Privacy Policy
Meer Foundation has been trusted with the personal data of donors, volunteers, students, and beneficiaries for 15 years. This policy explains, in plain language, what we collect, why we collect it, how we protect it, and the rights you have over your own data.
A note on privacy
Meer Foundation, registered in Dhamtari, Chhattisgarh (Reg. No. 3588, 23 December 2011), is the data controller responsible for your personal data. This policy applies to all visitors, donors, volunteers, students, and beneficiaries who interact with our website, programmes, or field operations. It was last reviewed and updated in July 2026.
This Privacy Policy is published in compliance with the Digital Personal Data Protection Act, 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. It is a living document — reviewed annually and updated whenever our data practices change materially.
By using this website, providing your personal data, or participating in any Meer Foundation programme, you acknowledge that you have read and understood this policy.
Lawful basis
We process personal data only on a lawful basis — consent, contract, legal obligation, or legitimate interest — and document the basis for each processing activity.
Minimal collection
We collect only the personal data that is necessary for a clearly defined purpose. No data is collected 'just in case' or for unspecified future uses.
Never sold
We do not sell, rent, or trade personal data. Third-party sharing is strictly limited to what is described in this policy.
What we collect — and why
We collect only the categories of personal data necessary for clearly defined purposes. The list below is exhaustive; if we ever need to collect a new category, we will update this policy and notify you before doing so.
Identity & contact
Name, email address, phone number, postal address — collected when you fill out a form, register for a course, sign up to volunteer, or subscribe to our newsletter.
Donation details
Transaction identifier, amount, date, and PAN (where required for 80G tax exemption). We do not store full card numbers, CVV, or net-banking credentials — these are handled entirely by our PCI-DSS-compliant payment gateway.
Form submissions
Volunteer applications, internship applications, CSR partnership enquiries, course enrolment forms, contact-form messages, and feedback submissions — including any free-text content you provide.
Usage & technical
IP address, browser type, device type, pages visited, and time spent — collected via cookies and analytics. This data is anonymised and aggregated; it is never used to identify an individual.
Programme records
For beneficiaries of our initiatives — SHG membership, training attendance, asset distribution, and outcome indicators. This data is collected with informed consent and stored separately from web-platform user data.
Purposes of processing
Each category of data we collect is tied to one or more specific purposes. We do not use your data for any purpose that is incompatible with the purpose for which it was originally collected.
How we protect your data
Data protection is not a one-time configuration — it is a continuous practice. The measures below are reviewed every quarter by our internal information-security working group and audited externally once a year.
Encryption in transit
All data submitted through this website is transmitted over TLS 1.3 (HTTPS). No plain-text transmission of personal information occurs on any page.
Encryption at rest
Personal data stored in our databases is encrypted using AES-256. Database backups are encrypted and stored in geographically separated facilities.
Role-based access control
Access to personal data is restricted on a need-to-know basis. Field teams see only the records of beneficiaries they directly work with; finance teams see only donation records; no single user has unrestricted access.
Regular audits
Internal data-handling audits are conducted twice a year. An external information-security review is commissioned annually. Findings are reviewed by the Management Committee.
Breach response
In the event of a confirmed data breach affecting personal information, we will notify the Data Protection Authority of India within 72 hours and affected users without undue delay.
Vendor due diligence
Every third-party processor — payment gateway, hosting provider, email service — is contractually bound to equivalent or stronger data-protection standards.
Data retention
Personal data is retained only as long as necessary for the purpose it was collected. Donation records are retained for 8 years as required by the Income Tax Act 1961. Programme beneficiary records are retained for 10 years for longitudinal impact assessment. Web-platform account data is retained until you request deletion, subject to statutory retention. Once the retention period expires, data is securely deleted or irreversibly anonymised.
Who we share with — and who we never share with
We share personal data with third parties only when necessary to deliver our services, comply with the law, or protect our legitimate interests. We never sell personal data. The list below is exhaustive.
We share with
- Payment gateways — to process donations. They receive only transaction identifiers and amounts; we never share your full card or banking details with them (you submit those directly on their PCI-DSS-compliant pages).
- Government authorities — when legally required. This includes the Income Tax department (80G donations), NGO Darpan, and the Societies Registrar.
- Hosting & email providers — to operate this website and send transactional emails. They are contractually bound to process data only on our instructions.
- Auditors — for statutory audit and CSR compliance. They receive aggregated or anonymised data wherever possible and are bound by confidentiality agreements.
We never share with
- Data brokers — we do not engage in any form of data broking.
- Advertising networks — we do not run any advertising on this website and do not share data with ad networks.
- Commercial partners — for marketing or lead generation. CSR partners receive only aggregated, anonymised impact data.
- Anyone, for money — personal data is never sold, rented, or traded for any consideration.
Your rights over your data
Under the Digital Personal Data Protection Act 2023 and applicable IT Rules, you have specific rights over your personal data. Exercising any of these rights is free of charge. Email meercare@live.com to begin.
How to exercise your rights
Email meercare@live.com with the subject line corresponding to your request (e.g., “Data Access Request”, “Data Correction Request”, “Data Deletion Request”). We will verify your identity and respond within 30 days. If we cannot comply — for example, because of a statutory retention obligation — we will explain why.
Questions about privacy?
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out. Our designated Data Protection Officer will respond within 7 business days.
Frequently asked questions
No. Meer Foundation has never sold, and will never sell, personal data to any third party — commercial, governmental, or otherwise. We do not engage in any form of data broking.