Privacy Policy
This policy explains what personal data WhizzGate collects, why we collect it, how we use and safeguard it, and the rights you have over it under the Digital Personal Data Protection Act, 2023 and the EU General Data Protection Regulation.
Section 1Overview
WhizzGate is a community operations platform for residential societies — covering gate security, visitor management, resident records, communications, billing and payments. Protecting the personal data entrusted to us is fundamental to that job. This Privacy Policy describes our practices for the WhizzGate website, web dashboards and mobile applications (together, the "Services").
We act in two capacities. For the account data of the societies and administrators who subscribe to WhizzGate, we are a Data Fiduciary / Controller. For the resident, visitor and staff data that a society manages through the platform, the society is the Data Fiduciary and we act as a Data Processor on its documented instructions.
Section 2Who we are
WhizzGate is a product of WhizzAct Private Limited, with its head office in Mumbai, Maharashtra, India (CIN U62099MH2023PTC401103, GSTIN 27AADCW5071H1Z6). Where this policy says "we", "us" or "WhizzGate", it refers to WhizzAct Private Limited.
For any privacy question you can reach us at hello@whizzact.com. Our designated contacts are listed in Section 12.
Section 3Personal data we collect
We collect only what we need to run the Services. Categories include:
| Category | Examples |
|---|---|
| Identity & contact | Name, flat/unit number, mobile number, email, profile photo. |
| Account & role | Society, building, role (resident, guard, manager, accountant, admin), login credentials (hashed). |
| Visitor & gate | Visitor name and phone, purpose of visit, vehicle number, entry/exit timestamps, gate-pass QR tokens, approval status. |
| Domestic staff & helpers | Helper name, contact, role, ID/verification documents, check-in/out records and feedback. |
| Vehicle & parking | Vehicle registration numbers, allotted parking slots and parking-violation records. |
| CCTV & surveillance | Where a society enables it, camera footage, detected events and clips saved as evidence, retained per the society's configuration. |
| Community life | Amenity bookings, event RSVPs, poll votes, meeting attendance, move-in/out and renovation records. |
| Financial | Maintenance invoices, ledgers, payment status and references. Card/UPI details are handled by our payment gateway — we do not store full card numbers. |
| Communications | Notices, complaints, messages and support tickets you send through the platform. |
| Consent & compliance | Consent records, data-request history, and audit logs of sensitive actions. |
| Technical | Device identifiers, IP address, app version, push-notification tokens, and diagnostic logs. |
CCTV footage and domestic-staff identity documents can be more sensitive by nature. Where a society uses these features, access is restricted by role, footage is retained only for the society's configured period, and it is used solely for community security. We do not use this data for any other purpose.
Section 4Why we use your data
- To provide and operate the Services — authenticating access, issuing visitor passes, recording gate entries and delivering notifications.
- To process maintenance billing and payments, and to keep an accurate financial record for the society.
- To keep the community secure — verifying visitors and maintaining an auditable access trail.
- To provide customer support and respond to your requests.
- To improve reliability, prevent fraud and abuse, and diagnose technical problems.
- To comply with legal obligations and enforce our terms.
We do not sell your personal data, and we do not use resident data to serve third-party advertising.
Section 5Legal basis for processing
Under the DPDP Act, 2023 we process personal data on the basis of your consent or for certain legitimate uses permitted by the Act. Under the GDPR (where it applies), we rely on:
- Contract — to deliver the Services you or your society signed up for.
- Consent — for optional features such as marketing emails or non-essential cookies, which you can withdraw at any time.
- Legal obligation — to meet tax, accounting and law-enforcement requirements.
- Legitimate interests — to secure the platform and community, provided these do not override your rights.
Section 7Data retention
We keep personal data only for as long as it is needed for the purposes above, or as required by law. Gate and visitor logs are retained for the period configured by your society; financial records are retained for the statutory accounting period. When data is no longer required, we delete or anonymise it. If your society ends its subscription, we make its data available for export for a limited window and then delete it in line with our agreement.
Section 8How we protect data
- Encryption in transit (TLS) and at rest for data stored in our databases.
- Role-based access control and strict per-society tenant isolation.
- Hashed passwords, signed and expiring links for public actions, and rate limiting.
- Audit logging of sensitive actions and least-privilege access for our staff.
- Regular backups and a documented incident-response process.
If a personal-data breach occurs, we will notify the Data Protection Board of India and affected users as required by the DPDP Act, and any relevant supervisory authority within 72 hours where the GDPR applies.
Section 9Your rights
Subject to applicable law, you have the right to:
- Access a summary of the personal data we hold about you and how it is processed.
- Correct, complete or update inaccurate data.
- Erase data that is no longer necessary (the "right to be forgotten").
- Withdraw consent at any time, as easily as you gave it.
- Nominate another individual to exercise your rights in the event of death or incapacity (DPDP Act).
- Portability, restriction and objection, and the right to lodge a complaint with a supervisory authority (GDPR).
WhizzGate is built to make these rights practical. Residents can review and manage the consents they have given from within the app, and can raise a data request — including data export and erasure — which the society processes through the platform's data-request workflow, with every step recorded for accountability. You can also email hello@whizzact.com. If your data is managed by your society (as Data Fiduciary), we route your request to them and assist as their processor. We respond within the timelines set by applicable law.
Section 10International transfers
We primarily store and process data on infrastructure located in India. Where data is transferred to or accessed from another country (for example by a sub-processor), we ensure an equivalent level of protection through appropriate safeguards such as Standard Contractual Clauses, and only to jurisdictions not restricted by the Central Government under the DPDP Act.
Section 11Children's data
The Services are intended for adults managing or living in a residential community. We do not knowingly process the personal data of a child (a person under 18 in India) without verifiable parental consent, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
Section 12Grievance & Data Protection Officer
If you have a concern about how your data is handled, you may contact our grievance officer, who will acknowledge and resolve it within the timelines prescribed by law:
- Email: hello@whizzact.com
- Data Protection Officer (GDPR): hello@whizzact.com
- Address: WhizzAct Private Limited, Mumbai, Maharashtra, India
You also have the right to complain to the Data Protection Board of India or, in the EU/EEA, to your local supervisory authority.
Section 13Changes to this policy
We may update this policy from time to time. Material changes will be notified through the Services or by email, and the "last updated" date above will change. Continued use of the Services after an update means you accept the revised policy.