WASHWise · Legal

Privacy Policy

How Terre des hommes collects, stores, uses and shares personal data when you use the WASHWise mobile app and web portal, and the choices you have.

Effective1 October 2026Last updated1 October 2026Published byTerre des hommes, India

At a glance

This notice is published by the Liaison Office of MIS Foundation Terre des hommes (UIN: KOL008000056), Kolkata, India (“Tdh”, “we”, “us”). It applies when you use the WASHWise Android app, sign in to the WASHWise web portal (including WASH Darpan), or contact us about WASHWise.

Who it is for

Health staff in public health facilities in West Bengal and Tdh programme staff. It is not a public or consumer app.

How accounts work

No self sign-up. A Tdh administrator creates your account; you sign in with a username and password.

What we process

Your name, contact details, gender, role and posting; records you submit; basic device data; and cleaning staff training details entered by ICNs.

Our legal basis

Your consent, given when you sign in. Cleaning staff consent is confirmed by the ICN in the app.

No patient or health data

WASHWise records facility hygiene, supplies and training. It never collects patient or health information.

No location tracking

The app has no location permission and never reads your GPS.

No ads, no selling

No advertising, no advertising IDs, no marketing analytics. We never sell personal data.

Stored in India

On Microsoft Azure, Central India. Only push notifications and crash reports pass through Google Firebase.

No system can be guaranteed 100% secure. We apply the safeguards in Section 10, but cannot promise that unauthorised parties will never defeat them. Questions? Write to our Data Protection Officer at ind.dpo@tdh.org.
1

About Tdh and WASHWise

Terre des hommes (Tdh) is an international non-governmental organisation working to improve the health and wellbeing of children, mothers and communities. In India, Tdh operates through its Liaison Office in Kolkata.

WASHWise is a digital public health tool developed for Tdh to support the Water, Sanitation and Hygiene (WASH) and Infection Prevention and Control (IPC) programme in public health facilities in West Bengal, India. It allows health staff to:

  • complete facility assessments based on WHO/UNICEF WASH FIT and the national Kayakalp framework, monthly supervision checklists and water quality reports;
  • keep a digital stock register for IPC consumables such as disinfectants, gloves and masks;
  • report and track facility maintenance issues, with supporting photos or documents;
  • complete IPC training modules and quizzes, and record facility-level training sessions for cleaning staff; and
  • view aggregated performance dashboards (WASH Darpan).
2

Who this notice applies to

App and portal users

Description
ICNs, BMOHs, CMOHs, state-level health officers, and Tdh programme, administrator and support staff who hold a WASHWise account.

Facility cleaning staff

Description
Cleaners and sanitation workers at health facilities. They do not use WASHWise, but an ICN may record their name, gender, training attendance and quiz score in facility profile and training reports.

Other people who contact us

Description
Anyone who writes to us about WASHWise, for example for support or to exercise a privacy right.
3

What personal data we collect

A. When your account is created

Your account is created by an authorised Tdh administrator, not by you. The administrator records:

  • full name and username;
  • official email address and mobile number;
  • gender;
  • role (for example ICN, BMOH or CMOH) and, for administrators, department; and
  • your place of posting: facility, block, district and state.

You can change your password in the app. We store only a one-way cryptographic hash of it, never the password itself. You can update your name, mobile number and gender under Profile > Edit Profile.

B. Records you create while using WASHWise

The records you submit are linked to your account and stored with the date and time:

  • facility profile reports (including the ICN’s name and gender and staff counts by sex), WASH FIT and Kayakalp assessments, monthly supervision checklists and water quality reports;
  • stock register entries;
  • maintenance issues, comments and attachments (photos or documents you choose to upload);
  • approval, review and “changes requested” actions on Kayakalp assessments;
  • training progress, quiz answers and scores, daily quiz responses and certificates earned;
  • which documents and training content you have opened; and
  • in-app notifications sent to you.

C. Information about facility cleaning staff

When completing a facility profile or training report, an ICN may record each cleaning staff member’s name, gender, training attendance and quiz score. This is used only to monitor training coverage and plan further training at that facility.

Consent comes first

Before saving a cleaning staff member’s details, the ICN must explain, in a language they understand, what is recorded and why, and confirm in the app that the person has agreed. Details are not saved without this confirmation. A cleaning staff member can withdraw at any time by telling the ICN or contacting us, and their details will be removed.

D. Device and technical information

The mobile app automatically sends us:

  • a random installation identifier created by the app (not a hardware or advertising ID);
  • device type (Android or iOS), manufacturer and model, and app version;
  • a push notification token issued by Google Firebase; and
  • the date and time your device last connected and last synchronised.

Our servers also record the IP address of requests in security and audit logs, for example when you approve a Kayakalp assessment or change a record.

E. Crash reports

If the app crashes, Google Firebase Crashlytics collects the error details, device model, operating system version, app version, time of the crash and a Crashlytics installation identifier. Crash reports are not linked to your name, username or account.

4

What we do not collect

Patient or health dataYour locationContacts, call logs, SMSMicrophone or calendarAdvertising IDsBiometric dataFinancial or payment data

The app contains no advertising and no marketing or behavioural analytics tools. The Google Advertising ID permission is removed from the app.

Please check photos before uploading

Do not upload photos or documents that show patients, patient records or identifiable people. If a photo of a facility area accidentally includes a person, crop it or choose another photo.
5

Device permissions

Internet and network state

Why it is used
To send and receive data, and to detect when you are back online so offline work can be synchronised.
Required?
Yes

Notifications

Why it is used
To show alerts about issue updates, approvals and reminders.
Required?
No. You can refuse or turn it off; the app still works.

App icon badge

Why it is used
To show the number of unread notifications on the app icon.
Required?
No

Files and photos (system picker)

Why it is used
To attach a photo or document you choose. The app only receives the file you pick; it does not use your camera or browse your gallery.
Required?
Only when you attach a file

You can change notification permissions at any time in your device settings.

7

Who we share data with

We do not sell, rent or trade personal data, and never share it for advertising or commercial purposes.
  • Your supervising health officers, limited by role and area: a BMOH sees their block, a CMOH their district, state officers the state. They see the records submitted for those facilities and who submitted them.
  • Tdh programme and support staff with an administrator or support account, to manage users and facilities and provide support.
  • Service providers (data processors) who act only on our written instructions, listed below.
  • Legal requirements: where required by law, a court order or a lawful direction from a competent authority.

Microsoft Azure

Role
Cloud hosting: servers, database and file storage
Where
India (Central India)

Google Firebase Cloud Messaging

Role
Delivering push notifications
Where
Global, including outside India

Google Firebase Crashlytics

Role
Crash reporting
Where
United States and other countries

Google Play

Role
App distribution and in-app updates
Where
Global

Markzin Young Private Limited

Role
Software development, hosting administration and technical support
Where
India

Tdh is responsible, as Data Fiduciary, for all personal data processed in WASHWise.

8

Where data is stored and international transfers

All WASHWise application data, including accounts, assessments, stock records, issues, attachments and training records, is stored on Microsoft Azure servers in the Central India region. A limited amount of technical data leaves India:

  • Push notifications are delivered through Google Firebase Cloud Messaging. Google receives the push token and short operational messages (for example “Issue #123 updated”), never patient data.
  • Crash reports are processed by Google Firebase Crashlytics, mainly in the United States.

These transfers are made under Google’s data processing terms and are permitted under Section 16 of the DPDP Act. We do not transfer data to any country restricted by the Government of India.

9

Offline storage on your device

WASHWise is designed to work where connectivity is poor:

  • Forms in progress, records waiting to upload and reference lists are kept in an encrypted database on your device, with the key held in the device’s secure keystore.
  • When a connection is available, pending records upload automatically. You can also sync manually.
  • If you enable Remember me, your username and password are saved in the secure keystore. Do not use this on a shared device.
  • Logging out removes your session. Unsynchronised drafts stay encrypted on the device so they are not lost. Uninstalling the app deletes all WASHWise data from the device.
  • Android system backups of app data are disabled, so WASHWise data is not copied to your Google account backup.
Records that have not yet been synchronised may be lost if the app is uninstalled or the device is reset.
10

How we keep your data safe

In transit

All traffic between the app or browser and our servers uses HTTPS (TLS 1.2 or higher).

At rest

Azure platform encryption for database and files; email, phone and IP addresses additionally encrypted with AES-256-GCM; passwords stored as bcrypt hashes; private file storage.

On your device

Encrypted local database (SQLCipher). The key, login tokens and saved credentials are held in the Android Keystore or iOS Keychain.

Access control

Role and area-based access, automatic session expiry, restricted server access with only required ports open, and audit logs of who acted, when and from which IP address.

11

How long we keep your data

We keep personal data only as long as needed for the purposes in Section 6, unless the law requires longer. When a period ends, the data is deleted or anonymised. If immediate deletion is not technically possible, for example in a backup, it is isolated from further use until deleted.

Account information

Kept for
While your role needs access, then 12 months after deactivation
Notes
Your account is deactivated when your posting ends, you withdraw consent or an administrator removes you. Identifiers are then erased or anonymised after 12 months, or earlier on a verified request.

Assessments, stock, issues, approvals, training records

Kept for
Duration of the WASHWise programme
Notes
At programme end, handed over to the competent public health authority or deleted, and removed from Tdh systems within 90 days. On an erasure request your name is removed while facility data is kept.

Cleaning staff details

Kept for
While the person works at the facility, at most the programme duration
Notes
Removed when the person leaves or withdraws consent.

Device information and push tokens

Kept for
While your account is active
Notes
Tokens Firebase reports as invalid are removed automatically.

Audit logs (with IP address)

Kept for
1 year
Notes
For security and accountability.

Server application logs

Kept for
180 days
Notes
Kept in India as required by the CERT-In Directions, then deleted automatically.

Crash reports

Kept for
90 days
Notes
Deleted automatically by Google.

Database backups

Kept for
30 days
Notes
Encrypted daily backups on Azure in India, not used for active processing.

Data on your device

Kept for
Until synchronised and cleared, or the app is uninstalled
Notes
12

Your rights and how to exercise them

Under the DPDP Act and other applicable law, you have the right to:

Information and access

Know whether we process your data, receive a summary of it and of the processing, and know who it was shared with.

Correction

Correct inaccurate or incomplete data. Edit your name, phone and gender in the app; ask us or your administrator for anything else.

Erasure

Ask us to delete data we no longer need. Where the law requires us to keep something, or facility data is kept without your name, we will tell you what and why.

Withdraw consent

At any time, as easily as you gave it, from Settings > Privacy or by writing to us.

Nominate

Nominate another person to exercise your rights if you die or are unable to do so.

Grievance redressal

Complain to us and, if unsatisfied, to the Data Protection Board of India.

How to make a request

  1. 1Email ind.dpo@tdh.org from your registered email address, or write to the postal address in Section 17.
  2. 2Include your name, username and registered mobile number so we can verify your identity. Cleaning staff may ask through their ICN or contact us directly.
  3. 3We acknowledge your request within 7 days and respond within 30 days.

We will not treat you differently for exercising your rights.

13

Cookies on the web portal

The web portal uses only strictly necessary cookies to keep you signed in securely. We use no advertising, analytics or tracking cookies, so no cookie banner is needed. The mobile app does not use cookies.

14

Children

WASHWise is intended only for adult health staff and programme personnel. We do not knowingly collect personal data from anyone under 18. If you believe a child’s data has been entered, contact us and we will delete it.

15

Personal data breaches

If a personal data breach occurs, we will contain it, notify the Data Protection Board of India and affected persons as required by the DPDP Act and its Rules, and report cyber security incidents to CERT-In within the time required by law.

16

Changes to this notice

We may update this notice when WASHWise changes or the law requires. The updated version will show a new “Last updated” date. For significant changes, we will tell you in the app before they take effect.

17

Contact us and grievance redressal

For questions about this notice, to exercise your rights or to make a complaint, contact our Data Protection Officer:

Data Protection Officer

Liaison Office of MIS Foundation Terre des hommes

UIN: KOL008000056

Unit 711, Acropolis Business Tower, 7th Floor1858/1 Rajdanga Main Road, Kolkata 700107West Bengal, India

For technical help with the app, such as login problems, use the Support section in the app.