PII / SPI Data Policy
How we handle Personally Identifiable Information and Sensitive Personal Information under Indian law.
Last updated: July 2025 · Khaira Digital Solutions Pvt. Ltd.
Table of Contents
1. What is PII and SPI?
Personally Identifiable Information (PII) is any data that can identify a specific individual, such as name, mobile number, email address, Aadhaar number, or location data.
Sensitive Personal Information (SPI) under the Information Technology (Reasonable Security Practices) Rules, 2011 and the Digital Personal Data Protection Act, 2023, includes passwords, financial data, health information, biometric data, and information related to sexual orientation.
2. PII We Collect
- Full name, mobile number, and email address
- Profile photo (optional)
- City, district, and state of residence
- Device identifiers and IP address (for security and fraud prevention)
- Location data when you report civic issues (with explicit consent)
3. SPI We May Collect
- Payment information — processed via Razorpay (PCI-DSS compliant). We never store card numbers or CVVs on our servers.
- Precise location data when you opt in for local issue reporting
We collect SPI only with your explicit, informed, and freely given consent. You will always be presented with a clear opt-in before SPI is collected.
4. How We Protect It
All PII and SPI is protected through multiple layers of security:
- AES-256 encryption at rest for all stored personal data
- TLS 1.2+ encryption for all data in transit
- Role-based access controls — only authorised personnel on a need-to-know basis
- Comprehensive audit logs for all access to sensitive data
- Regular penetration testing and third-party security audits
5. Consent and Withdrawal
We collect SPI only with your explicit, informed consent. You may withdraw consent and request deletion of your SPI by emailing info@cityweaver.in. Withdrawal of consent is prospective only and does not affect processing that occurred before withdrawal. Note that certain SPI withdrawals may limit access to specific platform features.
6. Data Breach Response
In the event of a data breach affecting your PII or SPI, we will notify affected users and relevant authorities (including CERT-In) within 72 hours of discovery as required by applicable law. Our incident response team will investigate, contain, and remediate any breach, and provide regular status updates to affected users.
7. Compliance
This policy complies with:
- Information Technology Act, 2000
- IT (Reasonable Security Practices and Procedures) Rules, 2011
- Digital Personal Data Protection Act, 2023 (DPDPA)
- Payment Card Industry Data Security Standard (PCI-DSS) via our payment partners
