1. Scope and promise
This notice applies to the Firyad.com website, mobile applications, and connected case-management services operated by Arkand Labs Private Limited. Firyad.com is an independent civic coordination service. It is not itself a government department or an official emergency channel.
Our product decision is simple: we do not ask residents for their names. A resident can sign in with Google, phone OTP, or Apple, then submit a complaint, request, letter, or petition using a protected account reference. Names can still appear in text or attachments if a resident chooses to include them, so the submission form warns residents to avoid unnecessary identifying details.
2. Information we collect
We will show a clear, standalone notice at the point of collection. The planned data fields are:
- Sign-in identity: the provider name and provider subject/identifier needed to keep the account secure. We will ignore profile display names and will not create a public name field.
- Contact channel: a phone number, email address, or both, only when the resident chooses to receive case updates. Phone is supported for residents who have limited email access.
- Case information: case type, title, description, department/category labels, state/district/city/PIN or other location details, urgency, attachments, and replies supplied by the resident.
- Case operations: case ID, timestamps, status changes, routing, office assignments, public updates, internal office notes, and audit events.
- Security and service data: limited device, browser, IP, session, error, and abuse-prevention information. This is used to secure the service, not to build political profiles.
We do not intentionally collect Aadhaar numbers, passwords, OTP values, political affiliation, caste, religion, biometric data, or a resident’s name for ordinary case submission. Residents should not put these details into free text unless a reviewed workflow specifically asks for them.
3. Why we use information
- to create and authenticate a protected resident account;
- to accept, label, route, prioritize, and track a case for the selected representative office;
- to send the status updates the resident requested by phone, email, or in-app notification;
- to let authorized office staff work cases, record next actions, and maintain an accountable history;
- to detect abuse, protect accounts, troubleshoot failures, and maintain service integrity; and
- to produce aggregate operational insights that do not identify a resident or target a political group.
We will not sell resident contact data, use case content for voter profiling or campaign targeting, or allow an office to search all resident submissions by name. Any future analytics, automation, or AI routing must preserve these boundaries and receive a separate review.
5. Retention and deletion
The final retention schedule is still a launch gate. The working design is to retain contact identity only while an account or active case needs it, delete it after a verified deletion request subject to lawful exceptions, expire case content after a defined period following closure, and keep security/audit records only as long as necessary for accountability and abuse prevention.
Backups, notification logs, exports, and office records must have their own expiry rules. Deleting an account will not be described as instantaneous if a legally required or time-limited backup copy remains. The final notice will state exact periods and the deletion process.
6. Resident choices and rights
Firyad.com will provide an in-app and website path to access, correct, export, or delete account and case information, withdraw optional update consent, change the contact channel, and raise a complaint. Withdrawing a notification consent may stop phone/email updates while leaving an in-app case tracker available.
Requests may require verification through the account or contact channel so that one person cannot obtain another resident’s complaint. We will respond through the designated grievance process published before launch.
7. Security and safety design
- separate account/contact data from case records;
- encrypt data in transit and at rest, with managed key rotation;
- use role-based office access, tenant isolation, least privilege, and immutable audit events;
- rate-limit OTP, sign-in, case tracking, uploads, and public endpoints;
- scan and quarantine attachments before office access;
- mask contact details in list, export, insight, and notification surfaces unless needed; and
- provide a safety route for harassment, threats, retaliation, and compromised accounts.
No online service can promise absolute security. If a production incident affects residents, the incident-response and notice process will be governed by the final reviewed policy.
8. Owner and privacy contact
Owner: Arkand Labs Private Limited, operating Firyad.com.
Planned privacy contact: privacy@firyad.com. This mailbox and the designated grievance contact must be created and monitored before public launch. Do not send sensitive personal information to this draft address until it is confirmed on the live domain.
We will publish any material change to this notice on this page and identify the effective date. This draft should be reviewed by qualified Indian privacy counsel before it is treated as a binding notice.