Legal

Privacy policy

Last updated: 18 May 2026 · DPDP Act 2023 aligned

Draft — review with counsel before launch. This is a working draft. Final DPDP wording, retention periods, and breach notification timelines should be reviewed by a privacy counsel before launch.

What we collect

We collect only what's needed to run the service:

  • Owner info: name, phone, email, GSTIN (if you provide one), and payment instrument details handled by Razorpay (we don't store card numbers).
  • Property info: property name, address, rooms, beds, rent structure.
  • Tenant info (you upload): name, phone, photo, ID documents if you upload them, emergency contacts, rent and deposit, due dates.
  • Payment records: rent payments you record, wallet recharges, subscription invoices.
  • Message logs: what was sent, when, delivery receipts, errors.
  • Operational telemetry: login timestamps, IP, browser, audit trail of financial actions. Used for security and debugging, not advertising.

How we use it

  • To operate the platform and show your dashboards.
  • To deliver the WhatsApp reminders you've configured, paid from your wallet.
  • To bill you and produce GST invoices.
  • To respond to support requests.
  • For aggregated, anonymised analytics about platform usage. No identifiable owner or tenant data is used for advertising or sold.

Tenant data & DPDP roles

Under the Digital Personal Data Protection Act, 2023:

  • For data about Owners (you), Aira Nexus is the Data Fiduciary.
  • For data about your Tenants, you are the Data Fiduciary and Aira Nexus acts as your Data Processor. We handle tenant data only on your instructions, to deliver the service you've configured.

Tenants' consent to operational messaging (rent reminders, receipts) is implicit in the tenancy relationship — they live in your PG and need these messages. We honour opt-out keywords (STOP / UNSUBSCRIBE) and stop sending immediately when invoked.

What we share

We do not sell personal data. We share only with the processors we need to run the service:

  • Razorpay — subscription billing and wallet recharges.
  • Meta WhatsApp Business Cloud API — WhatsApp message delivery.
  • MSG91 — WhatsApp message delivery in India.
  • AWS (Mumbai, ap-south-1) — hosting and storage.
  • Amazon SES — transactional email (invoices, receipts).
  • Operational logging via pino, retained per the schedule below.

We share data with law enforcement only when compelled by valid Indian legal process, and we notify the affected account where legally permitted.

Retention

  • Owner data — kept while your account is active, plus up to 7 years after closure to meet Indian tax and financial-records retention obligations.
  • Tenant data — kept while the tenancy is active. After move-out we retain it for 3 years for dispute and audit purposes, then anonymise or delete it.
  • Message logs — 18 months, then aggregated and the personal content removed.

Owner rights

As an Owner you can:

  • Access your personal data and account information.
  • Correct anything inaccurate.
  • Request erasure, subject to legal/tax retention obligations (invoices, for example, we must keep).
  • Export your data in a portable format (CSV / JSON).
  • Raise a grievance via the officer listed below.

Tenant rights

Because you are the Data Fiduciary for tenant data, tenant requests (access, correction, erasure) should be directed to you. We will support you in fulfilling them — including providing data exports and helping you action erasures within the platform.

Children's data

Stay is designed for business use by PG operators housing adult tenants. We do not knowingly process personal data of children under 18. If you suspect tenant data relating to a minor has been added without verifiable parental consent, contact us and we will act.

Security

  • TLS 1.2+ in transit; AES-256 at rest.
  • JWT-based authentication; scoped access by role within your account.
  • Audit logs for financial actions.
  • Backups encrypted and stored within the AWS Mumbai region.
  • Periodic dependency and vulnerability scans.

Cross-border transfers

Data is stored in India (AWS Mumbai). Limited operational data may transit through provider infrastructure that has global routing (Meta WhatsApp). Where DPDP requires specific disclosure of cross-border processing for a sub-processor, we will update this policy and notify you.

Cookies

We use only essential cookies: session, authentication, and your interface preferences (e.g. dark mode). No third-party tracking and no marketing cookies in Phase 1. If we add analytics later, it will be privacy-respecting (e.g. Plausible) and disclosed here.

Breach notification

In the event of a personal data breach affecting your account, we will notify you and the Data Protection Board of India within 72 hours of becoming aware, in accordance with DPDP timelines. The notice will include what was affected, what we are doing, and what steps you should take.

Grievance officer

For privacy concerns, contact our grievance officer: admin@airanexus.in. We will acknowledge within 7 days and resolve within 30 days, in line with DPDP requirements.

Aira Nexus Stay is operated by CodeLadder Technologies Pvt. Ltd., Bengaluru, Karnataka, India.