Your privacy is important to us. Learn how we collect, use, retain, and protect personal data across Gracelist services.
Effective date: 15 September 2026
This Privacy Policy explains the principal categories of personal data processed through Gracelist and the purposes for which that information may be used. Additional programme, form, or service-specific notices may apply where a particular activity requires more specific information.
This Privacy Policy applies to the Gracelist platform and services available through gracelist.co, including applicable mobile versions and applications operated by Piana IT Solutions Private Limited ("Piana", "we", "us", or "our").
Gracelist may be used by individuals, organisations, programmes, projects, and other authorised users for activities including profile management, organisation and project administration, registrations, forms and surveys, document management, communications, reporting, and related platform services.
Where Gracelist processes personal data on behalf of an organisation or other customer, the applicable responsibilities between Piana and that organisation may depend on the particular service, purpose, instructions, and applicable law.
Piana IT Solutions Private Limited is committed to protecting personal data and maintaining appropriate technical and organisational safeguards when operating Gracelist.
We process personal data only for defined and legitimate purposes connected with the services being provided. Depending on the circumstances and applicable law, processing may be based on consent, contractual or service requirements, legal obligations, or another applicable lawful basis.
Where we rely on consent, consent is requested for the relevant purpose and may be withdrawn in accordance with applicable law. Withdrawal of consent does not affect processing that was lawfully carried out before withdrawal and does not prevent processing that may continue on another applicable lawful basis.
If you have a question about how your personal data is being processed, or wish to submit a privacy request, please contact us at info@gracelist.co.
GracelistApp is a unified service operated by Piana IT Solutions Private Limited. Certain features may be made available across affiliated or related domains and applications. Depending on the service being used, the following privacy notices may also be relevant:
Data shared between services is handled according to the applicable purpose, user relationship, service configuration, and privacy notice. A feature being available across domains does not by itself mean that personal data may be used for unrelated purposes.
The information collected through Gracelist depends on the service, form, programme, organisation, or feature you use. We seek to collect only information that is reasonably necessary for the relevant purpose.
Gracelist may process information submitted through forms, surveys, registrations, feedback activities, and programme workflows. Depending on the particular form, this may include identifying information, contact information, programme or educational information, responses, location information, photographs, attachments, or other information specifically requested by the organisation or programme conducting the activity.
Forms should collect only information necessary for their stated purpose. Where a form collects information about beneficiaries, participants, students, or other individuals, the applicable organisation or programme may determine the purpose and scope of that collection.
Users or authorised organisations may upload documents, certificates, photographs, reports, or other files. Such information is processed to provide the relevant document management, verification, reporting, compliance, or programme functionality for which the information was submitted.
Some programmes or forms may request demographic or other information, such as gender or other characteristics, where there is a defined and appropriate purpose. Such information should be provided only where requested for the relevant programme or purpose and where permitted by applicable law.
We may automatically collect limited technical and activity information when you use Gracelist. The information collected depends on the feature, device, and security requirements.
Information about activity performed through the platform, such as interactions with programmes, projects, forms, submissions, or platform features.
Technical information such as IP address, browser or device information, operating system, device identifiers where required, and security-related logs.
Certain forms or platform features may request location information where it is necessary for the stated purpose, such as mapping, field activities, programme reporting, or analytics.
Where enabled, notification or push-token information may be processed to deliver platform notifications to a user's device.
Personal data is used only for purposes connected with the relevant Gracelist service, feature, programme, or organisational workflow. Depending on the context, these purposes may include:
Providing requested services, administering accounts, and responding to support requests.
Supporting forms, surveys, projects, beneficiaries, participants, reporting, and organisational workflows.
Protecting accounts and services, detecting misuse, preventing fraud, and maintaining platform security.
We do not use personal data for unrelated purposes merely because the data is available to us. Where a new purpose is materially different from the original purpose, the applicable notice, consent, authorisation, or other lawful basis will be considered before processing begins.
We seek to limit personal data collection to information that is reasonably necessary for the specified purpose of the relevant service or activity.
Personal data is retained only for as long as it is reasonably required for the purpose for which it was collected, to provide the relevant service, to meet applicable legal or contractual requirements, or to establish, exercise, or defend legal claims.
Specific retention periods may depend on the organisation, programme, record type, contract, or applicable legal requirement. Where applicable, the relevant retention schedule or programme-specific notice will provide further information.
We maintain technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss, misuse, or destruction.
Depending on the service and risk involved, safeguards may include access controls, authentication mechanisms, secure communications, database and server protections, logging, backups, vulnerability management, and administrative controls.
Access to personal data should be limited to authorised users and systems that require the information for legitimate operational purposes.
No method of transmission or storage can be guaranteed to be completely secure. We therefore continuously work to improve security controls appropriate to the risks associated with the services we provide.
Where you choose to connect a supported third-party publishing service, such as Meta/Facebook, Gracelist may use the applicable provider APIs to facilitate actions that you initiate.
Depending on the feature and the permissions approved by the third-party provider, the connection may allow Gracelist to access information such as Pages you manage and publish authorised content.
pages_manage_postsPublish authorised content to Pages.
pages_read_engagementAccess applicable Page engagement information.
pages_show_listView Pages available to the connected account.
Depending on the approved connection, we may receive and store information such as:
Gracelist does not request or store your third-party social account password.
Third-party platform data is processed to provide the feature that you or an authorised organisation has requested, such as publishing content or displaying relevant performance information.
You may disconnect a supported third-party connection through the available Gracelist controls or through the applicable third-party platform settings. Disconnecting a third-party integration is separate from withdrawing consent for unrelated processing activities.
Certain affiliated websites and applications may integrate with GracelistApp to allow authorised users to publish content, manage connected Pages, or view analytics relating to content initiated through the relevant service.
Where analytics functionality is enabled, Gracelist may process performance metrics associated with content published through the applicable integration. The information is used to provide the relevant analytics functionality and improve understanding of content performance.
Analytics data is not intentionally used for unrelated advertising or profiling purposes merely because it is available through the integration.
You may contact us regarding your personal data, including requests for access, correction, deletion, or withdrawal of consent where consent is the applicable basis for processing.
To submit a privacy request, contact:
Open Privacy CenterPlease provide enough information for us to identify the relevant account, organisation, programme, or processing activity. We may need to verify the identity or authority of the person making a request before acting on it.
You may request deletion of personal data where applicable. Deletion may be subject to legal, contractual, security, organisational, or record-retention requirements. Where data cannot be deleted immediately because an applicable requirement requires retention, we will handle the information according to the applicable retention requirements.
Where processing is based on consent, you may request withdrawal of that consent. Withdrawal applies to the relevant consent based processing and does not affect processing that was lawful before withdrawal or processing that may continue under another applicable lawful basis.
A request to withdraw consent is separate from disconnecting a third-party integration such as Facebook.
If you wish to stop a connected third-party publishing service, you may disconnect the relevant social account through the available Gracelist controls or the third-party provider's settings. This may invalidate or remove the connection used for publishing or other authorised functionality.
Subject to applicable law and the role of the parties involved, individuals may have rights relating to their personal data. These may include:
Request information about personal data processed about you, where applicable.
Request correction of inaccurate or incomplete personal data, where applicable.
Request deletion of personal data where applicable and where no overriding retention requirement applies.
Where processing relies on consent, request withdrawal of that consent.
The exact rights available and the manner in which they may be exercised depend on the applicable law, the purpose of processing, and whether Piana or another organisation is responsible for the relevant processing activity.
Organisations may use Gracelist for document management, compliance tracking, CSR project collaboration, reporting, and related activities. These workflows may involve organisational documents, financial records, certificates, participant information, beneficiary information, and other personal data.
Depending on the service and processing activity, Piana may process personal data on behalf of an organisation or may process certain data for its own service, security, or operational purposes. The applicable roles and responsibilities should be determined according to the particular processing activity, contractual arrangements, and applicable law.
Unless expressly stated otherwise, Gracelist does not represent that uploaded documents are authentic, accurate, or complete. Responsibility for information supplied by an organisation or user remains with the party responsible for submitting or maintaining that information.
For additional information about data protection controls and compliance practices:
View Full Compliance PolicyWe're here to help. Contact us regarding privacy questions, requests, or concerns.
© 2026 Piana IT Solutions Private Limited. All rights reserved.
Registered Office: A-2 East of Kailash, New Delhi - 110065
Privacy Policy Version 2.0 — Effective 15 September 2026.
We may update this policy from time to time. Material changes will be communicated through appropriate channels where required.