Who we are
Data controller
The Blue Syndicate Consultants (Private) Limited
Incorporated under the Companies Act, 2017 · CUIN 0351079
Registered in Hyderabad, Sindh, Pakistan
Our registered postal address is held on the SECP company register and is provided on request.
What this policy covers
We run two quite different kinds of service, and they handle data differently. Read the part that applies to what you are using.
- Part 1 — SALAR Navigate, our mobile application for iOS and Android. No account, and nothing about you is stored.
- Part 2 — our web services: this website, Sindh WAT, the Daily Regulation Plan, the Kotri Barrage model, the e-Library and SALAR. Some of these require an account, and one of them takes payment.
The sections after Part 2 apply to everything.
Part 1 — SALAR Navigate (mobile app)
What it collects
With your permission, the app reads your device's GPS position while you are using it. iOS and Android both ask you first, and you can withdraw permission at any time in your device settings — the map still works, it simply cannot show you where you are or navigate.
Your position is used for three things, and nothing else:
- drawing your location on the map;
- working out a route when you ask for directions;
- following that route as you drive, so the guidance stays in step.
What it does not collect
- No advertising identifier, no contacts, no calendar and no files. The map itself needs no account: browsing the network, searching a channel and reading its register entry all work signed out. Signing in is only for field teams — see below.
- The camera, photo library and microphone are used only when you take a photograph or record a clip for your team, and never otherwise.
- No advertising identifier, and no tracking across other apps or websites.
- No analytics or crash-reporting service. The app contains no third-party tracking code of any kind.
What leaves your device
The entire Sindh irrigation network — every canal, barrage, bund and boundary the app draws — is stored inside the app itself. Browsing the map, searching for a channel and reading its register entry all happen on your phone, with nothing sent anywhere.
Two things do leave the device, and only when you ask for them:
- Directions. Your starting coordinates and your destination are sent to our server, which asks the Google Directions API on your behalf and returns the turns. We route this through our own server so the Google key cannot be extracted from the app and spent by someone else — not to see where you are going.
- Spoken guidance. The words of each instruction — for example "turn right onto the Hyderabad bypass" — are sent to our server, which turns them into audio. The text is sent; your position is not.
We do not store your location. Coordinates are used to answer the request in front of them and are written to no database. Our web server logs are deliberately configured so that the coordinates and the spoken text are not recorded — the log shows that a route was requested, not where from or where to.
Part 2 — our web services
Accounts
Sindh WAT, the Daily Regulation Plan and SALAR require you to sign in. For an account we hold your username, email address, name and a cryptographic hash of your password — we never store the password itself and cannot read it. Departmental accounts are created by us for named staff; SALAR subscriber accounts are created by the subscriber.
Where you enter data into the system as part of your work — discharge readings, gauge entries, regulation figures — that record is attributed to your account, because an operational record has to be attributable.
SALAR conversations
When you ask SALAR a question, the question and its answer are stored against your account, together with a record of what the request cost to process. This is what lets you reopen a past conversation and lets us bill accurately.
To produce an answer, your question and the relevant conversation history are sent to Anthropic's Claude API. Where a spoken or Urdu reply is requested, the text of the answer is sent to Google Cloud Text-to-Speech or Google Translate. We do not use your conversations to train any model.
Field teams and location sharing
Staff who join a field team share their position with the other members of that team, so that a supervisor can see where the team is working. This is the only part of anything we run that shares a person's location.
Being in a team is what shares your position. In the mobile app there is no separate switch: joining a team starts it and leaving the team ends it. Your phone also asks your permission before any app may read your location at all, and you can withdraw that at any time in your device settings — the map still works, it simply cannot show where you are.
While you are in a team, this continues with the app in your pocket. It has to: a field team is a team in a vehicle, and until September 2026 the app stopped reporting the moment the screen went dark, so two engineers travelling together could be drawn kilometres apart. The app does not ask for the “Always” location permission — “While Using the App” is enough — and for as long as your position is going out with the app in the background, iOS shows a blue indicator in the status bar. That indicator is the point: nothing is read from your phone without something on your phone saying so. Leaving every team stops it, and so does closing the app from the app switcher.
What is held, and what is not:
- Only your current position. Each reading overwrites the last. No history is kept — there is no trail of where you have been, because none is recorded. The single exception is a journey, which exists only while you have chosen to record one and is described below.
- Only your team can see it. Not other teams, not other staff, not the public. Someone waiting for approval to join sees nothing.
- Leaving ends it immediately. Leave a team and your position stops being shared at once; once you are in no team at all, the stored position is deleted rather than kept. This is how you stop sharing.
- Which teams you are in is shown on your profile. Anyone who shares a team with you sees, on your profile, the names of the other teams you belong to and whether you are a member or an administrator of each. Nothing else crosses: they cannot open a team they are not in, and they see none of its members, positions, photographs or journeys. This is so that work filed against the wrong team can be found and corrected.
- If your phone loses signal, or you close the app, or you leave the team, your last position stops moving. Your team sees the pin fade and carry the time it was last heard from — “last seen 46 minutes ago” — rather than a fresh-looking pin at a place you left an hour ago.
Notices to a team administrator
Twice a day, at 10 in the morning and 6 in the evening, a report is compiled for each field team whose members recorded a journey or took a photograph or a video in the hours since the last one, and every administrator of that team is told it is ready. Nothing is compiled or sent when nothing was done. Each photograph and recording carries the category its officer had chosen when it was taken — Barrage, Canal, Development Scheme, or a name of his own — and the report is divided and read by that category.
- To administrators of that team, and to nobody else. A member is not sent these and cannot see them.
- The report is kept under that team and is readable by administrators of that team only. It holds the team’s tours, photographs and what was read from them — nothing an administrator could not already open one item at a time. Keeping it means the same document reads the same way every time it is opened.
- Who pays for it. Compiling a report uses SALAR, and its cost is taken from the credit of one administrator of the team who holds a SALAR subscription. The other administrators are told of the same report and are not charged. A team none of whose administrators holds SALAR credit has no report compiled. Each charge appears on the paying administrator’s statement.
- To show the message on your phone we hold a notification token issued by Apple for that installation, and nothing else about the device. It identifies the app on one phone, is meaningless to anyone but Apple, and is deleted when Apple tells us the app has been removed. Turning notifications off in your phone's settings, or never granting them, changes nothing else — the messages are still in the app.
Every member can leave any team at any moment, without asking anyone, and that is what stops their position being shared. We also hold the messages sent in team chat and in direct messages between members.
Field photographs
A member of a field team can take a photograph from inside the map. Unlike a position, a photograph is kept — that is what it is for. Each one is stored with the coordinates and the time it was taken, and with the name of the person who took it.
This is the one place where we hold a record that says a particular person was at a particular place at a particular time, and we would rather say so plainly than leave you to work it out:
- Only when you take one. Nothing is photographed automatically, and taking a photograph is the only thing that creates such a record. Your position itself still keeps no history.
- Your team only, unless an admin publishes it. A new photograph is visible to the members of your team and to nobody else. A team administrator can publish an individual photograph to the public map, one at a time and never in bulk, and can make it team-only again afterwards. There is no setting that publishes photographs automatically.
- Published means public. The Live Irrigation Map needs no sign-in, so a published photograph — with its place and time — can be seen by anyone who opens it.
- Yours to delete. The person who took a photograph can delete it at any time, and so can an administrator of that team. Deleting removes the image file as well as the record.
- Location is required to take one, because a photograph that cannot be placed is of no use to the team. The coordinates are read from your browser at the moment of capture, not from the image file.
- Kept until deleted. Field photographs are not removed on a timetable; they remain until somebody entitled to delete one does.
- Each one is read by software, and the picture is sent to
Anthropic for that. Shortly after a
photograph or recording arrives, it is described — what kind of
structure is in frame, whether there is water, whether silting, weed, a
breach or damage is visible. That description is stored beside the picture
and used to assemble an inspection report from a
journey. Four things about it:
- the description is visible to your team only, and is never shown on the public map, even for a published photograph;
- it is labelled as a machine reading wherever it appears, and is never presented as the officer’s own observation. It describes only what is in the frame: no place, chainage or discharge is taken from a photograph, because those are already recorded;
- what is sent is the picture and its caption — not your name, not the coordinates, not the team. People who happen to be in a photograph are in what is sent, as they are in the photograph;
- deleting the photograph deletes the reading, and Anthropic does not use it to train any model.
Journeys
A journey is a tour you choose to record: you press Start before you set off and End when you are back. It is the only thing we run that keeps a record of where you have been, and because that is a real departure from everything said above, this section says exactly what it holds.
What a journey records:
- How far you travelled, measured by your phone, and the vehicle odometer readings if you enter them.
- Where you stopped and for how long. A stop is recorded when the vehicle stands still for more than three minutes. Each is saved with its coordinates, the time you arrived and the time you left, and — where the app can work it out from the drawn network — the channel and chainage, such as “Phuleli Canal RD 32.8”.
- What you recorded along the way: the findings you tag yourself, such as a breach or an encroachment, each with its position and the time you tagged it.
- What the journey was for, and any note you add.
What a journey does not record:
- Not the route you drove. The individual positions your phone reads are used to work out the distance and to notice that you have stopped, and are then discarded. They never leave your phone and no line of your movement is stored anywhere.
- Nothing at all unless a journey is running. No journey starts by itself; you start one and you end it. While one is running it keeps measuring with the app in your pocket — a tour is driven, not watched on a screen — and iOS shows the blue indicator in the status bar for the whole time it does. Ending the journey ends that.
Who can see one, and for how long:
- You, and an admin of the team the journey was made for. Not other members of that team, not other teams, not the department at large and not the public.
- Only you can delete one, and doing so removes it for the team admin as well. An admin can read a journey and cannot remove one.
- Kept until you delete it. Journeys are not removed on a timetable, because their purpose is to substantiate a tour diary or a travelling allowance claim long after the tour.
If you would rather not have this recorded, do not start a journey. Nothing else in the app depends on it, and every other part works exactly as it did before.
Subscribers and payment
For a paid SALAR subscription we additionally hold your organisation and phone number, your credit balance, and a record of each payment: the amount, the date, the method and the gateway's reference.
Payments are taken by Safepay. You are redirected to Safepay's own checkout to enter your card details, which means your card number never reaches our servers and we never store it. We keep only what Safepay returns to us for reconciliation.
Visitor counts
To know which of our pages and tools are actually used, our website and web services count visits with Cloudflare Web Analytics. It sets no cookies and stores nothing on your device, and Cloudflare states that it does not fingerprint or follow individuals across websites. For each page viewed, the count records the page's address without anything after a “?”, the site that linked to it, your country, browser, operating system and type of device, and how quickly the page loaded. It contains nothing that identifies you. Cloudflare keeps full detail for 7 days and then only a sample, and its reports go back six months.
It is not on the Live Irrigation Map or on anything belonging to field teams, because those addresses can carry a position. It is not in SALAR Navigate or any other app.
Cookies
Our web services set two cookies, both strictly necessary: a session cookie so you stay signed in, and a CSRF token that protects forms from being submitted by another site. We set no advertising or analytics cookies; the visitor count described above uses none.
What we never do
- We do not sell your data, and we never will.
- We run no advertising, and share nothing with advertisers or data brokers.
- We use no advertising, tracking or crash-reporting service, and nothing that follows you from page to page or site to site. The one measurement we run is the anonymous visitor count described above, and it is not in the app.
- We do not build behavioural profiles or track you across other sites.
- We keep no record of anyone's movements — not in the app, and not in field teams, where only the latest position exists. The single exception is a field photograph, which you create deliberately by taking one and can delete yourself.
Others who are involved
These are the only third parties that receive any data, each for a stated purpose:
- Google Maps Platform — draws the maps, and calculates routes from the coordinates described in Part 1.
- Google Cloud — converts instruction and answer text into speech, and hosts our infrastructure.
- Anthropic — processes SALAR questions to generate answers, and reads field photographs to describe what is visible in them.
- Cloudflare — counts visits to our website and web services, as described in Visitor counts.
- Safepay — takes card payments on its own checkout.
Each handles data under its own privacy policy, including the Google Privacy Policy. We share your data with no one else, and with no government body except where the law of Pakistan compels us and we have no lawful means to refuse.
How long we keep things
- Location — not stored at all for SALAR Navigate. For field teams, only the current position, overwritten each time and deleted when you leave your last team. No history in either case.
- Field photographs — kept, with their coordinates and the time they were taken, until the person who took one or a team administrator deletes it. There is no automatic expiry.
- Server logs — up to 14 days, then deleted automatically, and excluding the location and spoken text described in Part 1.
- Accounts, conversations and payment records — kept while your account is open. Payment records are kept afterwards for as long as Pakistani tax and company law requires.
- Operational records entered as part of departmental work are retained as departmental records.
Security
Everything is served over HTTPS, passwords are stored only as salted hashes, and access to the systems that hold personal data is limited to those of our staff who need it. No system is perfectly secure, and we do not claim otherwise; if a breach ever affects your data we will tell you.
Your rights
You may ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete your account and its data. Write to admin@thebluesyndicate.org and we will respond within 30 days. Some records — payment history, and operational records belonging to a government department — we may be required to retain.
For SALAR Navigate specifically there is generally nothing to export or erase, since it holds no account and stores no history. Revoke location permission in your device settings at any time; uninstalling removes everything it holds, because it holds it all locally.
Children
Our software consists of professional tools for irrigation engineers, planners and administrators. It is not directed at children, and we do not knowingly collect data from anyone under 13.
Changes
If this policy changes we will update the effective date above and, for any change that affects what we collect, say so in the relevant release notes. We will not begin collecting something new without telling you.
Governing law
This policy is governed by the laws of the Islamic Republic of Pakistan.