandatory or optional based on your employer's policy. You will be informed before enrollment.
You have the right to refuse biometric enrollment. However, this may affect your ability to use certain features of the Service or perform certain job functions.
4.7 Your Rights Regarding Biometric Data
You have the right to:
- Request access to your biometric data
- Request correction of inaccurate biometric data
- Request deletion of your biometric data (subject to legal retention requirements)
- Withdraw your consent (which may affect Service functionality)
To request deletion, use Profile → Delete Account in the app or email support@commando360.ai. For access, correction, or consent withdrawal, contact support@commando360.ai. Requests remain subject to documented legal retention requirements.
5. Location Data Collection and Sharing
⚠️ IMPORTANT NOTICE: LOCATION SHARING
If you grant location consent and device permission, we collect and share location only during authorized work-session windows and the other limited situations described below. Please read this section carefully.
5.1 What Location Data We Collect
| Data Element | Description |
|---|---|
| GPS coordinates | Latitude and longitude of your device |
| Location accuracy | Precision of the GPS reading in meters |
| Speed | Movement speed (if available) |
| Heading | Direction of movement |
| Altitude | Elevation (if available) |
| Battery level | Device battery percentage |
| Network type | WiFi, 4G, 5G, or offline status |
5.2 When Location Sharing Occurs
Location sharing may be ACTIVE only during:
- A site-level window before the stated start time. Your organization selects 0 to 120 minutes in 15-minute increments; the default is 30 minutes. The app does not begin this before-start session unless you open it and the server confirms your assignment.
- A factually checked-in session, from recorded check-in until recorded checkout, subject to a maximum duration of 24 hours from check-in.
- A site-level window after recorded checkout. Your organization selects 0 to 120 minutes in 15-minute increments; the default is 30 minutes.
- A manager field session you explicitly start.
- An emergency SOS situation.
If no checkout is recorded, location sharing cannot continue beyond the 24-hour maximum. A recorded checkout may begin the site's configured after-end window rather than stopping sharing immediately.
Location sharing is DISABLED:
- Outside the authorized windows and situations listed above.
- When you use Stop Sharing Location, unless you later resume sharing while an authorized window remains active.
- After you end a manager field session or the emergency SOS situation ends.
- When location consent or required device permission is not active.
Attendance, network connectivity, and location sharing are separate states. Stopping sharing does not change the attendance record. If sharing becomes unavailable during a checked-in session, authorized supervisors or the site's escalation chain may be notified.
5.3 Purpose of Location Collection
We collect location data for:
- Attendance Verification: Confirming your presence at assigned posts
- Geofence Monitoring: Alerting if you move outside your assigned area
- Safety: Enabling SOS features and emergency response
- Operations: Providing real-time status to supervisors
- Analytics: Aggregated, anonymized analysis to improve service delivery
5.4 Location Data Sharing
Your location data and current sharing status may be shared with:
- Your employer or organization, including authorized supervisors, command-center personnel, and configured escalation personnel, for operational management and safety response.
- Authorized site or client administrators, limited to the sites and personnel within their permitted scope.
- Emergency services when reasonably necessary in an SOS or other emergency.
Depending on their role and permissions, authorized operational personnel may see real-time location during an authorized window as well as historical location records and summaries.
5.5 Location Data Retention
| Data Type | Retention Period |
|---|---|
| Detailed location points | 30 days |
| Five-minute location summaries | Up to 90 days |
| Attendance records | May be retained longer for legal or contractual requirements |
| Anonymized analytics | As needed |
5.6 Consent and Control for Location Sharing
The app requests location consent and required device permission before location sharing is activated. Your organization is responsible for informing you of its site-level settings and lawful workplace policies. You may stop or withdraw location sharing by:
- Using Stop Sharing Location in the app.
- Disabling location permission in your device settings, which may affect location-dependent functionality.
- Contacting support@commando360.ai to withdraw recorded location consent.
Stopping location sharing does not check you out or change your attendance record. If you stop sharing or location becomes unavailable during a checked-in session, the Service may notify your supervisor and the configured escalation chain. Outside a checked-in session, using the stop control does not send that operational alert. You may resume sharing only while an authorized window remains active and consent and device permission remain available.
6. Voice Recording (Push-to-Talk)
⚠️ IMPORTANT NOTICE: PTT RECORDING
Voice transmissions through PTT may be recorded.
6.1 What Voice Data We Collect
| Data Element | Description |
|---|---|
| Audio recordings | Voice transmissions in .ogg format |
| Sender identity | Who made the transmission |
| Timestamp | When the transmission occurred |
| Channel information | Which PTT channel was used |
| Duration | Length of the transmission |
6.2 Recording Retention Tiers
| Tier | Retention Period | Typical Use |
|---|---|---|
| Basic | 30 minutes | Standard operations |
| Pro | 30 days | Incident investigation |
| Enterprise | 90 days | Compliance and auditing |
| Annual | 365 days | Extended customer access where authorized |
Recording occurs only when the organization enables recording for that channel. The tier controls how long an authorized customer user can play the recording through the Service. It does not, by itself, determine the final storage-deletion date.
6.3 Purpose of Recording
PTT recordings are used for:
- Security incident investigation
- Training purposes
- Compliance audits
- Dispute resolution
6.4 Access to Recordings
Recording history and playback require a current active channel subscription with read permission. The Service re-checks that permission, the recording's channel, its expiry, and its deletion state for each authenticated playback request. Depending on the organization's configuration, authorized users may include channel members, supervisors, administrators, or compliance personnel.
The Workforce app may remain joined to one authorized organization channel while backgrounded or locked through Apple's Push to Talk framework. The microphone opens only for a user-started transmission. Leave, checkout or session end, access removal, logout, or force-stop ends that background channel session.
6.5 Your Rights Regarding PTT Recordings
You may request access to recordings in which you participated, subject to:
- Privacy rights of other participants
- Ongoing investigation restrictions
- Technical availability after the configured retention period
After the configured customer-access period, the recording becomes unavailable through ordinary Service playback. A restricted compliance copy may remain until the later of: (a) the applicable legal or regulatory retention period, (b) a documented legal hold or investigation hold, or (c) another lawful period stated in the customer agreement. For the India launch configuration, the deletion service uses a one-year compliance date unless a longer documented hold applies. Customer administrators cannot shorten a mandatory compliance period or extend storage indefinitely without a documented lawful basis.
When the controlling date passes, the Service schedules the source recording for verified object deletion and retries failed deletion attempts. Limited residual copies may remain temporarily in protected backups or provider recovery systems until their documented overwrite or lifecycle period ends. Such residual copies are not available for ordinary customer use and will not be restored except for legitimate disaster recovery or legal obligations.
7. Visitor Data (VMS)
7.1 What Visitor Data We Collect
When you check in at a Site through our Visitor Management System:
| Data Element | Purpose |
|---|---|
| Full name | Identification |
| Phone number | Contact, badge verification |
| Email address | Pre-registration, notifications |
| Company/organization | Visitor categorization |
| Photograph | Visual identification |
| Purpose of visit | Security logging |
| Host information | Visit coordination |
| Vehicle information | Parking management |
| ID document type and number | Identity verification |
| Check-in/out timestamps | Access logging |
7.2 Visitor Data Retention
Visitor data is retained for 12 months for security audit purposes, after which it is deleted unless:
- Required by law
- Subject to an ongoing investigation
- Requested by the site owner for longer retention
7.3 Visitor Rights
Visitors have the right to:
- Refuse photography (may result in entry denial)
- Request deletion of their data after visit completion
- Access records of their visits
8. Technical and Session Data
8.1 Automatically Collected Data
When you use our Service, we automatically collect:
| Data Element | Purpose |
|---|---|
| IP address | Security, geolocation |
| Device type and model | Compatibility, support |
| Operating system | Compatibility |
| Browser type | Compatibility |
| Device fingerprint | Fraud prevention |
| Session tokens | Authentication |
| Login timestamps | Security auditing |
| Last activity time | Session management |
| App version | Support, updates |
8.2 Cookies and Tracking
We use essential cookies for:
- Session management
- Authentication
- Security
We do not use third-party advertising cookies or cross-site tracking.
8.3 Home-Screen Widgets and Live Activities
The optional mobile home-screen widgets and Workforce Live Activity display locally cached summaries of information the signed-in user is already authorized to see, such as work status, manager-session status, attendance, personnel, or incident counts. They do not independently contact the server or start location sharing.
Operational widget and Live Activity content is marked privacy-sensitive so iOS can redact it when device privacy settings require. Logout or loss of the authenticated session replaces widget content with a signed-out state and ends the Workforce Live Activity.
9. How We Use Your Personal Data
9.1 Primary Purposes
| Purpose | Legal Basis |
|---|---|
| Providing the Service | Contract performance |
| User authentication | Contract performance |
| Shift attendance tracking | Contract performance |
| Payroll processing | Contract performance |
| Incident management | Legitimate interest (security) |
| Communication with you | Contract performance |
9.2 Secondary Purposes
| Purpose | Legal Basis |
|---|---|
| Fraud prevention | Legitimate interest |
| Security monitoring | Legitimate interest |
| Service improvement | Legitimate interest |
| Compliance with laws | Legal obligation |
| Responding to legal requests | Legal obligation |
9.3 Anonymized Analytics
We may use anonymized, aggregated data for:
- Service performance analysis
- Trend identification
- Business planning
Anonymized data cannot be used to identify you.
10. Data Sharing and Disclosure
10.1 Categories of Recipients
| Recipient | Data Shared | Purpose |
|---|---|---|
| Your Employer or Organization (Client) | Attendance, authorized real-time and historical location, location-sharing status, and incidents | Operational management, site coverage, and safety response |
| Supabase | Database records, files | Cloud storage |
| Vultr | PTT audio and recordings | Hosted PTT infrastructure and recording storage |
| LiveKit | Real-time audio streams | PTT functionality |
| MSG91 | Phone numbers | OTP delivery |
| Vercel | Request data | Application hosting |
| AI processing providers (Anthropic, OpenAI, or Google, depending on the configured feature) | The user's question, up to 40 recent AI-conversation messages, account identifiers, organization-scope identifiers, and limited app/guided-assistant context needed to answer | Optional AI-assisted responses after explicit user permission |
Some configurations use Commando360-hosted models instead of a third-party AI provider. The mobile Client app names the possible provider categories and describes the data before the first request, sends nothing until the user agrees, and allows later withdrawal. We send only the content and operational context needed for the requested feature. Do not submit information to an AI-enabled feature unless you are authorized to share it for that purpose.
We require service providers to process personal data for the contracted service and subject to applicable confidentiality, security, and data-protection terms. Provider availability and processing locations may change over time.
10.2 Legal Disclosures
We may disclose your data when required by:
- Valid court orders or subpoenas
- Law enforcement requests (with valid legal process)
- Regulatory authorities
- To protect our legal rights
10.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity. We will notify you of any such transfer.
10.4 No Sale of Personal Data
We do NOT sell your personal data to any third party.
11. International Data Transfers
11.1 Data Storage and Processing Locations
The production biometric database and private object storage are hosted through Supabase in the ap-south-1 (Mumbai, India) region. Other cloud providers may store or process limited personal data in India, the United States, the United Arab Emirates, and other configured provider regions. The hosting location may differ from your location, and a provider may process limited data from other locations to operate, secure, or support its service.
Our provider categories currently include:
- Database and file-storage providers in the configured project region
- Application and API hosting providers, including infrastructure in the United States
- Real-time communications and recording-storage providers in configured regions
- Messaging, support, security, and AI providers in their applicable service regions
11.2 Cross-Border Transfers
Where personal data crosses borders, the customer and Commando 360 use contractual, organizational, technical, or other legally recognized transfer mechanisms as applicable to their respective roles and the relevant law. Contact us for information about the safeguards applicable to a particular service or transfer.
12. Data Retention
12.1 Retention Schedule
The periods below describe standard configured periods or legal and operational targets. The actual period may vary based on customer instructions, applicable law, an active investigation, a legal hold, or the availability of the relevant feature. A more specific consent or jurisdictional notice controls if it states a different required schedule.
| Data Category | Retention Period | Reason |
|---|---|---|
| Employee identity data | Employment + 7 years | Labor law compliance |
| Biometric templates and enrollment images | Employment/engagement + 90 days | Verification purposes |
| Verification and face-evidence photos with associated results | 3 years by default | Audit trail and identity verification |
| Detailed location points | 30 days rolling | Recent safety and operations |
| Five-minute location summaries | Up to 90 days | Historical safety and operations |
| Attendance records | 7 years | Legal compliance |
| PTT customer playback | 30 min / 30 days / 90 days / 365 days | Channel tier |
| PTT restricted compliance copy | India launch: 1 year; otherwise applicable law/contract | Compliance, legal hold, or investigation |
| Session data | 1 year | Security auditing |
| Visitor data | 1 year | Security audit |
| Financial data | Employment + 7 years | Tax compliance |
| Incident records | 7 years | Legal compliance |
12.2 Data Deletion
After the applicable retention period or hold ends, data is scheduled for deletion or de-identification from active systems. Where a deletion workflow records a provider deletion result, Commando 360 treats deletion as complete only after the source object is no longer present. Protected residual copies may remain temporarily in backups, logs, or provider lifecycle systems and are restricted from ordinary use until overwritten or deleted, except where retention is legally required.
13. Data Security
13.1 Technical Measures
Safeguards vary by system, data type, feature, and provider. They may include:
- Encrypted transport: HTTPS/TLS for supported network connections
- Stored-data protection: Provider-managed encryption at rest and private storage where applicable
- Access controls: Role- and attribute-based application controls and tenant-scoped data access
- Session protection: Device and session controls for supported workflows
- Multi-Factor Authentication: Available for portal users
- Logging and monitoring: Security and activity logging for selected events and systems
No security program eliminates all risk, and we do not represent that every system uses the same cipher, protocol, or logging coverage.
13.2 Organizational Measures
Our organizational controls include access limitation, incident-response procedures, and periodic review of access and security practices. Additional measures, such as personnel screening, training, or independent review, are used where adopted, contractually required, or required by applicable law.
13.3 Data Breach Response
If a personal-data breach occurs, we investigate, contain, and document the incident and notify affected customers, regulators, or individuals in the manner and time required by applicable law and our contractual role. When we act as a processor or service provider, we also provide the customer information reasonably needed for the customer to meet its obligations.
14. Your Rights
14.1 Privacy Rights
Subject to applicable law, identity verification, lawful exceptions, and whether Commando 360 or the customer organization controls the relevant record, you may have the right to:
| Right | Description | How to Exercise |
|---|---|---|
| Access | Obtain a copy of your personal data | Email support@commando360.ai |
| Correction | Rectify inaccurate or incomplete data | Profile settings or email |
| Deletion | Request erasure of your data (with limitations) | In-app or email |
| Portability | Receive data in machine-readable format | Email request |
| Objection | Object to processing based on legitimate interest | Email request |
| Withdraw Consent | Revoke previously given consent | In-app settings or email |
14.2 Account Deletion
You may request deletion of your account and associated personal data.
How to Request:
- In-App: Settings → Profile → Delete Account
- Email: support@commando360.ai with subject "Account Deletion Request"
What Happens:
- We acknowledge the request and may verify your identity.
- For customer-controlled workforce or employment records, we notify the organization and request a category-level retention review. The organization must identify the record category, lawful or contractual basis, and requested end date; a general objection does not automatically prevent account deactivation or deletion of unrelated data.
- We deactivate, delete, or de-identify eligible data as applicable and communicate the expected timing.
- Data required by law, an active legal hold, security needs, or the customer's documented lawful instructions may be retained only for the applicable purpose and period.
- Data already de-identified so that it no longer identifies you may be retained.
Operational assignments or financial records may require correction, reassignment, or category-specific retention before that record is removed. They do not create an unlimited right to keep the user's login active or retain unrelated personal data.
15. Jurisdiction-Specific Rights
15.1 India (DPDP Act 2023)
As the relevant provisions of the Digital Personal Data Protection Act, 2023 apply and come into force, individuals in India may have the following rights, subject to the Act and implementing rules:
Your Rights as a Data Principal:
- Right to access personal data
- Right to correction and erasure
- Right to grievance redressal
- Right to nominate another person to exercise rights in case of death or incapacity
Grievance Redressal: If you have a complaint, contact our Grievance Officer:
- Name: Nidhi Singh
- Email: support@commando360.ai
- Phone: +91 95020 56901
- Response Time: Within 30 days
If not satisfied, you may lodge a complaint with the Data Protection Board of India.
Where consent is the applicable legal basis, we request a clear affirmative action through the relevant feature or another legally valid process and provide a means to withdraw consent that is comparable in ease, subject to lawful consequences and alternative legal bases.
15.2 UAE (Federal PDPL)
If you are located in the UAE, you have rights under Federal Decree-Law No. 45 of 2021:
Your Rights:
- Right to access your personal data
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to object to automated decision-making
- Right to data portability
Cross-Border Transfer: Your data may be processed outside the UAE. We use contractual, organizational, technical, or other legally recognized safeguards as applicable to the transfer and our role.
Contact: For UAE-specific inquiries: support@commando360.ai
15.3 United States
California (CCPA/CPRA)
If you are a California resident, you have rights under the California Consumer Privacy Act and California Privacy Rights Act:
Categories of Personal Information Collected:
- Identifiers (name, email, phone, government IDs)
- Biometric Information (facial geometry)
- Geolocation Data (GPS coordinates)
- Professional/Employment Information
- Internet/Network Activity (session data)
- Audio/Visual Information (photos, PTT recordings)
- Sensitive Personal Information (precise geolocation, biometrics)
Your California Rights:
- Right to Know: Request disclosure of personal information collected
- Right to Delete: Request deletion of personal information
- Right to Correct: Request correction of inaccurate information
- Right to Opt-Out of Sale/Sharing: We do NOT sell or share your data for cross-context behavioral advertising
- Right to Limit Use of Sensitive Personal Information: Request limitation on use of sensitive data
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
How to Exercise California Rights:
- Email: support@commando360.ai
- Phone: +91 95020 56901
- We will verify your identity before processing requests
- Response within 45 days (may be extended by additional 45 days with notice)
Authorized Agents: You may designate an authorized agent to make requests on your behalf.
Illinois (BIPA)
If you are an Illinois resident, you have rights under the Biometric Information Privacy Act:
For complete Illinois BIPA disclosures, please see our Illinois Biometric Information Privacy Act Notice.
ILLINOIS BIOMETRIC INFORMATION PRIVACY ACT NOTICE
Commando 360 collects facial geometry scans ("face descriptors"), enrollment photographs, verification and face-evidence photographs, and associated match or liveness results.
Purpose: Biometric data is collected solely for enrollment and identity verification during shift check-in and check-out and, when configured by an organization, periodic attendance checks, manager spot-checks, and patrol-route checkpoints. These uses support attendance integrity, fraud prevention, and protected-site security.
Retention: Face descriptors and enrollment images are retained for the duration of employment or engagement plus 90 days. Verification and face-evidence photographs and their associated match or liveness results are retained for three years by default or a shorter documented customer or legal period. Transient face-verification job metadata is retained for 90 days after completion or failure.
Destruction Schedule: Each category is scheduled for deletion at the end of its applicable period or earlier when required by law or a valid deletion request, subject to documented legal holds and limited protected backup or provider lifecycles. See the complete BIPA Notice for the controlling Illinois destruction standard.
Disclosure: We will NOT sell, lease, trade, or otherwise profit from your biometric data. We will NOT disclose biometric data to any third party without your prior written consent, except as required by law.
Written Consent: Before collecting biometric data, we will obtain your written informed consent.
16. Children's Privacy
Our Service is not intended for persons under the age of 18. We do not knowingly collect personal data from children.
If we discover that we have collected personal data from a child without parental consent, we will delete that data promptly. If you believe we have collected data from a child, please contact support@commando360.ai immediately.
17. Third-Party Links
Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Email notification to your registered address
- In-app notification
- Posting on our website
Where required by law or contract, we will provide advance notice of material changes or request updated consent. Otherwise, the updated policy takes effect on the date stated at the top.
19. Contact Us
For questions, concerns, or requests regarding this Privacy Policy:
General Inquiries: Email: support@commando360.ai
Grievance Officer (India): Name: Nidhi Singh Email: support@commando360.ai Phone: +91 95020 56901
Data Protection Requests: Email: support@commando360.ai Subject: "Data Subject Request - [Your Request Type]"
Mailing Address: Commando360.ai Private Limited PNO 4, H.no 3-1-2(1-D), A-2, Trimulgherry Village Thirumalgherry X Roads, Secunderabad Hyderabad, Telangana 500015, India
20. Acknowledgment
By using our Service, you acknowledge that:
- You have read and understood this Privacy Policy
- You understand your rights and how to exercise them
Where consent is required, it is requested separately and is not inferred solely from viewing this notice or using the Service.
Last Updated: September 1, 2026 Version: 2.4