Legal
Privacy Policy
Last updated: 16 July 2026
Plain summary
- The public Data scorecard shows rates and government delivery — not a public list of villagers’ names.
- If you create an account or send a form, we store what you submit to run the village platform.
- You can ask to access, correct, or delete account data using the contact path below.
1. Who we are
This website (“Sunaray Gaon”, “Lamahatta OS”, “the platform”) is operated for the community of Sunaray / Seemana Gaon, Lamahatta, Darjeeling district, West Bengal, India, and related Samaj / village operating purposes. For privacy requests, use the contact options on Partners / service enquiry forms, or the email channel used for official village correspondence by the platform operator.
This notice is written for transparency and good practice under Indian data-protection expectations (including the spirit of the Digital Personal Data Protection Act, 2023). It is not a substitute for formal legal advice.
2. What data we process
2.1 Public, non-identifying content
Aggregate statistics (for example household counts, literacy rates, occupation groups, age bands), official Local Government Directory codes (e.g. Gram Panchayat LGD code), public governance scorecards, and RTI metadata (subject, office, dates, question titles, status). These are intended not to identify a specific private individual on the public page.
2.2 Account data (if you register)
Name, phone number and/or email, password (stored by our auth provider as secure credentials, not as plain text readable by staff), role (villager/admin), preferred language, and optional link to a household record after admin verification.
2.3 Household registry (members / admin)
After login, authorised users may see household directory fields managed by the Samaj (for example head of household, occupation, family size, skills, notes). This is not published on the public Data scorecard. Access is restricted by authentication and role-based rules.
2.4 Forms and enquiries
Service requests, partner enquiries, and similar forms may collect name, organisation, phone, email, and message content so we can respond.
2.5 Community posts (Hub)
If you post in the community hub, the content you submit (and your account identity as shown) may be visible to other logged-in users according to product settings.
2.6 Technical data
Standard server and security logs (IP address, browser type, timestamps), session cookies required to keep you signed in, and hosting telemetry from our infrastructure providers.
3. Why we use data
- Operate a village information and opportunity platform
- Authenticate members and administer household records
- Respond to service, partner, and support requests
- Publish aggregate civic metrics and government-delivery scorecards
- Track public RTI process metadata (not unredacted third-party personal files by default)
- Secure the service and prevent abuse
4. Legal bases (plain language)
We process personal data because you ask us to (account, forms), because it is needed to run the service you use, for legitimate community-administration interests balanced against your rights, and where required by law. Where consent is the right basis, you may withdraw it for future processing by contacting us, subject to legal retention needs.
5. Children and household survey data
Community surveys may include age bands that cover minors. On the public website we only show aggregated age and education statistics. We do not intentionally publish minors’ names on public pages. Guardians who believe a child’s personal data appears publicly should contact us for urgent removal.
6. Sharing
We do not sell personal data. We share data only with:
- Infrastructure processors that host the app and database (for example Vercel for the website; Supabase for authentication and data) under their terms and security controls
- Village administrators who need enquiry or household data to respond or govern the registry
- Authorities when required by applicable law
Servers may be located outside India depending on provider configuration. By using the service you understand that processing may involve cross-border transfers subject to provider safeguards.
7. Retention
- Account data: while the account is active, then deleted or anonymised within a reasonable period after deletion request
- Enquiry forms: as long as needed to respond and keep minimal operational records
- Security logs: short rolling windows unless investigating abuse
- Public aggregates and governance records: kept as part of the living village record
8. Security
We use industry-standard hosting, encrypted transport (HTTPS), authentication sessions, and database access controls (including role-based rules where configured). No method of transmission or storage is perfectly secure. Phone-based signup may not use OTP verification; choose a strong unique password.
9. Your rights
Subject to law, you may request access, correction, or deletion of personal data we hold about you, or withdraw consent where processing is consent-based. We may need to verify identity and may retain data where law requires. Contact us via the platform enquiry channels. We aim to respond within a reasonable time.
10. Cookies
Essential cookies keep you signed in and secure the session. We do not currently use third-party advertising cookies. If analytics cookies are added later, this policy will be updated.
11. RTI and governance pages
Pages that track Right to Information applications publish process metadata for transparency. Full application PDFs and government replies are not automatically published; if published later, they should be reviewed so third-party personal data is redacted where appropriate.
12. Changes
We may update this policy. The “Last updated” date will change. Continued use after updates means you accept the revised notice for future processing.