01 / OVERVIEW
1. Introduction & Governance Scope
Welcome to Prithvi Buildcon ("Company", "we", "our", or "us"). We are committed to safeguarding the privacy of our customers, buyers, investors, website visitors, and mobile application users. This Customer Data Privacy Policy and Application Security Framework outlines how we collect, process, store, protect, and dispose of personal information when you access or use:
- The official web portal at prithvibuildcon.com
- The dedicated mobile web/application portal at aap.prithvibuildcon.co
- Prithvi Buildcon iOS and Android native/hybrid mobile applications
- Our on-site customer service kiosks, customer relationship management (CRM) portals, and digital booking systems
This policy is formulated in strict compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act, India), the Information Technology Act, 2000 (including the Reasonable Security Practices and Procedures and Sensitive Personal Data or Information Rules, 2011), the Real Estate (Regulation and Development) Act, 2016 (RERA), Google Play Developer Distribution Agreement & User Data Policies, and Apple App Store Review Guidelines.
02 / DATA INVENTORY
2. Categories of Customer Data We Collect
In order to deliver seamless real estate browsing, project booking, construction updates, and financial advisory services, we collect the following categories of customer information:
A. Personal Identification & Contact Data
Full name, email address, mobile phone number, secondary contact number, permanent/current residential address, and profile photo when creating an account.
B. Statutory KYC & Property Documentation
Government-issued identification (PAN card, Aadhaar number/card copy, Passport) collected strictly when mandated for drafting legal agreements to sale, registry, bank loan applications, or RERA regulatory filings.
C. Property Preferences & Inquiries
Plot or unit size preferences, project location interest (e.g., Venus Park, Lotus Tower), budget limits, site visit schedule bookings, and feedback inquiries.
D. Financial & Transaction Logs
Booking token receipts, payment milestone transaction reference IDs, GST invoices, and payment mode history. Note: We never capture or store raw credit/debit card PINs or CVVs on our servers.
E. Geolocation Information
Approximate or precise device location (only with your explicit permission) to provide turn-by-turn navigation to project sites and show nearby residential or commercial properties.
F. Technical Telemetry & Device Data
Device hardware model, operating system version, unique device identifier (Android ID / IDFV), IP address, crash analytics, app build version, and network performance logs.
03 / USAGE PROTOCOL
3. How Customer Data Is Used & Legal Grounds
We process your information on lawful grounds including performance of contractual agreements, compliance with legal obligations (RERA & Tax laws), legitimate business interests, and explicit user consent:
| Operational Purpose |
Description of Processing |
Legal Basis |
| Project Booking & Allocation |
Processing real estate bookings, generating allotment letters, milestone tracking, and executing sales deeds. |
Contract Performance |
| RERA & Statutory Compliance |
Submitting required customer details to Real Estate Regulatory Authorities, municipal corporations, and taxation portals. |
Legal Obligation |
| Site Visits & Consultation |
Scheduling guided property visits, assigning sales advisors, and providing real-time property directions. |
User Consent |
| Construction Updates & Alerts |
Sending push notifications, SMS, or WhatsApp alerts regarding project progress, EMI schedules, and receipt generation. |
Contract Performance |
| Security, Fraud & Risk Prevention |
Detecting unauthorized access attempts, verifying OTPs, preventing malicious transactions, and server defense. |
Legitimate Interest |
04 / APP PERMISSIONS (GOOGLE PLAY & APPLE APP STORE)
4. Mobile App Device Permissions & Access
The aap.prithvibuildcon.co application requests only those device permissions that are strictly necessary to deliver core features. You can enable or revoke these permissions at any time via your device's system settings:
Location Services (ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION)
Why required: Used exclusively to help you find nearby Prithvi Buildcon projects, calculate driving distance, and provide turn-by-turn navigation during scheduled site visits. We do not track your location in the background when the app is closed.
Camera Access (CAMERA)
Why required: Used when you choose to take a photo of KYC documents (e.g., PAN card for registration verification), scan on-site QR codes, or update your customer profile photo.
Storage / Photo Library (READ_MEDIA_IMAGES / READ_EXTERNAL_STORAGE)
Why required: Required to allow you to upload property agreement documents, download project brochures, and save payment receipts/invoices directly to your device storage.
Push Notifications (POST_NOTIFICATIONS)
Why required: Delivers critical updates regarding project construction milestones, payment receipt confirmations, site visit alerts, and customer support ticket resolutions.
Biometric Authentication (USE_BIOMETRIC / Touch ID / Face ID)
Why required: Allows instant, secure app unlocking. Important: Biometric data remains securely stored in your device's hardware Secure Enclave / Android KeyStore and is never sent to our servers.
05 / CYBERSECURITY ARCHITECTURE
5. Application Security & Data Protection Standard
At Prithvi Buildcon, data security is engineered directly into our infrastructure stack using multi-tier enterprise defenses:
TLS 1.3 & Transport Encryption
All network communications between the mobile application, web portal (`aap.prithvibuildcon.co`), and backend cloud servers are encrypted using Transport Layer Security (TLS 1.3/HTTPS) with HSTS and Certificate Pinning to prevent Man-in-the-Middle (MitM) eavesdropping.
AES-256 Encryption at Rest
Sensitive records, customer identification details, and uploaded legal contracts are stored on encrypted database volumes using AES-256 cryptographic standards. Passwords are cryptographically salted and hashed using Bcrypt/Argon2.
Authentication & Session Hardening
We employ short-lived, signed JSON Web Tokens (JWT) / OAuth2 session tokens with automatic session timeouts, rate-limiting on login endpoints, and brute-force lockouts. Session cookies are configured with HttpOnly, Secure, and SameSite=Strict flags.
WAF, DDoS & Penetration Defense
Our server endpoints are protected behind advanced Web Application Firewalls (WAF) to filter SQL Injections (SQLi), Cross-Site Scripting (XSS), and Cross-Site Request Forgery (CSRF). We conduct continuous vulnerability scanning and periodic third-party penetration audits.
Breach Notification Protocol (CERT-In Compliance)
In the improbable event of a security anomaly or data breach affecting customer personal data, Prithvi Buildcon maintains an incident response protocol to notify the Indian Computer Emergency Response Team (CERT-In) and impacted data principals within statutory timelines (within 72 hours) along with remediation guidance.
06 / TRUSTED PROCESSORS
6. Third-Party Service Providers & Non-Sale Pledge
Our Absolute Commitment: We DO NOT sell, rent, monetize, or trade your personal customer data with external marketing brokers or unauthorized advertising networks.
We disclose data strictly on a need-to-know basis to vetted, compliant technical service providers who assist us in operating our platform:
- Cloud Infrastructure Providers: High-security ISO-27001 certified cloud servers (e.g., AWS / DigitalOcean / Linode) located in compliant data centers.
- PCI-DSS Compliant Payment Gateways: RBI-licensed payment processors (e.g., Razorpay, PayU, Stripe) to process booking payments safely without storing raw card data on our servers.
- Communication Gateways: Firebase Cloud Messaging (push alerts), official WhatsApp Business Cloud API, and Telecom Regulatory Authority of India (TRAI) compliant SMS gateways for OTPs.
- Statutory Authorities: Regulatory authorities including Chhattisgarh RERA, registrar offices, and judicial law enforcement authorities only when compelled by valid legal court orders.
07 / RETENTION & ACCOUNT ERASURE
7. Data Retention & Account Deletion Policy
We retain customer personal data only for as long as necessary to fulfill the purposes for which it was collected, or to comply with statutory legal, tax, and RERA accounting requirements.
How to Request Complete Account & Data Deletion
In adherence to Google Play Store & Apple App Store developer policies and the DPDP Act 2023, you have the unrestricted right to delete your account and associated personal data at any time:
1
In-App Self Service: Open the Prithvi Buildcon app > Navigate to Profile / Settings > Tap Privacy & Security > Select Delete My Account.
* Upon receipt of your confirmed deletion request, your active account profile, session credentials, device tokens, and marketing records are purged from our live database within 30 days. Non-identifying transactional records required by RERA/Tax statutory statutes are securely archived until statutory audit expiration.
08 / PRINCIPAL RIGHTS
8. Customer Data Privacy Rights
Under applicable data privacy laws, you possess the following enforceable rights regarding your personal information:
Right to Access & Summary
Request a complete summary of the personal data we hold about you and third-party processors who have received it.
Right to Correction & Update
Update, rectify, or complete any inaccurate, outdated, or incomplete personal details in our records.
Right to Withdraw Consent
Opt out of non-essential communications, marketing notifications, or revoke device permissions at will.
Right to Erasure / Forgotten
Request total erasure of your personal data when it is no longer required for legitimate or statutory purposes.
09 / SPECIAL PROTECTIONS
9. Children's Privacy & Minor Protection
Our services, properties, and mobile applications are designed solely for adults and individuals legally capable of entering into binding real estate transactions (18 years and above). We do not knowingly collect, track, or solicit personal data from children under 18 years of age. If you believe a minor has provided us with personal information, please contact us immediately, and we will promptly purge such records.
10 / STATUTORY OFFICER
10. Grievance Redressal Officer & Legal Contact
In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, the contact details of our designated Grievance Officer are published below:
Grievance Redressal & Data Protection Officer
Legal & Compliance Department, Prithvi Buildcon
Orrange Hive, 7th Floor, Office-706 Main Road, Mowa, Raipur - 492001, Chhattisgarh, India
Redressal Resolution Timelines
- Acknowledgment: Within 24 to 48 business hours of receipt.
- Investigation & Resolution: Completed within a maximum of 30 calendar days.
- Escalation: You retain the right to lodge a formal complaint with the Data Protection Board of India under the DPDP Act.