Privacy Policy
S3KN Software Solutions Pvt. Ltd. — GP MNREGA Platform
Last updated: 01 January 2025 · Effective immediatelyIndia's Digital Personal Data Protection Act, 2023
This Privacy Policy complies with the DPDP Act 2023. As a Data Fiduciary, S3KN Software Solutions Pvt. Ltd. processes your personal data only for lawful purposes with your consent or other permissible grounds, protected with appropriate security safeguards.
1Who We Are (Data Fiduciary)
S3KN Software Solutions Pvt. Ltd.
SY 953/*/P2 107, Sai Park Ring Road, Vijayapur – 586 109, Karnataka, India
Email: admin@gpmnrega.com
2Personal Data We Collect
We collect only the minimum data necessary (principle of data minimisation under DPDP Act 2023):
| Data | Purpose | Legal Basis |
|---|---|---|
| Name, Email, Phone | Account creation & communication | Consent / Contract |
| Panchayat Code, GP Name, Block, District, Vidhan/Lok Sabha | Generating correct reports with regional data | Contract |
| Payment transaction ID | Subscription management & receipts | Contract / Legal obligation |
| Login timestamps, IP (hashed) | Security & fraud prevention | Legitimate use (S.7 DPDP) |
| Session cookies | Keeping you logged in, CSRF protection | Consent / Contract |
3How We Use Your Data
- Consent (S.6): By registering, you consent to processing your data to provide the GP MNREGA service.
- Contractual obligation: To fulfil your subscription, generate reports, and send transactional emails.
- Legal obligation: To maintain financial records under GST and Income Tax Act.
- Legitimate use (S.7): Security logging and fraud prevention using anonymised data.
4When We Share Your Data
- Payment processor: Name, email, phone shared with our UPI gateway solely to process transactions.
- Google Cloud Translate: Panchayat/block/constituency names (no personal identifiers) sent to generate Kannada translations.
- Legal requirements: Disclosure to law enforcement only when required by a valid legal order under Indian law.
5Your Rights Under the DPDP Act, 2023
6Cookies
- Authentication cookie (.S3KN_AUTH2): HttpOnly, Secure — keeps you logged in. Cannot be read by JavaScript. Expires after 24 hours of inactivity.
- Anti-forgery token: Prevents CSRF attacks on forms.
We do not use advertising cookies, third-party tracking, or analytics. Disabling cookies will prevent login.
7Security
- HTTPS / TLS 1.2+: All data in transit is encrypted.
- BCrypt password hashing: We cannot read your password.
- HttpOnly cookies: Auth cookies protected against XSS theft.
- Data breach notification: Affected users and the Data Protection Board notified as required under DPDP Act 2023 (S.8).
8Data Retention
- Account data: Deleted within 30 days of account deletion request.
- Payment records: Retained 7 years under Income Tax Act and GST law.
- Server logs: 90 days, no personal data.
- Contact form submissions: 12 months then deleted.
9Children's Privacy
GP MNREGA is intended for adult government officials. We do not knowingly collect data from persons under 18, in accordance with Section 9 of the DPDP Act 2023.
10Changes to This Policy
Material changes will be notified to registered users by email and the "Last updated" date revised. Continued use constitutes acceptance.
?Questions or Complaints
Email admin@gpmnrega.com with subject "Data Rights Request". If unsatisfied with our response, you may escalate to the Data Protection Board of India under DPDP Act 2023.