1Who is responsible for your data
The Data Fiduciary for the purposes of the Digital Personal Data Protection Act, 2023 is EFLAG CORP PRIVATE LIMITED.
| GSTIN | 27AAGCE6423L1ZE |
| Principal place of business | Pritham Plaza, 18 Yellamman Koil Street, Off Kensington Road, Adj. to Gurudwara, Bangalore, Karnataka – 560008 |
| Data protection contact | [email protected] |
| Grievance Officer | [email protected] |
This policy covers bappa.org, kaladhipati.com, their subdomains, and the WhatsApp service operated alongside them. One policy covers both websites because they are one platform, with one account behind them.
2Where this service is offered
This service is offered from India, under Indian law, to users in India. We do not market to, target, or solicit users in the European Economic Area or the United Kingdom.
We do not claim compliance with the EU GDPR or the UK GDPR. We have not appointed an Article 27 representative and we do not operate the specific rights and transfer machinery those laws require.
If you are in the European Economic Area or the United Kingdom you are welcome to read the public pages. Please do not create an account, contribute content, or ask us to ship anything to you. Deliveries are made only to India, South-East Asia and the Gulf.
3What we collect, and why
3.1 What you give us
| What | When | Why |
|---|---|---|
| Mobile number | Sign-up and every sign-in | It is your account identifier, and how we send the one-time passcode. |
| Name or display name | Optional, in your profile | Shown on your contributions if you choose to show one. Leave it blank and they appear unnamed. |
| Language and theme | When you set them | So the app appears in your language, and in the colours you chose. |
| City and a coarse area | Optional | Panchang and moonrise times are only true of a place. See 3.2. |
| Your contributions | When you submit | Stories, recipes, traditions, photographs, voice recordings, videos, where you learned a tradition, and the region it belongs to. |
| Postal address and a contact number | Only when you redeem a physical reward | To deliver the item. Used for that shipment and nothing else. |
| Mandal details | Only if you claim a mandal page | To verify the claim and to run the page. |
3.2 Location: what we actually store
We do not retain your latitude and longitude, and our servers never receive them.
We may obtain your approximate location in one of two ways: from your device's location permission, if you grant it, or from the city you type into your profile. When you grant location permission, your device converts its position into a five-character geohash before anything is sent to us; the precise coordinates never leave your device. A five-character geohash describes an area of roughly five kilometres by five kilometres. It is not enough to say which street you are on. The WhatsApp service does not accept location pins.
We keep only the city name and the geohash, and we use them to provide location-based features: local events and mandals, nearby stories, and location-specific astronomical information such as moonrise and panchang times.
We retain your city name and geohash for as long as your account exists, or until you replace them from your profile, unless a longer period is required by law. They are deleted with your account.
We do not sell your location information. Your city name and geohash are stored with our hosting provider in Mumbai, India, under our contract with it, and are not shared with any other third party, advertiser or analytics provider.
3.3 What the system records as you use it
| Karma activity | A record of Karma earned and spent, so the score can be explained and corrected. |
| Usage events | Which screens and features are used, recorded on our own servers. See section 5. |
| WhatsApp messages | What you send the service and what it replies, so a conversation can continue across messages. |
| Technical logs | IP address, browser or device type and timestamps, held for security, abuse prevention and debugging. |
| Notification subscriptions | Only if you allow notifications in your browser. |
| Referral codes | If you invite someone, or arrive by an invitation. |
| Sign-in sessions | A record of each sign-in and the session it opened, so that you can sign out of every device and so that a stolen token can be revoked. One-time passcodes are stored only as a keyed hash and expire after a short time. |
| Support and enquiry messages | What you write to us for help, and, on the marketplace, an enquiry you send to a maker together with the name and mobile number you give with it, so the conversation can be answered. |
| Payment and order records | Where a purchase or a Karma redemption is made: the item, the amount, the payment reference returned by the payment gateway, and a delivery address if something is shipped. Never a card number. See section 3.4. |
| Audit records | Certain significant events are written to an append-only, tamper-evident record. See section 9. |
3.4 What we do not collect
- We do not ask for, and have no field for, your email address, date of birth, gender, caste, religion, income, Aadhaar, PAN or other government-issued identifiers.
- We do not ask for or collect health data or biometric data.
- We do not access your contacts, photo library, calendar, SMS or other messages. A photograph is received by us only when you voluntarily select and upload it to use a feature of the service.
- We do not retain your precise latitude and longitude. Where you provide or permit location information, we retain only your city name and five-character geohash, as described in section 3.2.
- We do not collect payment card details. Where payments are enabled, they are processed by a licensed payment gateway, and we do not receive or store your card details.
5Analytics
We measure how the platform is used so that we can improve it.
- Measurement is first-party. Events are recorded by our own servers. There is no Google Analytics, no advertising SDK and no third-party measurement service of any kind.
- Personal data is removed at the point of collection. The code that records an event rejects fields that look like personal data, including phone numbers, names, addresses, tokens and email addresses, before the event is written.
- We do not sell or share it. Aggregate figures may be reported to a government partner as programme statistics. Those are counts, not people.
Where you are signed in, a usage event is stored against your account identifier, so usage is linkable to your account. It is not used to build a profile of you, to make decisions about you, or to target you with advertising.
6What we do with your contributions
This is set out in full in clause 6 of the Terms of Use. In summary:
- You keep ownership. We claim none.
- We use contributions for non-commercial educational and cultural purposes, for festival and heritage promotion, and for archival work with a government partner.
- We do not sell your content, and we do not licence it to anyone for advertising.
- Contributions are published under your chosen display name if you have set one, and otherwise without a name. Never with your mobile number.
- Entry into a State heritage inventory is a separate, explicit choice, set to no unless you change it, following Article 15 of the 2003 Convention for the Safeguarding of the Intangible Cultural Heritage.
Automated processing. Submissions are classified, scored for quality, checked for spam, tagged and translated by automated systems, and where a contribution has no image we may generate a labelled illustration for it. Illustrations are reviewed by a person before they appear. Automated systems assist a decision about your submission; they do not make a final decision about you, and you can ask a person to look again.
8Your choices, and how to exercise them
You have the following rights under the Digital Personal Data Protection Act, 2023.
| Right | How |
|---|---|
| Know what we hold about you and how it is used | Write to the data protection contact. |
| Correct or complete your data | Most of it is editable in the app. For the rest, write to us. |
| Withdraw consent | Turn the setting off, or write to us. Withdrawing a consent the service depends on may mean we can no longer provide it. |
| Ask for erasure | Write to us. Section 9 sets out what we can and cannot delete. |
| Nominate a person to exercise your rights if you die or become incapacitated | Write to the data protection contact. |
| Complain | To our Grievance Officer first, and then to the Data Protection Board of India. |
Settings you control yourself:
- Reminders and nudges: off unless you turn them on. Change them in settings, or reply STOP on WhatsApp.
- Browser notifications: off until your browser asks and you allow them.
- Showing a public display name: off until you set one.
- Person-to-person connection: off unless you turn it on, and even then the other person receives a display name only. Neither party is shown the other's phone number.
- Heritage archive consent: off, asked separately, for each contribution.
We respond to a request within 30 days. We will ask you to make the request from your registered mobile number, so that nobody else can act on your account.
9How long we keep data, and what we cannot delete
We keep personal data while your account is active and for as long as it is needed for the purposes set out above.
- Your account and profile: deleted or irreversibly anonymised on request.
- Published contributions: removed from public view on request. Where a contribution has already entered a formal heritage inventory record shared with a government partner, we may be unable to withdraw it from that record, and we will tell you so.
- Shipping records: kept while needed for delivery, and then for as long as tax and accounting law requires.
- Payment records: kept for the period required by financial and tax law.
- Security and access logs: kept for a limited period for security and abuse investigation.
- The audit record: certain platform events are written to an append-only, hash-chained record, so that the platform can demonstrate to a government partner that its records have not been altered. That record is designed so that it cannot be rewritten. Where it refers to you, we can sever the link to your identity so that the entry no longer identifies you, but we cannot remove the entry itself.
10Security
- All traffic is encrypted in transit, and the site sits behind a web application firewall.
- Sign-in is by one-time passcode to your registered number. There is no password to be stolen.
- Administrator accounts require two-factor authentication, and administrative actions are logged.
- Access to production data is limited to the people who need it.
- Rate limits and abuse controls protect the sign-in and submission paths.
- Backups are taken so that the service can be restored.
No system is perfectly secure. If a personal data breach occurs we will notify the Data Protection Board of India and affected users, as the Digital Personal Data Protection Act, 2023 requires.
11Children
This service is for people aged 18 and over. We do not knowingly collect personal data from anyone under 18, and we do not use anyone's data for tracking, behavioural monitoring or targeted advertising.
If we learn that an account belongs to a child we will close it and delete the associated personal data. A parent or guardian who believes a child has an account should contact the Grievance Officer.
12Links and embedded content
Our pages link to other websites and may embed third-party media players. Opening an embed loads content from that provider, which may see your IP address and set its own cookies under its own policy. We have no control over those websites and this policy does not cover them.
Some images and reference texts come from open sources such as Wikimedia Commons, used under their licences with attribution.
13Changes to this policy
We may update this policy. Material changes will be notified on the platform and, where we can, through the channel you use. The date at the top of this page always shows the version in force.
14Contact
| Privacy and rights requests | [email protected] |
| Complaints | Grievance Officer, [email protected] |
| Post | EFLAG CORP PRIVATE LIMITED, Pritham Plaza, 18 Yellamman Koil Street, Off Kensington Road, Adj. to Gurudwara, Bangalore, Karnataka – 560008 |
| Regulator | The Data Protection Board of India, if we have not resolved your complaint |