Skip to main content

Privacy Policy

Last updated 30 July 2026

Draft for review by qualified Indian legal counsel. This text is an operational template and has not yet been reviewed by counsel.

Draft for review by qualified Indian legal counsel.

This Privacy Policy describes how NangalDewat.com (the "Platform"), a privately owned and independently operated information platform, handles personal data. It is prepared as a template with reference to applicable Indian data-protection law, including the Digital Personal Data Protection Act, 2023 (the "DPDP Act"), and must be reviewed by qualified Indian legal counsel before being treated as final.

1. Who operates the Platform

The Platform is operated by its private owner. It is not operated by any Resident Welfare Association, residents' body, village committee, government authority, or municipal body. The platform owner determines the purposes and means of processing personal data on the Platform.

2. Privacy by design and minimal collection

The Platform is built on a privacy-by-design approach:

  • Only the minimum personal data needed for a stated purpose is collected.
  • Sensitive directory fields (such as phone numbers, email addresses, and household references) are private by default and are subject to field-level visibility controls.
  • Private areas of the Platform are excluded from search-engine indexing.
  • Access to personal data is restricted by role-based access control, and access to directory data is logged.

3. What we collect

Depending on how you interact with the Platform, we may collect:

  • Account data: email address, display name, and a password (stored only as a cryptographic hash).
  • Directory data (invite-only, consent-based): name, and only those optional fields a participant chooses to provide, such as a locality descriptor, profession, phone, or email.
  • Form submissions: the name, email address, and message you provide when contacting the Platform or submitting content, together with a reference number.
  • Technical data: limited technical logs (such as IP address and browser type) for security, rate limiting, and audit purposes.

4. What we do not collect

  • The Platform does not collect Aadhaar numbers.
  • The Platform does not request government identity numbers, financial account details, or biometric data.
  • The Platform does not use third-party advertising or tracking cookies. See the Cookie Policy.

5. Purposes of processing

Personal data is processed only for the following purposes:

  1. Operating and securing the Platform, including authentication, session management, rate limiting, and the tamper-evident audit log.
  2. Maintaining the private, consent-based directory for the participants who have joined it.
  3. Receiving, tracking, and resolving contact requests, corrections, privacy requests, and legal notices.
  4. Publishing content that a submitter has provided for publication, subject to editorial review.
  5. Complying with legal obligations.

6. Consent and voluntary participation

Directory participation is voluntary and invitation-based. Consent is recorded, including its purpose and scope, and may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

7. Role-based access

Personal data is accessible only to the platform owner and to specifically authorised roles, each limited to the data needed for their function. Administrative access does not constitute ownership of any data or of the Platform. Directory data is never exposed on public pages.

8. Retention

Personal data is retained only as long as needed for the purpose for which it was collected, for the resolution of any open request, or as required by law. Records that must be preserved for audit integrity are retained in the append-only audit log with minimal personal data.

9. Your requests

Subject to applicable law, you may ask the Platform to act on your personal data. Supported workflows are:

  • Correction of inaccurate or outdated personal data.
  • Withdrawal of consent to continued processing.
  • Restriction of how your data is used or displayed.
  • Export of the personal data you have provided, in a portable format.
  • Anonymisation of records where full deletion is not possible or lawful.
  • Deletion of your personal data, subject to legal retention requirements.

Requests may be submitted through the contact page (choose "Privacy request" or "Directory removal"). Every request receives a reference number and is tracked to resolution. We may need to verify your identity before acting on a request.

10. Children and minors

The Platform is not directed at children. The directory does not knowingly list minors without the verifiable consent of a parent or lawful guardian, and personal data of minors is never published on public pages. Processing of children's data, where it occurs at all, is intended to comply with the protections of the DPDP Act.

11. Security and breach response

The Platform uses hashed credentials, hashed session tokens, encrypted secrets, role-based access controls, rate limiting, and an append-only audit log. In the event of a personal data breach, the platform owner will assess the breach, mitigate it, and notify affected individuals and the relevant authority where and as required by applicable law.

12. Disclosure

Personal data is not sold. It is disclosed only to service providers strictly needed to host and operate the Platform, or where disclosure is required by law or by a lawful order.

13. Grievances and contact

Privacy questions, grievances, and requests may be raised through the contact page. Where the DPDP Act or other applicable law requires a designated grievance or contact mechanism, the details will be published on the Platform once confirmed with counsel.

14. Changes to this policy

This policy may be updated from time to time. The current version, with its date of last update, will always be published on this page.