Privacy Policy — DRAFT
This is a starting draft, not legal advice. India's Digital Personal Data Protection Act, 2023 (DPDP Act) applies to you as a Data Fiduciary. Have a qualified advisor confirm this against the Act and its rules before publishing. Fill in every [bracketed] placeholder.
Last updated: [date] Data Fiduciary: [Openlogic Business Solutions Pvt. Ltd.], [address], Assam, India. Grievance contact: [name], [email], [phone].
1. Scope
This policy explains what personal data we collect, why, and your rights under the DPDP Act, 2023. By using the Platform you consent to this processing for the purposes below.
2. What we collect
From relief organisations (applicants):
- Organisation name, description, district, address, website.
- Contact person's email and phone.
- Registration number, NGO Darpan ID, PAN.
- UPI ID and payee name (so contributors can pay you directly).
- Uploaded verification documents (registration certificate, 80G/12A, ID proof).
- Account password (stored only as a secure hash).
From contributors:
- We do not require an account to contribute.
- If you report a listing, the reason you give and any optional contact you provide.
- Basic technical logs (IP address, timestamps) for security and abuse prevention.
We never see contribution amounts or payment details — payments happen inside your own UPI app, directly to the organisation. That data never reaches us.
3. Why we process it (purposes)
- To verify organisations and decide whether to list them.
- To display verified organisations and their UPI details to contributors.
- To handle reports of suspicious listings and prevent fraud and abuse.
- To secure the Platform and comply with law.
4. Legal basis
We rely on your consent (given when you submit information) and, where applicable, on legitimate uses permitted by the DPDP Act such as security and prevention of fraud.
5. Sharing
- Public display: a verified organisation's name, district, description, and UPI details are shown publicly — that is the purpose of listing. Uploaded documents are not public; only our reviewers see them.
- We do not sell personal data.
- We may share data with law-enforcement or regulators where legally required.
- We use [hosting provider] to host the Platform; they process data on our behalf under contract (Data Processor).
6. Retention
We keep applicant data while a listing is active and for [X months/years] after it is removed, for audit and fraud-prevention, then delete or anonymise it. Report and log data is kept for [X months].
7. Security
We use hashed passwords, access controls, documents stored outside the public web root, and encrypted transport (HTTPS). No system is perfectly secure; we cannot guarantee absolute security.
8. Your rights under the DPDP Act
You may, by contacting our Grievance Officer:
- Access a summary of the personal data we hold about you.
- Request correction, completion, or updating of your data.
- Request erasure of your data (subject to legal retention needs).
- Withdraw consent (this may mean we can no longer list your organisation).
- Nominate another person to exercise your rights in case of death or incapacity.
- Raise a grievance; if unresolved, escalate to the Data Protection Board of India.
9. Children
The Platform is not intended for anyone under 18. We do not knowingly collect data from children.
10. Changes
We may update this policy; the "last updated" date will change. Material changes will be notified on the Platform.
11. Grievance Officer
[Name] · [email] · [phone] · [address] We will acknowledge grievances within [X] days.