Privacy Policy
This policy explains how Smart VC collects, uses, stores, shares, and protects personal and administrative data generated by Village Council officials and District Administration officers.
01Introduction
This Privacy Policy explains how Smart VC collects, uses, stores, shares, and protects personal and administrative data generated by Village Council (VC) officials and District Administration officers who use the Smart VC application. Smart VC is a role-based digital governance platform developed to modernise Village Council administration across Lunglei and Hnahthial districts of Mizoram.
Accounts are created and assigned by District Admins or Council Presidents — users do not self-register. By using Smart VC, users acknowledge that they have read and understood this policy. Continued use of the application constitutes acceptance of the data practices described herein.
02Scope and Applicability
This policy applies to:
- All registered users of the Smart VC mobile application (Android and iOS).
- Users of the Smart VC District Administration Dashboard.
- All data created, transmitted, stored, or processed within the Smart VC platform.
- District Admin officers and Council Presidents exercising supervisory and account-management functions.
This policy does not apply to third-party websites or services that may be linked from Smart VC communications.
03Information We Collect
3.1 Authentication Data
Smart VC uses mobile number and one-time password (OTP) authentication. The only personal information collected at the point of authentication is the user's registered mobile phone number. No passwords are created or stored. Name, designation, Village Council affiliation, and role are assigned administratively by a District Admin or Council President when the account is created; users do not enter this information themselves.
3.2 Administrative Records
Smart VC digitises existing VC administrative functions. As part of normal use, the system stores:
- Meeting minutes and formal resolutions, which may include typed text and attached photos or PDF documents uploaded by the user. Uploaded files are stored as-is; no content extraction, OCR, or indexing is performed on attachments.
- Village works records, project progress updates, and completion reports.
- Correspondence between Village Councils and district offices. While message content is only accessible to authorised parties, metadata for all correspondence — including sender identity, recipient, and timestamp — is always logged regardless of the confidentiality of the content.
- Financial registers maintained by Treasurers. These may include transaction amounts, dates, payee or vendor names, descriptions, and supporting documents. Most financial fields are optional; the level of detail recorded varies by council practice.
- Documents, notices, and circulars issued by the district administration.
- Private one-to-one messages between users. These are subject to stricter access control: unlike other records, private messages are not accessible to a user's successor if that user leaves office (see Section 10).
3.3 Activity and Audit Data
To support transparency, accountability, and supervisory oversight, the system automatically records:
- Login timestamps and session information for each user.
- Actions performed within the application — record creation, editing, submission, and deletion requests.
- The identity of the user associated with each action, forming a permanent audit trail.
- Correspondence metadata: sender identity, recipient, and timestamp are logged for all messages, including private correspondence, even where message content is restricted.
- Deletion requests, approvals, and rejections with reasons.
- Access logs visible to District Admin for oversight purposes.
3.4 Device and Notification Data
Smart VC uses a third-party push notification service to deliver notifications to users' devices. For this purpose, the application collects a device identifier generated by the notification service, used solely to route push notifications to the correct device. This identifier is transmitted to the notification service provider's infrastructure. The notification service does not receive any VC administrative record content as part of this process.
Push notifications sent by Smart VC may include message previews or record-related details (for example, the subject of a new correspondence item). Users should be aware that this content may be visible on device lock screens depending on the user's device notification settings.
Beyond the device identifier required for notification delivery, the application collects basic technical information — including device operating system version and application version — to ensure compatibility and support. No crash reporting service is used; error logs remain within the cloud hosting environment.
04How We Use Your Information
Smart VC uses the information collected solely for the following purposes:
- Authentication and access control — verifying user identity via OTP and enforcing role-based permissions.
- Record digitisation and storage — maintaining structured, searchable digital records of VC administration.
- Correspondence management — enabling secure digital communication between VCs and district offices, with full metadata logging for audit purposes.
- Push notification delivery — alerting users to new correspondence, circulars, and activity relevant to their role via Firebase Cloud Messaging.
- Monitoring and reporting — providing District Admin with dashboards, activity summaries, and compliance visibility.
- Audit trail maintenance — recording all significant actions to support accountability and dispute resolution.
- System security and integrity — detecting unauthorised access, preventing data loss, and maintaining application reliability.
- Service improvement — analysing anonymised usage patterns to improve application performance and user experience.
We do not use personal data for commercial profiling, advertising, or any purpose outside of legitimate e-governance functions.
05Legal Basis for Data Processing
Smart VC processes data under the following legal bases:
- Public task and lawful authority — processing is necessary for the performance of official government administrative functions carried out by Village Councils and district administration under applicable Mizoram state laws and local governance statutes.
- Legitimate interests — audit trail and security logging, including metadata logging of all correspondence, are necessary to protect the integrity of official records and prevent unauthorised access or tampering.
- Consent — where processing involves optional data fields (such as financial register entries) or notification preferences, processing is based on informed consent given through continued use of the application.
06Data Sharing and Disclosure
6.1 Within the Smart VC System
Data is shared within Smart VC strictly on a need-to-know basis, governed by role-based access control:
- VC Secretaries can access records, minutes, and correspondence for their own Village Council only.
- VC Members have read access to records relevant to their roles within their own Village Council.
- Treasurers can access and maintain financial registers for their own Village Council.
- Council Presidents can create and manage user accounts within their Village Council.
- District Admins have supervisory access to activity logs, dashboards, and submitted reports across all Village Councils within their district.
- No user can access records of a different Village Council without explicit authorisation.
6.2 Government and Legal Disclosure
We may disclose data to other government bodies or law enforcement agencies where required by law, court order, or for the prevention or investigation of unlawful activity. Such disclosures will be limited to the minimum information necessary and documented in the audit trail.
6.3 No Commercial Sale of Data
Smart VC does not sell, rent, license, or otherwise commercially exploit personal data or administrative records to any third party.
07Data Retention
Smart VC retains all administrative records, correspondence, and associated data for a period of 10 years from the date of creation. This retention period is designed to:
- Ensure continuity of Village Council records across changes in elected or appointed officials.
- Support audit, legal, and regulatory requirements applicable to local government bodies.
- Enable historical reporting and trend analysis for district administration.
Daily automated backups are performed and retained in accordance with the 10-year retention policy. Backup integrity is verified regularly.
At the conclusion of the retention period, data will be reviewed for archival or secure deletion in accordance with applicable government records management policies.
08Data Security
Smart VC implements technical and organisational security measures appropriate to the sensitivity of government administrative data, including:
- OTP-based authentication — no passwords are stored; access is verified at each session via one-time codes sent to the user's registered mobile number.
- Role-based access control — strict permission boundaries prevent unauthorised access to records across users and Village Councils.
- Encrypted data transmission — all data between user devices and the server is encrypted in transit.
- Encrypted storage — data at rest on Microsoft Azure is encrypted using industry-standard protocols.
- Audit trails — all significant user actions are logged with user identity, timestamp, and action details.
- Controlled deletion — records cannot be permanently deleted without authorisation; deletion requests are logged and subject to approval.
- Daily backups — automated daily backups reduce the risk of data loss.
- Access monitoring — District Admin has visibility of access logs to detect unusual activity.
While we take all reasonable steps to protect your data, no system is completely immune to security risks. Users are responsible for keeping their registered mobile numbers secure and reporting suspected unauthorised access immediately. Users should also review their device notification settings to control whether message previews are displayed on lock screens.
09User Rights
As a registered user of Smart VC, you have the following rights with respect to your personal data:
- Right of access — you may request a summary of the personal information held about you in the system.
- Right to correction — if your personal details are inaccurate, corrections should be requested through your Council President or District Admin, who manages account information.
- Right to be informed — this Privacy Policy constitutes our commitment to transparency about how your data is used.
- Right to object — if you believe data is being processed outside the scope of your official role or in violation of this policy, you may raise a formal objection with the Smart VC support team.
Please note that the right to deletion of administrative records is limited, as Village Council records are official government documents subject to mandatory retention requirements. All actions within the system are recorded permanently in the audit trail to maintain accountability.
Users may request account deletion or deactivation through the Request Account Deletion page. Account deletion requests may take up to 30 days to review and process. Approved requests disable future login access where appropriate, but do not remove official records, correspondence, financial entries, or audit trail entries that must be retained for governance, accountability, legal, or archival purposes.
10Account Lifecycle and Succession
Smart VC is designed to preserve administrative continuity when officials change. The following applies when a user leaves office or their role changes:
- The departing user's account is deactivated by the District Admin or Council President. Deactivated accounts cannot log in.
- All administrative records created by the departing user — including meeting minutes, resolutions, village works records, and correspondence — remain in the system, linked to their identity, and are fully accessible to their successor and other authorised users.
- Private one-to-one messages sent or received by the departing user are an exception: these are not accessible to the successor after account deactivation, in order to protect the confidentiality of personal communications.
- The audit trail entries associated with the departing user's actions remain permanently in the system and cannot be removed.
This approach ensures that official records are never lost due to a change in personnel, while maintaining appropriate confidentiality around personal communications.
11Minors
Smart VC is an official government administrative tool intended exclusively for authorised Village Council officials and district government employees. It is not designed for, directed at, or accessible to persons under 18 years of age. We do not knowingly collect data from minors. Account creation is controlled by District Admins and Council Presidents, who are responsible for ensuring only eligible officials are registered.
12Changes to This Privacy Policy
This Privacy Policy may be updated periodically to reflect changes in the Smart VC application, applicable law, or data processing practices. When material changes are made:
- The updated policy will be published within the Smart VC application and on the official department portal.
- The effective date at the top of this document will be updated.
- Users will be notified via an in-app notification at their next login.
Continued use of Smart VC after the effective date of any revised policy constitutes acceptance of the updated terms.
13Contact
Smart VC is developed by Lushai Technologies and Consulting Private Limited (also known as LushAITech).
For any questions, concerns, or requests relating to this Privacy Policy or the handling of your data within Smart VC, please contact us at info@lushaitech.com.