Privacy Policy

Last Updated: November 12, 2024

Introduction

The Information Warfare Foundation of India ("IWF", "we", "us") respects your privacy. This Privacy Policy explains what personal data we collect through iwf.org.in and our related services, why we collect it, how we use, share and protect it, and the rights and choices you have.

We handle personal data in line with the laws of India, including the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Information Technology Act, 2000 with the rules made under it. This Policy is read with our Terms of Service and Refund Policy.

1. Scope and Who We Are

IWF, based at Rajkanika, Kendrapara, Odisha, India, 754220, decides why and how your personal data is processed through our Services and is therefore the "Data Fiduciary" under the DPDP Act. "Services" has the meaning given in our Terms of Service and covers the website, accounts, forms, donations and payments, and volunteer and program applications.

This Policy applies to visitors, donors, account holders, volunteers, applicants, partners and anyone else who gives us personal data through the Services. It does not apply to websites run by others that we link to.

2. Personal Data We Collect

We collect only the data we need for the purposes in this Policy. It falls into these groups:

Data you give us

  • Account and sign-in: name, email address, password (stored only in a hashed form by our authentication provider), profile details you add (such as phone, address, photo, bio and interests), and, if you sign in with Google, Facebook or GitHub, the basic profile that provider shares with us.
  • Contact and enquiries: name, email, subject and message from our contact, consultation, partnership and media-collaboration forms, and anything else you choose to tell us.
  • Donations and payments: name, email, phone number, amount, payment method type, transaction and order IDs, any message you add, and, where you ask for a tax receipt, details such as address and PAN. We do not receive or store your full card number, CVV, UPI PIN or net-banking credentials. These are entered on the payment gateway's secure page.
  • Volunteer and job applications: name, contact details, city and state, skills, interests, availability, education, profession, languages, experience, your reasons for applying, references you list, and any documents you attach.
  • Communications: your emails and calls with us, and your choices about newsletters or updates.

Data collected automatically

  • Technical data: IP address, browser type and version, device and operating system, referring page, pages requested, and date and time of access. These appear in server logs and are recorded with form submissions for security and abuse prevention.
  • Cookies and local storage: described in the "Cookies and Local Storage" section.

Data from others

  • Confirmation of payment status from our payment gateway and bank.
  • Profile data from a social sign-in provider you choose to use.
  • Information about you from a person who lists you as a reference.

We do not ask for sensitive categories of data (such as health, religion, caste or biometric data) through the website. Please do not send them to us.

3. How and Why We Use Your Data

We process personal data on the basis of your consent, or for the "legitimate uses" the DPDP Act allows, such as when you voluntarily give us data for a stated purpose and have not objected to its use, to meet a legal obligation, or to respond to a medical or safety emergency. Our purposes are:

  • Providing the Services: creating and managing your account, authenticating you, and showing you the pages and tools your role allows.
  • Responding to you: answering enquiries, considering consultation, partnership and media requests, and handling support and grievances.
  • Donations and payments: processing and confirming payments, issuing acknowledgements and receipts, preventing fraud, and handling payment disputes and approved refunds.
  • Volunteers and programs: assessing applications, matching volunteers to work, running programs and events, and keeping records of participation.
  • Communications: sending service messages (such as receipts and account notices) and, only where you have agreed, updates about IWF's work and campaigns. You can opt out of updates at any time.
  • Security and integrity: detecting and preventing abuse, attacks, spam and unauthorized access, and keeping audit logs.
  • Improving the Services: understanding in an aggregated way how the website is used so that we can fix problems and make it better.
  • Legal and accounting duties: meeting obligations under tax, accounting, charity and other laws, and responding to lawful requests from authorities.
  • Reporting: publishing aggregated or anonymized statistics about our work, which do not identify you.

We do not use your personal data to make decisions about you by purely automated means that have legal or similarly significant effects, and we do not sell your personal data.

4. Cookies and Local Storage

The website uses only the small pieces of data it needs to work. At the time of this Policy, it does not use advertising cookies or third-party tracking pixels.

  • Strictly necessary: a secure session cookie that keeps you signed in, and security tokens (such as CSRF protection) that protect forms. The website cannot work properly without them.
  • Preferences: your light or dark theme choice is saved in your browser's local storage so that your preference is remembered. It stays on your device and is not sent to us.
  • Embedded content: if a page loads an embedded map or similar third-party content, the provider (for example Google) may receive your IP address and set its own cookies under its own policy.

You can block or delete cookies and local storage in your browser settings. If you block the strictly necessary cookies, you will not be able to sign in. If we later add analytics or other optional cookies, we will update this Policy and ask for your consent where the law requires it.

5. Who We Share Data With

We do not sell, rent or trade your personal data. We share it only as follows:

  • Service providers (processors). Companies that process data for us under contract and only on our instructions, namely: web hosting (Hostinger); our database and authentication provider (Supabase); payment processing (Razorpay and the banks involved); and email delivery (SMTP email service). They must protect the data and may not use it for their own purposes.
  • Sign-in providers. If you use Google, Facebook or GitHub to sign in, that provider and we exchange the data needed to log you in.
  • Professional advisers and auditors who are bound by confidentiality, such as our accountants, auditors and legal advisers.
  • Authorities. Courts, regulators, law-enforcement or tax authorities where the law requires it or to protect legal rights, or to prevent fraud or serious harm.
  • Organizational changes. A successor or affiliated organization if IWF's activities are transferred, on terms that keep your data protected.
  • With your consent or at your direction, for example a reference you ask us to share.

Within IWF, access to personal data is limited to authorized trustees, staff and volunteers who need it for their role.

6. Where Your Data Is Processed

Our providers may store and process data on servers inside or outside India. Where data is transferred outside India, we do so only as the DPDP Act allows, and we rely on providers that apply appropriate security and contractual safeguards.

7. How Long We Keep Data

We keep personal data only for as long as it is needed for the purpose it was collected for, and then delete or anonymize it. In general:

  • Account data is kept while your account is active and is deleted or anonymized after you close it, except for records we must keep.
  • Enquiries and contact messages are kept for as long as needed to deal with them and for a reasonable period after, in case of follow-up.
  • Donation and payment records are kept for the period required by tax, accounting and charity laws.
  • Volunteer and job applications are kept while your application or volunteering is active and for a reasonable time after, unless you ask us to delete them earlier.
  • Security logs are kept for a limited period to investigate abuse and incidents.

We may keep data for longer where needed to meet a legal duty, resolve a dispute or enforce our terms.

8. How We Protect Data

As a cybersecurity organization, we take security seriously. Our reasonable safeguards include:

  • encrypted connections (HTTPS) and security headers on the website;
  • hashed and salted password storage handled by our authentication provider;
  • role-based access control, with database-level row security so people can reach only the data their role allows;
  • server-side verification of every sign-in, rate-limiting of forms and login attempts, and verification of payment confirmations before we act on them; and
  • limiting staff and volunteer access to what they need, and keeping secrets and service keys out of the browser.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. You can help by using a strong, unique password, keeping it private and signing out on shared devices. Report a suspected weakness or misuse of your account to info@iwf.org.in.

9. Your Rights

Under the DPDP Act you have the right to:

  • Access information: ask for a summary of the personal data we process about you, the processing we carry out, and the other parties we have shared it with.
  • Correction and erasure: ask us to correct inaccurate or incomplete data, update it, or erase data that is no longer needed for its purpose or for a legal requirement.
  • Withdraw consent: withdraw a consent you gave at any time. This does not affect processing already done, and we will stop the processing unless the law allows or requires us to continue. Withdrawing may mean that we can no longer provide a service that needs the data.
  • Grievance redressal: have a complaint about our handling of your data heard and answered (see the "Grievance Redressal" section).
  • Nominate: nominate another person to exercise your rights if you die or become unable to do so.

To use a right, write to privacy@iwf.org.in from the email address linked to your account or submission, and tell us what you want. We may ask for information to confirm your identity before we act, to protect your data from being given to the wrong person. We aim to reply within 30 days. You can opt out of updates using the unsubscribe link in any message or by emailing us. Rights apply to the extent provided by law, and some requests (for example to erase records we must keep by law) may be declined with an explanation.

We ask that you also use our grievance process first, as described below. If you are not satisfied with our response, you may complain to the Data Protection Board of India once it is in operation, as the DPDP Act provides.

10. Children's Privacy

Under the DPDP Act a "child" is a person under 18. We do not knowingly collect personal data of a child through the Services without the verifiable consent of a parent or lawful guardian, and we do not track or monitor children's behaviour or send them targeted advertising. If you are a parent or guardian and believe your child has given us personal data without your consent, write to privacy@iwf.org.in and we will delete it.

11. Third-Party Sites

Our website may link to websites and services run by others, such as social media platforms and our partners. We are not responsible for their privacy practices. Please read their policies before you give them any personal data.

12. Data Breaches

If a breach of personal data occurs, we will take steps to contain it and reduce harm, and we will notify the Data Protection Board of India and affected persons in the way and within the time the law requires.

13. Grievance Redressal

For any concern about how your personal data is handled, or for any request under this Policy, contact us at privacy@iwf.org.in (or legal@iwf.org.in), writing "Privacy Grievance" in the subject line, or write to the address in the Contact section below. We will acknowledge your complaint within 48 hours and aim to resolve it within 30 days of receiving it.

14. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, the Services or the law. The revised Policy will be posted here with a new "Last Updated" date. If a change is material, we will make reasonable efforts to notify you, such as by a notice on the website or by email, and we will ask for fresh consent where the law requires it.

15. Contact Us

If you have any questions about this Privacy Policy or want to exercise your rights, please contact us at:

Address:

Information Warfare Foundation of India, Rajkanika, Kendrapara, Odisha, India, 754220

Email:

Privacy requests and grievances: privacy@iwf.org.in

Legal: legal@iwf.org.in

General: info@iwf.org.in

Chairman's Signature

Chairman

Information Warfare Foundation of India

November 12, 2024