A private platform by Sahaj Connect · not affiliated with any government body

Legal

Privacy Policy

Last updated October 2026 · Governed by the laws of India

SocietyConnect ("we", "us", "the platform"), a Sahaj Connect initiative, is committed to protecting personal data in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000. This policy explains what we collect, why we collect it, how long we keep it, and the rights you can exercise. It applies to the marketing website, society websites hosted on the platform, and all console areas.

1. Who we are and our role

For data you give us directly (your account, registrations, enquiries), Sahaj Connect is the Data Fiduciary under the DPDP Act. For data a society enters about its own members, donors, beneficiaries and staff, the society is the Data Fiduciary and we act as its Data Processor — we process that data only on the society's instructions and never for our own purposes.

2. Data we collect

Account data (name, email, phone, password hash); organization data you provide (society name, registration particulars, committee details, addresses); operational data your society enters (members, donations, finances, documents, events, communications); payment references from our payment gateway (we never store card or UPI credentials); and technical data (IP address, device and browser type, pages visited) used to secure and improve the service.

3. Purpose and lawful basis

We process personal data to provide the ERP and website services you signed up for (performance of contract), to send statutory-compliance reminders and service notices (legitimate use under the DPDP Act), to respond to enquiries you initiate, to prevent fraud and abuse, and to meet our own legal obligations. Marketing messages are sent only with consent and always carry an opt-out.

4. What we never do

We do not sell personal data. We do not show third-party advertising. We do not pool or route donation money (gifts settle directly in each society's own bank account). We do not read your society's private records except when you ask for support or the law requires it.

5. Data ownership and portability

Your data belongs to you. Societies can export members, finances, documents and reports in standard formats (CSV/PDF) at any time from the console, without needing our permission.

6. Retention and deletion

We keep personal data only as long as an account is active or as needed for the purposes above. On verified account-closure requests we delete or anonymise personal data within 90 days, except records we must retain under Indian law (e.g. financial and tax records, retained up to 8 years) and backup copies, which are purged on their normal rotation cycle within a further 35 days.

7. Security

Data is encrypted in transit (HTTPS/TLS) and protected at rest, hosted on servers located in India, guarded by role-based access control, per-tenant isolation (every record is scoped to its society), audit logging and daily backups. Access by our staff is limited to what support requires and is logged.

8. Sharing and processors

We share data only with sub-processors needed to run the service — such as hosting infrastructure, an email delivery provider, the WhatsApp Business API (Meta) for messages you trigger, and the Razorpay payment gateway for payments — each bound by contract to process data solely for us. We may disclose data when required by law or a competent authority.

9. Cookies

We use essential cookies for login and security, plus limited preference cookies. See the Cookie Policy for details and choices.

10. Children

The platform is intended for use by adults acting on behalf of organizations. Where a society records data about minors (e.g. scholarship beneficiaries), the society is responsible for obtaining verifiable parental or guardian consent as the DPDP Act requires.

11. Your rights under the DPDP Act

You have the right to access a summary of your personal data and processing activities, to correction and erasure, to grievance redressal, to nominate a person to exercise your rights in case of death or incapacity, and to withdraw consent where processing is based on consent (withdrawal does not affect prior lawful processing).

12. Breach notification

In the event of a personal data breach we will notify the Data Protection Board of India and affected users in the form and manner prescribed under the DPDP Act and its rules.

13. Grievance officer & contact

For any privacy request or concern, write to our Grievance Officer at hello@sahajconnect.in with the subject "Privacy request". We acknowledge within 72 hours and resolve within the timelines mandated by law. If unsatisfied, you may approach the Data Protection Board of India.

14. Changes to this policy

We may update this policy as the service or the law evolves. Material changes are notified by email or a console notice, and the "Last updated" date above always reflects the current version.

Questions about this document? Write to hello@sahajconnect.in. This page is provided for transparency and general information; it is not legal advice to you or your organization.

Install this app

Add it to your home screen for a fast, full-screen, app-like experience.

Tap the Share icon, then Add to Home Screen.