Data Retention & Consent Policy
This policy governs how TMPK retains, stores, and disposes of personal and organisational data collected through the membership lifecycle.
1. Aadhaar Data
Aadhaar numbers are encrypted at rest using AES-256-GCM (Galois/Counter Mode). The ciphertext is stored in a dedicated column and is inaccessible to unauthorised personnel. Encryption keys are rotated periodically. Aadhaar data is retained only while the individual holds an active membership and is permanently purged within 90 days of a verified deletion request or membership termination.
2. Membership Data
Personal data — including name, date of birth, contact details, address, photograph, and demographic information — is retained for the duration of active membership. Upon a member's resignation, expiry, or status change to inactive, personal data is scheduled for deletion within 90 days.
3. Data Deletion on Request
Members may request deletion of their personal data at any time by submitting a formal request to the Central Committee. Requests are processed within 30 days. Certain records may be excluded from deletion where required by law (e.g., financial transactions, audit trails).
4. Audit Logs
Audit logs — recording administrative actions, data modifications, and access events — are retained permanently for security, accountability, and compliance purposes. These logs contain minimal personal data and are not subject to deletion requests.
5. Consent at Registration
Explicit consent is captured during member registration via a mandatory checkbox. The consent statement references this Data Retention & Consent Policy and confirms that the member understands how their data will be stored, used, and retained. Consent records are stored in the member's profile and are immutable once submitted.
6. Data Portability
Upon request, members may receive a copy of their personal data in a structured, commonly used format (CSV or JSON). Requests should be addressed to the Central Committee.