Privacy Policy

Svarga Griha (CGCP Saathi)

Last Updated: July 4, 2026 | Compliant with DPDP Act, 2023 (India)

This Privacy Policy describes how CGCP Saathi (operated under the sole proprietorship "Svarga Griha", headquartered in Bengaluru, Karnataka) handles personal and sensitive data collected through our B2B SaaS platforms, trainee portals, and administrator tools.

Secure Storage

Industry-standard AES encryption for trainee identity archives and log sheets.

Aadhar Vault

Aadhar details are checked instantly to block duplicate logins and then masked.

Zero Ads sharing

We do not sell student demographics to advertising brokers or marketers.

1. Information We Collect

In operating the CGCP Saathi system on behalf of institutional training providers (the "Tenants"), we act as a Data Fiduciary and/or Data Processor under local regulations. We collect and process the following information:

  • Trainee Personal Data: Full name, age, educational qualifications, 12-digit numeric student ID, contact numbers, and qualification documents.
  • Identity Proofs: Aadhar Number (used exclusively for real-time validation to verify intake caps and prevent dual registrations across centers).
  • Clinical & Performance Logs: Community orientation visit journals, ward assignments, patients attended counts, daily vital checks, and Master Trainer grading logs.
  • Logistics Data: Training center coordinates, batch dates, hospital permissions, and staff roles (Principal, Coordinator, Master Trainer).

2. Processing Purpose & Legal Grounds

We process your personal data under the following legitimate grounds:

  • Contractual Obligation: To manage center admissions, trainee registrations, and batch boundary configurations requested by the Tenant.
  • Identity Protection: To run cross-verification checks on Aadhar numbers, blocking duplicate profiles to maintain clean admissions rosters.
  • Audit Compliance: To generate standard A4-formatted performance logs containing trainee signatures and trainer comments required by MoU institutions and public audit entities.

3. Data Preservation & Deletion

Student data is stored as long as the Tenant keeps an active software subscription or as required by government program guidelines. Tenants may request database exports or total trainee archives erasure by contacting the support desk.

4. Operational & Technical Safeguards

We implement comprehensive technical and administrative protection protocols:

  • Indian Data Localization: All core databases, backup storage systems, and uploaded candidate documents (Aadhar cards, qualification certificates) reside on cloud infrastructure located physically within the borders of the Republic of India (Bengaluru/Mumbai regions).
  • Logical Multi-Tenant Isolation: Logical organization boundaries isolate NGO/Training center workspaces. Database schemas are filtered dynamically based on custom request header mappings (slug-based filtering), preventing cross-institution data exposures.
  • Granular Role-Based Access Control (RBAC): Access limits prevent unauthorized logs lookup. Trainees can access only their personal logs dashboard; Master Trainers are constrained to logging observations within assigned batch classrooms; Coordinators supervise their respective training academies.
  • Real-time Duplicate Filtering: Real-time Aadhar string lookups run automatically during student registration, displaying warning notifications and blocking overallocation/duplicate enrollment records.

Important: While we apply strict multi-tenant isolation layers and HTTPS transfer tokens, no web transmission is 100% immune to leaks. Users are instructed to safeguard their unique login credentials and coordinate with local administrators in case of account compromises.

Data Fiduciary Contact Details

If you have questions, corrections, or erasure requests regarding your personal data:

Svarga Griha (Proprietorship), 15, 1st Main, Chowdeshwarinagar, Laggere Outer Ring Road, Bengaluru - 560058
info@cgcpsaathi.in | support@cgcpsaathi.in