Manifesto for a Clear Indian Political System
|
Macipolisys

Privacy Policy

1. Preamble:

1.1 Welcome to the MACIPOLISYS mobile application ("App"), operated by MACIPOLISYS ("we", "our", or "us"). We are committed to protecting your privacy and handling your personal information responsibly.

1.2 This Privacy Policy ("Policy") sets out the manner in which the Party collects, receives, stores, processes, discloses, transfers, deals with and otherwise handles Personal Data and Sensitive Personal Data or Information of natural persons who download, install, register on, access or otherwise use the App (each, a "User" or "you").

1.3 This Policy is published in compliance with, and is to be read consistently with:

1.3.1 the Information Technology Act, 2000 ("IT Act") and the rules framed thereunder, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules");

1.3.2 the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021;

1.3.3 the Digital Personal Data Protection Act, 2023 ("DPDP Act"), and the rules framed thereunder, to the extent notified and in force;

1.3.4 the Representation of the People Act, 1651, the Conduct of Elections Rules, 1661, and the directions, model code of conduct and guidelines issued from time to time by the Election Commission of India ("ECI"); and

1.3.5 all other applicable laws of India (collectively, "Applicable Law").

1.4 By downloading, installing, accessing, registering on or using the App, you signify your free, specific, informed, unconditional and unambiguous consent to the collection, processing, use, storage, transfer and disclosure of your Personal Data in accordance with this Policy and the Terms of Use of the App. If you do not agree to any part of this Policy, you must not access or continue to use the App.

1.5 For the purposes of this Policy, the Party acts as the "Data Fiduciary" within the meaning of Section 2(i) of the DPDP Act, and the User is the "Data Principal" within the meaning of Section 2(j) thereof.

2. Definitions:

2.1 "Personal Data" means any data about an individual who is identifiable by or in relation to such data.

2.2 "Sensitive Personal Data or Information" or "SPDI" shall have the meaning ascribed to it under Rule 3 of the SPDI Rules.

2.3 "Processing" means the whole or any part of an automated operation or set of operations performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination, restriction, erasure or destruction.

2.4 "Data Principal Rights" means the rights available to a Data Principal under Chapter III of the DPDP Act.

2.5 "Child" means an individual who has not completed the age of eighteen (15) years.

2.6 Capitalized terms not defined herein shall have the meaning ascribed to them under Applicable Law.

3. Scope and Applicability:

3.1 This Policy applies exclusively to Personal Data collected through the App, including any of its features, forms, in-app surveys, chat/messaging modules, event registrations, volunteer enrolment modules and membership modules.

3.2 This Policy does not apply to:

3.2.1 any third-party website, application, platform, plug-in or service that may be accessed through hyperlinks or integrations available on the App; or

3.2.2 information collected by the Party through offline channels, physical membership forms or the Party's official website, save to the extent such information is subsequently linked to your App account.

3.3 The Party is not responsible for the privacy practices of any third party, and you are advised to review the privacy policies of such third parties independently.

4. Categories of Personal Data Collected:

4.1 Information provided by you directly. In the course of registration and use of the App, the Party may collect the following categories of Personal Data:

4.1.1 Identity and contact information: full name, date of birth, gender, photograph, residential address, PIN code, mobile number, email address;

4.1.2 Electoral information: Elector Photo Identity Card (EPIC) number, Assembly Constituency, Parliamentary Constituency, polling booth number, part number and serial number in the electoral roll — collected solely to the extent voluntarily furnished by you;

4.1.3 Membership and affiliation data: primary membership number, unit/Mandal/booth affiliation, designation (if any), date of joining and status of membership;

4.1.4 Volunteer/karyakarta data: skills, interests, availability, preferred areas of engagement, and campaign role;

4.1.5 User-generated content: feedback, grievances, survey responses, opinions, comments, photographs, audio and video submissions uploaded on the App;

4.1.6 Communication data: records of correspondence, in-app chat, requests, complaints and support tickets.

4.2 Information collected automatically. When you use the App, we may automatically collect:

4.2.1 device information (device model, operating system, unique device identifiers, mobile network information);

4.2.2 log data (IP address, access timestamps, App version, crash reports, diagnostic data);

4.2.3 usage data (features accessed, screens viewed, time spent, click-stream data); and

4.2.4 approximate or precise location data, only where you have expressly granted location permission through your device settings.

4.3 Information from third parties. With your consent, we may receive limited information from:

4.3.1 authentication providers (where you sign in using a third-party login);

4.3.2 publicly available electoral rolls published by the ECI.

4.4 Sensitive categories. The App does not knowingly collect information regarding your caste, religion, community, political ideology, financial information (beyond donation-related fields), health, biometric or genetic data, unless the same is (i) voluntarily provided by you, (ii) with your explicit consent, and (iii) strictly necessary for a lawful purpose disclosed at the point of collection.

5. Purposes of Processing:

5.1 Personal Data collected through the App shall be processed only for the following specific and lawful purposes:

5.1.1 to create, authenticate and administer your user account and Party membership;

5.1.2 to communicate Party news, campaigns, programmes, manifestos, event invitations, and calls to action;

5.1.3 to enable your participation in surveys, opinion polls, feedback drives and consultative exercises conducted by the Party;

5.1.4 to organize, coordinate and manage volunteering, booth-level activities and karyakarta deployment;

5.1.5 to receive, acknowledge, record, redress and follow up on grievances and public representations;

5.1.6 to comply with directions, orders and requirements of the ECI, statutory authorities, and courts;

5.1.7 to detect, prevent, investigate and address fraud, impersonation, unauthorized access, security incidents and violations of the Terms of Use;

5.1.8 to conduct internal analytics, improve the functionality, reliability and user experience of the App; and

5.1.9 to fulfil any other purpose disclosed to you at the time of collection, for which your consent has been obtained.

5.2 The Party shall not process your Personal Data for any purpose that is materially different from, or incompatible with, the purposes set out above without obtaining your fresh consent.

6. Legal Basis for Processing:

6.1 The Party processes your Personal Data on one or more of the following lawful bases:

6.1.1 your consent provided at the time of registration and at subsequent granular permission prompts (in accordance with Section 6 of the DPDP Act);

6.1.2 for certain legitimate uses as recognized under Section 7 of the DPDP Act, including compliance with any judgment, decree, order or direction under Applicable Law, and for responding to a medical emergency involving a threat to life or immediate threat to health; and

6.1.3 to discharge any obligation under Applicable Law.

6.2 Your consent may be withdrawn at any time in accordance with Clause 11 below, without prejudice to the lawfulness of Processing carried out prior to such withdrawal.

7. Disclosure and Sharing of Personal Data:

7.1 The Party shall not sell, rent, trade or commercially exploit your Personal Data.

7.2 Your Personal Data may be shared, on a need-to-know basis and subject to appropriate confidentiality and security safeguards, with:

7.2.1 office-bearers, functionaries and authorized karyakartas of the Party at the national, state, district, Mandal and booth levels, strictly for the purposes set out in Clause 5;

7.2.2 service providers and data processors engaged by the Party for hosting, cloud storage, analytics, communication (SMS/email/WhatsApp), payment processing, customer support and IT security, each of whom is bound by written contractual obligations of confidentiality and data protection consistent with this Policy and Applicable Law;

7.2.3 statutory and regulatory authorities, including the ECI, the Central Board of Direct Taxes, the Ministry of Corporate Affairs, law-enforcement agencies, courts, tribunals, or any other governmental authority, where such disclosure is required under Applicable Law or pursuant to a lawful order; and

7.2.4 professional advisors such as legal counsel, auditors and consultants, subject to appropriate confidentiality obligations.

7.3 The Party shall not disclose Sensitive Personal Data or Information to any third party without your prior consent, save where such disclosure is necessary for compliance with a legal obligation or is made to any government agency mandated under law.

8. Cross-Border Transfer:

8.1 Where any Personal Data is stored on cloud infrastructure or processed by service providers located outside India, such transfer shall be undertaken:

8.1.1 in accordance with Section 16 of the DPDP Act and any restrictions notified by the Central Government;

8.1.2 subject to contractual safeguards ensuring a standard of protection at least equivalent to that under Applicable Law; and

8.1.3 only to the extent necessary for the purposes set out in Clause 5.

9. Data Retention:

9.1 The Party shall retain Personal Data only for so long as is necessary to fulfil the purposes for which it was collected, or as required to comply with Applicable Law.

9.2 By way of indicative retention periods:

9.2.1 Account and membership data — for the duration of your active membership and up to 10 years thereafter;

9.2.3 Grievance and communication records — for 12 months from the date of closure of the grievance;

9.2.4 Log and diagnostic data — for 12 months from the date of collection; and

9.2.5 Data of users who withdraw consent or delete their account — shall be erased in accordance with Clause 11.5, subject to overriding legal retention obligations.

9.3 Upon expiry of the applicable retention period, Personal Data shall be securely deleted, anonymized or destroyed.

10. Security Safeguards:

10.1 The Party has implemented reasonable security practices and procedures commensurate with the nature of the Personal Data collected, in accordance with Rule 8 of the SPDI Rules and Section 8(5) of the DPDP Act, including:

10.1.1 encryption of data in transit (TLS/SSL) and at rest, as appropriate;

10.1.2 access controls, role-based access management and multi-factor authentication for administrative access;

10.1.3 periodic vulnerability assessments and penetration testing;

10.1.4 secure software development practices and periodic code review;

10.1.5 written information security policies and staff training; and

10.1.6 incident response and business continuity procedures.

10.2 Notwithstanding the foregoing, no system of electronic transmission or storage can be guaranteed to be entirely secure, and the User acknowledges that any transmission of Personal Data is undertaken at the User's own risk to the extent permitted by Applicable Law.

10.3 In the event of any Personal Data breach, the Party shall notify the Data Protection Board of India and each affected Data Principal in the manner and within the timelines prescribed under the DPDP Act and the rules thereunder.

11. Rights of the Data Principal:

11.1 Subject to Applicable Law, you are entitled to exercise the following rights in respect of your Personal Data:

11.1.1 Right to access — to obtain a summary of the Personal Data being processed and the processing activities undertaken by the Party;

11.1.2 Right to correction and erasure — to seek correction of inaccurate or misleading data, completion of incomplete data, updating of data, and erasure of data that is no longer necessary for the purpose for which it was processed;

11.1.3 Right to grievance redressal — as set out in Clause 14 below;

11.1.4 Right to nominate — to nominate any other individual who shall, in the event of your death or incapacity, exercise these rights on your behalf; and

11.1.5 Right to withdraw consent — to withdraw your consent to Processing at any time, with such ease as that with which consent was given.

11.2 Requests to exercise the above rights may be submitted through the "Manage My Data" section within the App, or by writing to the Data Protection Officer at the contact details set out in Clause 15.

11.3 The Party shall respond to such requests within the timelines prescribed under Applicable Law, and in any event without undue delay.

11.4 The Party may seek reasonable verification of identity before acting on any request, in order to prevent unauthorized access.

11.5 Upon withdrawal of consent or a valid erasure request, the Party shall cease Processing your Personal Data and shall cause its data processors to do the same, save where retention is required under Applicable Law.

12. Children's Data:

12.1 The App is not intended for use by, and the Party does not knowingly collect Personal Data from, any Child.

12.2 Where the App is used by a Child, or by a person with disability who has a lawful guardian, Processing shall be undertaken only after obtaining verifiable consent of the parent or lawful guardian in accordance with Section 9 of the DPDP Act.

12.3 The Party shall not undertake tracking, behavioral monitoring or targeted advertising directed at Children, nor shall it undertake any Processing that is likely to cause any detrimental effect on the well-being of a Child.

13. Cookies, SDKs and Similar Technologies:

13.1 The App may use cookies, software development kits (SDKs), pixels and similar technologies to authenticate sessions, remember preferences, measure usage and improve performance.

13.2 You may control such technologies through your device settings; however, disabling certain technologies may impair the functionality of the App.

14. Compliance with Election Laws:

14.1 The Party affirms that its communications through the App shall abide by:

14.1.1 the Model Code of Conduct issued by the ECI, during any period when the same is in operation;

14.1.2 restrictions on political messaging during the "silence period" of forty-eight (48) hours prior to the conclusion of polling, in terms of Section 126 of the Representation of the People Act, 1651; and

14.1.3 all directions issued by the ECI regarding pre-certification of political advertisements on electronic media, where applicable.

14.2 The App shall not be used to send bulk unsolicited political communications in contravention of any regulations issued by the Telecom Regulatory Authority of India, including the Telecom Commercial Communications Customer Preference Regulations, 2015.

15. Third-Party Links and Integrations:

15.1 The App may contain links to, or integrations with, third-party websites, applications or services. The Party does not endorse and is not responsible for the content, privacy practices or policies of such third parties.

15.2 Users are encouraged to review the privacy policies of such third parties before providing any Personal Data thereto.

16. Changes to this Policy:

16.1 The Party reserves the right to amend, modify or update this Policy from time to time to reflect changes in Applicable Law, technology or Party practices.

16.2 The revised Policy shall be posted on the App with an updated "Last Updated" date, and where the changes are material, notice shall be provided through the App and/or by email or SMS to the registered contact details of the User.

16.3 Continued use of the App after the effective date of any revised Policy shall constitute acceptance of such revisions.

17. Governing Law and Jurisdiction:

17.1 This Policy shall be governed by and construed in accordance with the laws of India.

17.2 Subject to the statutory grievance redressal mechanism under the DPDP Act and other Applicable Law, the courts and tribunals at Bengaluru, Karnataka, India shall have exclusive jurisdiction over all matters arising out of or in connection with this Policy.