Privacy Policy

Last updated: 8 August 2026

Also see our Terms of Service

1. Who we are

Societly Technologies LLP, operating under the brand name Societly ("Societly", "we", "us", "our"), is a limited liability partnership registered under the Limited Liability Partnership Act, 2008 in India. We operate the website societly.co and the related applications at app.societly.co and admin.societly.co, as well as the Societly mobile application available on iOS and Android (collectively, the "Platform").

For the purposes of applicable data-protection law, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 ("DPDPA"), Societly is the data fiduciary with respect to personal data processed through the Platform.

2. Scope

This Privacy Policy applies to all personal data we collect or process when you visit our website, register for an account, use the Platform as a resident, committee member, staff, vendor, or administrator, contact us, or otherwise interact with our services.

3. Personal data we collect

Account information: When you register or are added to a society, we collect your name, email address, and optionally your phone number and profile photo.

Society and property data: Society name, address, unit or flat number, and your role within the society (resident, committee member, staff).

Society onboarding and KYC data: When a Society activates online collections, we collect the Society's registration certificate, PAN, settlement bank account details, GST registration (if any), authorised-signatory identity documents, and the managing-committee resolution authorising collections. These are shared with our RBI-regulated banking and payment partner solely for merchant/sub-merchant KYC and settlement setup as required under RBI directions.

Financial and billing data: Maintenance billing records, invoice amounts, payment status, and payment metadata processed through our RBI-regulated payment gateway partner. We do not store full card numbers or bank account details on our servers — these are handled directly by that partner under its own PCI-DSS compliance.

Operational data: Visitor logs, gate-pass records, complaint or ticket details, amenity-booking records, vendor information, meeting minutes, announcements, polls, and documents that your society chooses to record through the Platform.

Tenant verification: Where a society runs police or tenant verification, it may record the tenant's name, a police-verification reference, and the supporting documents the tenant provides. Aadhaar: we store only the last four digits, as a cross-check against the document the tenant uploaded. We never store, display or allow searching by a full Aadhaar number, in line with the Aadhaar Act 2016 and UIDAI's masking guidance.

Emergency and health information (optional, entered by you): If you choose to create an emergency card, we store the details you enter — blood group, allergies, medical conditions, your doctor's name and phone number, health-insurance provider and policy identifier, and up to two emergency contacts. This is information about your physical health, which Indian law treats as sensitive personal data, so it is handled to a higher standard than the rest of your profile. Creating an emergency card is entirely optional; only you can create or edit your own card, and nobody in your society is asked to fill one in on your behalf.

Who can see your emergency card: By default, nobody but you. Your card stays private until you switch on "Share with management" yourself. Only if you switch it on can your society's committee and management see it — the intent being that someone can reach your emergency contacts or tell paramedics your blood group if you are unwell and cannot speak for yourself. You can switch sharing off, edit the card, or delete it outright at any time. Other residents can never see it, whatever you choose.

Communications: Messages you send through support channels, the contact form on our website, or in-app communications.

Technical and usage data: IP address, device type and operating system, browser type, app version, screen resolution, pages or screens viewed, actions performed, timestamps, crash logs, and performance metrics. On mobile, this includes data collected by Firebase Analytics, Firebase Crashlytics, Firebase Performance Monitoring, and Firebase Cloud Messaging (push notification delivery).

Contact-form submissions: Name, email, phone number, society name, inquiry type, approximate unit count, and message content submitted through societly.co/contact.

Subscription data: Plan type, billing cycle, subscription status, and transaction identifiers processed through our RBI-regulated payment gateway partner.

4. How we use your data

We process personal data for the following purposes:

Providing and operating the Platform — authenticating users, displaying society dashboards, processing maintenance bills, recording visitor entries, managing complaints and amenities, and delivering notifications.

Payments and billing — generating invoices, processing subscription fees, reconciling payments, and maintaining financial records as required by law.

Communications — sending transactional emails (invoices, password resets, OTP codes, society invitations and notices) via Zoho ZeptoMail on its India data centre, SMS and OTP delivery via MSG91, push notifications via Firebase Cloud Messaging, and responding to support or sales inquiries.

Emergency response — where you have created an emergency card and chosen to share it, making your blood group, medical information and emergency contacts available to your society's committee so they can act if you are unwell and cannot speak for yourself. We use this data for no other purpose.

Security and fraud prevention — monitoring for unauthorised access, enforcing acceptable-use policies, and logging access events.

Analytics and improvement — understanding how the Platform is used in aggregate to fix bugs, improve features, and plan the product roadmap. Analytics data is aggregated and does not identify individual users in reports.

Legal compliance — meeting obligations under Indian tax law (GST), the Limited Liability Partnership Act, 2008, the IT Act, and any applicable housing-society regulations.

5. AI features

On-device AI (mobile app): The Societly mobile app includes optional AI-assisted features — such as meeting recording and transcription with draft minutes, bill explanations, complaint-triage suggestions, and drafting help for notices and replies — that run entirely on your device using a locally downloaded AI model.

On-device processing: When you use these features, your audio, transcripts, documents, and other content are processed locally on your phone. This on-device content is not transmitted to Societly's servers or to any third-party AI service. Meeting audio is transcribed using your device's on-device speech recognition, and recordings and transcripts stay on your device unless you explicitly choose to save the resulting minutes to your society's records or share them.

Server-side AI: Content you post inside your society — complaints, notices, community posts, classifieds and the like — is not sent to any cloud AI service. Where the Platform suggests a category or priority for a complaint, that runs on your device (see "On-device AI" above). Importing your society's historical records from a spreadsheet or another software system is handled entirely on Societly's own servers: your file, and every name, email, phone number and amount in it, is never sent to any external service. A small number of other features do use a cloud-based AI service. Specifically, when you contact Societly's own support team or make a sales enquiry, we may use the AI service to categorise your request or draft a reply for our team to review; in that case personal identifiers — email addresses, phone numbers, government ID numbers, and account-number-like digit sequences — are automatically removed from the text first, and you are identified by first name only. The AI service is used solely to provide these features and is bound by our sub-processor terms (see Section 8).

Translation: When you tap to translate a notice, message, or other text into your preferred language, that text is sent to a third-party translation service (Microsoft Azure Translator or Amazon Translate) to produce the translation, and is not used by them for any other purpose.

Model download: To enable these features, the app downloads an AI model file (approximately 0.4–1 GB depending on your device) from our content delivery network. The download happens only after you opt in, and you can remove the model at any time from the app's settings, which also frees the storage space. The download itself transfers the model to your device; it does not send any of your content to us.

AI feedback: If you rate an AI result (thumbs up or down, with an optional reason), we record only the rating, the reason category, the feature name, the model identifier, and the content language — never the underlying content, audio, or transcript. This feedback is used to monitor and improve AI quality.

Optionally sharing a sample: When you give a thumbs-down, you may separately choose to tick "Share this response with Societly to help improve AI". Only if you explicitly tick that box do we receive the specific input and generated text of that one result, so our team can review why it was unhelpful and improve the models. This is off by default, is decided by you per result, and applies only to the individual response you were rating — nothing else you write or generate is ever sent. If you leave the box unticked, no content leaves your device.

Microphone access is requested only when you start a meeting recording and is used solely for on-device transcription. You can revoke microphone permission at any time in your device settings.

6. Legal basis for processing

Under the DPDPA, we process personal data based on one or more of the following grounds:

Consent — where you have given clear consent for us to process your personal data for a specific purpose, such as when you create an account or submit a contact form.

Performance of a contract — where processing is necessary to deliver the services you or your society have subscribed to.

Legitimate uses permitted by law — where processing is necessary for compliance with a legal obligation, or is expressly permitted under applicable Indian law.

7. Cookies and tracking technologies

We classify cookies and similar technologies into two categories:

• Strictly necessary — Required for the Platform to function. The web application uses an HttpOnly refresh-token cookie to keep you signed in securely. These cookies do not track you across sites and cannot be disabled, because without them the Platform cannot operate.

• Analytics & performance — Used only with your consent. On the marketing website (societly.co) we use Google Analytics 4 (gtag.js), alongside first-party page-view events of our own, to understand which pages are useful. On the web application (app.societly.co) we use Firebase Analytics (Google Analytics 4) and Firebase Performance Monitoring to measure usage and detect slow pages. On the mobile apps we use Firebase Analytics, Firebase Crashlytics, and Firebase Performance Monitoring.

When you first visit the website or sign in to the dashboard, a consent banner asks whether you want to allow analytics. No analytics SDK loads and no analytics event is sent until you click "Accept all". If you click "Reject non-essential", no analytics processing takes place.

You can change your choice at any time using the "Cookie preferences" link in the website footer, or under Settings → Account → Cookie & analytics preferences inside the web application. Your decision is stored in your browser and applies for 12 months, after which we will ask again. Withdrawing consent is as easy as giving it, in line with the DPDPA.

Disabling analytics will not affect your ability to use the Platform.

8. Data sharing and third-party processors

We do not sell personal data. We share data only in the following circumstances:

Service providers (sub-processors) — We use third-party services to operate the Platform, each under contractual obligations to protect your data:

• Amazon Web Services (AWS) — Cloud infrastructure and data storage. Data is stored in AWS regions in India.

• Zoho Corporation (ZeptoMail) — Delivery of transactional email (invoices, verification and OTP codes, password resets, society invitations and notices). Your name, email address and the content of those messages are processed to deliver them. We use ZeptoMail's India data centre, so this data does not leave India.

• Firebase (Google) — Analytics, crash reporting, and performance monitoring.

• Firebase Cloud Messaging (Google) — Push notification delivery.

• MSG91 — SMS and OTP delivery within India.

• RBI-regulated banking & payment partner — Payment processing for subscriptions and society transactions, and merchant/sub-merchant KYC verification for Societies that activate online collections (see Section 3).

• Meta (WhatsApp Business Platform) — Delivery of WhatsApp messages where you contact us on WhatsApp or opt in to WhatsApp updates; your WhatsApp phone number and message content are processed by Meta to deliver the conversation.

• Translation services (Microsoft Azure Translator / Amazon Translate) — Translating text you choose to translate into your preferred language (see Section 5).

• Cloud AI service — Limited, personal-identifier-redacted or anonymised text for the server-side AI features described in Section 5.

Society administrators — Committee members and administrators of your society can view member directories, billing records, visitor logs, and other operational data for their society. The visibility of certain resident information (such as phone numbers in the directory) may be controlled by society administrators in accordance with their society's bye-laws.

Health information is never shared. The emergency-card data described in Section 3 is not disclosed to any of the sub-processors listed above, is never sent to any AI or translation service, is not used for analytics, and is never sold or shared for advertising. It leaves your own account only in the one case you choose: sharing it with your society's committee by switching on "Share with management".

Legal and regulatory — We may disclose personal data if required by law, regulation, legal process, or government request, or if disclosure is necessary to protect the rights, property, or safety of Societly, our users, or the public.

Business transfers — In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the successor entity, subject to the same privacy commitments.

9. Data retention

We retain personal data for as long as necessary to provide the Platform and fulfil the purposes described in this policy. Specific retention periods:

Account data — When you delete your account, your access ends immediately and every session is signed out. Within 30 days we then irreversibly anonymise the account: your name, email address, phone number, profile photo and login identifiers are replaced with placeholders, and your name is removed from anything you posted or raised, which then shows as "Deleted member". This is automated, not on request.

What survives that anonymisation, and why — Records that Indian tax and accounting law requires us to keep (invoices, payments, receipts and the ledger entries behind them) are retained for 8 years. After anonymisation those records no longer identify you: they reference an account number that has no name, contact detail or login attached to it.

Being removed from a society is not the same as deleting your account. If a society ends your membership, your membership record stays with that society as part of its own records, and your Societly account continues to exist until you delete it.

Gate and security records — Visitor passes, delivery logs and vehicle entry logs are automatically deleted after 12 months. Guard patrol rounds and staff or domestic-help attendance records are automatically deleted after 24 months. Salary records are financial and follow the 8-year period above.

Emergency card — kept for as long as you keep it. It has no automatic expiry, because it is only useful if it is current. You can delete it yourself at any time, and it is erased along with the rest of your account when you delete your account.

Notifications are deleted after 6 months. Audit records of sensitive actions are kept for 8 years to match statutory books-of-account requirements.

Server logs and security data are retained for up to 12 months.

Contact-form submissions are retained for up to 24 months for follow-up and business-development purposes.

Analytics data is retained in aggregated, anonymised form and is not subject to deletion requests.

10. Data security

We implement administrative, technical, and organisational security measures to protect personal data, including:

• Encryption of data in transit (TLS/HTTPS) and at rest.

• Access controls with role-based permissions and multi-factor authentication for internal systems.

• Regular security reviews and dependency auditing.

• Cloud infrastructure hosted with industry-standard security certifications.

Despite these measures, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security but are committed to promptly addressing any incident in accordance with applicable breach-notification requirements.

11. Your rights

Under the DPDPA and applicable Indian law, you have the following rights as a data principal:

Right to access — You do not have to ask us. In the app, go to Profile → Download my data; on the web, Settings → Download my data. You will get a file containing your account, your memberships, and your own records in the society you are signed into — what you were billed and paid, the complaints you raised, bookings, visitors you pre-approved, what you posted, your household and emergency-card entries. If you belong to more than one society, switch society and download again. Credentials are excluded by design.

Right to correction — You may request correction of inaccurate or incomplete personal data. You can update most account information directly through the Platform.

Right to erasure — You may delete your account yourself from the app or the web. Access ends immediately and your account is irreversibly anonymised within 30 days; see Section 9 for exactly what that removes and what tax law requires us to keep.

Right to grievance redressal — You may raise concerns about our data-processing practices with our Grievance Officer (see Section 15 below).

Right to nominate — Under the DPDPA, you may nominate another individual to exercise your data-protection rights in the event of your death or incapacity. Write to our Grievance Officer with the nominee's name and contact details; we will record the nomination against your account and confirm it to you.

To exercise any right that is not self-service above, contact us at privacy@societly.co or write to our Grievance Officer. We will respond within 30 days of receiving your verified request.

12. Children's data

Societly accounts are for adults. We do not create accounts for, or knowingly collect personal data directly from, anyone under 18.

A resident may list a child as a member of their household — a name and relationship on their own flat's roster, so the child is recognised at the gate. Because that is a child's personal data, the app asks the adult adding them to confirm two things before it is saved: that the person is under 18, and that they are the child's parent or lawful guardian and consent to the details being recorded. That confirmation, and who gave it, is stored as the consent record the DPDPA requires. Without it the record is not created.

We deliberately do not ask for a child's date of birth, photograph, contact details or any other information beyond a name and relationship — knowing that a household member is a minor is enough to protect them, and anything further would be more data about a child for no benefit to them.

We do not track children, profile them, or direct advertising at them — the Platform carries no advertising at all.

A parent or guardian can remove a child's household record at any time from the app, or ask our Grievance Officer (Section 15) to do it.

13. Data transfers

Primary data storage and processing occurs within India, including transactional email, which is delivered through Zoho ZeptoMail's India data centre. Certain third-party sub-processors — such as Google Analytics 4 and Firebase (Google) (analytics events, crash reports, push notification tokens), Meta (WhatsApp message delivery), translation services, and the cloud AI service described in Section 5 (redacted or anonymised text only) — may process limited data on servers outside India. Where such transfers occur, we rely on each provider's published data-processing terms and their own data-protection commitments; we are formalising written data-processing agreements with each sub-processor. We will comply with any data-localisation requirements notified by the Central Government under the DPDPA.

14. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Platform, or applicable law. When we make material changes, we will notify you by posting the updated policy on this page with a revised "Last updated" date, and where appropriate, through an in-app notification or email. Your continued use of the Platform after such changes constitutes acceptance of the updated policy.

15. Grievance Officer

In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDPA, we have appointed a Grievance Officer. For any concerns, complaints, or requests regarding your personal data or content on the Platform:

Grievance Officer: Ahmed Sharief

Email: privacy@societly.co

Postal address: Societly Technologies LLP, HBR Layout, Bengaluru, Karnataka 560043, India

We will acknowledge your grievance within 24 hours and resolve it within 15 days from the date of receipt, or within such other period as applicable law prescribes for the nature of the grievance.

16. Contact us

For general inquiries about this Privacy Policy, contact us at:

Email: hello@societly.co

Website: societly.co/contact