Differences

This shows you the differences between two versions of the page.


privacy-policy [2026/07/22 17:44] (current) – created - external edit 127.0.0.1
Line 1: Line 1:
 +{{htmlmetatags>metatag-keywords=(rti wiki privacy policy, privacy policy india, dpdp compliance, rti wiki data, cookie policy)
 +metatag-description=(RTI Wiki privacy policy: what data we collect, how we use it, how long we keep it, your rights under DPDP Act 2023, contact for data requests.)}}
 +
 +====== Privacy Policy — RTI Wiki — RTI Wiki Citizen Guide 2026 ======
 +
 +
 +
 +{{ :social:auto:privacy-policy.png?direct&1200 |Privacy Policy — RTI Wiki — RTI Wiki Citizen Guide 2026 — RTI Wiki}}
 +
 +<WRAP center round info 95%>
 +**Quick Reply:** RTI Wiki privacy policy: what data we collect, how we use it, how long we keep it, your rights under DPDP Act 2023, contact for data requests.
 +</WRAP>
 +
 +<WRAP info>**Plain-English summary.** We collect the minimum necessary data to run the site and our app. We do **not** sell your data. We do **not** share your RTI drafts or filing records with anyone other than the AI provider that processes your tool input. You can **delete your account and all your data at any time** at [[https://righttoinformation.wiki/delete-account|righttoinformation.wiki/delete-account]].</WRAP>
 +
 +===== 1. Who is the Data Fiduciary =====
 +RTI Wiki (operating entity: Bighelpers Software and Solutions Pvt. Ltd., bighelpers.in) is the **Data Fiduciary** under the Digital Personal Data Protection Act, 2023.
 +Contact for data requests: **[email protected]**
 +
 +===== 2. What we collect =====
 +
 +**Category A — when you visit the site**:
 +  * Standard server logs (IP, timestamp, browser, page requested)
 +  * Cookies for session, preference and (where consented) advertising
 +  * Anonymised analytics (page views, session duration)
 +
 +**Category B — when you create an account**:
 +  * Username, email, name (optional), password (hashed bcrypt)
 +  * Articles you bookmark / save (My Learnings)
 +  * Forum posts, comments, Q&A you author
 +  * One account-onboarding email record (email, name, username, queued/sent status) so we can send your registration reference email after account creation
 +
 +**Category C — when you use AI tools (Drafter, AwaazRTI, etc.)**:
 +  * The problem description / voice input you provide
 +  * Your generated draft (saved only if you choose "Save to My Learnings")
 +  * Tool usage statistics (anonymous)
 +
 +**Category D — when you subscribe to newsletter or push notifications**:
 +  * Email (newsletter) or push subscription endpoint (browser- or device-managed)
 +  * Topic preferences (interest category — e.g. cyber safety, RTI, schemes)
 +  * Consent timestamp (the date and time you ticked the opt-in box)
 +
 +**Category E — when you download a free citizen-action checklist**:
 +  * Your username and email (already on file from your account)
 +  * The slug of the resource downloaded, an SHA-256 hash of your IP, and the timestamp — used only to show your personal download history on **/account**, to surface popular resources, and for abuse prevention. We do **not** store the contents of the checklist or anything you write into it.
 +
 +**Category F — when you use the CPD academy (courses, quizzes, PIO training)**:
 +  * Course enrolments, module and quiz progress, scores and simulator submissions
 +  * Your CPD / PIO **certificate record** and the holder name printed on the certificate
 +  * These are tied to your account and shown to you under **/account** and the CPD dashboard.
 +
 +**Category G — when you use our Android / iOS app**:
 +  * The app shares your website account and adds mobile advertising via **Google AdMob** (which may read your device advertising ID) and, if you opt in, a push-notification token. Full details are in the [[:privacy-policy-app|App Privacy Policy]].
 +
 +We do **not** collect: payment data (we have no paywall); precise geolocation; biometric data; sensitive personal data per DPDP Act §2(36) without explicit opt-in.
 +
 +===== 3. How we use it =====
 +
 +  - **Service operation** — server logs to debug, prevent abuse, secure the site
 +  - **Personalisation** — remember your preferences (language, ads, notifications)
 +  - **AI tool processing** — your problem text is sent to the AI provider (Anthropic / Groq / OpenAI) to generate your draft; processing is real-time, not stored on AI provider beyond their default retention
 +  - **CPD academy** — record your course progress and scores, and issue your completion certificate
 +  - **Communication** — one account-onboarding email after registration; //Citizen Alert Weekly// newsletter and push notifications only if you opted in. The newsletter checkbox is **unchecked by default**. Each newsletter email carries a one-click unsubscribe.
 +  - **Free downloads** — we use your account email and the download timestamp only to show your personal download history and to surface popular resources. The checklist files themselves are static content; we do not personalise them.
 +  - **Statistics** — aggregate page-view counts, tool-usage counts (no individual tracking)
 +
 +We do **not** use your data for: cross-site tracking, profiling for advertising-buyer purposes, sale to third parties.
 +
 +===== 4. Cookies =====
 +
 +We use the following cookie types:
 +
 +| Type | Purpose | Duration |
 +| Strictly necessary | Session, login, CSRF | Session / 30 days |
 +| Functional | Language, theme, ad preference | 12 months |
 +| Analytics | Anonymised page-view counting | 24 months |
 +| Advertising (Google AdSense) | Ad personalisation (when not opted out) | Up to 24 months |
 +
 +You can decline non-essential cookies via the consent banner shown on first visit.
 +
 +===== 5. Third-party services we use =====
 +
 +  * **Google AdSense** — for ads on the website (logged-in members see fewer)
 +  * **Google AdMob** — for ads in our mobile app (reads the device advertising ID; see the [[:privacy-policy-app|App Privacy Policy]])
 +  * **Google Analytics** — anonymised, aggregate usage measurement
 +  * **Anthropic / Groq / OpenAI** — for AI tool processing
 +  * **sansad.in / rsdoc.nic.in** — official MP/bill data (we read; we do not send your data to them)
 +  * **Wikipedia** — public Wikipedia API for MP bios (read-only)
 +  * **Cloud / hosting** — server hosting (cPanel)
 +
 +Each service has its own privacy policy. We use them with the least-data principle.
 +
 +===== 6. How long we keep data =====
 +
 +  * **Account data** — until you delete your account, then 30 days for backup recovery, then permanent deletion
 +  * **CPD academy data** — progress, scores and certificate records are kept while your account exists; cleared on account deletion (then the 30-day backup window)
 +  * **Server logs** — 90 days, then anonymised
 +  * **AI tool input/output** — not stored on our servers unless you click Save (then per Account data retention)
 +  * **Saved RTI drafts** — until you delete them
 +  * **Forum posts** — kept indefinitely as part of the public record (but you can delete your own posts via your account, or ask us to delete them when you delete your account)
 +  * **Account-onboarding email queue/log** — kept for operational audit and duplicate prevention; it is not a newsletter subscription record.
 +  * **Newsletter subscriber list** — until you unsubscribe (one-click). The consent timestamp is retained as a DPDP audit record after that.
 +  * **Download history** — kept while your account exists; cleared on account deletion.
 +
 +===== 7. Your rights under DPDP Act 2023 =====
 +
 +You have the right to:
 +  - **Access** the personal data we hold on you
 +  - **Correct** any inaccuracy
 +  - **Erase** your data (account deletion)
 +  - **Withdraw consent** to specific processing
 +  - **Grievance** — file with our Grievance Officer, then with Data Protection Board
 +
 +**To delete your account and all associated data** (website and app — they share one account), use our self-service page: **[[https://righttoinformation.wiki/delete-account|righttoinformation.wiki/delete-account]]** (no login required). You can also email **[email protected]**. We action deletion within **7 days** and purge backups within **30 days**.
 +
 +To exercise any other right, email **[email protected]**. We respond within 7 days.
 +
 +===== 8. Children =====
 +Our service is not directed at children under 18. If you believe we have inadvertently collected data from a minor, email [email protected] for prompt deletion.
 +
 +===== 9. Data security =====
 +  * **HTTPS** sitewide with HSTS
 +  * Passwords hashed with bcrypt
 +  * Per-user encryption of sensitive saved data
 +  * Regular automated security scans
 +
 +We do not guarantee absolute security; no internet system can. We promise to follow industry best-practice + report breaches to affected users within **72 hours** as DPDP Act requires.
 +
 +===== 10. International transfer =====
 +Data primarily stored in India. AI providers may process your input in their respective jurisdictions (US-based for Anthropic, OpenAI). We use providers with appropriate contractual safeguards.
 +
 +===== 11. Changes to this policy =====
 +Material changes are highlighted at the top of this page for 30 days. Last revised date is at the bottom.
 +
 +===== 12. Contact =====
 +  * **Privacy / data requests**: [email protected]
 +  * **Grievance Officer**: [email protected]
 +  * **Delete your account**: [[https://righttoinformation.wiki/delete-account|righttoinformation.wiki/delete-account]]
 +  * **Data Protection Board** (per DPDP Act): https://www.meity.gov.in/data-protection
 +
 +//Last reviewed: 11 July 2026 — added CPD academy data (Category F), the mobile app / Google AdMob disclosure (Category G), the self-service account-deletion page, and standardised the operating entity (Bighelpers Software and Solutions Pvt. Ltd.) and the single data-protection contact ([email protected]) across all legal pages. Newsletter opt-in remains default-unchecked.//
 +
 +===== 🔗 Related guides =====
 +  * [[:exercise-data-protection-rights-dpdp-2026|How to exercise your Data Protection rights under DPDP — complete 2026 guide]]
 +  * [[:privacy-policy-app|App Privacy Policy — RTI Wiki Android and iOS app]]
 +  * [[:pio-faa-knowledge-base|Section 8(1)(j) after DPDP 2025 — A Decision Framework for Public Information Officers]]
 +
 +{{tag>privacy data-protection dpdp-act}}
  
📱Test our Android app — free beta!Join Beta GroupYou'll receive the install link by email after joining.