Privacy Policy
Version 1.1 · effective May 2026 · governed by the Digital Personal Data Protection Act 2023 (India), the Information Technology Act 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011
PG Saathi is a software product that helps Paying-Guest owners in India run their hostels via WhatsApp. This policy is the formal Notice required under Section 5 of the Digital Personal Data Protection Act 2023 ("DPDP Act") and the SPDI Rules 2011. It tells you who we are, exactly what personal data we hold, the lawful basis under which we hold it, how long we keep it, with whom we share it, and the rights you have as a Data Principal.
At a glance
- Your data is stored in Mumbai, India (Supabase ap-south-1). Sub-processors are listed in section 7.
- We never store your full Aadhaar — only the last 4 digits, in line with DPDP data-minimisation.
- Lawful basis: your consent plus the "legitimate use" provisions of DPDP Section 7 (e.g. statutory tax obligations, fraud prevention).
- You can withdraw consent, export your data, correct it, or erase it at any time from
/account/deleteor by writing to the Grievance Officer (section 17). - We will notify you and the Data Protection Board within 72 hours of any personal-data breach affecting you (section 14).
1. Who we are (Data Fiduciary)
PG Saathi is the trading name of the entity operating this service from Ahmedabad, Gujarat. For the purposes of the DPDP Act we are the "Data Fiduciary" — the party that determines the purpose and means of processing your personal data.
- Entity
- Marnel Technologies Ltd
- Address
- Ahmedabad, Gujarat 380009, India
- privacy@pgsaathi.in
- Phone
- +919978536480
- GSTIN
- GSTIN: not yet registered (turnover below threshold)
- CIN
- Entity registration: pilot stage; details published on request.
2. Definitions
- Personal Data — any data about you from which you can be identified, as defined in DPDP Section 2(t).
- Sensitive Personal Data or Information (SPDI) — financial information (UPI ID, payment records), passwords, and similar categories listed in Rule 3 of the SPDI Rules 2011.
- Processing — any operation on personal data: collection, storage, use, disclosure, erasure (DPDP Section 2(x)).
- Data Principal — you, the individual whose personal data is being processed (DPDP Section 2(j)).
- Data Fiduciary — PG Saathi (Section 1 above).
- Data Processor — the third parties listed in Section 7 below who process personal data on our behalf under a written contract.
3. Personal data we collect
We follow the DPDP principle of data minimisation — we collect only what is needed to run a PG ledger and a WhatsApp bot. Categories:
- Owner / Manager identity: legal name, mobile phone number (used for WhatsApp sign-in and account recovery), preferred language (English / हिन्दी / ગુજરાતી).
- Owner financial data (SPDI): UPI ID for receiving rent, UPI holder name. We never see or store your bank password, OTPs, or full bank-account number.
- Tenant identity: name, mobile phone, optional alternate phone, gender, dietary preference, last 4 digits of Aadhaar only (DPDP minimisation — we explicitly refuse to store the full 12-digit Aadhaar), emergency-contact name & phone.
- Property metadata: PG name, neighbourhood/area, address, sharing type, room numbers, default rent, total beds.
- Payments (SPDI): rent and deposit amounts, UPI transaction reference (UTR) submitted by the tenant, owner's verify/reject decision, payment date and timestamp.
- Compliance documents: scanned copies of Society NOC / Fire NOC / Police NOC / BU Permission you upload to track expiry. Stored in Supabase Storage in Mumbai.
- Operational telemetry: every WhatsApp message body sent or received via the bot (so the owner has an audit trail), language detection and intent-classification result, IP address and user-agent for magic-link sign-in events (security audit).
4. Lawful basis for processing (DPDP Sections 6 & 7)
We rely on the following lawful bases:
- Your free, specific, informed, unconditional consent for all processing not covered below — captured at sign-up via the consent line accompanying the form. You may withdraw consent at any time (DPDP Section 6(4)).
- Performance of contract — processing necessary to provide the service you signed up for (e.g. generating an invoice you can show your tenant).
- Legal obligation — compliance with the Income Tax Act 1961 (rent receipts retention), the GST 0% rules under the Supreme Court's Taghar Vasudev Ambrish v. Commissioner of Central Tax (2022) judgement, AMC's mandatory PG NOC framework (Sep 2025), DPDP record-keeping (Section 8(7)).
- Fraud prevention & service security — DPDP Section 7(g) legitimate use, e.g. rate-limiting webhook abuse, investigating disputed UPI payments.
5. Specific purposes of processing
- Service operation — generate monthly invoices, accept tenant payments, surface overdue balances, run reminders, file the four AMC compliance documents (Society NOC, Fire NOC, Police NOC, BU Permission).
- Authentication — verify your identity via WhatsApp magic-links so only the owner / manager / tenant can act on their account.
- Tax & regulatory compliance — track GST 0% conditions (contracts ≥90 days, rent ≤₹20K, no food bundling), retain financial records for 7 years (Income Tax Act).
- Security & fraud prevention — detect and rate-limit abusive webhook traffic, investigate disputed payments via UTR, log magic-link consumption events.
- Service improvement — internal aggregate analytics on intent-classification accuracy and feature usage. Never sold or shared.
- Legal claims — defend against complaints, claims, or proceedings before any court, tribunal, or regulator.
6. Data minimisation, accuracy & retention principles
We are bound by the DPDP processing principles (Section 8). In practice:
- Minimisation: we collect only fields used by a specific feature. Aadhaar last-4 only. No marriage status, no caste, no biometric data.
- Accuracy: owners and tenants can edit their own data anytime; corrections propagate immediately.
- Storage limitation: retention periods are listed in Section 8 and enforced by automated cron jobs.
- Purpose limitation: data collected for one purpose (e.g. WhatsApp delivery) is not repurposed for another (e.g. marketing).
7. Who we share data with (Data Processors & sub-processors)
PG Saathi does not sell personal data. We share narrowly with the following Data Processors, each under a written Data Processing Agreement that mirrors the DPDP obligations onto them:
- Meta Platforms — WhatsApp Business Platform / BSP (Ireland for EU users; routed via Indian PoP for IN). Message bodies and phone numbers transit Meta's infrastructure to deliver WhatsApp messages. Mandatory for the WhatsApp channel.
- Sarvam AI (Bengaluru, India) — owner / tenant message text is sent to Sarvam's hosted LLM for intent classification. India-resident; same DPDP zone as Supabase.
- Anthropic PBC (San Francisco, USA) — two uses: (1) intent-classification fallback when Sarvam is unavailable — phone and Aadhaar digits are programmatically masked (
[PHONE_1]placeholders) before the text leaves India and restored locally on receipt; (2) ledger-photo OCR via Claude Opus Vision — raw photos of owner-supplied ledger pages are sent because pre-redaction would defeat the OCR. Photos are not retained server-side after the parsed JSON returns; Anthropic operates under a zero-retention API DPA with no training on prompts. See Section 9 (cross-border transfer). - Supabase (Mumbai, ap-south-1) — primary database, authentication and file storage. Data physically resides in India.
- Sentry (Vienna, Austria) — automated error monitoring. Personal identifiers (phones, emails, UUIDs, IBANs) are scrubbed locally before any event is dispatched.
- Vercel (Salt Lake City, USA) — hosts the PWA and runs the cron jobs. PWA pages render server-side; persistent personal-data writes go directly to Supabase Mumbai.
- Government, regulators, courts — only when compelled by valid legal process (DPDP Section 7(d)). We will notify you unless the order forbids it.
8. Cross-border transfer (DPDP Section 16)
DPDP Section 16 allows transfer of personal data outside India except to countries notified as restricted by the Central Government. As of the version date of this policy no country is on that list. Where we do route data outside India (Anthropic, Sentry, Vercel) we apply the additional safeguards described in Section 7 — masking PII before transit and contracting under DPAs that mirror DPDP. If the Central Government later restricts a destination we use, we will discontinue that processor.
9. How long we keep your data
- Active tenant data — for the duration of the contract.
- After move-out / archive — 7 years, to satisfy Income Tax Act 1961 audit retention and rent-receipt evidentiary requirements.
- WhatsApp message logs — 12 months for owner audit; thereafter the body is retained but personal
user_id/tenant_idlinks are removed once your account is deleted. - Audit log of financial actions — 7 years; preserved even after account erasure (anonymised but retained).
- Magic-link tokens — 30 days after use, then purged.
- Deletion-pending accounts — soft-archived for 30 days during which you may cancel; then hard-deleted by daily cron.
10. Your rights as a Data Principal (DPDP Sections 11–14)
- Right to information (Section 11) — know what data we have, the purposes, and the processors involved. The current section gives you that summary.
- Right to access & a copy — request a structured export of all personal data we hold about you.
- Right to correction & completion — fix anything inaccurate. Most fields you can edit yourself; for the rest, write to the Grievance Officer.
- Right to erasure — delete your account and linked data. Use
/account/deletefrom the dashboard — a 30-day grace window applies. - Right to grievance redressal (Section 13) — escalate to our Grievance Officer (Section 17). We respond within 30 days; if unsatisfied you may then approach the Data Protection Board of India.
- Right to nominate (Section 14) — nominate another person to exercise these rights on your behalf in case of death or incapacity.
- Right to withdraw consent (Section 6(4)) — at any time, with no penalty. Service that depended on the withdrawn consent will stop, but past lawful processing remains valid.
11. How to exercise your rights
Two routes:
- In-app: edit your own profile / tenant data directly in the dashboard, or trigger erasure at
/account/delete. - By email or letter: write to the Grievance Officer (Section 17). Include your registered phone number and a brief description of the request. We will verify your identity by sending a magic-link to that phone — this prevents an attacker from impersonating you.
- Response time: within 30 days, free of charge for reasonable requests. Repetitive or manifestly unfounded requests may attract a small fee under DPDP Section 7(2).
12. How we secure your data (DPDP Section 8(5) & SPDI Rule 8)
- All data in transit uses TLS 1.2+ with modern cipher suites. All data at rest is encrypted by Supabase using AES-256.
- Row-level security policies on every user-facing table prevent cross-property reads.
- Magic-link tokens are single-use and atomically consumed on redeem — one click = one valid session.
- WhatsApp webhooks are HMAC-SHA-256 signed and verified server-side.
- Aadhaar storage is structurally limited to the last 4 digits via a database CHECK constraint.
- Phone numbers and Aadhaar digits are programmatically masked before any cross-border LLM call.
- Audit log captures every mutating action with actor, timestamp, and entity reference.
- Cron jobs are protected by a rotating shared secret in the
Authorizationheader.
13. Data breach notification (DPDP Section 8(6))
If a personal-data breach affecting you occurs we will, within 72 hours of becoming aware: (i) notify the Data Protection Board of India in the prescribed form; (ii) notify each affected Data Principal directly via the registered phone number / email; (iii) describe the nature of the breach, the data categories affected, the likely consequences, and the steps we are taking to mitigate. Where direct notification is impractical, we will publish a public notice.
14. Cookies and similar technologies
We use a single first-party cookie `pgs_lang` to remember your preferred language. Authentication uses HTTP-only Supabase session cookies bound to your browser. We do **not** use third-party advertising cookies, fingerprinting trackers, or session-replay tools. Posthog product analytics, when enabled, runs in cookieless mode with PII redaction.
15. Children's data (DPDP Section 9)
PG Saathi is for adults running paying-guest businesses. DPDP defines a "child" as anyone under 18. We do not knowingly collect personal data from children. If a tenant under 18 is registered (e.g. a hostel for younger PG residents), processing requires verifiable parental consent, which we currently do not support — those owners should not register such tenants on PG Saathi until we add the consent flow. Behavioural tracking, profiling, or targeted advertising directed at children is not done at all.
16. Significant Data Fiduciary status & Data Protection Officer
PG Saathi is **not** currently classified as a Significant Data Fiduciary under DPDP Section 10. We do not yet meet the volume / sensitivity thresholds the Central Government has indicated. Accordingly we are not required to appoint a DPO based in India, conduct a Data Protection Impact Assessment, or run a periodic DPDP audit. If we are subsequently classified as an SDF we will appoint a DPO within 30 days and update this policy.
17. Consent records
We maintain timestamped records of when each Data Principal accepted these Terms / Privacy Policy, the policy version they accepted, and the IP / user-agent at the time. These records are produced if there is a future dispute about whether consent was given.
18. Changes to this policy
When we update this policy we will: (i) notify all registered owners via WhatsApp (template message); (ii) bump the version number and effective date at the top; (iii) preserve the prior version on request. Material changes (new processors, new purposes, expanded categories of data) require fresh consent under DPDP Section 6.
19. Grievance Officer (DPDP Section 8(9))
For any privacy concern, request, or exercise of your DPDP rights:
- Name
- Grievance Officer, PG Saathi
- privacy@pgsaathi.in
- Phone
- +919978536480
- Address
- Ahmedabad, Gujarat 380009, India
We acknowledge within 7 days and resolve within 30 days as required by DPDP Section 13(3).
20. Further escalation — Data Protection Board of India
If you are not satisfied with the Grievance Officer's response, you may escalate to the Data Protection Board of India under DPDP Section 27. The Board's contact details will be published on its official website at https://dpb.gov.in once constituted.
21. Governing law & jurisdiction
This policy and any dispute about your personal data are governed by the laws of India. The courts at Ahmedabad, Gujarat have exclusive jurisdiction, subject to your right to approach the Data Protection Board of India under DPDP Section 27.