Legal
Privacy Policy
Effective date: 20 August 2026 · Version 2026-08-20
This Privacy Policy explains how Beyond Basics ("we", "us", "our"), the operator of the Linia application and related services (the "Service"), collects, uses, stores, shares, and protects your personal data. We are committed to handling your information in accordance with the Digital Personal Data Protection Act, 2023 (the "DPDP Act"), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").
By creating an account and using the Service, you acknowledge that you have read and understood this Policy. Where the law requires consent, we collect it separately at sign-up and you may withdraw it at any time (see "Your rights").
1. Who we are (Data Fiduciary)
For personal data where we determine the purpose and means of processing, Beyond Basics is the Data Fiduciary. You can reach us, or our Grievance Officer, using the contact details at the end of this Policy.
Important: Linia is a workplace tool used by organizations, managers and teams (our "Business Users") to run their day-to-day operations. When a Business User records information about their employees, clients or other people in the app, that Business User is the Data Fiduciary for that information and we act as a Data Processor on their behalf. See "Data you enter about other people".
2. Information we collect
We collect the following categories of personal data:
- Account & profile data: your name, email address, password (stored only as a secure hash by our authentication provider), profile photo (if you sign in with Google), email-verification status, and a record of the consent you gave (the Policy version and the date and time you accepted it).
- Organization & role data: the organization(s) you belong to, your role (owner, admin, manager, employee or client), your department, who you report to, and the date you joined.
- Operational data you create: tasks and subtasks, checklists, priorities, due dates and time tracking; meetings and calendar events; notes and to-dos; tags; and related timestamps and activity logs.
- Performance & review data: when your organization uses task review, the ratings (for example task completion, quality, timeliness and ownership), star scores, approval decisions, review remarks and the review history recorded against work you submit or approve.
- Leave & absence data: leave requests including the leave type (such as sick, casual or work-from-home), start and end dates, the reason you provide, and the approving manager's decision and notes. A reason you enter may reveal health-related information; provide only what you are comfortable sharing.
- Reimbursement & financial data: expense and reimbursement claims including amount, category, payment method, transaction reference, the party paid, dates, status, and any receipts or invoices you attach.
- Messages & communication: the content of chat messages you send, attachments (images, files and voice notes, including a voice note's duration and audio waveform), reactions, reply and forwarding references, and delivery/read status.
- Uploaded files: images and documents you attach to tasks, messages, reimbursements or your profile/background, together with basic file metadata (name, size, type, upload time and uploader).
- Device & notification data: a Firebase Cloud Messaging (FCM) push token, a per-device identifier, platform label and browser user-agent, and last-active time, used to deliver notifications to your devices. Push tokens are removed when you sign out.
- On-device preferences: theme, font size, dashboard widget layout and saved filter choices stored locally in your browser. These are not transmitted to us.
- Usage & diagnostics data: aggregate, largely pseudonymous usage and performance signals (page views and Core Web Vitals) collected through Vercel Analytics and Vercel Speed Insights, and error/diagnostic logs, used to keep the Service reliable. Analytics load only after you accept them in our cookie/consent banner.
We do NOT use third-party advertising SDKs, we do not build advertising profiles, and we do not sell your data.
3. How we use your information
We process personal data to:
- create and secure your account and authenticate sign-in;
- provide the core features of the Service — tasks, dashboard, messaging, meetings and calendar, notes, leave and reimbursements;
- enforce role-based access so people only see data appropriate to their role;
- send operational push, in-app and email notifications (for example an assigned task, an approval decision, a meeting reminder or a mention);
- maintain audit trails and prevent misuse, fraud and security incidents;
- understand how the Service is used and diagnose errors, so we can improve reliability and features;
- respond to your support requests and meet our legal obligations.
4. Legal basis and consent
We process your personal data on the basis of your consent, obtained at sign-up, and for the legitimate purpose of providing a service you have requested. Consent we rely on is free, specific, informed, unconditional, and unambiguous. We record the version of this Policy you accepted and the date you accepted it. You can withdraw your consent as easily as you gave it, from Settings > Data & Privacy. Because we provide the Service on the basis of your consent, withdrawing it will close your account and delete your personal data; withdrawal does not affect processing carried out before withdrawal.
5. Sensitive information
Some information you may enter — such as the reason for a leave request, or financial details in a reimbursement claim — can be sensitive. It is visible only to authorised members of your organization (for example your manager or admin) according to their role, is transmitted over encrypted connections (HTTPS/TLS), and is stored with our infrastructure providers. Please share only what is necessary for the request you are making.
6. Data you enter about other people
The Service lets you record data about your employees, colleagues, clients and others. When you do this, you (or your organization) are the Data Fiduciary for that data and are responsible for having a valid legal basis and any required consent from those individuals, for collecting only what is necessary, and for responding to their requests. We process such data only to provide the Service to you and on your instructions.
7. How we share information
We do not sell your personal data. We share it only as needed to run the Service, with the following categories of processors and recipients:
- Google Firebase: authentication, database (Cloud Firestore and Realtime Database), file storage, and push messaging (Firebase Cloud Messaging).
- Vercel: hosting of the application and backend functions, and privacy-friendly usage analytics and performance monitoring (Vercel Analytics and Speed Insights).
- Resend: delivery of transactional email such as sign-up one-time passcodes (OTP) and notification emails.
- Cloudflare R2: object storage for uploaded files (task and message attachments, receipts, images and voice notes).
- cron-job.org: an external scheduler that triggers our backend on a timetable to send reminders and digests (for example due-soon and overdue task reminders and upcoming-meeting reminders).
- Members of your organization: data is visible to other members according to their role, as configured by your organization's admin.
- Legal & safety: authorities or advisors where required by law, or to protect rights, safety, and the integrity of the Service.
8. International data transfers
Our infrastructure providers (Google, Vercel, Cloudflare, Resend) may process and store data on servers located outside India. Where data is transferred internationally, we rely on providers that offer appropriate security safeguards and contractual protections, consistent with applicable Indian law.
9. Data retention
We keep personal data only for as long as it is needed for the purpose it was collected, after which it is deleted or de-identified. Indicative retention periods are:
- Account & profile data: until you delete your account (see "Your rights"). Push notification tokens are removed when you sign out.
- Financial & tax records: reimbursement and expense records may be retained for up to 8 years to meet Income-Tax Act and audit obligations, even after you leave an organization, because they form part of that organization's statutory books of account.
- Completed to-dos: items you tick off may be automatically removed a short time after completion.
- Diagnostic/error logs: kept only for a limited period to investigate and fix problems.
- On-device preferences: stored only in your browser until you clear the app's data.
You can delete individual records and uploaded files within the app at any time. When you delete your account, we delete or de-identify the personal data associated with it, except where retention is required by law or for legitimate business records (such as an organization's financial history that other members rely on).
10. How we protect your data
We implement reasonable security practices proportionate to the sensitivity of the data, including:
- encryption in transit (HTTPS/TLS) for all network communication;
- role-based access control enforced by server-side security rules;
- authentication and email verification for account access;
- server-validated, time-limited links for file uploads;
- the principle of least privilege — members access only what their role requires.
No method of transmission or storage is completely secure, but we work to protect your data and to address any incident promptly.
11. Your rights
Subject to applicable law, you have the right to:
- access a summary of the personal data we process about you;
- correct or update inaccurate or incomplete data;
- erase your personal data and delete your account;
- withdraw consent at any time;
- nominate another individual to exercise your rights in case of death or incapacity;
- grievance redressal, and to complain to the Data Protection Board of India.
Several of these rights are built into the app. From Settings > Data & Privacy you can update your name, download a copy of your personal data ("Download my data"), withdraw your consent, and delete your account. For any other request, contact our Grievance Officer (details below).
12. Children
The Service is intended for business and workplace use by adults and is not directed to children. You must be at least 18 years old to create an account, and you confirm this when you sign up. We do not knowingly collect the personal data of children or undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child's data has been provided to us, contact us so we can remove it.
13. Data breach
In the event of a personal-data breach that is likely to affect you, we will take prompt remedial action and notify affected users and the Data Protection Board of India (and any other authority) in the manner and within the timelines required by the DPDP Act and other applicable law.
14. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the effective date and version and, where appropriate, notify you in the app. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
15. Grievance Officer & contact
In accordance with the DPDP Act and the Information Technology Act, 2000 and rules thereunder, the contact details of our Grievance Officer are:
- Grievance Officer: Beyond Basics
- Operated by: Beyond Basics
- Email: beyondbasicstech@gmail.com
- Website: https://beyondbasics.global
- Address: MG Road, Bengaluru, Karnataka, India
We will acknowledge grievances within 72 hours and endeavour to resolve them within a reasonable period, and in any case within the timelines required by applicable law.