Privacy Policy
Last updated: April 22, 2026
Developed by Pavankumar Deshetty · In partnership with Dataworx (Manjunath YN, CEO)
FieldGovern ("we", "our", or "us") is committed to protecting the privacy of organizations and individuals who use our field data collection platform. FieldGovern is developed by Pavankumar Deshetty (Research Associate & Data Analyst, Kalike — Tata Trusts) in strategic partnership with Dataworx, a Bengaluru-based data science and analytics firm led by Manjunath YN (CEO).
This Privacy Policy explains what information we collect, how we use it, how we protect it, and your rights with respect to that information. By using FieldGovern, you agree to the practices described in this policy.
Plain-language summary: We collect only what is necessary to provide the service. We never sell your data. Your organization's data is strictly isolated from all other organizations. You own your data and can export or delete it at any time.
1. Who We Are
FieldGovern is a B2B SaaS platform for offline-first field data collection, designed for India's research and development sector. The platform is operated by Pavankumar Deshetty, with strategic support from Dataworx. For all privacy-related queries, contact us at hello@fieldgovern.com.
2. Information We Collect
We collect information in two ways: information you provide directly, and information collected automatically.
Information you provide:
- Account credentials — phone number and hashed password (we never store plain-text passwords; bcrypt with cost factor 12 is used)
- Organization details — organization name, administrator name, designation, and contact information
- Form definitions — the survey/questionnaire forms your organization creates on the platform
- Submission data — field data collected by your enumerators through FieldGovern forms
- Media files — photographs and audio recordings uploaded as part of field submissions
- GPS coordinates — captured only when your form includes a location/GPS field, and only during active data collection
- Support communications — messages, emails, or queries you send to us
Information collected automatically:
- Browser type, device type, and operating system
- IP address and approximate location (country/region level only)
- Pages accessed, session timestamps, and usage patterns within the platform
- Service worker and PWA activity logs, used exclusively for offline sync diagnostics and error detection
- API request logs for security monitoring and abuse prevention
3. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, operate, maintain, and improve the FieldGovern platform and its features
- To authenticate users and enforce role-based access control (enumerator / supervisor / org_admin / master_admin)
- To synchronize offline-collected data between field devices and your organization's central account
- To send important service notices — account changes, security alerts, billing events, and policy updates
- To respond to support requests and technical queries
- To analyze aggregate, anonymized usage patterns to guide product improvement decisions
- To detect and prevent fraud, abuse, and unauthorized access
- To comply with applicable legal obligations
We do not sell, rent, share, or otherwise monetize your personal data or your organization's research data with any third party for marketing, advertising, or commercial purposes.
4. Multi-Tenant Data Isolation
FieldGovern is a multi-tenant platform. Every piece of data — forms, submissions, users, media files, API keys — is strictly isolated to your organization's tenant account. Data isolation is enforced at two independent layers:
- Database layer — Row-Level Security (RLS) policies on PostgreSQL ensure that every query is scoped to the authenticated tenant. Even a misconfigured application query cannot cross tenant boundaries.
- Application layer — Every API endpoint validates the requesting user's tenant membership before processing any request.
This dual-layer isolation means no organization can ever access another organization's data, even in the event of a software defect in the application layer.
5. Data Storage and Infrastructure
All production data is hosted on servers operated by Contabo GmbH (EU-based infrastructure). Data in transit is encrypted using TLS 1.2 or higher. Passwords are stored as bcrypt hashes (cost factor 12) — plain-text passwords are never stored or logged anywhere in our system.
Authentication tokens (JWT) expire after 2 hours. API keys are hashed using SHA-256 before storage. Database backups are taken daily, compressed, and retained for 30 days. Backup files are encrypted at rest.
Media files (photos, audio recordings) uploaded by enumerators are stored on encrypted server local storage by default. Enterprise customers may configure their own Google Drive or AWS S3 bucket to store media under their own credentials and data governance policies.
While we implement industry-standard security measures, no system can be guaranteed 100% secure. In the event of a data breach, we will notify affected organization administrators within 72 hours of discovery.
6. Offline Data on Field Devices
A core feature of FieldGovern is its ability to work completely offline. When enumerators collect data without internet connectivity, form responses and media files are stored locally on their device using browser storage technologies — OPFS (Origin Private File System) on Chrome/Android, or IndexedDB on Safari/iOS. This data remains on the device and is uploaded to the server when connectivity is restored.
FieldGovern does not control the physical security of field devices. We strongly recommend that your organization enforce device-level screen locks, PIN protection, and remote wipe capability on all devices used for field data collection. Lost or stolen devices should be reported to your Org Admin immediately so API access can be revoked.
7. Data Retention
We retain your organization's data for as long as the account remains active. Inactive accounts (no login for 12+ months with no active subscription) may be flagged for deletion with 30 days' prior notice to the registered org admin email.
Upon account termination or cancellation, we will retain your data for 30 days to allow for final exports. After this grace period, data is permanently deleted from production systems within 7 days. Encrypted backup copies are cycled out within 30 days following the deletion. To request early deletion, email hello@fieldgovern.com with the subject line "Data Deletion Request".
Aggregate anonymized statistics (total form count, submission volumes, feature usage — never individual records) may be retained indefinitely for internal analytics.
8. Cookies and Local Storage
The FieldGovern web application uses minimal browser storage. JWT tokens (session credentials) are stored in localStorage. Offline form data and queued submissions are stored in OPFS or IndexedDB for sync functionality. We do not use any third-party tracking cookies, advertising cookies, or behavioral analytics scripts.
Our marketing website (fieldgovern.com) loads Google Fonts from fonts.googleapis.com — this is the only third-party request made by the marketing site. No other external tracking scripts are loaded.
9. Third-Party Integrations
FieldGovern supports optional integrations with third-party services. These are opt-in and configured by your organization's administrator:
- Google Drive — for media file storage using your organization's own Google credentials
- AWS S3 — for media file storage using your organization's own AWS credentials
- Google Sheets — for data export and live sync, requires your explicit OAuth authorization
- SMTP email providers — for automated digest emails and notifications, configured by your organization
When you enable these integrations, data shared with those services is subject to their respective privacy policies. FieldGovern does not retain credentials beyond what is necessary to maintain the connection you have authorized.
10. Your Rights
As a user or administrator of a FieldGovern organization account, you have the following rights:
- Access — Request a summary of personal data we hold about your account
- Correction — Request correction of inaccurate or incomplete data
- Deletion — Request permanent deletion of your personal data and your organization's account data
- Portability — Export your organization's data in CSV, JSON, or Excel format at any time from the platform dashboard
- Objection — Object to or request restriction of specific processing activities
- Withdrawal of consent — Withdraw consent for optional integrations (Google Drive, Sheets, etc.) at any time from the integrations settings page
To exercise any of these rights, contact us at hello@fieldgovern.com. We will acknowledge your request within 3 business days and fulfil it within 30 days.
11. Children's Privacy
FieldGovern is a B2B platform designed for use by organizations and their adult employees. We do not knowingly collect personal data from anyone under the age of 18 as account holders.
If your research involves collecting data about minors as research subjects through your forms, your organization acts as the data controller and is solely responsible for obtaining appropriate informed consent from parents or guardians in accordance with applicable law, including India's Digital Personal Data Protection Act (DPDP) 2023, the Protection of Children from Sexual Offences (POCSO) Act, and any ethics committee requirements applicable to your research.
12. Research Ethics and Data Collection Responsibility
FieldGovern is a tool. The ethical responsibility for how data is collected, from whom, and for what purpose rests entirely with the organizations and researchers using the platform. We strongly encourage all organizations using FieldGovern to:
- Obtain Institutional Review Board (IRB) or ethics committee approval where applicable
- Provide informed consent to all research participants in their local language
- Comply with India's DPDP Act 2023 and any sector-specific regulations (health data, financial data, biometric data)
- Maintain participant confidentiality by anonymizing personally identifiable information (PII) before export or sharing
- Implement appropriate data classification and access controls within your FieldGovern organization
13. Changes to This Policy
We may update this Privacy Policy from time to time as the platform evolves or as legal requirements change. When we make material changes, we will notify all registered Org Admins by email at least 14 days before the changes take effect, and update the "Last updated" date at the top of this page. Your continued use of FieldGovern after the effective date constitutes acceptance of the updated policy.
For minor changes (corrections, clarifications that don't affect your rights), we may update this policy without individual notice. We encourage you to review this page periodically.
14. Contact Us
For privacy-related questions, data requests, or to report a concern:
- Email: hello@fieldgovern.com
- Developer: Pavankumar Deshetty — apranjipavan2-spec.github.io/portfolio
- Strategic Partner: Dataworx — pallavi@dataworx.co.in
- Website: www.fieldgovern.com
We aim to respond to all privacy enquiries within 3 business days.