Legal

Privacy Policy

How KARDIA collects, uses and protects the information you share with us.

Last updated 02 Sep 2026

This policy explains what KARDIA collects, why, how long it is kept and what choices you have. It is written for a demonstration prototype and would require legal review before any live public deployment.

Information we collect

  • Complaint details - the sector, issue type and description you submit.
  • Photographs - only images you choose to upload with a complaint.
  • Location - only if you allow it. You may permit browser geolocation, place a pin on the map yourself, type an address, or submit no location at all.
  • Contact details - name, phone and email are entirely optional, and are used only to follow up on your complaint.
  • Technical data - the IP address of the submitting device is recorded to deter abuse of the complaint form.
  • Administrative accounts - for municipal staff, the name, official email, department, role and sign-in activity.

How we use it

Complaint information is used to route your report to the correct department, to resolve it, and to report on resolution performance in aggregate. Operational data across the portals is used to run and report on city services. We do not sell personal information, and we do not use it for advertising.

Data minimisation

We ask for the minimum needed to act on a report. Contact details are optional. Location is optional. If you provide nothing beyond the issue itself, your complaint is still accepted and tracked.

How it is protected

  • Passwords are stored only as one-way hashes, never as recoverable text.
  • Database access uses prepared statements throughout.
  • Administrative access is role-based, enforced on the server, and recorded in an audit trail.
  • Uploaded photographs are stored outside the executable web directory, renamed on receipt, validated as genuine images, and served only through a controlled handler.
  • Sessions use HttpOnly cookies, rotate periodically and expire after inactivity.

Retention

Complaint records and their attachments are retained while the complaint is open and for a defined period after closure for audit purposes. Sign-in attempt records are retained only as long as needed for throttling and security review.

Your choices

You can submit a complaint without any personal information. You can decline the location permission - the browser will not ask again for that site unless you reset it. To request information about, or deletion of, a complaint you submitted, contact the Citizen Grievance Cell with your complaint reference number.

Cookies

KARDIA sets one essential cookie to maintain your session and protect forms against cross-site request forgery. There are no advertising or third-party tracking cookies.

Third-party services

Map tiles are served by OpenStreetMap, which will receive the requests needed to render the map. Web fonts are served by Google Fonts. No personal information is sent to either.

Compliance note

This prototype is designed with the principles of India's Digital Personal Data Protection framework in mind - purpose limitation, data minimisation, role-based access and auditability. No certification or formal compliance assessment has been carried out for this build, and none is claimed.

Questions about this page? Contact the command centre at contact@kardia.gov.in.