01 — INTRODUCTION01
About this Privacy Policy
The Raha College NSS website is intended to provide information about National Service
Scheme activities, college-level NSS initiatives, announcements, events, volunteers,
certificates, photographs, notices, educational resources, and related public information.
This Privacy Policy explains the general principles that should govern the collection,
use, storage, disclosure, publication, and protection of information connected with the
website.
The purpose of this policy is to make website visitors, NSS members, volunteers, students,
staff members, event participants, and other users aware of what information may be
provided to the website, why that information may be needed, how it may be handled, and
what reasonable choices are available to the user.
Privacy depends not only on the visible pages of a website but also on the services used
behind or alongside those pages. Examples may include hosting providers, domain services,
authentication systems, form providers, analytics tools, cloud storage, email services,
image-hosting services, or other third-party services. The actual services connected to
the deployed website should therefore be reviewed before publication of this policy.
02 — SCOPE02
Where this policy applies
This policy applies to information handled through the Raha College NSS website and its
related website pages, forms, certificate pages, event pages, notice pages, galleries, and
other online features that are expressly connected with the website.
It does not automatically govern websites or services operated independently by third
parties. When the website links to another service, that service may have its own privacy
policy and terms.
03 — INFORMATION03
Information users may provide
Depending on the features actually enabled, users may voluntarily provide information
such as:
- name and preferred form of identification;
- college, class, semester, or NSS-related details;
- contact information such as email or telephone number;
- information needed to participate in an NSS event or activity;
- information submitted through a problem report, contact form, or feedback form;
- information required for certificate or ID-card generation;
- photographs or other media submitted for an NSS activity;
- any other information that a user deliberately enters into a website form.
04
Public information
Some information may be intentionally displayed publicly, for example event notices,
official announcements, activity descriptions, publicly approved photographs, or volunteer
recognition content.
05
Do not submit secrets
Users should not enter passwords, banking details, government identity numbers, private
medical records, or other highly sensitive information into an ordinary NSS form unless a
specific official process clearly requires it.
06
Accuracy
Users are encouraged to provide information that is accurate and belongs to them or that
they are authorized to submit.
07 — AUTOMATIC INFORMATION07
Technical information that may be processed
Like many websites, the hosting environment or connected services may technically process
limited information associated with a visit. Depending on the provider and configuration,
this can include IP address, browser type, operating system, device characteristics,
approximate technical location derived by a provider, referring page, requested page,
timestamps, error information, and security logs.
The NSS website should only describe automatic collection that is actually enabled by its
hosting provider or integrated services. A static HTML page, for example, does not by
itself create a database of every visitor. However, the hosting platform may still keep
server or security logs according to its own policies.
Technical information may be used for purposes such as delivering pages, preventing abuse,
maintaining availability, diagnosing errors, protecting the site, measuring basic
technical performance, and responding to security incidents.
08 — COOKIES08
Cookies and local storage
Cookies are small pieces of information stored by a browser. Websites may also use browser
storage such as localStorage or sessionStorage. These technologies can be used for
preferences, login state, temporary functionality, security, or remembering information
entered during a session.
If the NSS website does not intentionally use cookies or browser storage for a particular
feature, it should not claim that it does. Third-party services embedded in the website
may independently set cookies or similar technologies.
09 — WHY INFORMATION IS USED09
Purpose of processing
- to provide NSS website functionality;
- to respond to questions or requests;
- to support certificate or ID-related features where enabled;
- to publish authorized NSS announcements and activity information;
- to maintain website security and reliability;
- to identify and correct technical problems;
- to prevent misuse, spam, fraud, or unauthorized access;
- to improve the clarity and usefulness of website content.
10 — NSS ACTIVITIES & PHOTOGRAPHS10
Photographs, videos and event documentation
NSS activities can involve photographs, videos, group documentation, event reports,
certificates, posters, or other media. Where photographs are intended for public display,
the responsible website team should consider the context in which the photograph was
obtained and whether individuals have a reasonable expectation of privacy.
A person who appears in an event photograph may request review of content that creates a
genuine privacy, safety, or personal concern. Requests should identify the relevant page
or image and explain the concern clearly. Removal or modification will depend on the
circumstances, the purpose of the publication, applicable institutional requirements, and
whether the material is required as an official record.
Users should not upload photographs containing private documents, confidential records,
financial information, medical information, or other sensitive material merely for an
ordinary NSS website request.
11 — CERTIFICATES11
Certificate and ID-card information
If the website provides certificate or ID-card generation, the information entered for
that purpose may be processed to create the requested document. Depending on the
implementation, generated files may be created locally in the browser or may involve an
external service.
The website should avoid collecting more information than is reasonably necessary for the
stated certificate or ID-card purpose.
12 — FORMS12
Contact and submission forms
If an online form is available, information entered into it may be transmitted to the
service configured to receive that form. The website administrator should verify the
provider, storage period, access permissions, and deletion process before enabling a form
in production.
Users should review the fields before submitting and provide only information relevant to
the request.
13
Voluntary use
Most informational pages can be viewed without submitting personal information. Optional
features may require information in order to work.
14
Data minimisation
The website should collect only information reasonably required for the specific feature
or administrative purpose.
15
Children & young users
NSS activities can involve students of different ages. The website should avoid
unnecessarily collecting personal information from minors and should use appropriate
institutional procedures where required.
16 — SHARING16
When information may be shared
Personal information should not be publicly disclosed merely because it was submitted to
an NSS form. Access should be limited to people or services that reasonably need the
information for the relevant purpose, subject to the actual technical setup.
Information may potentially be accessible to:
- authorized NSS or college personnel responsible for the relevant activity;
- website administrators responsible for maintenance and security;
- hosting, storage, form, authentication, or infrastructure providers used by the site;
- service providers that are technically necessary to deliver a requested feature;
- authorities or other recipients where disclosure is required by applicable law or a
valid legal process.
The exact list of recipients depends on the live website configuration. Third-party
providers may have their own terms and privacy policies.
17 — SECURITY17
Reasonable security measures
Appropriate technical and organizational measures should be used to reduce the risk of
unauthorized access, accidental loss, alteration, misuse, or disclosure of information.
Examples include HTTPS where supported, access controls, secure account credentials,
limited administrative access, software maintenance, and careful handling of submitted
files.
No internet system can be guaranteed to be completely secure. Users should therefore
avoid submitting information that is unnecessarily sensitive.
18 — RETENTION18
How long information is kept
Information should be retained only for as long as reasonably necessary for the purpose
for which it was collected, for legitimate institutional recordkeeping, or as required by
applicable obligations.
Retention periods can differ between website forms, event records, certificates,
security logs, backups, and third-party services. If a specific retention period is
required, it should be added here after confirming the actual system configuration.
19 — THIRD-PARTY SERVICES19
External websites, links and embedded services
The NSS website may contain links to external websites, social-media pages, educational
resources, cloud services, maps, document viewers, image hosts, or other third-party
platforms. Once a visitor leaves the NSS website, the privacy practices of the destination
service apply.
A link from the NSS website does not necessarily mean that the external service is operated
by Raha College NSS. Users should read the privacy information provided by the external
service before submitting personal information.
20
Social links
Opening a social-media link may allow the destination platform to process information
about the visit according to its own policies.
21
External content
Embedded fonts, videos, maps, forms, images, analytics, or other resources may cause a
third-party server to receive a browser request.
22
Provider changes
If an external provider is replaced, the site's privacy documentation should be reviewed
and updated accordingly.
23 — USER CHOICES23
Access, correction and deletion requests
Where appropriate and subject to applicable requirements, a user may ask what personal
information they submitted through an NSS website feature, request correction of an
inaccurate submission, or ask whether information can be deleted.
A request should include enough information to identify the relevant submission without
unnecessarily sending sensitive information. For security reasons, an administrator may
need to verify the identity or authority of the person making a request.
Deletion may not always be possible immediately. For example, information may be present
in institutional records, backups, security logs, or documents that must be retained for a
legitimate purpose. If deletion cannot be completed, the reason should be explained where
appropriate.
24 — ACCOUNT SECURITY24
User responsibility
If the website ever provides user accounts, users should keep their login credentials
confidential, use strong passwords, avoid sharing account access, and notify the relevant
administrator if unauthorized activity is suspected.
Website administrators should never ask a user to publish a password in a public form.
25 — INCIDENTS25
Security and privacy incidents
If a suspected privacy or security incident is discovered, the responsible administrator
should investigate the issue, secure affected systems, preserve relevant evidence where
appropriate, and take reasonable corrective action.
Where applicable, affected individuals or relevant authorities should be informed in
accordance with the requirements governing the incident.
26 — LEGAL BASIS & COMPLIANCE26
Applicable requirements
The website should be operated in accordance with applicable Indian law, institutional
requirements, contractual obligations, and the rules applicable to the specific technology
providers used by the site. The exact legal obligations can depend on the type of
information processed, the purpose of processing, the people involved, and the systems
used.
This page is a website privacy-policy document and is not a substitute for legal advice.
Before using it as a formal institutional policy, the college or responsible authority
should review the final wording against its actual data practices and applicable
requirements.
27 — UPDATES27
Changes to this policy
This policy may be updated when the NSS website adds or removes features, changes a data
processor, changes how forms work, introduces authentication, adds analytics, changes
storage arrangements, or otherwise changes its privacy practices.
The date shown below should be updated whenever a substantive revision is published.
28 — VERSION28
Policy version information
| Website | Raha College NSS Website |
| Document | Privacy Policy |
| Version | 1.0 |
| Published | September 2026 |
| Last reviewed | |
29 — PRIVACY PRINCIPLES29
Plain-language principles
“Collect what is needed, explain why it is needed, protect it appropriately, and avoid
publishing private information unnecessarily.”
The website should be designed around a small number of practical privacy principles:
transparency, purpose limitation, data minimisation, reasonable security, controlled
access, responsible publication, and respect for user requests.
Privacy should also be considered when designing new NSS features. Before adding a form,
database, authentication system, gallery, volunteer directory, certificate generator,
analytics service, or external integration, the responsible website team should ask what
information the feature requires, where the information goes, who can access it, how long
it is retained, and whether the feature can work with less personal information.
30 — CONTACT30
Privacy questions, corrections or concerns
For a privacy question, correction request, removal request, security concern, or concern
about an image or personal information published on the website, users should contact the
responsible Raha College NSS website administrator or the appropriate NSS/college
authority through the official contact method published on the live website.
Recommended contact fields to complete before publishing:
- Official NSS/college email address
- Official contact number, if applicable
- Name or designation of the responsible website/NSS contact
- Official college or NSS address, if the institution wishes to publish it
- Link to the website's Contact page
PLEASE DO NOT SEND PASSWORDS
31 — FINAL NOTE31
Privacy in practice
A privacy policy is useful only when the website's actual behaviour matches what the policy
says. The Raha College NSS website team should therefore review this document whenever a
new technical feature is added. In particular, any future login system, database,
certificate verification system, volunteer registration system, event registration form,
cloud storage, analytics platform, email service, or third-party API should be checked and
reflected in this policy where it changes how personal information is handled.
This page is intentionally written in long-form so that users can understand the major
privacy topics in one place. It should be kept accessible from the main NSS website,
especially on pages where visitors are asked to submit information.
Raha College NSS — National Service Scheme website, Raha College,
Nagaon, Assam.