1. Information We Collect
Grameen Foundation India ("we," "our," or "us") operates FPO Sehat to foster transparency, governance, and AI-assisted capacity building for Farmer Producer Organizations. To deliver accurate diagnostic benchmarks, we collect:
-
Organizational & Institutional Data: FPO registration number, legal name, date of establishment, registered address, district, state, pin code, and secondary contact personnel.
-
Operational & Financial Records: Annual turnover, net profit, paid-up share capital, total member counts, and diagnostic response rubrics across financial, operational, and market criteria.
-
Account Credentials: Official email address, salted password hashes, mobile contact numbers, and profile avatars.
-
Technical Telemetry: IP addresses, browser agent headers, login timestamps, and device operating system parameters for session defense.
2. How We Use Collected Information
We process information strictly for legitimate development, governance, and diagnostic assessment purposes:
-
Diagnostic Scoring & AI Insights: Calculating holistic organizational health indices across governance, compliance, and creditworthiness pillars.
-
Field Audit Integrity: Validating that assessment submissions and FPO onboarding workflows originate from verified physical field locations.
-
Executive & Donor Reports: Compiling benchmarked maturity matrices and customized capacity-building roadmaps for FPO leadership and partner organizations.
-
Support & Communications: Responding to help-desk tickets, transactional security alerts, and system notices.
3. Browser Geolocation & Spatial Data Policy
FPO Sehat incorporates real-time geolocation tracking to maintain audit veracity and power our ISRO Bhuvan GIS Map Engine. Here is how spatial data is handled:
navigator.geolocation). We never capture GPS telemetry without user consent or when your browser is closed.
-
Sign-In Verification: Device coordinates are verified during login to protect institutional accounts against unauthorized geographic spoofing.
-
Onboarding & Submission Geostamping: When an FPO is registered or an assessment is submitted, the latitude, longitude, and reverse-geocoded locality (e.g., District, State) are recorded as tamper-proof audit trails.
-
ISRO Bhuvan Visualization: Aggregated, role-scoped coordinates are rendered on the ISRO Bhuvan geospatial map layers so Super Admins and Partner Admins can monitor cluster coverage and field operations.
4. Data Security & Storage Controls
We implement defense-in-depth architectural safeguards to protect agricultural records against unauthorized intrusion, alteration, or interception:
-
Cryptographic Protection: User passwords are encrypted using one-way
BCRYPThashing with dynamic salt vectors. API and browser traffic is enforced over TLS 1.3 encryption. -
Tenant Scoping & Role Isolation: Partner Admins and Member accounts can only access data belonging to their licensed institutional organization (
partner_idenforcement). -
Continuous Audit Logging: Sensitive actions—including user authentication, score overrides, and profile updates—are timestamped and preserved in the tamper-evident
activity_logsaudit trail.
5. Third-Party Service Providers
We share data solely with trusted infrastructure vendors essential to platform functionality:
-
Spatial Services (ISRO Bhuvan / NRSC): WMS tile rendering to display spatial base maps. Only coordinate pairs are mapped; no private commercial financials are transmitted to mapping providers.
-
Reverse Geocoding: Open-source geospatial services (Nominatim / BigDataCloud) convert lat/long coordinates into district/city text labels without storing user identifiers.
-
Payment Gateways (Razorpay): Tokenized, PCI-DSS Level 1 payment processing for license quotas and FPO subscriptions. We never store credit/debit card numbers on our servers.
6. Your Rights & Data Ownership
In compliance with the Digital Personal Data Protection Act (DPDPA) and global best practices, registered organizations possess:
-
Right to Access & Rectify: You can review, update, or correct contact, financial, and organizational details via your administrative portal.
-
Right to Data Portability: Export diagnostic reports, maturity matrices, and audit logs to structured CSV or PDF formats at any time.
-
Right to Withdraw Consent: You may disable location permissions in your browser settings, recognizing that location-gated audit submissions will require reactivation.
7. Contact Data Protection Officer
If you have questions, grievances, or requests concerning this Privacy Policy or your institutional data rights, please contact our designated Privacy and Compliance team:
E86, Suncity, Sector 54 Chawk, Gurugram, Haryana - 122002, India
Email: privacy@grameenfoundation.in / info@grameenfoundation.in