PG Saathi
← Back to overview
🔒

DPDP-compliant

Stored on our server in Mumbai. Aadhaar: last 4 digits everywhere, full number only in the owner's encrypted vault. Erasure after 30 days.

What it does

The DPDP Act 2023 imposes real obligations on anyone holding Indian residents' personal data. PG Saathi was built with those obligations as constraints, not afterthoughts.

Everything PG Saathi stores — database, uploaded files, logs — sits on our own server in Mumbai. The text of messages to the bot is read by Sarvam AI (India) to work out what you asked, with Google Vertex AI in Mumbai as the fallback. Ledger photos you upload for import are read by Google Vertex AI in Mumbai and are not kept by us afterwards. WhatsApp messages themselves travel through Meta, which runs WhatsApp.

Lists, forms, exports and messages use only the last 4 digits of Aadhaar. An owner may choose to record a tenant's full 12-digit Aadhaar for AMC / police inspections; it is then stored encrypted with a passphrase only the owner knows. A `delete my data` request starts a 30-day grace period (during which you can cancel); then personal data is erased, and the financial records tax law requires us to keep stay with personal identifiers stripped.

On WhatsApp

  • Owner or manager: `delete data` — starts the erasure flow. Tenants: ask the PG owner, or write to our Grievance Officer.
  • 30 days to change your mind. After that, irreversible.
  • Receipts and bot replies never leak Aadhaar in full.

On the dashboard

/account/delete — request erasure with the confirmation phrase. /settings shows your data retention summary.

Why it matters

DPDP penalties run up to ₹250 crore for serious data-protection failures. Building compliance into the schema (column-level constraints, retention windows, region locking) is the only way a small PG SaaS can credibly serve real Indian users without one breach ending the business.

A shared sandbox PG with sample tenants, payments, expenses. Resets hourly.

What it does