At a glance
This notice is published by the Liaison Office of MIS Foundation Terre des hommes (UIN: KOL008000056), Kolkata, India (“Tdh”, “we”, “us”). It applies when you use the WASHWise Android app, sign in to the WASHWise web portal (including WASH Darpan), or contact us about WASHWise.
Who it is for
Health staff in public health facilities in West Bengal and Tdh programme staff. It is not a public or consumer app.
How accounts work
No self sign-up. A Tdh administrator creates your account; you sign in with a username and password.
What we process
Your name, contact details, gender, role and posting; records you submit; basic device data; and cleaning staff training details entered by ICNs.
Our legal basis
Your consent, given when you sign in. Cleaning staff consent is confirmed by the ICN in the app.
No patient or health data
WASHWise records facility hygiene, supplies and training. It never collects patient or health information.
No location tracking
The app has no location permission and never reads your GPS.
No ads, no selling
No advertising, no advertising IDs, no marketing analytics. We never sell personal data.
Stored in India
On Microsoft Azure, Central India. Only push notifications and crash reports pass through Google Firebase.
About Tdh and WASHWise
Terre des hommes (Tdh) is an international non-governmental organisation working to improve the health and wellbeing of children, mothers and communities. In India, Tdh operates through its Liaison Office in Kolkata.
WASHWise is a digital public health tool developed for Tdh to support the Water, Sanitation and Hygiene (WASH) and Infection Prevention and Control (IPC) programme in public health facilities in West Bengal, India. It allows health staff to:
- complete facility assessments based on WHO/UNICEF WASH FIT and the national Kayakalp framework, monthly supervision checklists and water quality reports;
- keep a digital stock register for IPC consumables such as disinfectants, gloves and masks;
- report and track facility maintenance issues, with supporting photos or documents;
- complete IPC training modules and quizzes, and record facility-level training sessions for cleaning staff; and
- view aggregated performance dashboards (WASH Darpan).
Who this notice applies to
| Group | Description |
|---|---|
| App and portal users | ICNs, BMOHs, CMOHs, state-level health officers, and Tdh programme, administrator and support staff who hold a WASHWise account. |
| Facility cleaning staff | Cleaners and sanitation workers at health facilities. They do not use WASHWise, but an ICN may record their name, gender, training attendance and quiz score in facility profile and training reports. |
| Other people who contact us | Anyone who writes to us about WASHWise, for example for support or to exercise a privacy right. |
App and portal users
- Description
- ICNs, BMOHs, CMOHs, state-level health officers, and Tdh programme, administrator and support staff who hold a WASHWise account.
Facility cleaning staff
- Description
- Cleaners and sanitation workers at health facilities. They do not use WASHWise, but an ICN may record their name, gender, training attendance and quiz score in facility profile and training reports.
Other people who contact us
- Description
- Anyone who writes to us about WASHWise, for example for support or to exercise a privacy right.
What personal data we collect
A. When your account is created
Your account is created by an authorised Tdh administrator, not by you. The administrator records:
- full name and username;
- official email address and mobile number;
- gender;
- role (for example ICN, BMOH or CMOH) and, for administrators, department; and
- your place of posting: facility, block, district and state.
You can change your password in the app. We store only a one-way cryptographic hash of it, never the password itself. You can update your name, mobile number and gender under Profile > Edit Profile.
B. Records you create while using WASHWise
The records you submit are linked to your account and stored with the date and time:
- facility profile reports (including the ICN’s name and gender and staff counts by sex), WASH FIT and Kayakalp assessments, monthly supervision checklists and water quality reports;
- stock register entries;
- maintenance issues, comments and attachments (photos or documents you choose to upload);
- approval, review and “changes requested” actions on Kayakalp assessments;
- training progress, quiz answers and scores, daily quiz responses and certificates earned;
- which documents and training content you have opened; and
- in-app notifications sent to you.
C. Information about facility cleaning staff
When completing a facility profile or training report, an ICN may record each cleaning staff member’s name, gender, training attendance and quiz score. This is used only to monitor training coverage and plan further training at that facility.
Consent comes first
Before saving a cleaning staff member’s details, the ICN must explain, in a language they understand, what is recorded and why, and confirm in the app that the person has agreed. Details are not saved without this confirmation. A cleaning staff member can withdraw at any time by telling the ICN or contacting us, and their details will be removed.D. Device and technical information
The mobile app automatically sends us:
- a random installation identifier created by the app (not a hardware or advertising ID);
- device type (Android or iOS), manufacturer and model, and app version;
- a push notification token issued by Google Firebase; and
- the date and time your device last connected and last synchronised.
Our servers also record the IP address of requests in security and audit logs, for example when you approve a Kayakalp assessment or change a record.
E. Crash reports
If the app crashes, Google Firebase Crashlytics collects the error details, device model, operating system version, app version, time of the crash and a Crashlytics installation identifier. Crash reports are not linked to your name, username or account.
What we do not collect
The app contains no advertising and no marketing or behavioural analytics tools. The Google Advertising ID permission is removed from the app.
Please check photos before uploading
Do not upload photos or documents that show patients, patient records or identifiable people. If a photo of a facility area accidentally includes a person, crop it or choose another photo.Device permissions
| Permission | Why it is used | Required? |
|---|---|---|
| Internet and network state | To send and receive data, and to detect when you are back online so offline work can be synchronised. | Yes |
| Notifications | To show alerts about issue updates, approvals and reminders. | No. You can refuse or turn it off; the app still works. |
| App icon badge | To show the number of unread notifications on the app icon. | No |
| Files and photos (system picker) | To attach a photo or document you choose. The app only receives the file you pick; it does not use your camera or browse your gallery. | Only when you attach a file |
Internet and network state
- Why it is used
- To send and receive data, and to detect when you are back online so offline work can be synchronised.
- Required?
- Yes
Notifications
- Why it is used
- To show alerts about issue updates, approvals and reminders.
- Required?
- No. You can refuse or turn it off; the app still works.
App icon badge
- Why it is used
- To show the number of unread notifications on the app icon.
- Required?
- No
Files and photos (system picker)
- Why it is used
- To attach a photo or document you choose. The app only receives the file you pick; it does not use your camera or browse your gallery.
- Required?
- Only when you attach a file
You can change notification permissions at any time in your device settings.
Why we process your data and our legal basis
We process personal data on the basis of consent under Section 6 of the Digital Personal Data Protection Act, 2023 (DPDP Act):
- Mobile app users give consent the first time they log in, after a short notice in English or Bengali that links to this policy. Consent is recorded with the date, time and version of the notice. If this notice changes significantly, you will be asked again.
- Web portal users give consent by signing in. The sign-in page states that by signing in you accept the Terms of Service and this Privacy Policy, with links to both. Your consent is recorded with the date, time and version each time you sign in.
- Facility cleaning staff give consent to the ICN, who records it in the app before their details are saved.
You can withdraw consent at any time from Settings > Privacy in the app or by writing to us. Because WASHWise cannot work without an account, withdrawing consent deactivates your account and your personal data is erased or anonymised as described in Section 11. Withdrawal does not affect processing already carried out.
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and managing your account, signing you in and keeping it secure | Account information, password hash, device information, IP address | Consent |
| Recording and reviewing assessments, stock registers, issues and approvals | Records you submit; your name and role as submitter or approver | Consent |
| Showing supervising officers their facilities and producing WASH Darpan dashboards | Facility records and submitter details; dashboards show facility-level and aggregated figures | Consent |
| Delivering and tracking IPC training, quizzes and certificates | Training progress, quiz results, certificates | Consent |
| Recording training coverage of cleaning staff | Cleaner name, gender, attendance, quiz score | Consent of the cleaning staff member, recorded by the ICN |
| Sending push notifications | Push token, device information | Consent (you may decline the permission) |
| Fixing crashes and keeping the app stable | Crash reports, not linked to your identity | Consent |
| Security, audit trail and preventing misuse | IP address, audit logs, server logs | Consent, and legal obligations including the CERT-In Directions (Section 7, DPDP Act) |
| Responding to your requests and complaints | Contact details and your request | Consent, given by making the request |
Creating and managing your account, signing you in and keeping it secure
- Data used
- Account information, password hash, device information, IP address
- Legal basis
- Consent
Recording and reviewing assessments, stock registers, issues and approvals
- Data used
- Records you submit; your name and role as submitter or approver
- Legal basis
- Consent
Showing supervising officers their facilities and producing WASH Darpan dashboards
- Data used
- Facility records and submitter details; dashboards show facility-level and aggregated figures
- Legal basis
- Consent
Delivering and tracking IPC training, quizzes and certificates
- Data used
- Training progress, quiz results, certificates
- Legal basis
- Consent
Recording training coverage of cleaning staff
- Data used
- Cleaner name, gender, attendance, quiz score
- Legal basis
- Consent of the cleaning staff member, recorded by the ICN
Sending push notifications
- Data used
- Push token, device information
- Legal basis
- Consent (you may decline the permission)
Fixing crashes and keeping the app stable
- Data used
- Crash reports, not linked to your identity
- Legal basis
- Consent
Security, audit trail and preventing misuse
- Data used
- IP address, audit logs, server logs
- Legal basis
- Consent, and legal obligations including the CERT-In Directions (Section 7, DPDP Act)
Responding to your requests and complaints
- Data used
- Contact details and your request
- Legal basis
- Consent, given by making the request
We will not use personal data for any unrelated purpose without asking for your consent again.
Where data is stored and international transfers
All WASHWise application data, including accounts, assessments, stock records, issues, attachments and training records, is stored on Microsoft Azure servers in the Central India region. A limited amount of technical data leaves India:
- Push notifications are delivered through Google Firebase Cloud Messaging. Google receives the push token and short operational messages (for example “Issue #123 updated”), never patient data.
- Crash reports are processed by Google Firebase Crashlytics, mainly in the United States.
These transfers are made under Google’s data processing terms and are permitted under Section 16 of the DPDP Act. We do not transfer data to any country restricted by the Government of India.
Offline storage on your device
WASHWise is designed to work where connectivity is poor:
- Forms in progress, records waiting to upload and reference lists are kept in an encrypted database on your device, with the key held in the device’s secure keystore.
- When a connection is available, pending records upload automatically. You can also sync manually.
- If you enable Remember me, your username and password are saved in the secure keystore. Do not use this on a shared device.
- Logging out removes your session. Unsynchronised drafts stay encrypted on the device so they are not lost. Uninstalling the app deletes all WASHWise data from the device.
- Android system backups of app data are disabled, so WASHWise data is not copied to your Google account backup.
How we keep your data safe
In transit
All traffic between the app or browser and our servers uses HTTPS (TLS 1.2 or higher).
At rest
Azure platform encryption for database and files; email, phone and IP addresses additionally encrypted with AES-256-GCM; passwords stored as bcrypt hashes; private file storage.
On your device
Encrypted local database (SQLCipher). The key, login tokens and saved credentials are held in the Android Keystore or iOS Keychain.
Access control
Role and area-based access, automatic session expiry, restricted server access with only required ports open, and audit logs of who acted, when and from which IP address.
How long we keep your data
We keep personal data only as long as needed for the purposes in Section 6, unless the law requires longer. When a period ends, the data is deleted or anonymised. If immediate deletion is not technically possible, for example in a backup, it is isolated from further use until deleted.
| Data | Kept for | Notes |
|---|---|---|
| Account information | While your role needs access, then 12 months after deactivation | Your account is deactivated when your posting ends, you withdraw consent or an administrator removes you. Identifiers are then erased or anonymised after 12 months, or earlier on a verified request. |
| Assessments, stock, issues, approvals, training records | Duration of the WASHWise programme | At programme end, handed over to the competent public health authority or deleted, and removed from Tdh systems within 90 days. On an erasure request your name is removed while facility data is kept. |
| Cleaning staff details | While the person works at the facility, at most the programme duration | Removed when the person leaves or withdraws consent. |
| Device information and push tokens | While your account is active | Tokens Firebase reports as invalid are removed automatically. |
| Audit logs (with IP address) | 1 year | For security and accountability. |
| Server application logs | 180 days | Kept in India as required by the CERT-In Directions, then deleted automatically. |
| Crash reports | 90 days | Deleted automatically by Google. |
| Database backups | 30 days | Encrypted daily backups on Azure in India, not used for active processing. |
| Data on your device | Until synchronised and cleared, or the app is uninstalled |
Account information
- Kept for
- While your role needs access, then 12 months after deactivation
- Notes
- Your account is deactivated when your posting ends, you withdraw consent or an administrator removes you. Identifiers are then erased or anonymised after 12 months, or earlier on a verified request.
Assessments, stock, issues, approvals, training records
- Kept for
- Duration of the WASHWise programme
- Notes
- At programme end, handed over to the competent public health authority or deleted, and removed from Tdh systems within 90 days. On an erasure request your name is removed while facility data is kept.
Cleaning staff details
- Kept for
- While the person works at the facility, at most the programme duration
- Notes
- Removed when the person leaves or withdraws consent.
Device information and push tokens
- Kept for
- While your account is active
- Notes
- Tokens Firebase reports as invalid are removed automatically.
Audit logs (with IP address)
- Kept for
- 1 year
- Notes
- For security and accountability.
Server application logs
- Kept for
- 180 days
- Notes
- Kept in India as required by the CERT-In Directions, then deleted automatically.
Crash reports
- Kept for
- 90 days
- Notes
- Deleted automatically by Google.
Database backups
- Kept for
- 30 days
- Notes
- Encrypted daily backups on Azure in India, not used for active processing.
Data on your device
- Kept for
- Until synchronised and cleared, or the app is uninstalled
- Notes
Your rights and how to exercise them
Under the DPDP Act and other applicable law, you have the right to:
Information and access
Know whether we process your data, receive a summary of it and of the processing, and know who it was shared with.
Correction
Correct inaccurate or incomplete data. Edit your name, phone and gender in the app; ask us or your administrator for anything else.
Erasure
Ask us to delete data we no longer need. Where the law requires us to keep something, or facility data is kept without your name, we will tell you what and why.
Withdraw consent
At any time, as easily as you gave it, from Settings > Privacy or by writing to us.
Nominate
Nominate another person to exercise your rights if you die or are unable to do so.
Grievance redressal
Complain to us and, if unsatisfied, to the Data Protection Board of India.
How to make a request
- 1Email ind.dpo@tdh.org from your registered email address, or write to the postal address in Section 17.
- 2Include your name, username and registered mobile number so we can verify your identity. Cleaning staff may ask through their ICN or contact us directly.
- 3We acknowledge your request within 7 days and respond within 30 days.
We will not treat you differently for exercising your rights.
Children
WASHWise is intended only for adult health staff and programme personnel. We do not knowingly collect personal data from anyone under 18. If you believe a child’s data has been entered, contact us and we will delete it.
Personal data breaches
If a personal data breach occurs, we will contain it, notify the Data Protection Board of India and affected persons as required by the DPDP Act and its Rules, and report cyber security incidents to CERT-In within the time required by law.
Changes to this notice
We may update this notice when WASHWise changes or the law requires. The updated version will show a new “Last updated” date. For significant changes, we will tell you in the app before they take effect.
Contact us and grievance redressal
For questions about this notice, to exercise your rights or to make a complaint, contact our Data Protection Officer:
Data Protection Officer
Liaison Office of MIS Foundation Terre des hommes
UIN: KOL008000056
For technical help with the app, such as login problems, use the Support section in the app.