Legal
Privacy policy
PG Nexon handles data about two very different groups — the operators who buy the software, and the tenants who live in their properties. This policy explains what we hold for each, why, and how long.
Last updated 1 September 2026
This policy explains how PG Nexon Technologies Private Limited (“PG Nexon”, “we”, “us”) collects and processes personal data through the PG Nexon platform, its owner dashboard, its tenant mobile app and pgnexon.in. It is written to meet the Digital Personal Data Protection Act, 2023 and the Information Technology (Reasonable Security Practices) Rules, 2011.
1. Who controls your data
The distinction matters, because it decides who you go to with a request:
- For property operators — the account holder, their staff and their billing details — we are the data fiduciary. We decide what we collect and why, and this policy governs it.
- For tenants — residents added to a property by its operator — the operator is the data fiduciary and we are a data processor acting on their instructions. We process tenant records only to deliver the service the operator has asked for; we do not sell, mine or independently exploit them. Requests to correct or erase a tenant record are handled by the operator, and we assist them.
2. What we collect
Account and operator data
- Name, email address, phone number and password hash for every owner and staff login.
- Business details: property names, addresses, branch structure, GSTIN where supplied.
- Role and permission assignments, so the platform knows what each staff member may see.
- Billing records: occupied-bed counts per month, invoices, and payment references.
Tenant data, entered by the operator
- Identity and contact details: name, phone number, email, emergency contact.
- Stay details: assigned bed, room, floor and branch, joining date, notice and exit dates.
- Financial records: rent invoices, payments, late fees, security deposit and its settlement.
- Operational records created in normal use: complaint tickets and their threads, visitor entries and the tenant’s approval of them, meal opt-ins, and community posts.
- Identity documents, where an operator chooses to upload them. We treat these as sensitive and restrict them to that operator’s authorised staff.
Technical data
- IP address, device and browser type, and timestamps, recorded in access logs.
- Audit entries for actions that change money or occupancy — who marked a payment received, who settled a deposit, who moved a tenant out.
- Strictly necessary cookies that keep you signed in. We do not run advertising cookies or third-party trackers on the product.
3. Why we process it
- To provide the service — issue invoices, track beds, settle deposits, run the visitor register and deliver the tenant app.
- To bill you — the platform is priced per occupied bed, so we must count beds to raise an invoice.
- To notify — rent reminders, complaint updates and visitor approval requests, by email, SMS or push notification. Service messages of this kind are part of the product and cannot be switched off while an account is active; marketing email can.
- To keep the platform safe and correct — abuse prevention, debugging, and the audit trail that lets a disputed deposit deduction be traced.
- To meet legal obligations — tax records, and lawful requests from authorities.
We do not sell personal data, and we do not use tenant data to train machine-learning models.
4. Who we share it with
- Sub-processors that run parts of the service — cloud hosting, payment gateways, email, SMS and push delivery. Each is bound by contract to process data only on our instructions and to comparable security standards.
- The operator of your property, if you are a tenant. Your rent, complaint and visitor records are visible to that operator and to the staff they have granted access.
- Authorities, where we are legally compelled. We satisfy ourselves that the request is valid and, unless we are barred from doing so, we tell the affected account.
We do not share data with other operators. One operator can never see another’s tenants, properties or finances.
5. How long we keep it
- Active accounts — for as long as the account is open.
- Former tenants — the stay and financial history stays with the operator for as long as they need it, because deposit and tax disputes surface late. The operator can delete a tenant record at any time.
- Closed accounts — we keep the data for 90 days so you can export it or change your mind, then delete it. Tell us sooner and we delete sooner.
- Invoices and tax records — retained for eight years, as Indian tax law requires, even after deletion of the rest.
- Backups — deleted data persists in encrypted backups for up to 35 days before those backups roll off.
6. Your rights
Under the DPDP Act you may ask us to:
- tell you what personal data we hold about you and who we have shared it with;
- correct data that is wrong, incomplete or out of date;
- erase data we no longer need for the purpose it was collected for;
- withdraw a consent you gave, without affecting processing already carried out;
- nominate someone to exercise these rights if you die or become incapacitated.
Write to privacy@pgnexon.in and we will respond within 30 days. If you are a tenant, send the request to your property operator first — they hold the record, and we act on their instruction.
7. Security
Data is encrypted in transit and at rest, access is scoped by server-side permission checks rather than by what the interface chooses to hide, and every money-moving action is logged. The full description is on our security page.
8. Children
The platform is not intended for anyone under 18. An operator who needs to record a minor as a resident must obtain verifiable consent from a parent or guardian before entering their details, as the DPDP Act requires.
9. Where data is stored
Personal data is stored on servers located in India. Some sub-processors — email and push notification delivery in particular — may process limited data outside India under contractual safeguards.
10. Changes
We will post any change here and update the date at the top. If a change materially reduces your rights, we will email account holders at least 30 days before it takes effect.
11. Contact and grievances
For privacy questions, write to privacy@pgnexon.in. If you are not satisfied with our answer, our Grievance Officer under the IT Rules and the DPDP Act is [Name], reachable at grievance@pgnexon.in or by post at PG Nexon Technologies Private Limited, [Registered office address], Bengaluru, Karnataka 560001, India. You may also complain to the Data Protection Board of India.