1. Who We Are
We act as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 for personal data processed on our platform.
Registered office: EBuilding Private Limited, India. Contact: support@ebuilding.in · +91 73836 31581
2. Data We Collect
2.1 Data You Provide Directly
- Account registration: Name, flat number, society name, mobile number, email address, and vehicle registration numbers (we store vehicle records strictly as provided by you or your society; E Building does not scrape public RTO records or track your vehicle outside the society gates)
- Society committee accounts: Name, designation, PAN/Aadhaar (for compliance where required), bank details for payment gateway setup
- Vendor/Partner applications: Name, business name, GST number, bank account details, skill category, service area
- Staffing applications: Name, address, mobile number, Aadhaar number (for background verification), work experience, photograph
- Home service bookings: Address, service requirements, preferred time slots
- Demo requests and inquiries: Name, phone, society details, role
- Payment information: UPI ID, card numbers (processed by PCI-DSS compliant payment partners — we do not store raw card data)
2.2 Data Collected Automatically
- Device type, operating system, browser version, IP address
- App usage patterns, feature interactions, session duration
- Crash reports and error logs (anonymised where possible)
- Push notification tokens for app alerts
- Location data (only during society onboarding to tag the building location, with explicit permission)
2.3 Data From Third Parties
- Payment status and transaction IDs from payment gateways (Easebuzz)
- Background verification results from licensed verification partners
- OTP verification from telecom providers
3. How We Use Your Data
We use your personal data only for the purposes described below. We rely on the following legal bases under the DPDP Act 2023: consent, legitimate use, and legal obligation.
- To create and manage your account and authenticate your identity
- To provide society management features — gate entry, billing, notices, amenities, expenses, vehicles
- To process maintenance payments and issue digital receipts
- To match service bookings with verified vendor partners in your area
- To conduct background verification for staffing applicants (with explicit consent)
- To send transactional notifications (OTP, payment confirmation, visitor alerts, society notices)
- To provide customer support and resolve disputes
- To detect and prevent fraud, unauthorised access, and security incidents
- To comply with legal and regulatory obligations
- To improve the platform through anonymised usage analytics
- To send relevant product updates and offers (with opt-in consent; you can unsubscribe at any time)
Sell, rent, or trade your personal data to advertisers, data brokers, or any third party. We do not display ads, use cross-site tracking pixels, or collect mobile advertising identifiers (such as Apple's IDFA or Google's GAID) for tracking. Your community space remains completely private and commercial-free.
4. Data Sharing
We share your data only in the following limited circumstances:
4.1 Within the Platform
- Society committees: Resident flat details, visitor logs, payment status visible to authorised committee members only. Administrative activity logs are maintained to record all edits, setting changes, and configuration updates made by society committee members.
- Security guards: Visitor pre-approval status and resident QR codes — gate entry data only
- Vendor partners: Booking details shared only upon confirmed booking
4.2 Service Providers (Data Processors)
- Cloud infrastructure: Amazon Web Services (AWS Mumbai region) — hosting and storage
- Payment processing: Easebuzz — PCI-DSS compliant, India-based
- SMS/notifications: MSG91 — strictly for account registration and login OTP verification
- Background verification: Licensed verification agencies — staffing applicants only, with explicit consent
- Analytics: Anonymised usage data processed via privacy-preserving analytics tools
4.3 Legal Requirements
We may disclose data if required by Indian law, court order, or government authority.
4.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, personal data may be transferred. We will notify you.
5. Data Storage & Security
- Location: All data stored on AWS Mumbai (ap-south-1) servers within India. No data transferred outside India without explicit consent.
- Encryption: Data encrypted in transit using TLS 1.3 and at rest using AES-256 encryption
- Access controls: RBAC limits who can view what data. All access is logged and audited
- Authentication: Multi-factor authentication for all admin accounts and optional 2FA for committee accounts
- Backups: Automated daily backups with 30-day retention. Disaster recovery tested quarterly
- Security reviews: Annual third-party security assessments
- Incident response: We notify affected users and regulators within required timelines
For details on our technical security measures, visit ebuilding.in/security/
6. Data Retention
- Active accounts: Data retained while account is active and for 2 years after deactivation
- Financial records: Billing and payment data retained for 7 years as required by Indian tax law
- Visitor logs: Gate entry records retained for 1 year, then anonymised or deleted
- Support interactions: Retained for 2 years for quality and dispute resolution
- Staffing background checks: Retained for the duration of employment plus 2 years
- Deleted accounts: Data purged within 30 days of account deletion request, except where required by law
- Anonymised analytics: Retained indefinitely (no personal identifiers)
7. Your Rights
Under the Digital Personal Data Protection Act, 2023 and applicable law, you have the following rights:
- Right to access: Request a copy of the personal data we hold about you
- Right to correction: Request correction of inaccurate or incomplete data
- Right to erasure: Request deletion of your personal data (subject to legal retention obligations)
- Right to withdraw consent: Without affecting prior processing
- Right to grievance redressal: Lodge a grievance with our Data Protection Officer
- Right to nominate: Nominate another person to exercise your rights in case of death or incapacity
To exercise any of these rights, email us at support@ebuilding.in or WhatsApp +91 73836 31581. We respond within 14 days for access/correction requests and within 30 days for deletion requests.
8. Cookies & Tracking
We use cookies and similar technologies to operate the website and improve your experience. For full details, see our Cookies Policy.
In brief: we use strictly necessary cookies (session management, security), functional cookies (your preferences), and anonymised analytics cookies. We do not use advertising or cross-site tracking cookies.
9. Children's Privacy
Our services are not directed at children under 18. We do not knowingly collect personal data from minors.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email, app notification, or a prominent notice at least 14 days before the change takes effect.
11. Contact & Grievance Redressal
For any privacy-related queries, requests to exercise your rights, or grievances, please contact:
Data Protection Contact
EBuilding Private Limited
We aim to resolve all grievances within 14 days.
Terms of Service · Refund Policy · Cookies Policy · Security