1 Data Fiduciary Statutory Obligations
ApnaRooms, under the leadership of Saksham Shakya as Data Fiduciary, strictly adheres to the obligations set out in Section 8 of the DPDP Act 2023:
- Ensuring data accuracy and completeness where personal data is used to make decisions affecting a tenant.
- Implementing reasonable security safeguards to prevent data breach, loss, or unauthorized access.
- Erasing personal data upon withdrawal of consent or when the specified purpose is no longer served.
2 Data Minimization Principles
We restrict data collection exclusively to fields essential for room booking, billing, police verification, and communication. Unnecessary sensitive personal data (such as financial passwords or biometrics) is never requested.
3 Technical & Organizational Security Safeguards
lock Transport Security
All browser-to-server traffic is encrypted using 256-bit TLS/SSL protocols with TLS 1.3 enforced.
key Credential Encryption
User passwords are hashed using bcrypt algorithm. Plaintext passwords are never stored.
folder_special File Storage Control
KYC scans and police verification forms are stored in non-public storage directories accessible only by authorized admins.
admin_panel_settings Role-Based Access
Strict RBAC ensures property managers and service workers access only relevant task records.
4 Data Lifecycle Phases
5 Detailed Data Retention Schedule Matrix
| Record Category | Data Elements | Retention Schedule | Statutory Basis |
|---|---|---|---|
| Tenant Identity & Contact | Name, Phone, Email, LPU ID | Active tenancy + 1 year | DPDP Act 2023 Sec 8(7) |
| KYC Scans (Aadhaar/Passport) | Aadhaar PDF, Passport scan | Active tenancy + 1 year | Punjab Police Verification Norms |
| Financial Receipts & Invoices | Rent logs, offline transaction IDs | 3 to 7 years | Income Tax Act & IT Act 2000 |
| Server Access Logs & IPs | IP address, request headers, logs | 180 days mandatory | CERT-In Cybersecurity Directions 2022 |
6 Data Breach Incident Management Protocol
In the event of a personal data breach, ApnaRooms will execute its incident response plan under Section 8(6) of the DPDP Act 2023:
- Notify the Data Protection Board of India (DPBI) without undue delay.
- Notify affected users via email detailing the nature of the incident, compromised fields, and remediation steps.
- Deploy technical security patches to isolate and contain the breach.
7 Cross-Border Data Transfer Disclosures
Primary database servers and document vaults are hosted in Indian datacenters (cPanel India). Third-party sub-processors operate under standard contractual terms:
- Firebase Auth (USA): User authentication token exchanges.
- Cloudflare CDN (Global): Edge caching and DDoS protection.
8 Automated Processing Disclosure
ApnaRooms utilizes automated scripts for roommate search indexing and monthly invoice generation. We do NOT perform automated profiling or credit scoring that produces legal effects without human oversight.
9 Data Audit & Compliance Review Cycle
We conduct biannual internal data protection reviews to audit database access logs, verify document purge scripts, and update security rules in alignment with evolving Indian cybersecurity standards.
Need a Data Export or Deletion?
Submit your data request ticket to our Data Governance desk.