Privacy Policy
This policy explains what information the DevlMon admin dashboard and the EmprendeAI executive portal (together, the “Service”), operated by Srikesh Infotech (“we”, “us”), collect, how it is used, and the choices you have. The Service is used by companies (“customers”) and their authorized users; the customer decides what data is connected to it.
1. Information the Service handles
Account information. Names, work email addresses, roles, and sign-in credentials (passwords are stored only as salted hashes) for the administrators and executives a customer creates.
Device activity signals (DevlMon). On company-owned Windows devices that carry a disclosed, named monitoring service, the Service records productivity signals: the foreground application name, its window title, idle/active periods, login and logout times, a device heartbeat, and, for recognized web browsers, the address-bar site being viewed. It does not capture keystrokes, passwords, screen images or recordings, clipboard contents, or the contents of documents or private messages. Customers are responsible for notifying their own employees under applicable law.
Business-system data. When a customer connects its own Odoo instances (operations and accounting) or GitHub organization, the Service reads records such as employees, tasks, timesheets, customers, invoices and payments, and commit metadata, to produce reports.
Google Drive data (only if you connect it). If an authorized user chooses to connect Google Drive,
the Service requests read-only access (the drive.readonly scope, plus your basic profile
email). It reads the file list and the contents of files that the user imports, in order to add them to the
customer’s private “Business Memory”. See section 3.
2. How we use information
- To provide the features you asked for: dashboards, productivity and billing reports, daily summaries, and the EmprendeAI assistant, advisor and marketing tools.
- To secure and operate the Service, prevent abuse, and fix problems.
- We do not sell personal information, and we do not use it for advertising.
3. Google user data and the Limited Use requirements
- What we access: the Google account email address, and Drive files and folder listings with read-only permission. We never modify, delete, or share your Drive files.
- Why: solely to let the connected user import documents into their own company’s Business Memory so that the user’s EmprendeAI assistant can answer questions using those documents. This is the only purpose.
- What we store: for files you import, only the extracted text and numeric search embeddings derived from it, together with the file name and Drive identifier, kept in the customer’s private workspace. We do not keep a copy of the original file; downloads are fetched live from Drive. Google sign-in tokens are stored encrypted.
- AI processing: when you ask the assistant a question, the most relevant excerpts of your imported documents are sent to the AI provider that the customer has configured (for example Google Gemini, Anthropic Claude, or OpenAI), only to generate the answer to that question. We do not use Google user data to develop, improve, or train generalized AI or machine-learning models, and we do not allow others to. The provider’s own terms govern how it handles that request.
- Sharing: we do not transfer or sell Google user data, other than to the hosting and AI-provider services described above as necessary to provide the feature, to comply with law, or with your explicit consent. Our staff do not read your Google data unless you ask us to for support, it is needed for security or to investigate abuse, or the law requires it.
- No advertising: Google user data is never used for advertising or to determine credit-worthiness.
4. Retention, deletion and your controls
- Disconnect Google Drive at any time from EmprendeAI → Business Memory → Google Drive → Disconnect. This revokes our access with Google and deletes our stored Google tokens. Imported documents remain in your Documents list until you delete them there; deleting a document removes its text and embeddings.
- You can also revoke access directly at myaccount.google.com/permissions.
- Account and business data are kept while the customer’s account is active. To request access to, correction of, or deletion of your data, contact us (section 8); we will respond within a reasonable time and in line with applicable law.
5. Security
Traffic is encrypted in transit (HTTPS). Sign-in tokens and integration API keys are encrypted at rest, passwords are hashed, and access is separated per customer and by role. No system is perfectly secure, but we work to protect the data we hold.
6. Service providers
We use cloud hosting to run the Service, and each customer chooses the AI provider it connects. Those providers process data only to perform their function for the Service.
7. Changes to this policy
If we make material changes, we will update the date above and, where appropriate, notify customers.
8. Contact
Questions or requests about this policy can be sent to Srikesh Infotech by email at info@srikeshinfotech.com or through our website at https://www.srikeshinfotech.com.