1. Who We Are
Infopace Management Pvt. Ltd. operates CSRTool.in and is the Data Fiduciary for personal data processed through the Platform under the Digital Personal Data Protection Act, 2023.
2. What We Collect
- Account data: name, email address, phone number, designation, and password (stored only in encrypted, hashed form).
- Organisation data: organisation name and type, PAN, registration numbers, address, CSR budget, focus sectors and states, and payment references such as UTR numbers.
- Documents: registration and compliance certificates (such as 12A, 80G, CSR-1, NGO Darpan), proposals, MoUs, reports, and milestone evidence.
- Field data: photos and GPS location submitted by NGO field users through the Field Data app.
- Usage and security data: login times, IP address, device and browser information, and activity logs recording who did what and when.
3. Why We Use It
- To create and manage accounts and verify organisations;
- To match companies with NGOs, including AI-assisted matching;
- To enable proposals, MoUs, milestones, disbursement tracking, audits, and reports;
- To send transactional emails and in-app notifications;
- To keep the Platform secure, prevent fraud, and maintain audit records;
- To comply with legal obligations.
We do not sell personal data and do not use it for third-party advertising.
4. Consent
We process your personal data based on the consent you give at signup, and for other lawful purposes permitted under applicable law. You may withdraw consent at any time by contacting us; this may mean we can no longer provide the service to you. Withdrawal does not affect processing carried out before it.
5. Who We Share It With
- Other users, only as needed for workflows you take part in (for example, your NGO profile and compliance documents with companies evaluating or funding you, and project data with your partner organisation and assigned auditor).
- Service providers that host or process data on our behalf, including database hosting, application hosting, email delivery, and AI processing providers. Some of these providers may process data outside India.
- Government or regulatory authorities where required by law.
6. How Long We Keep It
We keep personal data while your account is active and for as long as needed for the purposes above or as required by law. For example: in-app notifications are deleted after 30 days; unverified signups are deleted after 7 days; project, financial, and audit records are kept for as long as required under applicable law. Data no longer needed is deleted or anonymised.
7. Security
We use encrypted connections (HTTPS), hashed passwords, role-based access, separation of each organisation's data, login attempt limits, and activity logs. No system is completely secure; if a personal data breach occurs, we will notify affected users and authorities as required by law.
8. Your Rights
Under the Digital Personal Data Protection Act, 2023, you may:
- request a summary of your personal data we process;
- request correction, completion, or updating of your data;
- request erasure of your data, subject to legal retention requirements;
- raise a grievance with us;
- nominate another person to exercise your rights in case of death or incapacity.
Contact our Grievance Officer below. If your grievance is not resolved, you may approach the Data Protection Board of India.
9. Children
The Platform is not intended for anyone under 18, and we do not knowingly collect their personal data as users.
10. Cookies and Local Storage
We use only essential cookies and browser storage needed to keep you logged in and remember your preferences.
11. Changes to This Policy
We may update this Policy and will notify registered users of material changes.
12. Grievance Officer
Name: [GRIEVANCE OFFICER NAME]
Designation: [DESIGNATION]
Email: support@infopaceindia.com