Privacy Policy

How we handle personal data, written for Indian readers using the terms of the Digital Personal Data Protection Act, 2023.

Last updated: 11 August 2026

BedDesk is a new business and its registration is in progress. Details shown like this are not yet available and will be filled in once registration completes. This document has not yet been reviewed by a lawyer. If anything here matters to a decision you are making, write to privacy@beddesk.in and ask — we would rather answer than have you assume.

1.Who we are

legal name, registered address. Contact: privacy@beddesk.in.

Grievance Officer — required under the DPDP Act and the IT Rules: name, privacy@beddesk.in, phone. We respond within 30 days of any request or complaint.

2.Our two roles — read this first

Whose dataOur role
Hostel owners and their staff who sign upData Fiduciary — we decide why and how it is processed
Residents whose details a hostel entersData Processor only — the hostel is the Data Fiduciary; we act on its instructions
If you are a resident and want your data corrected or erased, contact your hostel — they control it. We will help them act on your request, and we will forward anything you send us.

3.What we collect

From hostel owners (as Fiduciary): name, business name, phone, email, address, GSTIN, staff names and roles, login credentials (passwords stored hashed, never in plain text), payment records, usage logs, IP address and device information.

From residents (as Processor, entered by the hostel): name, phone and WhatsApp number, alternate phone, email, gender, date of birth, permanent address, occupation and institution, emergency contact details, identity document images and the last four digits of the identity number, room and bed allocation, rent and payment history, meal opt-out records, WhatsApp message history with the Service, and exit and settlement details.

We do not collect: biometrics, location tracking, card or bank credentials, or data from anyone under 18 without the verifiable parental consent the DPDP Act requires.

4.Why we process it

To provide the Service; to authenticate users; to send transactional WhatsApp and email messages; to bill subscriptions; to provide support; to detect abuse and secure the platform; and to comply with the law.

We do not sell personal data. We do not use it for advertising. We do not use it to train AI models.

5.Identity documents — a specific disclosure

Hostels may upload images of identity documents, including Aadhaar. We handle them as follows:

  • Stored in a private, encrypted store, never publicly accessible.
  • Reachable only through links that expire in 60 seconds, and only for the hostel’s owner and manager roles.
  • Only the last four digits of an identity number are stored in readable form.
  • Every view, download and deletion is logged, and that log is available to the hostel.
  • Deleted three months after the resident leaves, automatically. The hostel is reminded 7 days beforehand.
  • Sent to our AI provider only to read the printed fields — not retained by them, never used to train a model, and full identity numbers are never transmitted.
We are not an Aadhaar authentication agency. We do not authenticate against UIDAI, do not use Aadhaar for identification or de-duplication, and do not perform e-KYC. Documents are stored as records at the hostel’s instruction, nothing more.

6.Who we share it with

RecipientPurpose
VercelApplication hosting
SupabaseDatabase and file storage — Mumbai, India
Meta PlatformsWhatsApp message delivery
AnthropicAI document reading and message understanding
ResendTransactional email
CloudflareDNS and email routing

Also disclosed where required by law or valid legal process, and to a successor on a business transfer, with notice.

7.How long we keep it

DataKept for
Identity document images3 months after the resident exits, then auto-deleted
Resident records (non-document)Duration of stay + 3 years
Financial records (invoices, payments)8 years — statutory requirement
WhatsApp message logs12 months
Owner account dataDuration of subscription + 1 year
Access and audit logs12 months

8.Security

Encryption in transit and at rest; database-level tenant isolation using row-level security; role-based access; private document storage with short-lived signed links; audited access to identity documents; hashed passwords; daily backups.

No system is perfectly secure. In a breach we will notify the Data Protection Board of India and affected persons as the DPDP Act requires.

9.Your rights under the DPDP Act 2023

Access, correction, completion, updating and erasure; nomination of someone to exercise your rights on your behalf; grievance redressal; and withdrawal of consent.

  • Hostel owners: write to privacy@beddesk.in.
  • Residents: contact your hostel — they are your Data Fiduciary. We will help them act on your request.

10.WhatsApp

Residents receive messages only where their hostel has recorded their consent. Reply STOP at any time to stop notifications. Messages are delivered by Meta and are subject to WhatsApp’s own privacy terms.

11.Cookies

Essential cookies only — session and security. We do not use advertising or tracking cookies. If we add analytics we will disclose the tool here first.

12.Children

The Service is not intended for anyone under 18. A hostel accommodating a minor must obtain verifiable parental consent before entering their data, as the DPDP Act requires.

13.Changes to this policy

Material changes are notified 15 days in advance, by email and in the app.

Questions about this document: privacy@beddesk.in