This Privacy Notice for Resido Technologies (‘Company’, ‘we’, ‘us’, or ‘our’) describes how and why we might access, collect, store, use, and/or share (‘process’) your personal information when you use our services (‘Services’), including when you visit https://app.residotech.com, download and use our mobile application (Resido), or engage with us in other related ways.

Questions or concerns? Please contact us at [email protected]. If you do not agree with our policies and practices, please do not use our Services.

Summary of Key Points

Table of Contents

  1. What Information Do We Collect?
  2. How Do We Process Your Information?
  3. When and With Whom Do We Share Your Personal Information?
  4. Tracking Technologies and Analytics
  5. Do We Offer Artificial Intelligence-Based Products?
  6. How Do We Handle Your Social Logins?
  7. How Long Do We Keep Your Information?
  8. How Do We Keep Your Information Safe?
  9. Do We Collect Information From Minors?
  10. What Are Your Privacy Rights?
  11. Controls for Do-Not-Track Features
  12. Artificial Intelligence and Automated Support
  13. Biometric Data Handling
  14. Institutional Data Sharing
  15. Device Integrity and Security Scanning
  16. Payment Processors
  17. Legal Basis for Processing
  18. Automated Decision-Making
  19. Data Breach Notification
  20. Data Portability and Export
  21. Cross-Border Data Transfers
  22. Grievance Officer and Data Protection Officer
  23. Age Requirement and Parental Consent
  24. Do We Make Updates to This Notice?
  25. How Can You Contact Us About This Notice?
  26. How Can You Review, Update, or Delete the Data We Collect From You?

1. What Information Do We Collect?

Personal information you disclose to us

We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us, participate in activities on the Services, or otherwise when you contact us. The personal information we collect may include:

Sensitive Information. When necessary, with your consent or as otherwise permitted by applicable law, we process: financial data (transaction amounts, payment statuses, bill histories); student data (academic batch, residential status, hostel assignment); and mess attendance and rebate records (leave dates, rebate amounts, approval statuses).

Payment Data. We may collect data necessary to process your payment. All payment data is handled and stored by HDFC Bank (SmartGateway), Juspay, and Google Play Billing. We do not store or retain your sensitive payment instrument details on our servers. All financial transactions are processed securely through our PCI-DSS compliant payment partners, and we only receive a confirmation of the transaction status along with a transaction reference ID.

Social Media Login Data. If you register using your Google account, we will collect your name, email address, and profile picture from Google, as described in Section 6.

Information automatically collected

We automatically collect certain information when you visit, use, or navigate the Services. The information we automatically collect includes:

Google API

Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Information collected from other sources

If you choose to sign in using your Google account, we receive personal information about you from such platforms such as your name, email address, and profile picture. Any personal information we collect from your social media account depends on your social media account’s privacy settings. Please note that their own use of your information is not governed by this Privacy Notice.

2. How Do We Process Your Information?

We process your personal information for a variety of reasons, including:

3. When and With Whom Do We Share Your Personal Information?

We may share your data with third-party vendors, service providers, contractors, or agents who perform services for us or on our behalf. We have contracts in place with our third parties which are designed to help safeguard your personal information — they cannot do anything with your personal information unless we have instructed them to do it, and they commit to protect the data they hold on our behalf.

The third parties we may share personal information with are as follows:

We also may need to share your personal information in the following situations: Business Transfers — in connection with any merger, sale of company assets, or acquisition; Legal Requirements — where we are legally required to do so in order to comply with applicable law, governmental requests, or a judicial proceeding; and Vital Interests and Legal Rights — where we believe it is necessary to investigate, prevent, or take action regarding potential violations of our policies, suspected fraud, or situations involving potential threats to the safety of any person.

4. Tracking Technologies and Analytics

As Resido is primarily a mobile application, we do not use traditional browser cookies for tracking or advertising. However, we use the following technologies and SDKs to collect usage data:

We do not use any advertising SDKs, and we do not display advertisements within the application. We do not share your data with advertising networks or use tracking technologies to serve targeted advertisements.

Note on Google Advertising ID: The Application declares access to the Google Advertising ID (AD_ID) solely because it is required by Firebase Analytics for demographic analytics reporting. We do not use the Advertising ID for advertising purposes.

5. Do We Offer Artificial Intelligence-Based Products?

As part of our Services, we offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies (collectively, ‘AI Products’). We provide these through third-party service providers (‘AI Service Providers’), including Google Cloud AI (Vertex AI / Gemini).

Our AI Products are designed for: AI-powered chatbot assistance for answering user queries related to hostel mess operations, and automated response generation using account context data.

All personal information processed using our AI Products is handled in line with our Privacy Notice and our agreement with third parties. We do not use your personal data to train public or third-party AI models. To opt out of AI-powered features, simply choose not to interact with the AI chatbot assistant within the application, or contact us using the contact information provided in this Notice.

6. How Do We Handle Your Social Logins?

Our Services offer you the ability to register and log in using your Google account. Where you choose to do this, we will receive certain profile information from Google, including your name, email address, and profile picture. We will use the information we receive only for the purposes described in this Privacy Notice. We do not control, and are not responsible for, other uses of your personal information by Google. We recommend that you review their privacy notice to understand how they collect, use, and share your personal information.

7. How Long Do We Keep Your Information?

We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law. Specific retention periods are as follows:

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise such information, or securely store your personal information and isolate it from any further processing until deletion is possible.

8. How Do We Keep Your Information Safe?

We have implemented appropriate and reasonable technical and organisational security measures designed to protect the security of any personal information we process. These measures include:

However, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure. You should only access the Services within a secure environment.

9. Do We Collect Information From Minors?

Our Services are intended for users who are at least eighteen (18) years of age, or who are at least sixteen (16) years of age and have obtained verifiable consent from a parent or legal guardian. This exception recognises that first-year students at certain educational institutions may be under the age of 18 at the time of enrolment.

If you are a student under the age of 18, you represent that you have obtained parental or guardian consent to use the Services. We do not knowingly sell personal information of users under 18 years of age. If we learn that personal information from users under 16 years of age has been collected without verifiable parental consent, we will deactivate the account and take reasonable measures to promptly delete such data. If you become aware of any data we may have collected from children under age 16 without appropriate consent, please contact us at [email protected].

10. What Are Your Privacy Rights?

Withdrawing your consent: If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time by contacting us using the details in this Notice. Please note that this will not affect the lawfulness of the processing before its withdrawal.

Account Information: If you would like to review or change the information in your account or terminate your account, you can contact us using the contact information provided, log in to your account settings and update your user account, or request account deletion through the in-app account deletion mechanism.

Upon your request to terminate your account, we will deactivate or delete your account and personal information from our active databases within thirty (30) days. However, we may retain financial records as described in Section 7.

If you have questions or comments about your privacy rights, you may email us at [email protected].

11. Controls for Do-Not-Track Features

Most web browsers and some mobile operating systems include a Do-Not-Track (‘DNT’) feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognising and implementing DNT signals has been finalised. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Notice.

12. Artificial Intelligence and Automated Support

We utilise Google Cloud Vertex AI (Gemini) to provide automated customer support and chat assistance within the application. When you interact with our support chatbot, the text of your queries and a summary of your account context (such as your current mess bill status, wallet balance, and active rebates) are processed by Google’s AI models to generate a response.

This processing is performed solely to answer your inquiries. We do not use your personal data to train public AI models, and your data is handled in accordance with Google Cloud’s data privacy and security terms. Conversations with the AI chatbot may be logged for the purpose of improving the quality and accuracy of the Service.

The AI chatbot provides informational responses only and does not constitute official administrative, financial, or legal advice. The Company is not liable for any loss or adverse outcome resulting from reliance on chatbot responses.

13. Biometric Data Handling

You may choose to use your device’s biometric security features (such as fingerprint or face unlock) to access the App. We do not collect, store, or transmit your biometric data to our servers. All biometric verification is performed locally by your device’s operating system using the device manufacturer’s hardware. The App only receives a ‘Success’ or ‘Failure’ result from your device to grant or deny access. Biometric authentication is optional and can be enabled or disabled at your discretion through the App’s settings.

14. Institutional Data Sharing

The Application serves as a management tool for enrolled educational institutions. You acknowledge and agree that your personal information, including your profile details, mess attendance records, rebate applications, and bill payment status, will be accessible to the Hostel Administration, Mess Committee, and authorised institutional staff for the purpose of managing hostel operations, auditing accounts, and enforcing institutional rules.

Service availability, features, and billing configurations may vary between institutions based on their individual agreements with the Company. Your data is scoped to the specific institution to which you are enrolled and registered within the App.

15. Device Integrity and Security Scanning

To ensure the security of financial transactions and prevent fraud, the Application performs comprehensive checks on your device’s integrity. These checks include scanning for:

If such modifications or threats are detected, access to the Application may be restricted or terminated to protect your account and financial data. This data is used solely for security verification purposes and is not shared with third parties beyond what is necessary to verify device integrity (e.g., Google Play Integrity API).

16. Payment Processors

We primarily utilise HDFC Bank (SmartGateway) and Juspay for processing mess bill payments, and Google Play Billing for app subscription fees. We do not store your complete banking or credit card information on our servers; this data is processed directly by these secure third-party payment gateways.

We receive only the following information from our payment processors: transaction status (success, failure, or pending), transaction reference ID, payment amount, and timestamp of the transaction.

For information on how these payment processors handle your data, please refer to their respective privacy policies: HDFC Bank · Juspay · Google Play Billing

17. Legal Basis for Processing

We process your personal information based on the following legal grounds under applicable Indian law, including the Digital Personal Data Protection Act, 2023 (DPDPA) and the Information Technology Act, 2000:

18. Automated Decision-Making

Certain features of the Services involve automated processing of your data without direct human intervention, including:

These automated decisions are based on institutional rules and not on AI-based profiling. If you believe an automated decision has been made in error, you have the right to contact the Hostel Administration or to reach out to us at [email protected] to request a manual review.

19. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

We will take all reasonable steps to mitigate the effects of any data breach and to prevent recurrence.

20. Data Portability and Export

You have the right to request a copy of the personal data we hold about you by contacting us at [email protected].

The Services do not currently offer an automated data export or portability feature within the application. If you require copies of your financial records (such as payment receipts or bill histories), please download available digital receipts through the App before initiating an account deletion request.

Upon receiving a valid data portability request, we will provide you with a copy of your data in a commonly used, machine-readable format (such as CSV or JSON) within thirty (30) days.

21. Cross-Border Data Transfers

Our Services are hosted on Google Cloud Platform infrastructure located in India and the United States. If you access the Services from any other region of the world, through your continued use of the Services, you are transferring your data to India and the United States, and you expressly consent to have your data transferred to and processed in India and the United States.

Google Cloud Platform maintains compliance with internationally recognised security and privacy frameworks, including SOC 2, ISO 27001, and ISO 27017. We ensure that any transfer of your data to a jurisdiction outside India is conducted in compliance with the requirements of the Digital Personal Data Protection Act, 2023.

22. Grievance Officer and Data Protection Officer

In accordance with the Information Technology Act, 2000 and Rules made thereunder, and the Digital Personal Data Protection Act, 2023 (DPDPA), the designated Grievance Officer and Data Protection Officer (DPO) for the Company is:

Maj (Dr) Kushvanth Kolibailu
Email: [email protected]
Address: House No. 04, 2nd Main, 4th Cross, Ward No. 07, Anjani Extension, Chintamani, Karnataka 563125, India
Availability: Monday to Friday, 10:00 AM to 4:00 PM IST

The Grievance Officer shall acknowledge your complaint within forty-eight (48) hours and shall resolve the complaint within thirty (30) days of receipt.

23. Age Requirement and Parental Consent

The Services are intended for use by enrolled students of educational institutions that have adopted the Resido platform. The general age requirement for using the Services is eighteen (18) years of age. However, we recognise that first-year students at certain educational institutions may be under the age of 18 at the time of enrolment. If you are a student between the ages of sixteen (16) and eighteen (18), you represent that you have obtained verifiable parental or guardian consent to use the Services and to share your personal information for the purpose of hostel administration.

We do not inadvertently collect data from minors; we collect data from enrolled students as authorised by their educational institution. Users under the age of sixteen (16) are not permitted to use the Services under any circumstances.

24. Do We Make Updates to This Notice?

Yes, we will update this notice as necessary to stay compliant with relevant laws. We may update this Privacy Notice from time to time. The updated version will be indicated by an updated ‘Last updated’ date at the top of this Privacy Notice. If we make material changes to this Privacy Notice, we will notify you by prominently posting a notice within the mobile application and may also send you a push notification. We encourage you to review this Privacy Notice frequently to be informed of how we are protecting your information.

25. How Can You Contact Us About This Notice?

If you have questions or comments about this notice, you may contact our Grievance Officer and Data Protection Officer using the contact details provided in Section 22 above, or contact us by post at:

Resido Technologies
Data Protection Officer
House No. 04, 2nd Main, 4th Cross
Ward No. 07, Anjani Extension
Chintamani, Karnataka 563125
India

For general inquiries: [email protected]

26. How Can You Review, Update, or Delete the Data We Collect From You?

Based on the applicable laws of your country, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law.

To request to review, update, or delete your personal information, please email [email protected] or use the account management features within the application. We will respond to your request within thirty (30) days of receipt. We may require you to verify your identity before processing your request.