Privacy Policy — Field Visitor Mobile Application
1. Introduction
This Privacy Policy outlines how the Field Visitor Mobile Application ("the Application") collects, uses, stores, and protects information when authorized officers and collection agents ("Field Agents" or "Collectors") use our mobile application, and how it handles information relating to the customers whose accounts are visited ("Customers" or "Data Subjects").
The Application is an internal enterprise tool designed exclusively for authorized bank field officers and collection personnel to manage assigned account visits, record field dispositions, navigate routes, and upload visit documentation.
This Policy applies to two distinct groups of individuals: (a) Field Agents, who are the users of the Application; and (b) Customers, who do not use the Application but whose personal data is recorded through it. Sections 2 to 7 describe data relating to Field Agents. Section 8 deals specifically with Customer data and Customer rights.
The data practices described in this Policy correspond exactly to the disclosures made in the Google Play Data Safety section for this Application.
2. Information We Collect
A. Location Data
- Precise GPS Location: We collect precise geographical coordinates (latitude and longitude) while the Application is in use and visibly open on screen (foreground only) when the user interacts with navigation features or submits visit updates.
- Purpose: Location data is used to plot assigned customer addresses on Google Maps, provide route navigation, and verify that field visits are conducted at the designated customer locations.
- Background Location: The Application does NOT collect location data when it is closed or running in the background.
B. Audio Recordings
- Microphone Access: With user runtime permission, the Application accesses the device microphone when the Field Agent initiates a visit update by tapping "Add Remarks".
- Purpose: Audio files are recorded during field visit logging as proof of customer interaction and evidence of disposition records for enterprise auditing.
- Recording Trigger: Audio recording starts automatically when the Field Agent presses the "Add Update" button and continues while remarks are logged for a maximum of 15 minutes. The Application does not record audio at any other time.
C. Camera, Photos & Document Files
- Camera & Storage Access: The Application accesses the camera and media files selected by the user.
- Purpose: Allows collectors to capture photos of visited sites, scan visit notices, and attach PDF or image proof of field visits.
- The Application only accesses the exact photos or files you pick — whether from your gallery/files or by taking a photo in the app — right when you upload them. It never scans, browses, or uploads anything else from your storage.
D. User Account & Authentication Information
- Officer Credentials: Collector ID, full name, username, and encrypted JSON Web Tokens (JWT) for secure authentication, device identifier, and login/logout timestamps.
- Purpose: To manage user authorization, verify identity, and attribute field visit records to the responsible officer.
E. Financial Visit & Loan Data
- Case Records: Loan account numbers, Customer Identification File (CIF) details, payment collection amounts, disposition status codes, and visit remarks, together with the Customer name, address, contact number and outstanding balance supplied to the Application by the Partner Bank.
- Purpose: To update bank collection records and synchronize offline field visit logs with the central enterprise server.
F. Device & Technical Information
- Technical Logs: Device model, operating system version, network connectivity status, and API request logs, crash reports, and diagnostic data.
- Purpose: Used for app stability, troubleshooting, network state monitoring, and security auditing.
G. Information We Do NOT Collect
- The Application does not collect contacts, SMS messages, call logs, calendar entries, installed application lists, or browsing history.
- The Application contains no advertising software development kits and displays no advertisements.
- The Application does not perform any user profiling, behavioural tracking, or automated decision-making that produces legal effects.
3. How We Use Information and Our Legal Basis
We use the collected information solely for enterprise field collection operations, including:
- Verifying and logging officer field visits to customer addresses.
- Navigating officers to assigned locations via integrated map tools.
- Storing field evidence, visit reports, and payment details securely.
- Synchronizing offline visit records when internet connectivity is restored.
- Ensuring security, preventing unauthorized access, and maintaining audit trails.
Legal basis for processing: We process personal data on the following grounds:
- Performance of a contract: to administer the loan agreement between the Partner Bank and the Customer, and the employment or service contract between us and the Field Agent.
- Legal obligation: to comply with State Bank of Pakistan regulatory requirements, record-keeping rules, and anti-money-laundering obligations.
- Legitimate interests: to prevent fraud, verify that field visits genuinely took place, and protect both Customers and Field Agents through accurate evidence of each interaction.
- Consent: for microphone recording and camera access granted via runtime app permission, which may be withdrawn at any time.
We do not use any collected data for advertising, marketing, credit scoring, or automated decision-making.
4. Data Sharing and Disclosure
We do not sell, rent, or trade any personal or operational data to third-party advertisers or data brokers. Information collected within the Application is disclosed only to:
- Partner Banks & Financial Institutions: Field visit records, disposition status, and uploaded documents are shared with the originating bank/financial institution managing the account.
- Authorized Service Providers: Encrypted data is transmitted to secured enterprise backend servers solely for API operations and database synchronization.
- Legal & Regulatory Compliance: Information may be disclosed if required by applicable law, court orders, or banking regulatory authorities.
Third-party services and sub-processors: The Application incorporates the following third-party components:
- Google Maps Platform — mapping and turn-by-turn navigation. Privacy Policy: https://policies.google.com/privacy
- On-premises data centre: application and database hosting.
- Data hosting location: The Application is used within Pakistan, and all application data is hosted on servers located in Pakistan. No international data transfer takes place as a result of your use of the Application.
5. Data Security & Protection
- Encryption in Transit: All communications between the Application and enterprise servers are transmitted using TLS 1.2 or higher over HTTPS, with certificate pinning enforced against the enterprise server certificate.
- Encryption at Rest (Device): Authentication tokens are held in the Android Keystore. Offline queued visit records, audio files and attachments are stored in an AES-256 encrypted local database (SQLCipher or equivalent) within the app-private sandbox, which is not readable by other applications.
- Encryption at Rest (Server): All data stored on enterprise servers is encrypted at rest using AES-256, and database backups are encrypted to the same standard.
- Session Management: Access tokens (JWT) expire after 2 hours of inactivity and are refreshed only against a valid refresh token. All tokens are revoked immediately on logout, on password change, and on deactivation of the officer’s account.
- Access Control: App access is restricted to authenticated enterprise users with valid credentials on a least-privilege, role-based basis. A field Agent can view only the accounts assigned to that Agent.
- Audit Logging: All access to and modification of Customer records is logged with the user identity, timestamp and action. Audit logs are retained for 1 year and cannot be edited or deleted by Application users.
6. Data Retention & Deletion
Field visit logs, audio recordings, attached documents, GPS coordinates, and Customer financial data are retained in accordance with the applicable Partner Bank's data retention policies, contractual agreements, and regulatory guidelines of the State Bank of Pakistan. Data is kept no longer than necessary for the enterprise and compliance purposes set out in Section 3.
- Field Agent Account & Data Deletion Requests: A Field Agent may request account deactivation or deletion of their personal account information by emailing itasia@ncrisolutions.com.
- What is deleted vs. what is retained: Upon receiving an approved deletion request, the officer's active login credentials and personal contact details will be deactivated/removed. However, operational field visit records, disposition logs, audio notes, location tags, and associated audit logs generated during past field visits are retained as historical enterprise records required for legal, regulatory, and bank audit compliance, and will be preserved under restricted access.
7. Permissions Required
- Location (
ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION): Required for map navigation and visit coordinate verification.
- Microphone (
RECORD_AUDIO): Required to record audio evidence during field visits remark submissions. Active only while adding remarks.
- Camera (
CAMERA): Required to photograph visited sites and scan visit notices.
- Media access (
READ_MEDIA_IMAGES, READ_MEDIA_VISUAL_USER_SELECTED on Android 13+; READ_EXTERNAL_STORAGE on Android 12 and below): Required to attach existing photographs or documents selected by the user.
- Internet & Network State (
INTERNET, ACCESS_NETWORK_STATE): Required to check connectivity and synchronize data with enterprise servers.
All permissions are requested at the moment the relevant feature is first used, together with an explanation of why the permission is needed. You may deny or later revoke any permission in your device settings.
8. Customer (Third-Party) Data
The Application records personal data about the Customer whose account is being visited. That Customer is not a user of the Application.
- Customer data recorded: Name, residential or business address, contact number, loan account number and CIF reference, outstanding balance and payment amounts, GPS coordinates of the visited premises, photographs of the premises, audio recordings of the visit conversation, and the Field Agent’s remarks.
- Source: Data supplied by the Partner Bank under the loan agreement or generated during the visit itself.
- Visit Operations: Audio recording and location verification automatically activate when the Field Agent taps "Add Remarks" to submit visit updates. Field Agents are required by internal conduct rules to identify themselves and state the institution they represent during field visits.
- Restrictions on Field Agents: Agents are prohibited from photographing the interior of private premises without permission, photographing objecting individuals, recording unconnected third parties, disclosing debt details to unauthorized third parties, or visiting outside permitted hours. Breach of these restrictions constitutes grounds for disciplinary action and potential legal liability.
- Customer rights & complaints: Customers seeking information regarding data held about them may submit inquiries to the Partner Bank holding their account or contact NCRi at itasia@ncrisolutions.com. Customers may also lodge complaints with the Partner Bank or the State Bank of Pakistan Banking Mohtasib (https://bankingmohtasib.gov.pk).
9. Your Rights as a Field Agent
Subject to applicable law and to our regulatory obligations, Field Agents have the right to:
- Request confirmation of personal account data held about them.
- Request correction of inaccurate account data.
- Request account deactivation/deletion by emailing itasia@ncrisolutions.com (subject to retention of field visit audit records as described in Section 6).
- Revoke app permissions (Location, Microphone, Camera) via device settings at any time.
- Complain to the relevant supervisory authority.
NCRi Solutions will not retaliate against any Field Agent for exercising these rights.
10. Data Breach Notification
In the event of a personal data breach, NCRi Solutions will contain and assess the incident without delay, notify the affected Partner Bank within 24 hours of becoming aware of it, notify competent regulators as required by law, and notify affected individuals where a breach poses a significant risk.
To report a security incident or vulnerability, contact itasia@ncrisolutions.com immediately.
11. Regulatory Compliance
- Regulatory Framework: Processed in accordance with the State Bank of Pakistan Enterprise Technology Governance & Risk Management Framework, SBP outsourcing rules, PECA 2016, and applicable Pakistan data protection laws.
- Google Play Compliance: The Application complies with Google Play User Data policies, Data Safety disclosure requirements, Location Permissions policies, and Photo/Video Permissions policies.
12. Children's Privacy
The Application is an enterprise business application intended exclusively for authorized professional personnel aged 18 and older. We do not knowingly collect data from minors. Field Agents are instructed not to record or photograph minors during visits.
13. Changes to This Privacy Policy
This Policy may be updated periodically. Any changes will be published in-app with an updated Effective Date. Where a change materially affects how data is processed, notice will be provided in-app prior to the change taking effect.
14. Contact Us
Organization: NCRi Solutions / Field Collection Division
Data Protection Officer: Hammad Shabbir | Senior Manager Infrastructure and Network
Privacy Enquiries & Data Requests: itasia@ncrisolutions.com
Security Incidents: itasia@ncrisolutions.com
General Email: itasia@ncrisolutions.com
Telephone: +92-301-2021932
Address: Galaxy Business Center, Street 9, I-9/3, Islamabad, Pakistan
Response Time: Acknowledgement within 7 working days, substantive response within 30 calendar days.