०१
स्थिती आणि व्याप्ती
ही सूचना फक्त सहकार मित्रच्या प्रतीक्षा यादीत रस नोंदवताना दिलेल्या मर्यादित संपर्क माहितीसाठी आहे. उत्पादन वापर, व्हॉट्सअॅप संभाषणं, पैसे, वकिलांची सेवा किंवा सोसायटीच्या प्रकरणांचा डेटा यासाठी स्वतंत्र सूचना आणि अटी लागतील.
२७ जुलै २०२६ रोजीची कायदेशीर स्थिती: डिजिटल वैयक्तिक डेटा संरक्षण अधिनियम, २०२३ मधील सूचना, संमती, डेटा सांभाळणाऱ्याची मुख्य कर्तव्यं, व्यक्तीचे हक्क आणि मुलांच्या डेटाविषयीची मुख्य कलमं १३ मे २०२७ पासून लागू होण्यासाठी अधिसूचित आहेत. त्यांच्याशी संबंधित मुख्य नियमही त्या दिवशी लागू होतील. तोपर्यंत माहिती तंत्रज्ञान अधिनियम, २००० चे कलम ४३A आणि २०११ चे संबंधित नियम लागू राहतात.
ही सूचना आज लागू असलेल्या नियमांनुसार माहिती देते आणि अधिसूचित आगामी चौकटीतील सूचना, संमती, सुरक्षा व हक्क यांचीही तयारी करते.
०२
प्रतीक्षा यादीत काय घेतलं जातं
प्रतीक्षा यादीचा फॉर्म पुढील माहितीपुरताच मर्यादित आहे:
एक संपर्क मार्गईमेल पत्ता किंवा भारतीय मोबाइल क्रमांक—आवश्यक.
ऐच्छिक भूमिकासचिव, अध्यक्ष, खजिनदार, समिती सदस्य, सोसायटी व्यवस्थापक, सदस्य किंवा इतर.
ऐच्छिक जिल्हा व आवडसध्याचा फॉर्म महाराष्ट्रातील ३६ जिल्ह्यांपैकी एक जिल्हा घेतो; आणि अनुपालन, सभा, थकबाकी, नोटिसा, नोंदी किंवा इतर. डेटाबेस योजनेतील जुना ऐच्छिक शहर-स्तंभ स्थलांतर-सुसंगततेसाठी राखला आहे; सध्याचा फॉर्म तो पाठवत नाही.
सर्व्हरने जोडलेली नोंदमराठी/इंग्रजी भाषा, संमतीची तारीख व वेळ, या सूचनेची व संमती-मजकुराची आवृत्ती आणि ब्राउझरने तयार केलेल्या पुनर्प्राप्ती कीचा SHA-256 हॅश. मूळ की डेटाबेसमध्ये साठवली जात नाही.
संदिग्ध पुन्हा-प्रयत्नासाठी ब्राउझर नोंदप्रतिसाद हरवल्यास तीच वजा करण्याची की पुन्हा वापरता यावी म्हणून मूळ धारक-वजा करण्याची गुप्त की आणि संपर्काचा नियत SHA-256 फिंगरप्रिंट प्रत्येक टॅबच्या sessionStorage मध्ये ठेवले जातात. त्याच मूळाच्या JavaScript ला ही माहिती वाचता येते. ती cookies किंवा localStorage मध्ये ठेवली जात नाही आणि साधारणपणे टॅब/ब्राउझर सत्र बंद झाल्यावर साफ होते. मूळ की URL query, अनुप्रयोग logs किंवा D1 मध्ये जात नाही.
निवडलेली भाषा localStorage मध्ये जतन होते आणि फॉर्मसोबत mr किंवा en म्हणून पाठवली जाते. बॉट-सापळा फील्ड भरल्यास विनंती स्वीकारल्यासारखी दिसते, पण कोणतीही प्रतीक्षा यादी नोंद साठवली जात नाही.
वेबसाइट आणि फॉर्म सुरक्षितपणे पोहोचवताना Cloudflare ला IP पत्ता, विनंतीची वेळ, मागितलेला URL आणि ब्राउझर/डिव्हाइसची तांत्रिक व सुरक्षा माहिती प्रक्रिया करावी लागू शकते. ही नेटवर्क माहिती प्रतीक्षा यादीच्या D1 नोंदीत जोडली जात नाही. आम्ही स्वतंत्र विश्लेषण साधन, जाहिरात ट्रॅकर किंवा जाहिरात cookie वापरत नाही.
आम्हाला यांची गरज नाही आणि आम्ही ती मागणार नाही: आधार किंवा इतर ओळखपत्र, पासवर्ड, बँक/कार्ड माहिती, आरोग्य किंवा बायोमेट्रिक माहिती, सोसायटीची सभासद यादी, केस क्रमांक, नोटीस, करार, पुरावे किंवा इतर कायदेशीर कागदपत्रं.
०३
ही माहिती का वापरली जाईल
- तुमची प्रतीक्षा यादीतील विनंती नोंदवण्यासाठी;
- उत्पादन सुरू होण्याची बातमी, मर्यादित प्रायोगिक वापराची संधी किंवा निमंत्रण पाठवण्यासाठी;
- तुमची संपर्क निवड, संमती मागे घेण्याची किंवा डेटा मिटवण्याची विनंती हाताळण्यासाठी;
- तक्रारी, सुरक्षितता आणि प्रतीक्षा यादीची साधी एकत्रित संख्या सांभाळण्यासाठी.
हा डेटा जाहिरातींचं लक्ष्य ठरवण्यासाठी, व्यक्तीचं प्रोफाइल बनवण्यासाठी, डेटा विकण्यासाठी/भाड्याने देण्यासाठी किंवा असंबंधित प्रचारासाठी वापरला जाणार नाही. प्रतीक्षा यादी कायदेशीर माहिती किंवा सल्ला देणार नाही.
०४
तुमची संमती
फॉर्म नोंदणीच्या आधी या सूचनेची लिंक आणि पूर्वनिवड न केलेली संमतीची चौकट दाखवतो. संमती स्वेच्छेची, विशिष्ट, माहितीवर आधारित आणि स्पष्ट आहे. आवश्यक नसलेला डेटा किंवा असंबंधित प्रचार त्यात जोडलेला नाही.
नोंदणी न करणं पूर्णपणे ऐच्छिक आहे. संमती दिल्याचा पुरावा म्हणून केवळ आवश्यक नोंद ठेवली जाईल. नवीन नोंदीनंतर दाखवलेली पुनर्प्राप्ती की जतन केल्यास स्वयं-सेवा मार्गाने संपूर्ण सक्रिय नोंद काढता येते. फक्त ईमेल किंवा मोबाइल क्रमांक देणं हे मिटवण्याचा अधिकार मानलं जात नाही.
सध्याचा फॉर्म माहिती देणारी व्यक्ती दिलेल्या ईमेल किंवा मोबाइलची मालक आहे किंवा त्यावर तिचं नियंत्रण आहे हे पडताळत नाही. पुनर्प्राप्ती की ही फक्त धारक-वजा करण्याची गुप्त की आहे; ती संपर्काची मालकी सिद्ध करत नाही. खरी ईमेल पुष्टी किंवा निवडलेली व चाचणी केलेली दूरसंचार-नियमांशी सुसंगत SMS/WhatsApp OTP व्यवस्था जोडली जाईपर्यंत उत्पादन संदेश आणि प्रवेश पाठवले जाणार नाहीत. सध्या कोणतीही संदेश सेवा जोडलेली नाही.
०५
सेवा पुरवठादार आणि डेटा कुठे राहील
ही वेबसाइट आणि फॉर्म Cloudflare Workers वर चालतात आणि प्रतीक्षा यादीची सक्रिय नोंद Cloudflare D1 मध्ये राहते. Cloudflare चे नेटवर्क, डेटाबेस व आपत्ती-पुनर्प्राप्ती तंत्र ऑपरेटरच्या वतीने ही माहिती प्रक्रिया करतात. कोणतीही स्वतंत्र ईमेल, SMS किंवा WhatsApp संदेश सेवा सध्या जोडलेली नाही.
Cloudflare चा आशिया-पॅसिफिक स्थान-संकेत एखाद्या विशिष्ट देशाची हमी देत नाही. नेटवर्क प्रक्रिया आणि सेवा-पुनर्प्राप्ती प्रती भारताबाहेर असू शकतात. सेवा पुरवठादाराला केवळ आवश्यक कामापुरता प्रवेश दिला जातो आणि लागू करार व सुरक्षा बंधनं वापरली जातात.
कायद्याने बंधनकारक मागणी आल्यास किंवा हक्कांचं संरक्षण करण्यासाठी आवश्यक असल्यास माहिती सक्षम प्राधिकरणाला दिली जाऊ शकते. प्रतीक्षा यादीची माहिती विकली किंवा भाड्याने दिली जाणार नाही.
०६
डेटा किती काळ ठेवला जाईल
डेटा फक्त प्रतीक्षा यादीचं सांगितलेलं काम सुरू असेपर्यंत आणि त्या कामासाठी आवश्यक असेपर्यंत ठेवला जातो. एखादा मनमानी कालावधी पूर्ण झाला म्हणून नव्हे, तर उद्देश संपणं, संमती मागे घेणं किंवा निमंत्रणावरील निर्णय यामुळे सक्रिय नोंद काढली जाते.
| नोंद | राखीव नियम |
| सक्रिय प्रतीक्षा यादी संपर्क | तुम्ही संमती मागे घेईपर्यंत, निमंत्रण स्वीकारेपर्यंत/नकार देईपर्यंत किंवा प्रतीक्षा यादी/प्रायोगिक उद्देश बंद होईपर्यंत—यापैकी जे आधी होईल. |
| वैध पुनर्प्राप्ती कीने स्वयं-सेवा काढणं | त्याच यशस्वी विनंतीत सक्रिय D1 नोंद पूर्णपणे मिटवली जाते; वेगळी सक्रिय टूम्बस्टोन नोंद तयार होत नाही. प्रतिसादात नोंद अस्तित्वात होती की नाही हे सांगितलं जात नाही. |
| सेवा-पुनर्प्राप्ती प्रती | Cloudflare च्या त्या वेळी लागू असलेल्या मर्यादित पुनर्प्राप्ती चक्रानुसार त्या कालबाह्य होतात. सक्रिय नोंद काढल्यावर या इतिहासातील प्रती ताबडतोब नाहीशा होतीलच असं नाही. आम्ही वेगळे मॅन्युअल डेटाबेस exports तयार करत नाही. |
| किमान संमती, सुरक्षा, विनंती व तक्रार नोंदी | संमती किंवा विनंती सिद्ध करणं, गैरवापर रोखणं, तक्रार सोडवणं किंवा लागू कायद्याचं पालन करणं यासाठी आवश्यक तेवढ्याच काळासाठी. |
पुनर्प्राप्ती इतिहासातून सेवा पूर्वस्थितीत आणावी लागल्यास, नोंदवलेल्या काढण्याच्या विनंत्या पुन्हा लागू करून त्यांची नोंद सामान्य वापरापूर्वी मिटलेली असल्याची खात्री केली जाईल. कायद्याने एखादी किमान नोंद ठेवणं आवश्यक असल्यास ती वेगळी, मर्यादित आणि सांगितलेल्या उद्देशासाठीच ठेवली जाईल.
०७
तुमच्या निवडी आणि विनंत्या
वैध पुनर्प्राप्ती की असलेल्या नोंदींसाठी स्वयं-सेवा काढण्याचा मार्ग उपलब्ध आहे. कीचा फक्त SHA-256 हॅश साठवला जातो, URL तुकड्यातील की सर्व्हरला पान मागताना पाठवली जात नाही आणि निकाल नोंद होती की नव्हती हे उघड करत नाही. ही की जुळणारी नोंद काढण्याचा अधिकार देते, संपर्काची मालकी पडताळत नाही.
संमती मागे घेणं, तुमचा डेटा पाहणं किंवा दुरुस्त करणं, पुनर्प्राप्ती की हरवलेली/जुनी नोंद मिटवणं किंवा इतर गोपनीयता विनंतीसाठी privacy@sahakarmitra.in वर लिहा. विनंतीच्या स्वरूपानुसार वाजवी ओळख किंवा नियंत्रण पडताळणी मागितली जाऊ शकते. फक्त ईमेल किंवा मोबाइल क्रमांक माहित असणं स्वतःहून मिटवण्याचा अधिकार देत नाही.
तक्रारीसाठी grievance@sahakarmitra.in वर तक्रार अधिकाऱ्याला लिहा. शक्य तितक्या लवकर आणि प्राप्त झाल्यापासून एका महिन्याच्या आत उत्तर दिलं जाईल. कायद्यानुसार काही डेटा ठेवावा लागल्यास, शक्य असेल तिथे कारण आणि कालावधी सांगितला जाईल. संबंधित DPDP तक्रार तरतुदी लागू झाल्यावर, आधी अंतर्गत तक्रार मार्ग वापरून नंतर डेटा संरक्षण मंडळाकडे जाता येईल.
०८
सुरक्षा
आम्ही डेटा कमी ठेवणं, HTTPS, फील्ड व request-body मर्यादा, same-origin तपासणी, बॉट-सापळा, rate limiting, D1 व deployment प्रवेशावर मर्यादा आणि घटना प्रतिसाद यांसारखे जोखमीला अनुरूप उपाय वापरतो. D1 मध्ये मूळ पुनर्प्राप्ती कीऐवजी फक्त तिचा SHA-256 हॅश ठेवला जातो.
कोणतीही इंटरनेट व्यवस्था पूर्णपणे सुरक्षित नसते. घटना घडल्यास ती नियंत्रित करणं, आवश्यक नोंदी सुरक्षित ठेवणं आणि त्या वेळी लागू कायद्यानुसार CERT-In, इतर सक्षम प्राधिकरण किंवा प्रभावित व्यक्तींना कळवणं यासाठी प्रक्रिया वापरली जाईल.
०९
१८ वर्षांखालील व्यक्ती
प्रतीक्षा यादी फक्त १८ वर्षं पूर्ण केलेल्या व्यक्तींसाठी आहे. १८ वर्षांखालील व्यक्तीने नोंदणी करू नये किंवा संपर्क माहिती पाठवू नये. आमच्याकडे पालक-संमतीची व्यवस्था नाही आणि आम्ही मुलांचा डेटा जाणूनबुजून घेत नाही. मुलाची माहिती मिळाल्याचं कळल्यास ती पडताळून शक्य तितक्या लवकर मिटवली जाईल.
१०
कायदेशीर प्रश्न किंवा कागदपत्रं पाठवू नका
प्रतीक्षा यादीत कायदेशीर प्रश्न विचारण्यासाठी किंवा नोटीस, करार, ठराव, सभासद यादी, कोर्ट/निबंधक कागदपत्रं अथवा पुरावे अपलोड करण्याची जागा नसेल. गोपनीयता संपर्कावरही अशी माहिती पाठवू नका.
मागितली नसताना अशी माहिती आली तर ती कायदेशीर सल्ल्यासाठी स्वीकारली जाणार नाही, तिच्यावर वकील–अशील गोपनीयता लागू असल्याचं मानलं जाणार नाही आणि सुरक्षितपणे मिटवण्याचा योग्य प्रयत्न केला जाईल.
११
या सूचनेतील बदल
या सूचनेवर लागू होण्याची तारीख आणि आवृत्ती क्रमांक दिसतो. डेटा, उद्देश, सेवा पुरवठादार, साठवण किंवा संपर्क मार्गात महत्त्वाचा बदल झाला तर ही सूचना अद्ययावत केली जाईल. नवीन उद्देशासाठी कायद्याने गरज असल्यास नवीन संमती घेतली जाईल; आधीची संमती असंबंधित उद्देशासाठी वापरली जाणार नाही.
१३
या सूचनेसाठी पाहिलेले अधिकृत कायदेशीर स्रोत
खालील दुवे भारत सरकारच्या अधिकृत मजकुराकडे नेतात. हा साधा सारांश त्या मजकुराची जागा घेत नाही.
वर जा ↑
01
Status and scope
This notice is only for limited contact information supplied when registering interest in the Sahakar Mitra waitlist. Product use, WhatsApp conversations, payments, advocate services, and housing-society matter data would need separate notices and terms.
Legal position on 27 July 2026: the notice, consent, principal Data Fiduciary duties, individual rights, and child-data provisions in the Digital Personal Data Protection Act, 2023 have been notified to commence on 13 May 2027. Their corresponding Rules commence on the same date. Until then, section 43A of the Information Technology Act, 2000 and the relevant 2011 Rules remain in place as applicable.
This notice explains the processing under the framework in force today and also prepares for the notified incoming requirements on notice, consent, security, and individual rights.
02
What the waitlist collects
The waitlist form is limited to:
One contact routeAn email address or Indian mobile number—required.
Optional roleSecretary, chairperson, treasurer, committee member, society manager, member, or other.
Optional district and interestThe current form collects one of Maharashtra’s 36 districts; and compliance, meetings, dues, notices, records, or other. The database schema retains a legacy optional city column for migration compatibility; the current form does not submit it.
Server-added recordMarathi/English language, consent date and time, this notice and consent-text version, and the SHA-256 hash of the browser-generated recovery key. The raw key is not stored in the database.
Browser record for ambiguous retriesThe raw bearer deletion token and a deterministic SHA-256 contact fingerprint are kept in per-tab sessionStorage so the same token can be retried after a lost response. Same-origin JavaScript can access this session data. It is not kept in cookies or localStorage and normally clears when the tab/browser session ends. The raw token is not put in a URL query, application logs, or D1.
Your language choice is saved in browser localStorage and sent with the form as mr or en. If the bot-trap field is filled, the request appears accepted but no waitlist record is stored.
When securely delivering the site and form, Cloudflare may process the IP address, request time, requested URL, and browser/device technical and security metadata. This network information is not added to the waitlist row in D1. We do not use a separate analytics tool, advertising tracker, or advertising cookie.
We do not need and will not ask for: Aadhaar or other identity documents, passwords, bank/card details, health or biometric information, society member lists, case numbers, notices, agreements, evidence, or any other legal documents.
03
Why we use it
- to record your request to join the waitlist;
- to send a launch update, limited pilot opportunity, or invitation;
- to manage your contact choice, withdrawal, and deletion request;
- to handle grievances, security, and simple aggregate waitlist counts.
The data is not used for targeted advertising, individual profiling, sale or rental, or unrelated promotion. The waitlist does not provide legal information or advice.
04
Your consent
The form links to this notice before signup and uses an unticked consent box. Consent is voluntary, specific, informed, and unambiguous. It is not bundled with unnecessary data collection or unrelated promotion.
Joining is optional. Only the minimum record needed to evidence the signup is kept. Saving the recovery key shown after a new signup enables self-service deletion of the complete active entry. Supplying an email address or mobile number alone is never treated as deletion authority.
The current form does not verify that the person submitting it owns or controls the supplied email address or mobile number. The recovery key is a bearer deletion secret only; it does not prove contact ownership. Product messages and access will not be sent until a real email-confirmation flow or a selected and tested telecom-compliant SMS/WhatsApp OTP flow is integrated. No messaging service is currently connected.
05
Service providers and where data is stored
This site and form run on Cloudflare Workers, and the active waitlist record is stored in Cloudflare D1. Cloudflare’s network, database, and disaster-recovery systems process this information on the operator’s behalf. No separate email, SMS, or WhatsApp messaging service is currently connected.
Cloudflare’s Asia-Pacific location hint does not guarantee a particular country. Network processing and service-recovery copies may be outside India. Provider access is limited to the work required and is governed by applicable contractual and security safeguards.
Information may be disclosed to a competent authority when legally required, or where necessary to protect legal rights. Waitlist information will not be sold or rented.
06
How long data is kept
Data is kept only while the stated waitlist activity continues and the data remains necessary for that purpose. An active entry ends because the purpose ends, consent is withdrawn, or an invitation is decided—not merely because an arbitrary timer expires.
| Record | Retention rule |
| Active waitlist contact | Until you withdraw, accept/decline an invitation, or the waitlist/pilot purpose closes, whichever comes first. |
| Self-service removal with a valid recovery key | The complete active D1 row is deleted in that successful request; no separate active tombstone is created. The response does not reveal whether an entry existed. |
| Service-recovery copies | They expire under Cloudflare’s then-applicable limited recovery cycle. Removing an active entry may not immediately erase copies in that history. We do not create separate manual database exports. |
| Minimal consent, security, request, and grievance records | Only for as long as needed to evidence consent or a request, prevent misuse, resolve a grievance, or comply with applicable law. |
If the service must be restored from recovery history, documented removal requests will be reapplied and their rows confirmed absent before normal use resumes. Where law requires a minimal record to be retained, it is kept separately, narrowly, and only for that stated purpose.
07
Your choices and requests
A self-service removal route is available for entries with a valid recovery key. Only the key’s SHA-256 hash is stored, a key in the URL fragment is not sent when the page is requested, and the result does not reveal whether an entry existed. The key authorises deletion of a matching row but does not verify contact ownership.
To withdraw consent, access or correct your data, delete an older entry or one whose recovery key was lost, or make another privacy request, email privacy@sahakarmitra.in. Reasonable identity or control verification may be requested depending on the request. Knowing an email address or mobile number alone does not establish deletion authority.
For a grievance, email the Grievance Officer at grievance@sahakarmitra.in. We will respond as soon as practicable and within one month of receipt. If data must be kept by law, the reason and period will be explained where possible. Once the relevant DPDP complaint provisions commence, you may approach the Data Protection Board after first using the internal grievance route.
08
Security
We use risk-appropriate measures including data minimisation, HTTPS, field and request-body limits, same-origin checks, a bot trap, rate limiting, restricted D1 and deployment access, and incident response. D1 stores only the recovery key’s SHA-256 hash, not the raw key.
No internet system is completely secure. If an incident occurs, we will use processes to contain it, preserve necessary records, and notify CERT-In, another competent authority, or affected people as required by the law then in force.
09
People under 18
The waitlist is for people who have completed 18 years of age. A person under 18 must not sign up or send contact details. We have no parental-consent flow and do not knowingly collect children’s data. If we learn that a child’s information was received, it will be verified and erased as soon as reasonably possible.
10
Do not send legal questions or documents
The waitlist will not provide a space to ask legal questions or upload notices, agreements, resolutions, member lists, court/Registrar papers, or evidence. Do not send those materials to the privacy contact either.
If unsolicited material arrives, it will not be accepted for legal advice, it should not be assumed to be confidential or protected by advocate–client privilege, and reasonable steps will be taken to delete it securely.
11
Changes to this notice
This notice shows its effective date and version. It will be updated for a material change to the data, purpose, service providers, storage, or contact route. Fresh consent will be requested where required for a new purpose; an earlier consent will not be repurposed for an unrelated purpose.
13
Official legal sources reviewed for this notice
These links lead to official Government of India materials. This plain-language summary does not replace them.
Back to top ↑