This Privacy Policy ("Policy") describes how the BLA Sanvad mobile application and its administrative web console at bla.loksetu.com (collectively, the "Service") collect, use, store, and share information. It is published in compliance with the Digital Personal Data Protection Act, 2023 of India, the Google Play User Data policy, and the Apple App Store Review Guidelines. By using the Service you confirm that you have read this Policy.
1. Who We Are
The Service is operated for the BLA Sanvad programme. For all data protection matters you can reach our designated grievance contact at support@bla.loksetu.com.
2. Information We Collect
We only collect information that is necessary to operate the Service. The categories below describe everything the app can transmit to our servers.
a. Information you provide as an enumerator
- Full name and (optionally) email address.
- Mobile number (used for OTP-based sign-in).
- Profile photograph (optional).
- Assigned geography — district, taluka, Lok Sabha, and Vidhan Sabha constituency — selected during registration.
- Team / organisation / booth number, when applicable.
b. Information collected while you conduct a survey
- The survey responses you record on behalf of the respondent, including demographic, economic, and political opinion answers required by the active survey definition.
- The respondent's consent flag and, where the respondent has consented, their name, mobile number, voter ID, and an optional photograph.
- GPS coordinates of the location where the survey is recorded, used to verify field coverage.
- Device-side timestamps for draft creation, save, and submit events.
c. Information collected automatically
- Authentication tokens stored locally on your device so you remain signed in between sessions.
- Offline draft payloads queued on your device when there is no network, until they successfully upload to the server.
- Basic technical logs on the server (request timestamps, status codes, anonymised IP, role) used for security and abuse monitoring.
We do not collect contact lists, SMS content, calendar data, microphone audio, advertising identifiers, or precise background location.
3. Why We Collect This Information
- To run the survey programme — collect, store, and aggregate respondent data for analysis and reporting.
- To authenticate you — verify your mobile number via one-time password (OTP) and maintain a signed-in session.
- To assign and audit fieldwork — link drafts and submissions to enumerators and their assigned geography so we can measure coverage and resolve duplicates.
- To improve quality — use GPS coordinates and timestamps to validate that surveys were conducted in the assigned area.
- To comply with law — respond to legitimate legal requests and meet our statutory obligations.
4. Permissions Used on Your Device
- Camera — only when you tap "Take photo" for the optional respondent or profile picture.
- Photo library — only when you tap "Choose from gallery" to attach a picture.
- Location (while in use) — only triggered when you press "Capture GPS" on a survey, and not used in the background.
- Storage — to keep offline drafts and queued photos on your device until they are uploaded.
You can revoke any permission at any time from your device settings. The corresponding feature will simply be unavailable until you grant the permission again.
5. How We Share Information
We do not sell or rent your personal information. Information is accessed only by:
- Authorised programme staff who require it to administer the survey programme.
- Service providers that host our infrastructure (cloud servers, managed databases, object storage). These providers process data on our behalf under contractual confidentiality and security obligations.
- Law-enforcement or regulators, only where we are legally compelled to do so.
Aggregated, de-identified statistics derived from survey responses may be shared with stakeholders for reporting purposes. These aggregates do not identify any individual respondent.
6. Data Storage and Security
All personal data is stored on servers located in India. Network traffic between the app and the server is encrypted in transit (HTTPS / TLS). Passwords are never stored in plain text. Profile and respondent photographs are stored in a private object-storage bucket and accessed only via short-lived, signed URLs.
Despite our safeguards, no system is perfectly secure. If we become aware of a personal-data breach that materially affects you, we will notify the relevant authority and, where required by law, the affected users.
7. Data Retention
- Account data — kept for as long as your account is active. After deactivation we retain the row in inactive state for audit, but you can no longer sign in.
- Survey responses and respondent contact details — retained for the duration of the BLA Sanvad programme and for any additional period required by law for audit and reporting.
- Profile and respondent photos — retained alongside the related survey row; removed when the row is deleted.
- Authentication tokens on your device — cleared when you sign out, deactivate your account, or uninstall the app.
8. Your Rights
You have the right to:
- Access the personal information we hold about you and request a correction if it is inaccurate.
- Deactivate your account from the Profile → Settings → Deactivate option in the mobile app.
- Request deletion of your personal information beyond the legal retention window by writing to the contact below. We will respond within a reasonable timeframe and confirm what we are able to delete without breaching audit obligations.
- Withdraw any consent you previously gave.
- Lodge a complaint with the Data Protection Board of India or any other competent authority.
9. Children
The Service is not directed to children below 18. We do not knowingly collect personal data from children. If you believe a minor has provided information to us, please contact us so we can remove it.
10. Third-Party Links
The Service may link to third-party websites such as the Apple App Store, Google Play, or the BLA Sanvad programme website. We are not responsible for the privacy practices of those sites; please review their own privacy notices.
11. Changes to This Policy
We may update this Policy from time to time. We will revise the "Last updated" date at the top of this page when changes take effect and, where required, notify you in the app. Continued use of the Service after a change indicates acceptance of the revised Policy.
12. Grievance Officer
In accordance with the Information Technology Act, 2000 and the rules made thereunder, the grievance officer for this Service can be contacted at:
BLA Sanvad — Grievance Officer
Email: support@bla.loksetu.com
We endeavour to acknowledge grievances within seven (7) working days and resolve them within thirty (30) days of receipt.