Gate footage, financial ledgers and resident details are among the most sensitive data a society holds. NivasaOne treats them that way from the ground up — encrypted end to end, guarded by role-based access, logged in an immutable audit trail and hosted entirely within India. Security here isn't a feature bolted on; it's the foundation the whole platform is built on.
Everything is encrypted with TLS 1.3 in transit and AES‑256 at rest, and payments are tokenised through PCI‑DSS‑certified gateways.
The committee, accountant, manager and guards each see only what their role needs, and access is revoked the moment it changes hands.
Every approval, payment and gate entry is logged with who, what and when — an immutable record that exports cleanly for your AGM.
Time‑bound OTP passes, a photo captured at the gate and a live resident approval together ensure no unverified person gets inside.
All of your data lives and is processed in Indian data centres, aligned with the DPDP Act, and never leaves the country.
Export residents, ledgers and reports in standard formats any time — no lock‑in, and full, verifiable deletion when you offboard.
Independently penetration-tested, with transparent policies, encrypted backups and a dedicated data-protection point of contact for every society we serve.
The DPDP Act, 2023 is India's law governing how personal data is collected, used and protected. It gives you — the Data Principal — a set of rights, and puts obligations on us as the Data Fiduciary. Here's exactly what that means in practice, not just a badge.
Gate logs, dues, complaints, who lives where — this is deeply personal information, and we don't treat it lightly. Every feature is built with data protection as a starting constraint, not an afterthought bolted on before launch. That's not just good practice; it's exactly what the DPDP Act asks of us as your data fiduciary, and we hold ourselves to it whether or not anyone's checking.
You can ask us, any time, exactly what personal data of yours we hold, why we collected it in the first place, and which third parties — if any — we've shared it with. No hidden processing, no surprises.
We only ever collect what a specific feature genuinely needs — a gate log, a due, a notice — and nothing more. If we ever want to use it for something new, we come back and ask again first.
If something we hold about you is wrong, out of date, or incomplete, you can ask us to fix it. If we no longer have a genuine reason to keep it — including any audit or legal retention requirement still running (see our data retention note below) — you can ask us to erase it outright.
Every resident record, financial ledger and gate log lives and is processed in Indian data centres, in line with the DPDP Act's data-localisation expectations — it never quietly leaves the country.
Something feel off about how your data was handled? Raise it with our Grievance Officer first, and escalate to the Data Protection Board of India if it isn't resolved to your satisfaction.
Before we collect anything, we explain what it is and why in plain, everyday language — not a wall of legal text you'd have to be a lawyer to actually understand before agreeing to it.
You can name a family member or someone you trust to exercise every right above on your behalf, in the event you're no longer able to — your data protection outlives any one moment.
Any society can export the whole of its data any time, and ask for deletion when it offboards — except for the specific records we're required to hold a while longer for audit or legal reasons, which we delete the moment that requirement lapses.
For any question about your data, or to exercise a right above, write to nivasaone@gmail.com. We aim to acknowledge within 2 business days.
Note: there is no official government-issued “DPDP certified” seal in India — compliance under the Act is self-attested by every organisation and enforced by the Data Protection Board of India, not awarded as a certificate. What's listed above is what we hold ourselves to; we'll keep this page current as our compliance programme matures ahead of public launch.
We haven't finalised NivasaOne's own retention schedule yet, so for now we follow the same norms most record-keeping platforms in India work to: financial ledgers and dues records are kept roughly 7–8 years, in line with typical income-tax and society audit-record expectations; routine gate and visitor logs for a much shorter window, usually 90 days to a year, unless one is tied to an open complaint or security incident, in which case it's kept until that's resolved; and complaint records until resolved plus a short buffer for any appeal.
This is a market-practice placeholder, not a finished policy — once we've worked out NivasaOne's own retention rules with proper legal input, we'll replace this note with our actual schedule.