Privacy Policy - eNaaka
Effective Date: January 1, 2026 | Last Updated: September 2026
1. Introduction
This Privacy Policy governs the manner in which the eNaaka application and associated Web API services (operated for Chandigarh Police) collect, use, maintain, and disclose information collected from authorized personnel and automated checkpoint scanning operations.
2. Information We Collect
In order to provide enforcement and checkpoint verification services, our system processes the following data:
- Officer & Personnel Credentials: Belt number, full name, official designation, registered mobile number, and authentication tokens/PINs.
- Automated Number Plate Recognition (ANPR) & Media: Vehicle registration images, scanned license plate numbers, OCR confidence scores, and detection timestamps.
- Geolocation Data: Device latitude and longitude captured during active checkpoint checks and ANPR scans.
- Vehicle & Owner Records: Registration certificate (RC) details, engine and chassis numbers, insurance status, PUCC validity, and blacklist flags.
- Audit & Telemetry Logs: Procedure execution logs, IP addresses, client application timestamps, and error diagnostics.
3. How We Use Collected Information
The collected information is utilized strictly for lawful law enforcement operations:
- Authenticating authorized police personnel via OTP and secure PIN verification.
- Verifying vehicle ownership, registration status, and detecting stolen, wanted, or blacklisted vehicles in real time.
- Maintaining operational checkpoint records, team rosters, and duty schedules.
- Generating automated audit trails, shift reports, and officer activity tracking.
4. Data Security and Encryption
We implement stringent technical and organizational security measures to protect law enforcement and citizen data against unauthorized access, alteration, disclosure, or destruction:
- All communication between mobile endpoints and the Web API is encrypted in transit using industry-standard TLS protocols.
- Sensitive fields (such as phone numbers, authentication tokens, and credentials) undergo field-level cryptographic encryption at rest and in transit.
- Stored procedures utilize strict allowlisting within gateway controllers to prevent SQL injection and unauthorized schema execution.
- Access is restricted solely to verified departmental users via role-based access control (RBAC).
5. Data Sharing and Third Parties
Data collected through eNaaka is strictly departmental and is never sold, rented, or commercialized. Information is only shared with authorized government databases and law enforcement systems, including:
- Central and State vehicle registries (e.g., VAHAN / eParivahan).
- Crime and Criminal Tracking Network & Systems (CCTNS) and Inter-Operable Criminal Justice System (ICJS) / Nyaay Setu platforms.
- Authorized institutional SMS gateways for official OTP and alert delivery.
6. Data Retention
Records, checkpoint logs, and system audit logs are retained in accordance with departmental data retention rules, state law enforcement standards, and judicial compliance mandates.
7. Contact Us
If you have questions regarding this Privacy Policy or technical security protocols, contact the administrative desk:
IT & Technical Services Wing
Chandigarh Police Headquarters
Sector 9, Chandigarh, India