Privacy Policy
Your data never leaves the police station.
Gradify PoliceTrust is deployed as an on-premise / department-hosted system. All operational data (First Information Reports (FIRs), case files, evidence records, chain-of-custody logs, personal data of complainants, witnesses and accused persons, and every blockchain record) is stored, processed and controlled exclusively on servers owned and operated by the deploying police station, district police unit or state police department. Gradify Labs LLP does not host, store, mirror, copy or retain a back-up of this operational data on any Gradify-controlled infrastructure. The department is the sole data controller and data fiduciary; we act only as a technology provider and, where contracted, as a data processor operating strictly within the department's own environment.
01Overview & scope
Gradify PoliceTrust is an AI and permissioned-blockchain platform for digital policing, deployed alongside existing government systems such as CCTNS and ICJS. Because the Platform processes sensitive law- enforcement records, privacy is designed into its architecture rather than added afterward.
This policy distinguishes clearly between two very different categories of data, because they are governed differently:
- Operational policing data: FIRs, case files, evidence, chain-of-custody records and the personal data of citizens, complainants, witnesses and accused persons. This data is created and held inside the police department's own environment. The department is the data controller / data fiduciary for it; Gradify Labs does not hold it.
- Website & commercial data : information you voluntarily provide to Gradify Labs through this Website (for example, a demo request or a support enquiry) and limited technical data from your visit. Gradify Labs is the data fiduciary for this narrow category, and this policy governs it.
02Who is the data controller
Under the DPDP Act, the “Data Fiduciary” is the entity that determines the purpose and means of processing personal data. For Gradify PoliceTrust, responsibilities are split as follows:
| Category of data | Data Fiduciary / Controller | Role of Gradify Labs |
|---|---|---|
| Operational policing data on the Platform | The deploying police station / district unit / State Police | Technology provider & (where contracted) Data Processor operating inside the department's own infrastructure |
| Website enquiry / demo-request data | Gradify Labs LLP | Data Fiduciary |
| Website technical / cookie data | Gradify Labs LLP | Data Fiduciary (see Cookie Policy) |
03Where your data lives: data residency & sovereignty
This is the most important commitment in this policy. Gradify PoliceTrust is delivered as an on-premise, department-hosted or GovCloud / state-data-centre deployment. Concretely:
- All operational data is stored, encrypted and processed exclusively on servers owned or controlled by the deploying police department (within the department's own premises, a Government of India empanelled cloud, or a State data centre, as the department elects).
- Gradify Labs does not host, mirror, replicate, back up, cache or retain a copy of operational policing data on any infrastructure controlled by Gradify Labs, any third-party cloud we contract, or any developer workstation.
- The permissioned blockchain ledger runs on department-authorised nodes only. There is no public, anonymous or Gradify-operated chain. Only SHA-256 fingerprints (hashes) are anchored, never the underlying documents.
- Encryption keys, administrative credentials and access-control policies are held by the department. Gradify Labs personnel have no standing access to production data.
- Any support, maintenance or upgrade access is granted only on the department's request, is time-bound, is logged in an immutable audit trail, and takes place inside the department's environment under its supervision (data is never exported to Gradify Labs).
04Definitions
- “Personal Data”: any data about an individual who is identifiable by or in relation to such data.
- “Data Principal”: the individual to whom the personal data relates (a citizen, officer, complainant, witness, or Website visitor).
- “Data Fiduciary / Controller” : the entity that determines the purpose and means of processing.
- “Data Processor” : an entity that processes data on behalf of, and under the instructions of, a Data Fiduciary.
- “Processing”: any operation performed on personal data, including collection, storage, use, indexing, disclosure or erasure.
- “Operational Policing Data” : data generated or held within the Platform in the course of policing (FIRs, cases, evidence, custody logs, ledger records).
05Data processed within the Platform
The following categories may be processed inside the Platform. In every case the department is the controller and the data resides on department infrastructure. This list is provided for transparency about the software's capabilities, not because Gradify Labs holds any of it:
| Category | Examples | Held by |
|---|---|---|
| Complaint & case data | FIR contents, case status, sections invoked, station of origin | Police department server |
| Identity data | Names, addresses, contact details of complainants, witnesses, accused | Police department server |
| Evidence & custody data | Evidence descriptions, seizure records, transfer/custody logs, file hashes | Police department server |
| Officer & role data | Officer identifiers, roles, permissions, action logs | Police department server |
| Ledger data | SHA-256 hashes, timestamps, anchoring metadata (no raw documents) | Permissioned nodes |
| AI-derived data | Classifications, summaries and analytical outputs generated on-premise | Police department server |
06Data Gradify Labs collects via this Website
When you interact with this Website, Gradify Labs (as Data Fiduciary) processes only the limited data below:
- Enquiry / demo-request data: your name, designation, department or organisation, email, phone number and the message you submit through the contact form. This is collected via our forms provider (Formspree) solely to respond to your request.
- Technical data: IP address, browser type, device type, referring page and pages viewed, collected through standard server logs and analytics.
- Cookie data: as described in our Cookie Policy.
We do not use this Website to collect operational policing data, and we ask that you never submit case-sensitive, evidentiary or citizen personal data through the contact form.
07Lawful basis of processing
- Consent: for Website enquiry data, we rely on the consent you give by voluntarily submitting the form. You may withdraw it at any time (see Your Rights).
- Legitimate uses / legal function : operational policing data is processed by the department in the performance of a function under law and in the interest of the State, as permitted under the DPDP Act; Gradify Labs, where acting as processor, does so strictly on the department's documented instructions.
- Contractual necessity: where processing is required to provide the Platform under a signed agreement.
08Purposes of processing
- Providing FIR verification, evidence integrity and chain-of-custody functions to the department.
- Enabling role-based access for officers, supervisors, forensic staff and citizens.
- Maintaining immutable audit logs for accountability and evidentiary value.
- Responding to your demo requests, enquiries and support tickets (Website data).
- Operating, securing, maintaining and improving the Platform and Website.
- Meeting legal, regulatory and government procurement obligations.
We do not sell personal data. We do not use operational policing data to train Gradify Labs' own models; any AI processing runs within the department's environment on the department's data under its control.
10Data retention
- Operational policing data is retained by the department in accordance with police record- retention rules, evidentiary requirements and applicable law. The department controls its retention and erasure; Gradify Labs holds no copy to retain.
- Website enquiry data is retained only for as long as necessary to respond to and follow up on your request, and thereafter for a limited period for record- keeping, typically not exceeding 24 months, unless a longer period is required by law.
- Technical / log data is retained for shorter operational and security periods.
11Security measures
Security is engineered into every layer. Measures include:
- AES-256 encryption of data at rest and TLS encryption in transit.
- SHA-256 cryptographic hashing and anchoring on a permissioned blockchain.
- Role-based access control and least-privilege authorisation.
- Zero-trust architecture: every request is authenticated and authorised.
- Immutable, independently verifiable audit logs.
- On-premise / GovCloud deployment keeping data within the department's boundary.
Details are set out in our Security Disclosures. No system is perfectly secure; we and the department maintain incident-response procedures consistent with applicable law.
12Your rights under the DPDP Act
As a Data Principal, subject to law, you may:
- Access a summary of your personal data being processed and the processing activities.
- Request correction, completion, updating or erasure of your personal data.
- Withdraw consent previously given (where processing is based on consent).
- Nominate another individual to exercise your rights in the event of death or incapacity.
- Grievance redressal, and the right to escalate to the Data Protection Board of India.
13Children's data
This Website is not directed at children. Where the Platform processes data concerning a child (for example, a minor complainant or victim), such processing is performed by the department in accordance with the DPDP Act's protections for children, including the requirement to avoid processing that is detrimental to the child.
14Grievance redressal
Gradify Labs has appointed a Grievance Officer to address questions and complaints regarding personal data for which we are the Data Fiduciary (Website / commercial data). We aim to acknowledge grievances promptly and resolve them within the timelines prescribed under applicable law. Grievances concerning operational policing data should be raised with the deploying department, which is the responsible fiduciary.
15Cross-border transfers
Operational policing data does not leave the department's infrastructure and is not transferred internationally by Gradify Labs. Limited Website data may be processed by service providers; where any such provider operates outside India, we take steps consistent with the DPDP Act and applicable restrictions on cross-border transfer.
16Changes to this policy
We may update this policy from time to time to reflect changes in law, technology or our practices. The “Last updated” date at the top indicates the latest revision. Material changes will be communicated through the Website or, for deployed departments, through the contractual notice mechanism.
17Contact us
For any question about this Privacy Policy or Website data for which Gradify Labs is the fiduciary:
- Entity: Gradify Labs LLP
- Address: Jaipur, Rajasthan, India
- Email: contact@gradifytech.com
- Phone: +91 86902 38350
This document forms part of the contractual and disclosure framework governing the use of Gradify PoliceTrust. It should be read together with the Privacy Policy, the Terms of Service, the Cookie Policy and the Security Disclosures. Where a signed Master Services Agreement, Data Processing Agreement or government procurement contract exists between Gradify Labs LLP and a deploying department, the terms of that executed agreement prevail over this document to the extent of any conflict.