Skip to main content

Privacy & governance

Privacy Policy

This policy formalises our Zero-Data Storage pledge. It is written to be read by your compliance officer, not only by your lawyer.

Last updated: 11 August 2026

1. Information collection

We process the minimum data required to operate the Uchal Suraksha Portal. In practice this means: irreversible SHA-256 hashed contractor and labourer identifiers; the mill's own account and login telemetry; contract status records indicating whether an advance is active, cleared or defaulted; and vehicle registration details submitted for fitness verification.

We do not collect, request or retain plain-text Aadhaar numbers. The 12-digit number is hashed at the point of entry, and only the resulting 64-character hash is transmitted or stored.

Marketing enquiries made through this website are not stored by the website. Contact and careers forms compose a message in your own WhatsApp or email client; nothing is submitted to a CaneLogic server until you choose to send it.

2. Zero-Data Storage commitment

CaneLogic Solutions declares explicitly that client commercial databases, internal financial records and proprietary mill metrics are never copied, resold, or permanently stored on our infrastructure.

Cross-mill intelligence operates on hashed identifiers and derived risk status alone. A participating mill can learn that a given contractor holds an active advance elsewhere; it cannot learn where, for how much, or with whom, and it cannot enumerate another mill's contractor directory.

This is enforced architecturally through data-layer tenant isolation, not merely by contractual undertaking.

3. Data protection protocols

All data in transit is protected with enterprise-grade SSL/TLS encryption. Identity data is hashed using SHA-256; authentication credentials for factory administrative users are hashed using bcrypt.

Access is controlled on a role-scoped basis — Super Admin, Sugar Factory and Contractor roles each see only the records their permissions allow. Multi-factor authentication is available for factory administrative users.

An append-only activity and identity audit log records every authentication, duplicate block, status lock, onboarding request, verification and credential event, with a timestamp and the originating co-operative.

Third-party gateway credentials for Aadhaar e-KYC, RTO and SMS services are held in server-side environment variables and are never exposed to browser code.

4. Retention & deletion

Hashed identifiers and contract status records are retained for the duration of the commercial relationship and for the statutory period thereafter, as required for audit and dispute resolution.

On termination, a client mill may request deletion of its account records. Aggregate, non-identifying network statistics may be retained, as they contain no client data and cannot be attributed to any mill or individual.

5. Contractor rights & dispute resolution

A contractor who believes they have been flagged in error may file an appeal through the support and dispute resolution desk. Mills and the Super Admin review the evidence and can clear a wrongful block or flag.

Every such action is recorded in the audit log, so a cleared record is demonstrably cleared rather than quietly amended.

6. Compliance & legal jurisdiction

CaneLogic Solutions Private Limited operates in accordance with the Information Technology Act, 2000 and the rules framed under it, together with applicable Indian data protection legislation as it comes into force.

This policy is governed by the laws of India. The courts at Pune, Maharashtra shall have exclusive jurisdiction over any dispute arising from it.

Questions about this policy

Write to support@uchalportal.in and mark the subject line “Privacy”. Compliance and security questionnaires from prospective client mills are welcome, and we will complete yours rather than send you a brochure.

support@uchalportal.in