How We Protect Beneficiary Data & Guarantee Privacy
At EKMS Data, worker privacy is not an afterthought—it is the foundational premise of our software architecture. We process quantitative health outreach telemetry without ever storing or exposing Insured Person (IP) or Insured Woman (IW) personal identities, contact numbers, or names on client screens.
Zero Personal Identity Storage
No worker identity exposure
Our system never retains or indexes worker identity keys—including beneficiary names, personal phone numbers, IP insurance card numbers, or residential addresses. The platform operates on anonymized records solely to analyze healthcare utilization trends.
Backend-Only Secured Persistence
Zero client browser caching
All spreadsheet data and operational configurations are stored exclusively in backend Google Cloud Firestore databases with AES-256 rest encryption and TLS 1.3 transport security. Nothing sensitive is cached in browser memory or persistent cookies.
Quantitative Telemetry Only
Aggregated mathematical metrics
Dashboard graphs visualize exclusively numerical indicators: total calls attempted, connected percentages, qualified response counts, confirmed appointment ratios, broad age cohort brackets, and survey feedback category frequencies.
Full Administrative Auditability
Complete historical traceability
Every database transaction—including file uploads, dataset deletions, baseline target updates, and authorized administrative logins—is recorded in real time on our audit log with precise timestamps and operator attribution.
Data Transparency Matrix: What Never Enters vs. What We Process
A granular comparison of data attributes handled by the EKMS Data architecture.
- ✕Beneficiary Full Names — Worker identities are strictly omitted from reporting streams.
- ✕Personal Phone Numbers — Contact digits are never stored in browser caches or analytics tables.
- ✕IP / IW Card Numbers — Official ESIC worker registration codes are strictly excluded.
- ✕Residential Street Addresses — Exact worker geographical coordinates are never collected.
- ✕Financial or Banking Records — No income, bank account, or salary details are processed.
- ✓Call Funnel Totals — Gross counts of attempted, connected, qualified, and confirmed calls.
- ✓Broad Age Brackets — Cohort tallies (e.g., 18–25, 26–35, 36–45 years) without personal dates.
- ✓Categorical Survey Feedback — Aggregated reasons (e.g., distance, timing, awareness).
- ✓Hourly & Daily Calling Patterns — Statistical volume histograms (8 AM – 8 PM calling distributions).
- ✓Anonymous Agent Benchmarks — Operational efficiency metrics for quality assurance.
Architecture of a Privacy-Preserving Health Analytics Platform
Published by EKMS Technical Engineering & Data Governance Committee • September 2026
This platform was engineered to solve a pivotal public health challenge: evaluating industrial workers access to annual preventive health check-ups while safeguarding the fundamental privacy rights of every beneficiary.
1. The Stateless Frontend Model
Traditional web applications frequently download raw database snapshots into browser memory, creating vectors for data scraping or unauthorized extraction. EKMS Data deliberately inverts this paradigm. The frontend acts strictly as a graphical rendering engine for pre-computed numerical aggregates. When you open the dashboard on mobile or desktop, the web application requests aggregate vectors rather than raw PII records.
2. Backend Ingestion & Sanitization Pipeline
When administrators ingest operational survey files, our backend data processing pipeline normalizes categorical feedback through a closed taxonomy (such as standardizing Chest Pain, Joint Pain, Hospital Distance, or Lack of Leave). Individual worker contact numbers and names are stripped from public analytical indexes. The resulting database collections store mathematical telemetry used to optimize medical camp logistics and mobile check-up van deployment.
3. Strict Role-Based Administrative Governance
Access to underlying administrative functions—including uploading survey sheets, establishing baseline beneficiary targets, and inspecting audit trails—requires authenticated administrative credentials managed through secure session tokens. Unauthenticated public visitors can only interact with read-only macro-analytics.
4. Alignment with the Digital Personal Data Protection (DPDP) Act
Our operational architecture strictly implements the core principles of India Digital Personal Data Protection Act 2023:
- Principle of Data Minimization: Only telemetry data strictly necessary to track check-up adoption is maintained.
- Purpose Limitation: Data is utilized solely to improve public health check-up scheduling and outreach efficacy.
- Storage Security: Industry-standard cryptographic controls protect data both in transit and at rest.
- Accountability: Transparent audit trails track every data alteration event across the system lifecycle.
Frequently Asked Questions on Data & Privacy
Clear answers to common questions regarding security, data retention, and privacy safeguards.
Our Ongoing Commitment to Data Protection
The EKMS Data management team continually audits our infrastructure to verify that no PII is leaked, cached, or stored on client devices. If you have inquiries or feedback regarding privacy governance, please contact the Administrative Data Committee:
