Last updated: Oct 06, 2026
Privacy Policy
Seeya Charitable Foundation (“we”, “us”, “the Foundation”) renovates and improves schools, hostels and playgrounds and runs skill development and women empowerment programmes. We respect your privacy and handle your personal data only as described here. In the language of the law we are the Data Fiduciary and you are the Data Principal.
1. The law we follow
We process personal data in line with India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 made under it, as amended from time to time, and with other laws that apply to us, such as tax, charity and payment laws. Where this policy and the law differ, the law prevails.
2. What we collect, why, and for how long
We collect personal data only when you give it to us (by registering, donating, writing to us, volunteering or joining our staff). At each of those points we show a short notice and ask for your consent.
| Who | Data | Why | How long |
|---|---|---|---|
| Visitors | No account needed to browse. Our servers and security provider see technical data such as your IP address and browser type while serving pages. | Deliver the site, prevent abuse and attacks. | Security and access logs: at least 12 months, then deleted. |
| Members (accounts) | Name, email, mobile number, company (optional), a password stored only as a salted one-way hash, sign-in sessions (IP address and device type), optional nominee, your PAN only if you choose to save it, and — if you choose Google sign-in — your Google name and verified email. | Create and secure your account; show your donations and receipts; pre-fill your PAN on donations if you saved it. | Until you delete your account. Sessions expire after 30 days. |
| Donors | Name, email, mobile, PAN (if you give it), amount, payment mode and payment reference, campaign chosen, and whether you agree to appear on our donor wall. | Process your donation, issue your receipt, claim and report tax benefits (80G), keep accounts, prevent fraud. | Name, PAN, amount, date and receipt number: 10 years after the end of the financial year, as tax and audit law require. Email and mobile: until you ask us to delete them. |
| People who write to us or volunteer | Name, email, mobile (optional) and your message. | Reply to you and, for volunteers, arrange your involvement. | 24 months, then deleted. |
| People shown publicly (team, gallery, donor wall) | Team members: name, role, short bio and photo. Gallery: photographs, which may show people. Donor wall: only the name you gave when you donated, and the month, and only if you ticked the box. | Tell our story and thank our supporters. | Until you ask us to take it down, or the content is retired. Team members and donors can withdraw at any time. |
| Staff | Contact details, employment details, attendance, leave, expense claims (and receipts you attach), salary slips. | Employment, payroll and legal compliance. | During employment and 10 years after you leave, then deleted. |
| Everyone who gives consent or makes a request | A record of what you agreed to and when (stored against your account, or against a one-way hash of your email if you have none), and a note that a request was handled. | Prove consent and show that we honoured your requests. | Consent records while your account exists. A record that an erasure happened (a hash only, never readable personal data) is kept as evidence. |
We do not ask for, and you should not send us, Aadhaar numbers, bank or card details, or health information. Card and UPI details are entered on our payment partner's page and never reach us.
3. Consent, and when we do not need it
Where we rely on your consent it is free, specific, informed and clear: you tick an unticked box next to a plain-language notice. You can withdraw consent at any time as easily as you gave it (see section 8). Withdrawing does not affect what we did lawfully before, and it may mean we can no longer provide the service that needed the data.
The law also allows processing without consent in limited cases. We rely on these only where they apply: you voluntarily gave us data for a specific purpose and have not objected (for example, a message you sent us); we must comply with a law, court order or tax requirement (for example, keeping donation records); and employment purposes for our staff.
4. Who we share it with
We do not sell or rent personal data, and we do not use it for advertising. We use trusted service providers (“processors”) who may handle data only on our instructions and to provide their service:
- Cloudflare — hosting, database, file storage and security for this website.
- Razorpay — takes online payments. Your card, UPI or bank details go to Razorpay and not to us.
- Brevo — sends our emails (account confirmation, password reset, receipts).
- Google Analytics — only if you accept analytics cookies. It tells us, in aggregate, which pages are visited and from roughly where, so we can improve the site. We switch off advertising features and Google signals.
- Google — only if you choose “Continue with Google”; Google tells us your name and verified email.
- An AI assistant — only if one of our administrators chooses to connect an AI agent to the admin tools. The agent can then see limited data (donor names without contact details, enquiry messages and site content) for as long as the administrator keeps it connected, and it cannot delete data or see staff, salary or privacy-request records.
We also disclose data where the law requires it (for example, to tax authorities) and to our auditors and advisers, who are bound by confidentiality.
5. Where your data is processed
Our providers run global networks, so your data may be processed outside India. We choose providers with strong security commitments, and we will not transfer data to any country that the Government of India restricts.
6. How long we keep data, and what happens when you delete
We keep personal data only as long as needed for the purpose it was collected for, or as long as a law requires. When you delete your account or withdraw consent:
- Deleted now: your account, sign-in sessions, linked Google sign-in, consent records and any messages you sent us.
- Kept for the law, with contact details removed: a donation you made is a tax and accounting record. We remove your email, mobile number and the link to your account at once, and keep only your name, PAN (if given), the amount, date and receipt number until 10 years after the end of that financial year. After that, we delete these as well.
- Staff: access is switched off when you leave; employment records are deleted 10 years later.
Security and access logs are kept for at least 12 months, as the Rules require, and then deleted. Our systems apply these retention periods automatically, and an administrator can run the clean-up on demand.
7. How we protect your data
- All traffic uses HTTPS, and our providers encrypt stored data.
- Passwords are stored only as salted one-way hashes. Sign-in and reset links are single-use and expire; session tokens are stored hashed.
- Staff see only what their role needs. Receipts you upload with expense claims are private and open only to you and authorised admins.
- Sign-in attempts and forms are rate-limited and protected against automated abuse.
- We keep an activity trail of sensitive actions, such as data exports and erasures.
No system is perfectly secure, but we work to keep risks low and to fix problems quickly.
8. Your rights, and how to use them
As a Data Principal you have the right to:
- Access a summary of your personal data and who it is shared with.
- Correct, complete or update your data.
- Erase your data (subject to the legal retention described in section 6).
- Withdraw consent at any time.
- Grievance redressal — have a complaint handled (section 12).
- Nominate another person to exercise these rights if you die or cannot.
Do it yourself, instantly: sign in and open Privacy & data to download all your data, name a nominee, or delete your account; use Profile to correct your details.
Donor wall: your name is shown only if you tick the box when you donate. Remove it any time from Donations in your account, or write to us. We will take it down within 30 days.
If you have no account (for example, you donated as a guest or wrote to us), or you prefer, use the privacy request form or write to the contact in section 13. We may ask you to confirm that you control the email address before we share or delete anything, so that nobody else can get your data.
We aim to respond within 30 days, and always within the time the law allows. There is no charge.
9. Children
This website is for people aged 18 or over, and we ask you to confirm this when you register or donate. We do not knowingly collect personal data of children (under 18) through the website, and we do not track or profile children. We publish a photograph or story of a child only with the verifiable consent of a parent or lawful guardian, and never in a way that could harm the child's well-being. If you believe a child has given us data, tell us and we will delete it.
10. Personal data breaches
If a breach affects your personal data, we will tell you without delay, in plain language, what happened, what it may mean for you, what we have done and what you can do. We will also report it to the Data Protection Board of India as the law requires.
11. Cookies
Essential cookies make the site work and need no consent: your sign-in session (up to 30 days), a short-lived Google sign-in check (10 minutes), and preferences — light/dark theme, whether the admin sidebar is open, and your cookie choice below (180 days).
With your consent only, we also use Google Analytics cookies (named _ga and _ga_*, kept up to 2 years) to count visits and see which pages are useful. Until you choose “Accept” in the cookie banner, these are not set. We do not use advertising cookies, and we turn off Google signals and ad personalisation. Choose “Decline” and nothing changes for you. You can change your mind at any time with “Cookie settings” in the page footer; declining stops new analytics data, and you can also delete cookies in your browser.
12. Complaints
If you are unhappy with how we handled your data or a request, contact our grievance contact below. We will acknowledge and resolve it within the time the law allows. If you are not satisfied with our response, you may complain to the Data Protection Board of India, after first raising it with us.
13. Contact
14. Changes to this policy
We may update this policy when our practices or the law change. The date at the top shows when it last changed. If a change affects your rights or what we do with your data, we will tell account holders by email and ask for fresh consent where the law requires it.
