Last updated 1 October 2026
Roles
- Your society is the Data Fiduciary. It decides what resident data is collected and why.
- CITYTECH INNOVATIONS PRIVATE LIMITED is the Data Processor. We process resident data only on the society's documented instructions, to provide CITYTECH INNOVATIONS.
- Residents, tenants, visitors and staff are Data Principals with rights under the DPDP Act.
Data we process for a society
- Flat or house numbers, owner and tenant names, phone numbers and email addresses.
- Complaint tickets, including photos and voice notes residents send.
- Visitor, daily-help and parcel logs.
- Maintenance bills, payment confirmations and receipts. We do not receive card or bank account credentials.
- Vendor records, AMC and renewal dates, and documents such as bylaws, circulars and AGM minutes.
Isolation and access control
Each society's data is logically isolated from every other society's. Residents can see only their own records. Committee members, staff and facility managers see what their role permits. Our own staff access production data only to provide support, with logged access.
Encryption and security
- Data is encrypted in transit with TLS and encrypted at rest.
- Production access requires multi-factor authentication.
- Backups are encrypted and retained for a limited period.
- Documents a society uploads are used only to answer that society's questions. They are not used to train AI models.
Sub-processors
We use a small number of sub-processors to deliver the service, under contracts with equivalent data protection obligations:
- WhatsApp Business Platform (Meta Platforms) for message delivery.
- An RBI-regulated payment gateway for maintenance payment links.
- Cloud hosting and database providers.
- A large language model provider, under terms that prohibit training on customer data.
- An email delivery provider for receipts and notifications.
The current list of named sub-processors is available to customer societies on request, and we notify societies before adding a new one.
Breach notification
If we become aware of a personal data breach affecting a society's data, we will notify the society without undue delay, share what we know, and support it in notifying the Data Protection Board and affected Data Principals as the DPDP Act requires.
Retention and deletion on exit
Each society sets retention periods for visitor logs and other records. When a society leaves, we make its data available for export for 30 days and then delete it from production systems, with backups expiring on their normal cycle.
Requests from residents
Residents can ask their society, or us, to access, correct or erase their data. We pass requests we receive to the society and help it respond.
Contact
Security questions or to report a vulnerability: security@citytechinnovations.si. Privacy questions: privacy@citytechinnovations.si.