Login
Home Features Documentation Contact Login
Legal Document · PAC System

Privacy Policy

We are committed to protecting your personal data. This policy explains what information we collect, how it's used, and the rights you hold over your data within the PAC Management System.

Effective: January 1, 2025
Last Updated: June 15, 2025
Version 2.0
English
Section 01
Overview & Scope

PAC Management System ("PAC System," "we," "us," or "our") is a centralized platform designed for managing Aadhaar enrollment centers, PAC records, and UCL owner networks across the CSC and BC operator ecosystem. This Privacy Policy governs all data processing activities on our platform, accessible at cscpac.vercel.app.

This policy applies to all users of the PAC System, including administrators, UCL owners, system operators, and center managers. By accessing or using our platform, you agree to the practices described in this document. If you do not agree, please discontinue use of the service immediately.

Jurisdiction: This platform operates primarily within the Republic of India and complies with the Information Technology Act, 2000, the IT (Amendment) Act, 2008, and the Digital Personal Data Protection Act (DPDPA), 2023. For users outside India, we make reasonable efforts to comply with applicable local laws.

We are committed to transparency about our data practices. If you have any questions that are not addressed in this document, please contact us using the information provided in Section 09.

Section 02
Data We Collect

We collect the minimum necessary data required to operate the PAC Management System effectively and securely. The following table summarizes the categories of data we process:

Data Type Examples Purpose Status
Account Identity Full name, email address, mobile number Authentication & profile management Required
Professional Info Operator ID, center code, UCL number, role designation Role-based access control & auditing Required
PAC Records PAC entry data, timestamps, submission status, center ID Core system functionality Required
Location Data Center geo-coordinates, district, state, PIN code Center mapping & network management Required
Device & Session IP address, browser type, device OS, session tokens Security monitoring & anomaly detection Automatic
Usage Analytics Page visits, feature usage patterns, click events Platform improvement & performance Optional
Uploaded Documents UCL verification documents, operator ID scans Identity verification & compliance Optional
Sensitive Data Notice: We do not collect or store Aadhaar numbers, biometric data, bank account details, or any other sensitive personal information as defined under Indian law. PAC records contain only administrative metadata, never biometric or identity verification content.
Section 03
How We Use Your Data

Data collected through the PAC Management System is used exclusively for the following purposes, all of which are necessary for providing the service you've signed up for:

Platform Operations: Processing PAC entries, synchronizing records across centers, generating reports, and maintaining real-time dashboards. This is the primary use of all data you submit.

Authentication & Security: Verifying your identity at login, detecting unauthorized access attempts, enforcing role-based permissions, and maintaining secure session management through Firebase Authentication.

System Monitoring: Tracking uptime, measuring database response times, and identifying performance bottlenecks to maintain our 99.7% SLA commitment.

Compliance & Auditing: Maintaining an immutable audit trail of all administrative actions, data modifications, and access events as required for regulatory compliance.

No Advertising: We do not use your data for advertising, marketing profiling, or selling to third parties. Your data is never used to target you with advertisements inside or outside our platform.

Service Communications: Sending you system alerts, backup confirmations, security notifications, and administrative announcements that are essential to the service. You cannot opt out of service-critical communications while maintaining an active account.

Section 04
Data Sharing & Third Parties

We do not sell, rent, or trade your personal data. We share data only in the following limited and controlled circumstances:

Recipient Data Shared Legal Basis
Google Firebase / Firestore All platform data (encrypted at rest and in transit) Service provider contract — Google Cloud DPA
Vercel (Hosting) IP addresses, HTTP request metadata Infrastructure provider — Vercel DPA
System Administrators Full data access within PAC System Employment contract & role necessity
Government Authorities As legally required under court order or law Legal obligation under Indian law

All third-party service providers are bound by contractual data processing agreements that restrict their use of your data to providing their services to us. We conduct periodic vendor assessments to ensure continued compliance.

Section 05
Security Measures

We implement multiple layers of technical and organizational security measures to protect your data from unauthorized access, loss, or disclosure:

Encryption: All data is encrypted in transit using TLS 1.3 and encrypted at rest using AES-256 through Google Cloud's managed encryption infrastructure. No data is ever transmitted or stored in plaintext.

Access Control: Firebase Security Rules enforce granular role-based access control at the database layer. Even if an application-level control were bypassed, database-level rules ensure unauthorized data access is impossible.

Authentication: Multi-factor authentication is available and strongly recommended for all administrator accounts. All sessions are time-limited and automatically invalidated after periods of inactivity.

Audit Logging: Every data access, modification, and deletion event is logged with a timestamp, user ID, IP address, and action description. Audit logs are immutable and retained for 12 months.

Incident Response: In the event of a data breach affecting your personal information, we will notify affected users within 72 hours of discovery through your registered email address, and report to relevant authorities as required by law.
Section 06
Data Retention

We retain your data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law:

Data Category Retention Period Deletion Trigger
Active Account Data Duration of account activity Account deactivation + 30 days
PAC Records 7 years Regulatory compliance period
Audit Logs 12 months Rolling deletion after 365 days
Session Tokens Up to 30 days Logout or session expiry
Backup Snapshots 30 days Automatic rolling deletion
Uploaded Documents Until verification complete + 90 days Manual deletion by admin

After the applicable retention period, data is permanently and irreversibly deleted from all our systems, including backup storage. You may request earlier deletion of certain data types where technically and legally feasible.

Section 07
Cookies & Local Storage

The PAC Management System uses cookies and browser local storage to enable core functionality and improve your experience. We do not use third-party advertising cookies.

Section 08
Your Rights

Under applicable data protection law, including India's Digital Personal Data Protection Act (DPDPA) 2023, you have the following rights regarding your personal data:

Right to Access
Request a complete copy of all personal data we hold about you in a structured, machine-readable format.
Right to Correction
Request correction of inaccurate or incomplete personal data. We will update records within 7 business days of verification.
Right to Erasure
Request deletion of your personal data where legally permissible. Some records may be retained for compliance purposes.
Right to Object
Object to specific processing activities, including analytics and non-essential communications, at any time.
Data Portability
Receive your data in a portable format (JSON or CSV) to transfer to another service or retain for your own records.
Right to Restrict
Request that we restrict processing of your data while a dispute or correction request is being resolved.

To exercise any of these rights, contact us using the information in Section 09. We will respond to all verified requests within 30 calendar days. We may require identity verification before processing sensitive requests.

No Fee: Exercising your rights is always free of charge. However, requests that are manifestly unfounded, repetitive, or excessive may be subject to a reasonable administrative fee or may be declined.
Section 09
Contact & Data Controller

For any questions, requests, or concerns regarding this Privacy Policy or our data practices, please contact our Data Controller directly. We are committed to responding to all inquiries promptly and transparently.

Data Controller
Sk Samrat — Lead Developer & System Administrator
PAC Management System · CSC / BC Network Platform
Singi, Bolpur, Birbhum, West Bengal — 731240, India

For privacy requests, data access queries, or to report a concern, please use the channels below. Include your full name, registered email, and the nature of your request for the fastest response.

We aim to acknowledge all privacy-related requests within 48 hours and resolve them within 30 calendar days. If you are unsatisfied with our response, you have the right to lodge a complaint with the relevant Data Protection Board of India as established under the DPDPA 2023.

Policy Updates: This Privacy Policy may be updated periodically. We will notify all registered users of material changes via email and a banner notice on the dashboard at least 14 days before the changes take effect. The "Last Updated" date at the top of this page will always reflect the most recent revision.