Privacy
Your society pays Parisar a subscription. That fee is the entire business. There is no second business built on your attention or your data, and there never will be.
The short version. No ads. No trackers. No data sold, shared or brokered — to anyone, for any price. No facial recognition. No location tracking. No biometrics, ever. You can export everything we hold about you, and delete your account yourself, from inside the app, without asking a committee for permission.
Who is responsible for your data
For information that belongs to your society — your unit, your visitors, your household — your society is the Data Fiduciary and Parisar is the Data Processor, acting on its documented instructions. For your platform account itself — how you sign in, and the contact details attached to it — Parisar is the Fiduciary.
This matters in practice: for society records, your society sets retention within the ranges below and answers correction requests. We act on its instructions and keep the audit trail that shows what was done.
Parisar is built to comply with India's DPDP Act 2023 and the DPDP Rules 2025, and is designed along GDPR lines — purpose limitation, data minimisation, storage limitation and privacy by default — because that is the standard we hold ourselves to, not because we are required to.
What we collect, and what we refuse to
| If you are a… | We collect | We never collect |
|---|---|---|
| Resident | Name, a verified phone or email, your unit and role, household declarations you choose to make, vehicle numbers, and your notification preferences. | Interests or a bio for profiling, birthdays for marketing, income, your contacts list, advertising identifiers, or your location. |
| Visitor | The name given, the purpose of the visit, the host unit, entry and exit times, a vehicle number, and a gate photo where the society has turned that on. | A mandatory phone number — approval by the household works without one — or an ID scan by default. No marketing consent of any kind is ever requested. |
| Domestic worker | Only what you have consented to: your name, the households you work for, and attendance recorded at the gate. | Biometrics — ever. This is a platform term, not a society setting. No society can switch it on. There is no fingerprint, face or iris field anywhere in our database, and a test fails our build if one is ever added. |
| Guard | Name, agency, shift, and the events recorded by the society's own gate device. | Anything that would require using a personal phone for society work. |
There is a rule behind this table rather than a promise: every field in Parisar that holds anything personal must declare, in code, what it is for and how long it is kept. A change that adds a personal field without both is rejected before it can ship.
How long we keep it
The table below is generated from the database itself, from the same declarations that produce your data export and drive the nightly deletion jobs. It is not a description of our intentions written by hand; it is what the system actually does, rendered when you loaded this page.
| What | Kept for | Then | Applies to |
|---|---|---|---|
| Statutory financial records — the fiduciary's duty | 2922 days | Archive (kept to meet a statutory duty) | Staff |
| Tickets; anonymized for SLA statistics after the window | 730 days | Anonymize | Resident |
| SOS and incident records; anonymized after the window | 730 days | Anonymize | Resident |
| Until either party deletes; 12 months inactivity purge | 365 days | Deleted | Resident |
| Worker profile as registered: name, photo, work types | 365 days | Deleted | Worker |
| Identity and police-verification artifacts a society's policy requires | 365 days | Deleted | Worker |
| Visitor entry logs; anonymized counts remain after purge | 90 days | Deleted | Visitor |
| Device-bound sessions and refresh tokens | 30 days | Deleted | Resident |
| One-time codes; short-lived by construction | 1 day | Deleted | Resident |
| Account identifiers (verified phone/email, name). Held for the life of the account; deleted on the Doc 1.6 §5 self-service deletion path, which needs no committee approval. | While your account is open | Deleted | Resident, worker |
| Append-only privileged-action log. Never purged on a clock: it is the evidence that the guardrails held (Doc 1.4 §7.8, 4.1 §10). | While your account is open | Archive (kept to meet a statutory duty) | Resident |
| Person x Unit x Role. Survives role end so a unit's history stays intact (Doc 1.4 §1 — records anchor to the unit), but carries no access after the end date. | While your account is open | Archive | Committee, resident |
Societies can adjust some of these within stated ranges. They cannot extend them indefinitely, and they cannot switch the deletion jobs off.
Photos, cameras and recognition
Where a society enables gate photos, they exist to verify an entry and nothing else. They are visible to the host household and to gate roles, and they are deleted on the schedule above.
There is no facial recognition in Parisar — not of residents, not of visitors, not of workers. Photos are never used to train anything, never used for marketing, and never matched across societies. CCTV remains the society's own system; where it is linked, we store nothing from it by default.
Who we share it with
Nobody. No third-party sharing, no sale, no ad networks, no data brokers, no "partners". Exactly three things can move data outside Parisar:
- An integration you turned on, with a plain statement of what crosses the boundary. These are off by default.
- The service providers listed below, each under contract with data protection terms.
- A legal demand — validated in writing, scoped narrowly, and logged. Your society is told unless we are legally barred from telling it.
Service providers we use
| Provider | For | Where |
|---|---|---|
| DigitalOcean | Hosting and the database | Bangalore, India |
| DigitalOcean Spaces | Photos and documents | India |
| Twilio | One-time sign-in codes, and gate calls where a society uses them | Global |
| Google Firebase Cloud Messaging | Push notifications to your device | Global |
| Google Workspace | Email we send you | Global |
Your society's data is hosted in India. Adding a provider to this list means telling societies first.
What you can do yourself
- Export everything. A complete, machine-readable copy of what we hold about you, on demand, from inside the app.
- Delete your account. One tap, applied immediately, with no committee approval and no waiting period. See deleting your account for what is removed and what has to stay.
- Correct what is wrong. Corrections are logged and visible to you.
- Raise a grievance at grievance@parisar.app. If you are not satisfied, you may escalate to the Data Protection Board of India.
How it is protected
Traffic is encrypted in transit and data is encrypted at rest. Access is controlled per role on the server, with database-level isolation between societies so one society's data cannot be read from another's session. Actions taken by administrators are written to an append-only, tamper-evident log. Backups are encrypted.
Parisar is designed to meet OWASP ASVS Level 2, ISO 27001 and SOC 2 Type II. We are not certified against any of them, and this page will say so plainly until we are.
If something goes wrong
If personal data is exposed, we contain it, assess the scope, and tell your society without undue delay with the facts it needs to meet its own obligations. Where people are affected, they are told in plain language what happened and what to do about it.
Our own restraint
No Parisar employee has a dashboard showing residents' personal content. Administrative access is limited to metadata, and emergency access is logged and disclosed. Our marketing never uses society data; any case study is consented to and reviewed by the society first.
Changes
Changes to this policy are versioned and notified inside the app. They are never buried.
Questions about this policy: grievance@parisar.app.