Legal

Privacy Policy

Last updated: 09 July 2026Version 1.0Gradify Labs LLP · Udaipur, Rajasthan, India
This Privacy Policy explains how Gradify Labs LLP (“Gradify Labs”, “we”, “us”, “our”) handles personal data in connection with the Gradify PoliceTrust platform (the “Platform”) and the website at which this policy appears (the “Website”). It is written to be consistent with the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the Information Technology Act, 2000 and rules made thereunder. Please read it carefully.

Your data never leaves the police station.

Gradify PoliceTrust is deployed as an on-premise / department-hosted system. All operational data (First Information Reports (FIRs), case files, evidence records, chain-of-custody logs, personal data of complainants, witnesses and accused persons, and every blockchain record) is stored, processed and controlled exclusively on servers owned and operated by the deploying police station, district police unit or state police department. Gradify Labs LLP does not host, store, mirror, copy or retain a back-up of this operational data on any Gradify-controlled infrastructure. The department is the sole data controller and data fiduciary; we act only as a technology provider and, where contracted, as a data processor operating strictly within the department's own environment.

01Overview & scope

Gradify PoliceTrust is an AI and permissioned-blockchain platform for digital policing, deployed alongside existing government systems such as CCTNS and ICJS. Because the Platform processes sensitive law- enforcement records, privacy is designed into its architecture rather than added afterward.

This policy distinguishes clearly between two very different categories of data, because they are governed differently:

  • Operational policing data: FIRs, case files, evidence, chain-of-custody records and the personal data of citizens, complainants, witnesses and accused persons. This data is created and held inside the police department's own environment. The department is the data controller / data fiduciary for it; Gradify Labs does not hold it.
  • Website & commercial data : information you voluntarily provide to Gradify Labs through this Website (for example, a demo request or a support enquiry) and limited technical data from your visit. Gradify Labs is the data fiduciary for this narrow category, and this policy governs it.

02Who is the data controller

Under the DPDP Act, the “Data Fiduciary” is the entity that determines the purpose and means of processing personal data. For Gradify PoliceTrust, responsibilities are split as follows:

Category of dataData Fiduciary / ControllerRole of Gradify Labs
Operational policing data on the PlatformThe deploying police station / district unit / State PoliceTechnology provider & (where contracted) Data Processor operating inside the department's own infrastructure
Website enquiry / demo-request dataGradify Labs LLPData Fiduciary
Website technical / cookie dataGradify Labs LLPData Fiduciary (see Cookie Policy)
For all operational policing data, the police department is the single point of accountability. If you are a citizen wishing to exercise rights over an FIR, case record or evidence item, those requests are handled by the department through its statutory processes and the Platform's in-built citizen portal, not by Gradify Labs, which has no access to and no copy of that data.

03Where your data lives: data residency & sovereignty

This is the most important commitment in this policy. Gradify PoliceTrust is delivered as an on-premise, department-hosted or GovCloud / state-data-centre deployment. Concretely:

  • All operational data is stored, encrypted and processed exclusively on servers owned or controlled by the deploying police department (within the department's own premises, a Government of India empanelled cloud, or a State data centre, as the department elects).
  • Gradify Labs does not host, mirror, replicate, back up, cache or retain a copy of operational policing data on any infrastructure controlled by Gradify Labs, any third-party cloud we contract, or any developer workstation.
  • The permissioned blockchain ledger runs on department-authorised nodes only. There is no public, anonymous or Gradify-operated chain. Only SHA-256 fingerprints (hashes) are anchored, never the underlying documents.
  • Encryption keys, administrative credentials and access-control policies are held by the department. Gradify Labs personnel have no standing access to production data.
  • Any support, maintenance or upgrade access is granted only on the department's request, is time-bound, is logged in an immutable audit trail, and takes place inside the department's environment under its supervision (data is never exported to Gradify Labs).
Because the department retains sole custody, deployment survives even if Gradify Labs is unavailable, and the department can independently verify integrity, run audits and meet its own statutory obligations without depending on us for data access.

04Definitions

  • “Personal Data”: any data about an individual who is identifiable by or in relation to such data.
  • “Data Principal”: the individual to whom the personal data relates (a citizen, officer, complainant, witness, or Website visitor).
  • “Data Fiduciary / Controller” : the entity that determines the purpose and means of processing.
  • “Data Processor” : an entity that processes data on behalf of, and under the instructions of, a Data Fiduciary.
  • “Processing”: any operation performed on personal data, including collection, storage, use, indexing, disclosure or erasure.
  • “Operational Policing Data” : data generated or held within the Platform in the course of policing (FIRs, cases, evidence, custody logs, ledger records).

05Data processed within the Platform

The following categories may be processed inside the Platform. In every case the department is the controller and the data resides on department infrastructure. This list is provided for transparency about the software's capabilities, not because Gradify Labs holds any of it:

CategoryExamplesHeld by
Complaint & case dataFIR contents, case status, sections invoked, station of originPolice department server
Identity dataNames, addresses, contact details of complainants, witnesses, accusedPolice department server
Evidence & custody dataEvidence descriptions, seizure records, transfer/custody logs, file hashesPolice department server
Officer & role dataOfficer identifiers, roles, permissions, action logsPolice department server
Ledger dataSHA-256 hashes, timestamps, anchoring metadata (no raw documents)Permissioned nodes
AI-derived dataClassifications, summaries and analytical outputs generated on-premisePolice department server

06Data Gradify Labs collects via this Website

When you interact with this Website, Gradify Labs (as Data Fiduciary) processes only the limited data below:

  • Enquiry / demo-request data: your name, designation, department or organisation, email, phone number and the message you submit through the contact form. This is collected via our forms provider (Formspree) solely to respond to your request.
  • Technical data: IP address, browser type, device type, referring page and pages viewed, collected through standard server logs and analytics.
  • Cookie data: as described in our Cookie Policy.

We do not use this Website to collect operational policing data, and we ask that you never submit case-sensitive, evidentiary or citizen personal data through the contact form.

08Purposes of processing

  • Providing FIR verification, evidence integrity and chain-of-custody functions to the department.
  • Enabling role-based access for officers, supervisors, forensic staff and citizens.
  • Maintaining immutable audit logs for accountability and evidentiary value.
  • Responding to your demo requests, enquiries and support tickets (Website data).
  • Operating, securing, maintaining and improving the Platform and Website.
  • Meeting legal, regulatory and government procurement obligations.

We do not sell personal data. We do not use operational policing data to train Gradify Labs' own models; any AI processing runs within the department's environment on the department's data under its control.

09Disclosure & sharing

Operational policing data is disclosed only by the department, through its own lawful processes (for example, to courts, prosecutors or oversight bodies). Gradify Labs cannot and does not disclose it, because we do not hold it.

Website data may be shared only with:

  • Service providers acting as our processors (e.g. our forms/email provider), under confidentiality obligations and solely to deliver the requested service.
  • Professional advisers (legal, accounting) where necessary.
  • Authorities, where disclosure is required by law or valid legal process.
  • A successor entity in the event of a merger, acquisition or reorganisation, subject to this policy.

10Data retention

  • Operational policing data is retained by the department in accordance with police record- retention rules, evidentiary requirements and applicable law. The department controls its retention and erasure; Gradify Labs holds no copy to retain.
  • Website enquiry data is retained only for as long as necessary to respond to and follow up on your request, and thereafter for a limited period for record- keeping, typically not exceeding 24 months, unless a longer period is required by law.
  • Technical / log data is retained for shorter operational and security periods.

11Security measures

Security is engineered into every layer. Measures include:

  • AES-256 encryption of data at rest and TLS encryption in transit.
  • SHA-256 cryptographic hashing and anchoring on a permissioned blockchain.
  • Role-based access control and least-privilege authorisation.
  • Zero-trust architecture: every request is authenticated and authorised.
  • Immutable, independently verifiable audit logs.
  • On-premise / GovCloud deployment keeping data within the department's boundary.

Details are set out in our Security Disclosures. No system is perfectly secure; we and the department maintain incident-response procedures consistent with applicable law.

12Your rights under the DPDP Act

As a Data Principal, subject to law, you may:

  • Access a summary of your personal data being processed and the processing activities.
  • Request correction, completion, updating or erasure of your personal data.
  • Withdraw consent previously given (where processing is based on consent).
  • Nominate another individual to exercise your rights in the event of death or incapacity.
  • Grievance redressal, and the right to escalate to the Data Protection Board of India.
Route matters. For operational policing data, exercise these rights with the concerned police station / department, which holds and controls the data. For Website enquiry data, contact Gradify Labs using the details below.

13Children's data

This Website is not directed at children. Where the Platform processes data concerning a child (for example, a minor complainant or victim), such processing is performed by the department in accordance with the DPDP Act's protections for children, including the requirement to avoid processing that is detrimental to the child.

14Grievance redressal

Gradify Labs has appointed a Grievance Officer to address questions and complaints regarding personal data for which we are the Data Fiduciary (Website / commercial data). We aim to acknowledge grievances promptly and resolve them within the timelines prescribed under applicable law. Grievances concerning operational policing data should be raised with the deploying department, which is the responsible fiduciary.

15Cross-border transfers

Operational policing data does not leave the department's infrastructure and is not transferred internationally by Gradify Labs. Limited Website data may be processed by service providers; where any such provider operates outside India, we take steps consistent with the DPDP Act and applicable restrictions on cross-border transfer.

16Changes to this policy

We may update this policy from time to time to reflect changes in law, technology or our practices. The “Last updated” date at the top indicates the latest revision. Material changes will be communicated through the Website or, for deployed departments, through the contractual notice mechanism.

17Contact us

For any question about this Privacy Policy or Website data for which Gradify Labs is the fiduciary:

This document forms part of the contractual and disclosure framework governing the use of Gradify PoliceTrust. It should be read together with the Privacy Policy, the Terms of Service, the Cookie Policy and the Security Disclosures. Where a signed Master Services Agreement, Data Processing Agreement or government procurement contract exists between Gradify Labs LLP and a deploying department, the terms of that executed agreement prevail over this document to the extent of any conflict.