PRIVACY & SECURITY

Your community's data, protected by design

Gate footage, financial ledgers and resident details are among the most sensitive data a society holds. NivasaOne treats them that way from the ground up — encrypted end to end, guarded by role-based access, logged in an immutable audit trail and hosted entirely within India. Security here isn't a feature bolted on; it's the foundation the whole platform is built on.

End‑to‑end encryption

Everything is encrypted with TLS 1.3 in transit and AES‑256 at rest, and payments are tokenised through PCI‑DSS‑certified gateways.

Role‑based access control

The committee, accountant, manager and guards each see only what their role needs, and access is revoked the moment it changes hands.

Complete audit trail

Every approval, payment and gate entry is logged with who, what and when — an immutable record that exports cleanly for your AGM.

Verified visitor entry

Time‑bound OTP passes, a photo captured at the gate and a live resident approval together ensure no unverified person gets inside.

Data residency in India

All of your data lives and is processed in Indian data centres, aligned with the DPDP Act, and never leaves the country.

You own your data

Export residents, ledgers and reports in standard formats any time — no lock‑in, and full, verifiable deletion when you offboard.

Built to a standard you can present at your AGM

Independently penetration-tested, with transparent policies, encrypted backups and a dedicated data-protection point of contact for every society we serve.

DPDP-alignedAES-256 at restPCI-DSS paymentsPen-tested
DPDP COMPLIANCE

Built around India's Digital Personal Data Protection Act

The DPDP Act, 2023 is India's law governing how personal data is collected, used and protected. It gives you — the Data Principal — a set of rights, and puts obligations on us as the Data Fiduciary. Here's exactly what that means in practice, not just a badge.

OUR DATA PROTECTION PROMISE

Home is where your family lets its guard down — your data deserves that same care.

Gate logs, dues, complaints, who lives where — this is deeply personal information, and we don't treat it lightly. Every feature is built with data protection as a starting constraint, not an afterthought bolted on before launch. That's not just good practice; it's exactly what the DPDP Act asks of us as your data fiduciary, and we hold ourselves to it whether or not anyone's checking.

YOUR RIGHTS AS A DATA PRINCIPALWHAT WE COMMIT TO AS A DATA FIDUCIARY
RIGHT 01Right to information

You can ask us, any time, exactly what personal data of yours we hold, why we collected it in the first place, and which third parties — if any — we've shared it with. No hidden processing, no surprises.

COMMITMENT 01Purpose limitation

We only ever collect what a specific feature genuinely needs — a gate log, a due, a notice — and nothing more. If we ever want to use it for something new, we come back and ask again first.

RIGHT 02Right to correction & erasure

If something we hold about you is wrong, out of date, or incomplete, you can ask us to fix it. If we no longer have a genuine reason to keep it — including any audit or legal retention requirement still running (see our data retention note below) — you can ask us to erase it outright.

COMMITMENT 02Data hosted in India

Every resident record, financial ledger and gate log lives and is processed in Indian data centres, in line with the DPDP Act's data-localisation expectations — it never quietly leaves the country.

RIGHT 03Right to grievance redressal

Something feel off about how your data was handled? Raise it with our Grievance Officer first, and escalate to the Data Protection Board of India if it isn't resolved to your satisfaction.

COMMITMENT 03Plain-language consent

Before we collect anything, we explain what it is and why in plain, everyday language — not a wall of legal text you'd have to be a lawyer to actually understand before agreeing to it.

RIGHT 04Right to nominate

You can name a family member or someone you trust to exercise every right above on your behalf, in the event you're no longer able to — your data protection outlives any one moment.

COMMITMENT 04Export & erasure on request

Any society can export the whole of its data any time, and ask for deletion when it offboards — except for the specific records we're required to hold a while longer for audit or legal reasons, which we delete the moment that requirement lapses.

NOTEGrievance Officer / data requests

For any question about your data, or to exercise a right above, write to nivasaone@gmail.com. We aim to acknowledge within 2 business days.

Note: there is no official government-issued “DPDP certified” seal in India — compliance under the Act is self-attested by every organisation and enforced by the Data Protection Board of India, not awarded as a certificate. What's listed above is what we hold ourselves to; we'll keep this page current as our compliance programme matures ahead of public launch.

NOTEHow long we keep your data

We haven't finalised NivasaOne's own retention schedule yet, so for now we follow the same norms most record-keeping platforms in India work to: financial ledgers and dues records are kept roughly 7–8 years, in line with typical income-tax and society audit-record expectations; routine gate and visitor logs for a much shorter window, usually 90 days to a year, unless one is tied to an open complaint or security incident, in which case it's kept until that's resolved; and complaint records until resolved plus a short buffer for any appeal.

This is a market-practice placeholder, not a finished policy — once we've worked out NivasaOne's own retention rules with proper legal input, we'll replace this note with our actual schedule.