Parisar

Privacy

Your society pays Parisar a subscription. That fee is the entire business. There is no second business built on your attention or your data, and there never will be.

The short version. No ads. No trackers. No data sold, shared or brokered — to anyone, for any price. No facial recognition. No location tracking. No biometrics, ever. You can export everything we hold about you, and delete your account yourself, from inside the app, without asking a committee for permission.

Who is responsible for your data

For information that belongs to your society — your unit, your visitors, your household — your society is the Data Fiduciary and Parisar is the Data Processor, acting on its documented instructions. For your platform account itself — how you sign in, and the contact details attached to it — Parisar is the Fiduciary.

This matters in practice: for society records, your society sets retention within the ranges below and answers correction requests. We act on its instructions and keep the audit trail that shows what was done.

Parisar is built to comply with India's DPDP Act 2023 and the DPDP Rules 2025, and is designed along GDPR lines — purpose limitation, data minimisation, storage limitation and privacy by default — because that is the standard we hold ourselves to, not because we are required to.

What we collect, and what we refuse to

If you are a…We collectWe never collect
Resident Name, a verified phone or email, your unit and role, household declarations you choose to make, vehicle numbers, and your notification preferences. Interests or a bio for profiling, birthdays for marketing, income, your contacts list, advertising identifiers, or your location.
Visitor The name given, the purpose of the visit, the host unit, entry and exit times, a vehicle number, and a gate photo where the society has turned that on. A mandatory phone number — approval by the household works without one — or an ID scan by default. No marketing consent of any kind is ever requested.
Domestic worker Only what you have consented to: your name, the households you work for, and attendance recorded at the gate. Biometrics — ever. This is a platform term, not a society setting. No society can switch it on. There is no fingerprint, face or iris field anywhere in our database, and a test fails our build if one is ever added.
Guard Name, agency, shift, and the events recorded by the society's own gate device. Anything that would require using a personal phone for society work.

There is a rule behind this table rather than a promise: every field in Parisar that holds anything personal must declare, in code, what it is for and how long it is kept. A change that adds a personal field without both is rejected before it can ship.

How long we keep it

The table below is generated from the database itself, from the same declarations that produce your data export and drive the nightly deletion jobs. It is not a description of our intentions written by hand; it is what the system actually does, rendered when you loaded this page.

WhatKept forThenApplies to
Statutory financial records — the fiduciary's duty 2922 days Archive (kept to meet a statutory duty) Staff
Tickets; anonymized for SLA statistics after the window 730 days Anonymize Resident
SOS and incident records; anonymized after the window 730 days Anonymize Resident
Until either party deletes; 12 months inactivity purge 365 days Deleted Resident
Worker profile as registered: name, photo, work types 365 days Deleted Worker
Identity and police-verification artifacts a society's policy requires 365 days Deleted Worker
Visitor entry logs; anonymized counts remain after purge 90 days Deleted Visitor
Device-bound sessions and refresh tokens 30 days Deleted Resident
One-time codes; short-lived by construction 1 day Deleted Resident
Account identifiers (verified phone/email, name). Held for the life of the account; deleted on the Doc 1.6 §5 self-service deletion path, which needs no committee approval. While your account is open Deleted Resident, worker
Append-only privileged-action log. Never purged on a clock: it is the evidence that the guardrails held (Doc 1.4 §7.8, 4.1 §10). While your account is open Archive (kept to meet a statutory duty) Resident
Person x Unit x Role. Survives role end so a unit's history stays intact (Doc 1.4 §1 — records anchor to the unit), but carries no access after the end date. While your account is open Archive Committee, resident

Societies can adjust some of these within stated ranges. They cannot extend them indefinitely, and they cannot switch the deletion jobs off.

Photos, cameras and recognition

Where a society enables gate photos, they exist to verify an entry and nothing else. They are visible to the host household and to gate roles, and they are deleted on the schedule above.

There is no facial recognition in Parisar — not of residents, not of visitors, not of workers. Photos are never used to train anything, never used for marketing, and never matched across societies. CCTV remains the society's own system; where it is linked, we store nothing from it by default.

Who we share it with

Nobody. No third-party sharing, no sale, no ad networks, no data brokers, no "partners". Exactly three things can move data outside Parisar:

  1. An integration you turned on, with a plain statement of what crosses the boundary. These are off by default.
  2. The service providers listed below, each under contract with data protection terms.
  3. A legal demand — validated in writing, scoped narrowly, and logged. Your society is told unless we are legally barred from telling it.

Service providers we use

ProviderForWhere
DigitalOceanHosting and the databaseBangalore, India
DigitalOcean SpacesPhotos and documentsIndia
TwilioOne-time sign-in codes, and gate calls where a society uses themGlobal
Google Firebase Cloud MessagingPush notifications to your deviceGlobal
Google WorkspaceEmail we send youGlobal

Your society's data is hosted in India. Adding a provider to this list means telling societies first.

What you can do yourself

How it is protected

Traffic is encrypted in transit and data is encrypted at rest. Access is controlled per role on the server, with database-level isolation between societies so one society's data cannot be read from another's session. Actions taken by administrators are written to an append-only, tamper-evident log. Backups are encrypted.

Parisar is designed to meet OWASP ASVS Level 2, ISO 27001 and SOC 2 Type II. We are not certified against any of them, and this page will say so plainly until we are.

If something goes wrong

If personal data is exposed, we contain it, assess the scope, and tell your society without undue delay with the facts it needs to meet its own obligations. Where people are affected, they are told in plain language what happened and what to do about it.

Our own restraint

No Parisar employee has a dashboard showing residents' personal content. Administrative access is limited to metadata, and emergency access is logged and disclosed. Our marketing never uses society data; any case study is consented to and reviewed by the society first.

Changes

Changes to this policy are versioned and notified inside the app. They are never buried.

Questions about this policy: grievance@parisar.app.