Skip to main content
GMDA-GMS Grievance Monitoring System
Home

Privacy Policy

Effective 1 September 2026 · Applies to the GMDA-GMS Field App and the GMDA-GMS web portal, which share the same backend and the same data practices.

1. Who This App Is For

GMDA-GMS (GMDA Grievance Monitoring System) is an internal system used by officers of the Guwahati Metropolitan Development Authority (GMDA) to register, process and track complaints and applications concerning unauthorized construction and related matters within GMDA's jurisdiction. It is not a public app: there is no self-registration, and no member of the public can create an account. Every account is created by a GMDA administrator for a specific officer.

2. Information We Collect

Account information. Your username, full name, email address, mobile number, and the role(s) an administrator has assigned you — used to identify you, deliver sign-in codes, and control what the app lets you do.

Case information. The details of the matters you or your colleagues register or process: the applicant's name, contact number and address, property/location details (ward, mouza, dag/patta number and similar), and the nature of the complaint.

Location data. Two distinct, purpose-specific kinds:

  • A GPS fix captured when you record a site inspection from the field app — where you stood when you made that observation. You may decline location permission and still record the inspection; it is simply saved without coordinates.
  • A GPS fix for where the site or property itself is, captured once per case so an officer can navigate there before ever visiting.

Photographs and documents. Images and PDFs you or a colleague upload as evidence, supporting documents, or at the start of a case, including photos captured directly through the field app's camera.

Device information. A label you choose for your device (e.g. "Rahul's Pixel 7"), its platform (Android/iOS), and a push-notification token issued by Firebase Cloud Messaging, so the app can alert you when a case is forwarded to you or reaches a status you've asked to be told about.

Authentication data. Your password and, if your account uses two-factor sign-in, one-time verification codes. Both are stored only as irreversible cryptographic hashes — never in plain text, and never written to any log.

Activity and audit data. The IP address a request came from, timestamps, and a record of actions taken on a case (forwarded, noted, its status changed) — kept for administrative accountability, in the same way a paper case file records who handled it and when.

3. How We Use This Information

Solely to operate the case management system: registering and processing the matters described above, verifying your identity when you sign in, notifying you about cases assigned to you, and investigating misuse or unauthorized access to an account. Nothing collected here is used for advertising, and nothing is sold.

4. Who Can See Your Data

Access is role-based: an officer sees only the cases and data their role and current assignment permit — the same rule the paper process followed, that a file is with one desk at a time. Location and photo data attached to a case are visible to whoever the case is forwarded to and to administrators, never published publicly. We do not sell, rent, or share your personal information with third parties for marketing purposes.

5. Service Providers We Use

A small number of external services help deliver the app's own functionality, each processing only what that function needs and never for their own separate purposes:

  • Amazon Web Services (S3) — stores uploaded photographs and documents.
  • Amazon Simple Email Service — delivers sign-in verification codes and notification emails.
  • An SMS gateway — delivers sign-in verification codes by text message.
  • Firebase Cloud Messaging (Google) — delivers push notifications to your device.

6. How We Protect Your Data

Passwords and one-time codes are hashed with an irreversible algorithm, never stored or logged as plain text. Every connection to the app, on both web and mobile, is encrypted (HTTPS/TLS). Sign-in can require a one-time code as well as a password (enabled per account by an administrator). Security-relevant actions — sign-ins, failed attempts, account changes — are recorded in an audit trail.

7. How Long We Keep Data

Records of verification emails/texts sent (not their content, and never the code itself) are kept for 90 days by default, then automatically deleted. Case records, notesheet entries, and the audit trail are kept as part of the official case file and are not deleted on a fixed schedule. When an officer leaves or no longer needs access, an administrator deactivates their account — this stops it from signing in, but does not erase the actions it performed, since those remain part of each case's permanent history.

8. Your Choices

You can sign a specific device out at any time from within the app, which revokes that device's access immediately; you can also ask an administrator to revoke a device on your behalf (for example, if it is lost). You can ask an administrator to correct your profile's contact details. Location permission for the field app is requested only when you use a feature that needs it, and declining it is always an option.

9. Children's Privacy

This is an internal tool for GMDA staff. It is not directed at, marketed to, or knowingly used by children.

10. Changes to This Policy

We may update this policy as the app's features change. The effective date at the top will always reflect the most recent version.

11. Contact Us

Questions about this policy, or a request to correct your account details, should go to your GMDA administrator, or to:
[GMDA Grievance Cell — insert official contact email/address here]