← Back to PG Saathi

Privacy Policy

Version 1.3 · September 2026 · written with reference to the Digital Personal Data Protection Act 2023, the Digital Personal Data Protection Rules 2025 and the Information Technology Act 2000 (India)

PG Saathi is software that helps Paying-Guest owners in India run their PG over WhatsApp. This policy explains, in plain terms, what personal data the system holds, why, where it is processed, which other companies receive it, how long it is kept, and what you can ask us to do. It covers PG owners and managers who use PG Saathi, the tenants whose details owners record in it, and people who send a booking or visit request from a public PG page.

At a glance

1. Who we are, and who decides what

PG Saathi is operated by Marnel Technologies Ltd from Ahmedabad, Gujarat; in this policy "PG Saathi" and "we" mean Marnel Technologies Ltd. PG Saathi provides the software, runs the server, and stores and processes data so that the system works. The PG owner decides whom to house, which tenant details to record, and what to do with them — for example, whether to hand a tenant verification form to the police. For owners' and managers' own account data (phone number, UPI ID, wallet and billing), PG Saathi is responsible. How the DPDP Act's roles ("Data Fiduciary", "Data Processor") apply to tenant data depends on these facts; this policy describes the facts and does not assign a label.

Entity
Marnel Technologies Ltd
Address
Ahmedabad, Gujarat 380009, India
GSTIN
GSTIN: not yet registered (turnover below threshold)
CIN
Entity registration: pilot stage; details published on request.

2. Definitions

  • Personal data — any data about a person who can be identified from it.
  • Data Principal — the person the data is about: you, whether you are an owner, a manager, a tenant or a prospect.
  • Processing — anything done with personal data: collecting, storing, using, sharing or erasing it.
  • Service provider — a company listed in section 7 that handles data for PG Saathi so that a feature works.

3. Personal data the system holds

We collect what is needed to run a PG ledger and a WhatsApp bot. Categories:

  • Owners and managers: name, mobile number (used to sign in over WhatsApp), preferred language, and an email address if you give one.
  • Owner payment details: UPI ID and UPI holder name for receiving rent; wallet top-ups and charges. We never see your bank password, OTPs or full bank-account number.
  • Tenants: name, mobile number, optional alternate number, gender, dietary preference, emergency-contact name and number, and the last 4 digits of Aadhaar. For a tenant under 18: a parent or guardian's phone number and the owner's confirmation that the parent or guardian agreed (section 15).
  • Full Aadhaar number — optional, the owner's choice: an owner can record a tenant's full 12-digit Aadhaar number in the Aadhaar vault, because AMC and police inspections can ask for it. It is encrypted (AES-256-GCM) with a key made from a passphrase that only the owner sets; we store a check-value of the passphrase, never the passphrase itself. Encryption and decryption happen on our server in Mumbai: when the owner records or opens a number, our server handles the number and the passphrase for that moment. The number is stored encrypted, but it is not end-to-end encrypted. Opening it needs the owner's passphrase, and after 5 wrong attempts in an hour the vault locks. The full number is not put into exports, lists, forms, receipts, audit records or messages — those use the last 4 digits.
  • Foreign-national tenants (Form III): a yes/no mark, set by the owner, that a tenant is not an Indian citizen, and for such a tenant the arrival and departure dates and whether the owner has marked Form III as filed. We do not store passport or visa details — the owner files Form III on the government portal (indianfrro.gov.in) themselves.
  • Property details: PG name, area, address, sharing type, rooms, rents, bed count.
  • Payments: rent and deposit amounts, the UPI transaction reference (UTR) a tenant sends, the owner's verify/reject decision, dates.
  • Compliance documents: NOC and certificate files you upload to track expiry, stored on our server in Mumbai.
  • Messages: the text of WhatsApp messages exchanged with the bot, the phone numbers involved, and the language and request the bot detected.
  • Booking and visit requests: name, WhatsApp number, message, preferred date and the device's IP address, when someone contacts a PG through its public page.
  • Consent and sign-in records: see section 17.

4. Why we may process it

The basis depends on whose data it is and why:

  • Tenant records — tenants give their details to the PG owner for their stay, and the owner records them in PG Saathi for that purpose. The DPDP Act allows processing of data a person has voluntarily provided for a specified purpose (section 7(a)).
  • Owner and manager accounts — you give us your details in order to use the service; the same basis applies (section 7(a)).
  • Marketing messages — only with your separate consent (section 6), which you can withdraw at any time from /legal/marketing-consent.
  • Disclosure to police or other authorities — only where a law obliges the disclosure (section 7(d)), or under a valid legal order. The tenant verification form and the police register are produced for the owner; the owner decides whether to hand them over.
  • Financial records — rent, payment and wallet records are kept for as long as tax law requires books of account to be kept (section 9).

5. What we use it for

  • Running the service — invoices, payments, overdue balances, reminders, receipts, and tracking your NOCs and certificates.
  • Sign-in — confirming who you are with sign-in links sent over WhatsApp.
  • Form III reminders — reminding the owner to file Form III for a foreign-national tenant within 24 hours of arrival and departure. The owner files it; PG Saathi does not.
  • GST exemption checks — refusing rent above ₹20,000 per person per month and contracts shorter than 90 days, and flagging a stay that ended before 90 days. These are conditions of the exemption in Notification No. 04/2024-Central Tax (Rate), entry 12A: up to ₹20,000 per person per month, for a continuous stay of at least 90 days.
  • Security and fraud prevention — limiting abusive traffic and investigating disputed payments.
  • Improving the bot — counting how features are used, and reviewing messages the bot did not understand (kept for 30 days). Never sold.
  • Legal claims — defending complaints or proceedings before a court, tribunal or regulator.

6. Collecting less, keeping it accurate

In practice:

  • Minimisation: a field exists only if a feature uses it. Aadhaar: the last 4 digits everywhere; the full number only in the owner's encrypted vault, and only if the owner records it. No caste or marital-status fields.
  • Accuracy: owners can correct tenant records at any time; anyone can ask the Grievance Officer to correct their data.
  • Storage limitation: section 9 lists what the system deletes automatically, and what it does not.
  • Purpose limitation: data collected for one purpose (for example, delivering WhatsApp messages) is not reused for another (for example, marketing).

7. Other companies that receive data

PG Saathi does not sell personal data. These companies receive data so that the service works:

  • Oracle Cloud (Mumbai) — hosting. PG Saathi runs on one server we operate in Mumbai: the database, uploaded files, the app, scheduled jobs and error tracking all run on it. Oracle provides the machine.
  • Meta Platforms — WhatsApp Cloud API. Every WhatsApp message to or from the bot, with the phone numbers involved, passes through Meta. Meta decides where it processes messages; this may be outside India.
  • Sarvam AI (India). The text of messages sent to the bot goes to Sarvam to work out what the message asks for. Phone numbers, Aadhaar numbers, UPI IDs, email addresses and UTRs in the text are masked before it is sent.
  • Google Cloud Vertex AI (Mumbai region). If Sarvam does not answer, the message text (masked the same way) goes to Google's Gemini model in Mumbai instead. Ledger photos an owner uploads for import are read by the same service in Mumbai; a photo cannot be masked, so it is sent as it is, and PG Saathi does not keep the photos afterwards.
  • Karza (India) — identity verification, when it is enabled. When an owner requests an automated tenant check and the service is switched on, Karza receives the tenant's name, mobile number and last 4 Aadhaar digits, and runs the check with the tenant's consent.
  • Email. If we email you (for example, a sign-in link), the message is sent through an outgoing mail (SMTP) relay.
  • Anthropic (USA) — not used on our live service. The code can fall back to Anthropic's Claude for message reading and ledger photos only on an installation that has no Google Cloud project. Our live service has one and has no Anthropic key, so nothing is sent to Anthropic. If that ever changes, this section will say so first.
  • PostHog (product analytics) — off. The code can load PostHog only after a visitor accepts it in the cookie banner, and only if it is configured. It is not configured on our live service.
  • Authorities — see section 4: only where a law obliges disclosure, or under a valid legal order.

8. Processing outside India

Our database and files stay on our server in Mumbai, and the AI services used on our live service run in India (Sarvam AI; Google Vertex AI in Mumbai). WhatsApp messages pass through Meta, which may process them outside India. Anthropic, the one provider in the code located outside India, is not used on our live service (section 7).

9. How long data is kept — what the system actually does

  • Tenant records — kept while the tenant stays and after move-out. The system does not delete moved-out tenants automatically; their records stay until the owner's account is erased or an erasure request is handled through the Grievance Officer.
  • Rent, payment, invoice and wallet records — kept. When an account is erased, these are anonymised rather than deleted, because tax law requires books of account to be kept for seven tax years.
  • Audit log — each entry is kept for 7 years, then deleted. When an account is erased, personal details such as names and phone numbers are removed from it; the entries stay.
  • WhatsApp messages received by the bot — the text and the sender's number are erased after 90 days; the rest of the record (time, direction, detected request) is kept.
  • WhatsApp messages sent by the bot — currently kept with no time limit.
  • Messages the bot could not understand — deleted after 30 days.
  • Booking and visit requests from public pages — requests the owner never acted on are deleted after about 18 months; requests that led to contact or a visit stay until the owner's account is erased.
  • Full Aadhaar in the vault — kept until the owner's account is erased.
  • Sign-in links — kept until the account is erased.
  • Error reports — deleted after 30 days.
  • Account deletion — delete my data starts a 30-day period during which you can cancel; after that, personal data is erased or anonymised as described above.

10. Your rights (DPDP Act, sections 11–13)

  • Information (section 11) — a summary of the data we hold about you, what we do with it, and who else received it.
  • Correction and erasure (section 12) — fix what is wrong, complete what is missing, or ask for erasure. Records that tax law requires us to keep are anonymised rather than deleted.
  • Grievance redressal (section 13) — complain to our Grievance Officer (section 19).
  • Nominate — name someone to exercise these rights for you in case of death or incapacity.
  • Withdraw consent — where we rely on consent (marketing messages), you can withdraw it at any time; processing done before that stays lawful.
  • Export — owners can download a copy of their PG data from settings.

11. How to exercise your rights

Three routes:

  • In the app: owners and managers can edit their data, export it, or request erasure at /account/delete.
  • On WhatsApp: owners and managers can send delete data to get a link to the erasure page. Tenants: ask the PG owner, or write to the Grievance Officer.
  • By email or letter: write to the Grievance Officer (section 19) with your registered phone number and what you are asking for. We may confirm your identity by sending a link to that number. Requests are free of charge.

12. How the data is protected

  • Connections to the site and the app use HTTPS.
  • Full Aadhaar numbers in the vault are encrypted with AES-256-GCM using a key made from the owner's passphrase (section 3 explains what this does and does not protect against).
  • Database access rules stop one PG's users from reading another PG's data.
  • Sign-in links work once and expire.
  • Messages arriving from WhatsApp are checked for Meta's signature before they are processed.
  • Phone numbers, Aadhaar and UPI details are removed from error reports before they are stored.
  • An audit log records who changed what, and when.
  • Scheduled jobs only run with a secret key.

13. If there is a data breach (DPDP Act section 8(6); Rules 2025, rule 7)

If a personal-data breach affects you, we will tell you without delay: what happened, which data was involved, the likely consequences, and what we are doing about it. We will also inform the Data Protection Board of India without delay, and send it a detailed report within 72 hours of becoming aware of the breach. If we cannot reach everyone directly, we will publish a notice.

14. Cookies

When you are signed in we set a language cookie (`pgs_lang`) and sign-in session cookies that page scripts cannot read. We do **not** use advertising cookies or session recording. The code includes PostHog analytics, which would run only after you accept it in a cookie banner; it is not switched on on our live service, so no banner is shown.

15. Tenants under 18 (DPDP Act section 9)

Some PGs house students under 18. When an owner adds such a tenant, PG Saathi requires the owner to mark them as under 18, enter a parent or guardian's phone number, and confirm that the parent or guardian agreed. Today that confirmation is the owner's own statement: PG Saathi does not yet check the parent or guardian's identity and age, which the DPDP Rules 2025 (rule 10) will require for verifiable consent when they take effect. We do not track or behaviourally monitor children, and we do not direct advertising at them (section 9(3)).

16. Significant Data Fiduciary

The Central Government has not notified PG Saathi as a Significant Data Fiduciary, and we have not appointed a Data Protection Officer. If that changes, this section will say so.

17. Consent records

When an owner accepts the terms, we record the time and the version accepted. When anyone gives or withdraws marketing consent, we record the time, the version, where it was given, and the IP address and browser details where available.

18. Changes to this policy

When this policy changes, the version and date at the top change. For significant changes — a new company receiving data, a new purpose, or new kinds of data — we will tell registered owners before the change applies.

19. Grievance Officer (DPDP Act section 8(10))

For any privacy concern, request, or exercise of your rights:

Name
Grievance Officer, PG Saathi
Address
Ahmedabad, Gujarat 380009, India

We acknowledge within 7 days and aim to resolve within 30 days.

20. Further escalation — Data Protection Board of India

If you are not satisfied with the Grievance Officer's response, you may approach the Data Protection Board of India.

21. Governing law & jurisdiction

This policy and any dispute about your personal data are governed by the laws of India. The courts at Ahmedabad, Gujarat have exclusive jurisdiction, without affecting your right to approach the Data Protection Board of India.