IT Act 2000 & SPDI Compliant
PCI-DSS Reference Ready
GDPR Context Architecture
Welcome to the Saugat Community Welfare Society (SCWS). We are fully committed to protecting your privacy and securing your personal data. This Privacy Policy explains how we collect, process, secure, and utilize your data when you interact with our web portal, APIs, registration forms, and manual entry systems.
1. Information We Collect
To ensure seamless onboarding, donation cycles, and robust account management on our portal, we collect data across three primary categories:
- Personal Identification Data: Your Full Name, Email Address, Verified Mobile Number, and your securely encrypted password (stored under the standard `PASSWORD_DEFAULT` cryptographic hash).
- Localized Geographic Data (Location APIs Context): Using our dynamic cascading lookup system during registration, we log your Country, State, District, Block, and Village/Area. This data is essential for tracking localized welfare schemes and community projects.
- Financial Transactions Log Data: When you submit a payment or donation via online interfaces or manual entries (QR Code, UPI, CASH, NEFT, Cheque, DD), we securely store the transaction status, timestamp, amount, unique tracking IDs, administrative manual notes, and any optionally attached file proofs within our secure database records.
2. API Integrations and Third-Party Data Processing
To ensure dynamic operations and unparalleled security, our system utilizes proprietary and standard Third-Party APIs:
- Google reCAPTCHA v3 API: To prevent spam, automated bots, and brute force access on registration and security-sensitive pages, we verify reCAPTCHA v3 tokens. Action is blocked if the background security score falls below acceptable parameters.
- Dynamic QR Server API Generator: For instantaneous payments at Point-of-Sale (POS) counters and donation subscriptions, we utilize external dynamic secure QR generation endpoints. Your real-time amount and transaction identifier string are forwarded in encrypted mode without exposing any dynamic banking metadata.
- PHPMailer (SMTP Engine): To securely dispatch automated receipts, confirmation notices, and billing alerts, our SMTP framework handles user data paired with encryption protocols (Port 465, SMTPS Secure SSL).
3. Data Security, Concurrent Session Control, and Data Locking
We implement robust application-level layers to maintain the integrity of financial systems and personal records:
Double-Entry & Concurrency Prevention: Whenever an admin generates a manual log or a user confirms a payment, the system runs an atomic condition verification query before executing the direct database state. If a record's status changes during the execution state, an automatic backend lock aborts the process, completely preventing double-entry fraud and financial collision risks.
Role-Based Access Governance: All administrative routes are protected by strict backend guard layers. Subscriptions, reports, and user search variables can only be accessed by personnel holding explicit authentication and approved database authorization rules.
4. Compliances and Legal Frameworks
Legal Disclosures (IT Act 2000 & Global Standards):
- Information Technology Act, 2000 (Section 43A): We comply with Reasonable Security Practices and Procedures (RSPP) rules and ensure strict protection of Sensitive Personal Data and Information (SPDI Rules 2011).
- Financial Logging Compliance: The SCWS portal never stores your core banking credentials, active passwords, card PINs, or direct raw banking tokens. We solely maintain public-facing reference hashes and operational status variables.
- Data Retention: Records required for active donation subscriptions or user tax audits are stored as long as the entity remains active. Archived data is isolated using system-level soft-delete patterns rather than destructive hard-deletes.
5. Cookies and Session Tracking Management
Our server-side code executes native PHP sessions and standard secure browser cookies to maintain operational state architecture. Cookies are utilized to verify login states, inject cross-site request forgery (CSRF) protection, and optimize smart user queries. You can deactivate cookies from your browser settings; however, doing so may affect the advanced operational functionality of the portal.
6. Your Rights and Operational Control
- You have the right to access, check, and update your profile data simply by logging into your user dashboard.
- If you experience missing data while selecting your geographic location during registration, you can instantly utilize the integrated WhatsApp Support Button to receive direct assistance from our team.
- You reserve the right to contact our designated data protection officer at any time to raise data rectification or modification requests.
7. Contact the Compliance Team
If you have any inquiries regarding this Privacy Policy, our data management practices, API limits, or the portal's security framework, please reach out to our official legal handling desk:
Email: support@saugatcwsociety.com
Saugat Community Welfare Society (SCWS Legal Desk)