dataset Data Governance & CERT-In Compliance Framework

Data Policy & Governance

This Data Governance Policy outlines how ApnaRooms manages, safeguards, retains, and audits tenant data, identity credentials, and digital records under the DPDP Act 2023 and CERT-In Cyber Security Directions 2022.

Effective Date: August 1, 2026 Scope: Platform Storage, Databases & Infrastructure

1 Data Fiduciary Statutory Obligations

ApnaRooms, under the leadership of Saksham Shakya as Data Fiduciary, strictly adheres to the obligations set out in Section 8 of the DPDP Act 2023:

  • Ensuring data accuracy and completeness where personal data is used to make decisions affecting a tenant.
  • Implementing reasonable security safeguards to prevent data breach, loss, or unauthorized access.
  • Erasing personal data upon withdrawal of consent or when the specified purpose is no longer served.

2 Data Minimization Principles

We restrict data collection exclusively to fields essential for room booking, billing, police verification, and communication. Unnecessary sensitive personal data (such as financial passwords or biometrics) is never requested.

3 Technical & Organizational Security Safeguards

lock Transport Security

All browser-to-server traffic is encrypted using 256-bit TLS/SSL protocols with TLS 1.3 enforced.

key Credential Encryption

User passwords are hashed using bcrypt algorithm. Plaintext passwords are never stored.

folder_special File Storage Control

KYC scans and police verification forms are stored in non-public storage directories accessible only by authorized admins.

admin_panel_settings Role-Based Access

Strict RBAC ensures property managers and service workers access only relevant task records.

4 Data Lifecycle Phases

Phase 1 — Collection: Data collected via forms with explicit DPDP consent checkboxes.
Phase 2 — Processing: Room allocation, verification form PDF compilation, invoice generation.
Phase 3 — Storage: Secured database storage on Indian web servers with daily backups.
Phase 4 — Archival & Purging: Inactive records purged after statutory retention windows expire.

5 Detailed Data Retention Schedule Matrix

Record Category Data Elements Retention Schedule Statutory Basis
Tenant Identity & Contact Name, Phone, Email, LPU ID Active tenancy + 1 year DPDP Act 2023 Sec 8(7)
KYC Scans (Aadhaar/Passport) Aadhaar PDF, Passport scan Active tenancy + 1 year Punjab Police Verification Norms
Financial Receipts & Invoices Rent logs, offline transaction IDs 3 to 7 years Income Tax Act & IT Act 2000
Server Access Logs & IPs IP address, request headers, logs 180 days mandatory CERT-In Cybersecurity Directions 2022

6 Data Breach Incident Management Protocol

In the event of a personal data breach, ApnaRooms will execute its incident response plan under Section 8(6) of the DPDP Act 2023:

  • Notify the Data Protection Board of India (DPBI) without undue delay.
  • Notify affected users via email detailing the nature of the incident, compromised fields, and remediation steps.
  • Deploy technical security patches to isolate and contain the breach.

7 Cross-Border Data Transfer Disclosures

Primary database servers and document vaults are hosted in Indian datacenters (cPanel India). Third-party sub-processors operate under standard contractual terms:

  • Firebase Auth (USA): User authentication token exchanges.
  • Cloudflare CDN (Global): Edge caching and DDoS protection.

8 Automated Processing Disclosure

ApnaRooms utilizes automated scripts for roommate search indexing and monthly invoice generation. We do NOT perform automated profiling or credit scoring that produces legal effects without human oversight.

9 Data Audit & Compliance Review Cycle

We conduct biannual internal data protection reviews to audit database access logs, verify document purge scripts, and update security rules in alignment with evolving Indian cybersecurity standards.

Need a Data Export or Deletion?

Submit your data request ticket to our Data Governance desk.

Submit Data Request