Legal

Privacy Policy

Effective Date: 15 August 2026

1. Introduction & Scope

CSRPath Projects and Partners ("CSRPath," "we," "us," or "our") is a partnership firm registered in Telangana, India. This Policy explains how we collect, use, store, and protect personal data across our websites and services, including our platform, CSRPath ONE, built to help Indian corporates manage their CSR compliance under Section 135 of the Companies Act, 2013, and work with NGO and implementation partners to run their programs.

This Policy is written for:

  • Corporate users — team members at corporate customers managing their organization's CSR program
  • Partner/NGO users — team members at NGOs or implementation partners connected through the platform
  • Visitors to our websites

We've tried to write this in plain language wherever we could, alongside the legal precision the subject deserves. It's meant to be read together with our Terms of Use.

2. Definitions

To keep this Policy clear, here's what a few recurring terms mean:

  • "Platform" — CSRPath ONE and any related websites or services operated by CSRPath.
  • "Personal Data" — any information that can identify a person, directly or indirectly (for example, a name, email, or phone number).
  • "Organization" / "Tenant" — a corporate customer or a partner/NGO's own workspace on the Platform, containing that entity's users, projects, and records.
  • "Beneficiary Data" — information about the individuals a CSR program serves, entered into the Platform by a corporate or partner, not by the beneficiary directly.
  • "Data Fiduciary" and "Data Processor" — terms used under India's Digital Personal Data Protection Act, 2023 (DPDP Act). In simple terms, a Data Fiduciary decides why and how personal data is processed, while a Data Processor processes it on the Fiduciary's instructions. Section 3 explains how these roles apply to CSRPath.
  • "Sub-processor" — a third-party service we use to help operate the Platform (for example, cloud hosting or email delivery), which may process personal data on our behalf.

3. Who We Are — Our Role in Data Processing

CSRPath plays different roles depending on whose data is involved:

  • For Platform user accounts (the login and profile details of corporate and partner team members), CSRPath determines what account information is needed to operate the Platform and why it's collected.
  • For data entered into the Platform by a corporate or partner — including beneficiary data, project records, and organizational data — CSRPath processes this data on behalf of, and under the instructions of, the corporate or partner using the Platform.

Corporates and partners are responsible for ensuring they have a lawful basis to collect and share the data they enter into the Platform, including any beneficiary data. CSRPath is responsible for processing that data securely and using it only to operate the Platform and deliver the service.

4. What Data We Collect

We collect different types of data depending on who you are and how you interact with the Platform.

4.1 Corporate and Partner Users

When someone joins their organization's workspace on CSRPath ONE, we collect:

  • Account information — full name, email address, phone number
  • Role and access details — department, assigned role within the organization (such as admin, user, or viewer), and the organization they belong to
  • Login and security data — authentication credentials (managed through a secure third-party authentication service — we do not store passwords directly), login verification records, and session information
  • Activity records — a log of actions taken within the Platform (such as creating a project, updating a record, or modifying settings), used for audit and accountability within the organization

This data is collected when an account is created by the organization's admin and updated as the user interacts with the Platform.

4.2 Corporate Entity Information

When a corporate customer is onboarded to the Platform, we store organizational information including:

  • Identity details — legal name, Corporate Identity Number (CIN), registered address, city, state, and industry classification
  • CSR program data — net profit figures, CSR budget allocations, project details, focus areas, and cost classifications (such as direct project spend and administrative overhead), as entered and managed by the corporate
  • Financial records — transaction amounts, dates, payment references, and allocation history, as recorded by the corporate through the Platform
  • Team configuration — allowed email domains for the workspace, and organizational settings chosen by the admin

All of this data is provided and maintained by the corporate customer — CSRPath stores and processes it to operate the service and does not use it for any other purpose.

4.3 Partner and NGO Organization Information

When a partner or NGO organization is onboarded to the Platform, we store:

  • Organization details — legal name, registered address, and legal form (such as Section 8 company, Society, Trust, or Statutory body)
  • Compliance documents — registration numbers for 12A, 80G, PAN, and GST, as provided by the organization

This data is provided by the partner organization and is used solely to operate the Platform.

4.4 Beneficiary Data

CSR programs ultimately serve individuals and communities — students, patients, families, and others. Corporates and partners may record information about these beneficiaries through the Platform to track program reach and outcomes.

CSRPath does not collect beneficiary data directly. All beneficiary information is entered by the corporate or partner managing the program. The type of data recorded varies by project and may include names, locations, demographic details, and other information relevant to the program's objectives.

Because CSR programs frequently serve children and young people — particularly in education-focused initiatives — beneficiary records may include personal data of minors. Corporates and partners entering such data are responsible for ensuring they have obtained appropriate consent or authorization, including from a parent or guardian where required under applicable law.

CSRPath processes beneficiary data only to provide the service and does not use it independently for any other purpose.

5. How We Use Data

We use the data we collect for the following purposes:

  • Operating the Platform — providing, maintaining, and improving CSRPath ONE and related services
  • Account management — creating and managing user accounts, verifying identity, and maintaining login security
  • Customer support — responding to queries and support requests submitted through the Platform
  • Security and fraud prevention — detecting unauthorized access, enforcing rate limits, and protecting the integrity of Platform data
  • Legal and regulatory compliance — meeting obligations under applicable Indian law, including responding to lawful requests from authorities
  • Service communications — sending transactional messages such as login verification codes, password resets, and account notifications

We do not use your data for advertising, marketing to third parties, or profiling. We do not sell personal data to anyone.

6. Legal Basis for Processing

We process personal data on one or more of the following grounds under applicable Indian law, including the Digital Personal Data Protection Act, 2023:

  • Consent — where you or your organization has provided consent for the collection and use of personal data, such as when registering for the Platform
  • Contractual necessity — where processing is required to deliver the service your organization has signed up for
  • Legitimate use — where processing is necessary for purposes such as maintaining Platform security, preventing fraud, or enforcing our Terms of Use
  • Legal obligation — where we are required to process or retain data to comply with applicable law, regulation, or a lawful order from an authority

Where consent is the basis for processing, it may be withdrawn at any time by contacting us. Withdrawal of consent does not affect the lawfulness of any processing carried out before the withdrawal.

7. Data Sharing & Disclosure

We do not sell, rent, or trade personal data. We share data only in the following circumstances:

Within the Platform

When a corporate and a partner organization are connected on the Platform, certain project-related data may be visible to both parties. The corporate organization controls what information is shared with its connected partners. No data is shared between unconnected organizations — each organization's workspace is fully isolated.

With service providers

We use a limited number of third-party service providers for purposes such as cloud infrastructure, data storage, computing, and transactional email delivery. These providers process data on our behalf and are bound by their own data protection terms.

When required by law

We may disclose personal data if required to do so by applicable law, regulation, court order, or a lawful request from a government authority.

8. Data Storage & Security

Where your data is stored

All customer and organizational data is stored on servers located in India. Certain supporting services, such as authentication and security verification, may process limited technical data through servers outside India.

How we protect your data

We take reasonable measures to protect personal data from unauthorized access, loss, misuse, or alteration. These include:

  • Each organization's data is logically isolated — no organization can access another's data through the Platform
  • User authentication includes a second verification step on login
  • Access to sensitive actions within the Platform is role-based and logged
  • Regular security reviews are conducted against standard vulnerability checklists
  • Automated daily backups are maintained for our production environment

No system can guarantee absolute security. If you become aware of any unauthorized access to your account, please contact us immediately at info@csrpath.in.

9. Data Retention & Deletion

How long we keep data

We retain personal data for as long as your organization's account is active on the Platform, or as needed to provide the service. Specific retention periods may vary depending on the type of data:

  • Account and user data — retained while the user's account is active. When a user is deactivated by their organization's admin, their profile data is retained in a deactivated state for administrative and audit purposes.
  • Organizational and program data — retained for the duration of the organization's use of the Platform, and for a reasonable period after account closure to allow for data export and to meet any statutory record-keeping requirements.
  • Activity and audit records — retained for a longer period to support compliance traceability. Because CSR programs operate under statutory obligations, a record of key actions may need to be preserved even after the underlying data has been modified or removed.

What happens when data is deleted

When a record is deleted by a user through the Platform, it is removed from the active workspace. However, a copy may be retained in our internal audit records for compliance and accountability purposes. This means that deletion from the user's view does not always mean permanent erasure from all systems.

If your organization wishes to close its account and request deletion of all associated data, please contact us at info@csrpath.in. We will process such requests within a reasonable timeframe, subject to any legal or regulatory obligations that require us to retain certain records.

10. Cross-Border Data Transfer

All customer and organizational data collected through the Platform is stored on servers located in India.

Some of the third-party service providers we use for infrastructure and email delivery may process limited operational data (such as email content during delivery) through servers that could be located outside India. Where this occurs, it is governed by the respective provider's own data protection terms and is limited to what is necessary to deliver the service.

11. Cookies and Tracking Technologies

The Platform uses cookies and similar technologies only where necessary to operate the service — such as maintaining your login session and remembering your preferences.

We do not use cookies for advertising, behavioral tracking, or profiling. We do not serve third-party advertising cookies on any of our websites.

We use a security verification service on certain forms (such as registration) to protect against automated abuse. This service may process technical information such as browser and device details for security analysis.

If we introduce analytics or usage-tracking tools in the future, this section will be updated to reflect what is collected and how you can manage your preferences.

12. External Links

Our websites and Platform do not currently contain links to third-party websites. However, users may share external links within their organization's workspace during the course of using the Platform. We are not responsible for the content, security, or privacy practices of any external websites accessed through such links. Users should exercise their own judgment and review the privacy policies of any third-party site they visit.

13. Your Rights

Under applicable Indian law, including the Digital Personal Data Protection Act, 2023, you have the following rights in relation to your personal data:

  • Access — you may request confirmation of whether we hold your personal data and, if so, a summary of that data
  • Correction — you may request that inaccurate or incomplete personal data be corrected or updated
  • Erasure — you may request deletion of your personal data, subject to any legal or regulatory obligations that require us to retain certain records
  • Consent withdrawal — where processing is based on your consent, you may withdraw that consent at any time. This does not affect the lawfulness of any processing carried out before the withdrawal
  • Grievance redressal — you have the right to raise a complaint about how your personal data is handled. Section 14 explains how to do this
  • Nomination — under the DPDP Act, you may nominate another individual to exercise your data rights on your behalf in the event of your death or incapacity

How to exercise your rights

If you are a platform user, some of these actions (such as correcting your profile information) can be done directly within the Platform. For all other requests, please contact us at info@csrpath.in. We will respond within a reasonable timeframe.

A note on organizational data

If your personal data was entered into the Platform by your organization (for example, as part of a CSR project's beneficiary records), your request may need to be directed to that organization first, since they control what data is recorded. We will assist where we can.

14. Grievance Officer / Contact

If you have any questions about this Privacy Policy, or wish to raise a concern about how your personal data is handled, you may contact us at:

Grievance Officer: Rahul Khareedula

Email: rahul.kh@csrpath.in

We will acknowledge your query and work to resolve it within a reasonable timeframe. If you are not satisfied with our response, you have the right to raise a complaint with the relevant data protection authority under applicable law.

15. Business Transfers

In the event that CSRPath undergoes a merger, acquisition, restructuring, or sale of assets, personal data held on the Platform may be transferred to the successor entity as part of that transaction. If such a transfer occurs, we will take reasonable steps to ensure that your data continues to be handled in a manner consistent with this Privacy Policy. Where required, we will notify affected users of any material change in how their data is processed.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our services, or applicable law. When we make changes, we will update the "Effective Date" at the top of this Policy.

For material changes that significantly affect how your personal data is handled, we will make reasonable efforts to notify you — such as through a notice within the Platform or an email to your registered address.

We encourage you to review this Policy periodically to stay informed.

17. Governing Law & Jurisdiction

This Privacy Policy is governed by and construed in accordance with the laws of India. Any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at Khammam, Telangana, India.