Privacy & Data Protection Policy
Comprehensive data protection and privacy framework compliant with the Digital Personal Data Protection Act, 2023 (DPDP Act) and IT Act 2000, governing donor data, volunteer information, rescue logs, and zero data monetization.
1. Statutory Governance & Scope
Ashjyoti Foundation ('Foundation', 'we', 'our', 'Data Fiduciary') is a registered Section 8 non-profit company (CIN: U80904DL2018NPL334576, NGO-DARPAN: DL/2018/0201066). This Privacy & Data Protection Policy is formulated in strict compliance with:
- Digital Personal Data Protection Act, 2023 (DPDP Act, 2023)
- Information Technology Act, 2000 (IT Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
- Reserve Bank of India (RBI) Card-on-File Tokenization and Payment Aggregator Frameworks
This policy governs all digital personal data processed across our public portal (ashjyotifoundation.org), 24/7 SOS distress reporting desk, volunteer and member portals, and charitable checkout integrations.
2. Categories of Personal Data Collected
We collect and process only minimum necessary personal data required for lawful charitable purposes:
- Charitable Donors: Full legal name, email address, mobile number, postal address, and Permanent Account Number (PAN) as mandated by Section 139A and Rule 114BA of the Income Tax Act, 1961 for statutory Form 10BD filing.
- Citizens Reporting Animal Distress (SOS Desk): Reporter name, contact telephone number, exact GPS location coordinates / landmark, and uploaded distress scene photographs or videos.
- Registered Volunteers & Gaushala Members: Full name, verified mobile number, email address, postal address, identity verification credential (for issuance of volunteer ID badges and digital certificates), emergency contact, and voluntary blood group for field rescue safety.
- Automated Technical Metadata: IP addresses, browser user-agent tokens, and security session logs processed exclusively for DDoS prevention, rate-limiting, and cyber defense.
3. Purpose Limitation & Zero Data Monetization Guarantee
In accordance with Section 4 and Section 6 of the DPDP Act, 2023, personal data is processed solely for specified, lawful non-profit objectives:
- Dispatching emergency veterinary ambulances, trauma medics, and rescue teams to reported GPS locations.
- Generating and transmitting authentic statutory donation receipts, tax certificates, and annual contribution summaries.
- Issuing verified digital volunteer registration certificates and gaushala membership credentials.
- Transmitting critical transaction receipts, passwordless authentication magic links, and secure 6-digit OTPs.
ABSOLUTE NON-MONETIZATION PLEDGE: Ashjyoti Foundation NEVER sells, rents, leases, trades, or commercializes donor or volunteer phone numbers, email addresses, or personal records to commercial advertisers, telemarketing agencies, or third-party data brokers.
4. Payment Security & RBI Tokenization Compliance
- Zero Raw Card Storage: All online donations are processed securely through RBI-authorized, PCI-DSS Level 1 compliant Payment Aggregators (Razorpay, Cashfree, PayU). Ashjyoti Foundation never captures, handles, or stores full 16-digit debit/credit card numbers, CVVs, card expiry dates, NetBanking passwords, or UPI MPINs on its servers.
- End-to-End Encryption: All data transmitted between user web browsers and our application infrastructure is encrypted using modern 256-bit TLS/SSL cryptographic protocols.
5. Protection of Children & Minors (Section 9 DPDP Act)
Ashjyoti Foundation does not track, profile, or conduct behavioral monitoring of children. Minors participating in educational school visits or supervised community feeding drives must have explicit parental or legal guardian consent before registering.
6. Rights of the Data Principal
Under Chapter III (Sections 11 to 14) of the DPDP Act, 2023, you hold enforceable statutory rights:
- Right to Access & Summary: You may request a summary of personal data held and processed by the Foundation.
- Right to Correction & Erasure: You may request the correction of inaccurate data or the deletion of data that is no longer required for statutory or regulatory compliance.
- Right of Grievance Redressal: You may file a formal privacy complaint with our designated Data Protection Desk.
- Right to Nominate: You may nominate any individual to exercise data rights on your behalf in the event of death or incapacity.
7. Data Retention & Automatic Purge Lifecycle
- Temporary Certificate Storage: Digital certificates generated dynamically are held in secure private storage for 10 days and automatically deleted, with seamless on-demand regeneration available for active members and volunteers.
- Statutory Financial Retention: Mandatory tax, PAN, and donation records are retained for 7 financial years in strict adherence to the Income Tax Act, 1961 and Ministry of Corporate Affairs regulations.
- Distress Call Records: GPS coordinates and bystander phone numbers are archived post-resolution and anonymized for public impact reporting.
8. Data Protection Officer & Privacy Desk
For inquiries or to exercise statutory privacy rights, contact our designated privacy desk:
- Email:
privacy@ashjyotifoundation.org(CC:info@ashjyotifoundation.org) - Postal Address: Data Protection Desk, Ashjyoti Foundation, Shakarpur, Delhi - 110092, India
- Response Timeline: Formal acknowledgment within 48 hours; resolution within 15 business days.
CIN: U80904DL2018NPL334576