1. Scope of this policy
This Privacy Policy applies to the Neighbium website, mobile applications and related services (together, the "Platform") operated by Neighbium ("Neighbium", "we", "us").
It covers everyone whose data passes through the Platform: managing committee members and society administrators, resident owners and tenants and their family members, security personnel and society staff, domestic help and vendor personnel, and visitors recorded at a society gate.
It does not cover how your housing society handles information outside the Platform, or the practices of any third-party website we link to.
2. Who controls your data: the society and Neighbium
This distinction matters, so we want to be explicit about it.
Your housing society, association or managing committee decides what information is collected about its residents, staff and visitors, who within the committee can see it, and how long gate records are kept. In data-protection terms the society is the entity determining the purpose of that processing.
Neighbium provides the software that stores and processes that information on the society's instructions. We do not sell it, we do not use it to build advertising profiles, and we do not share one society's data with another.
For information you give us directly — for example when you contact us through this website, or when a committee signs up — Neighbium determines the purpose itself, and this policy governs that processing.
If you want data held by your society corrected or deleted, the fastest route is usually your managing committee, because they control the records for your community. You can also contact us using the details in section 14.
3. Information we collect
We collect only what the Platform needs to function for your community.
Resident and member information: name, flat or unit number, block or tower, ownership or tenancy status, mobile number, email address, family members linked to the unit, vehicle registration numbers, parking allocation, and a profile photograph where you choose to add one.
Society and financial information: maintenance invoices and receipts, dues and payment history, billing heads and rates, bank account details recorded by the committee for collections, expense and vendor records, and accounting ledgers.
Gate and visitor information: visitor name and purpose of visit, the unit being visited, entry and exit timestamps, delivery and cab details, vehicle numbers, and where the society has enabled it, a visitor photograph.
Staff and service-provider information: name, contact number, the units served, identity documents where the society requires them, attendance records, and — only where your society has enabled biometric or face-recognition attendance — the biometric template used for that verification.
Community activity: complaints and helpdesk tickets you raise, amenity bookings, notices you publish or read, poll and election votes, meeting attendance, and documents uploaded to the society repository.
Technical information: IP address, device type and identifier, operating system, browser type, app version, crash reports, and log data about how the Platform is used.
Communications: messages you send us by email or through the contact form on this website, and our replies.
We do not ask for and do not want sensitive information beyond what is described above. Please do not upload identity documents, financial records or health information to free-text fields where they are not required.
4. How we use your information
- To operate the Platform: authenticate you, show your unit's dues, route your complaints and record your bookings.
- To run gate security: notify you of visitors awaiting approval, alert security to overstays, and notify parents of a child's exit where the society has enabled it.
- To process maintenance billing: generate invoices, send reminders, record payments and maintain the society's accounts.
- To communicate: deliver notices, poll invitations, meeting agendas and service messages about your account.
- To provide support: investigate and resolve problems you or your committee report to us.
- To keep the Platform secure: detect and prevent unauthorised access, fraud and abuse, and maintain audit trails.
- To improve the product: understand which features are used, diagnose failures and plan changes — using aggregated or de-identified data wherever it is sufficient.
- To meet legal obligations: retain records we are required to keep, and respond to lawful requests from authorities.
We do not sell personal data. We do not run third-party advertising on the Platform, and we do not share resident data with advertisers or data brokers.
5. Consent and lawful basis
We process personal data on the basis of the consent you or your society provide when an account is created and the Platform is used, and, where applicable, for the legitimate uses permitted under the Digital Personal Data Protection Act, 2023.
Where consent is the basis, you may withdraw it at any time by contacting your managing committee or us. Withdrawing consent does not affect processing already carried out, and it may mean parts of the Platform stop working for you — for example, you cannot receive visitor-approval notifications if you withdraw consent to receive them.
Biometric and face-recognition features are optional. They operate only where a society deliberately enables them, and only for the staff and personnel that society enrols.
7. How long we keep information
We keep personal data only as long as it is needed for the purpose it was collected for, or as long as the law requires.
- Gate and visitor records are retained for the period your managing committee configures, subject to a platform default. Committees can shorten this.
- Financial records — invoices, receipts and ledgers — are retained for as long as your society requires them and for any statutory retention period applicable to society accounts.
- Resident account data is retained while the unit is active on the Platform and for a reasonable period afterwards to allow for handover and dispute resolution.
- Support correspondence is retained for as long as needed to resolve the matter and to handle any follow-up.
When a society leaves the Platform, its data is deleted or returned in line with the arrangement agreed with the committee. Backups are purged on their normal cycle.
8. How we protect information
We use reasonable security practices and procedures appropriate to the sensitivity of the information we hold, including encryption of data in transit and at rest, role-based access control so people see only what their role requires, phone-number masking in the resident intercom, permission-scoped document storage, monitoring, and regular backups.
No system can be guaranteed completely secure. If a personal data breach occurs that is likely to affect you, we will notify the affected societies and the relevant authority as required by law.
You also have a part to play: keep your login credentials confidential, use a device lock, and tell us promptly if you believe your account has been accessed without authorisation.
9. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you and a summary of how it is processed.
- Correct or complete information that is inaccurate or out of date.
- Request erasure of personal data that is no longer needed for the purpose it was collected for, unless retention is required by law.
- Withdraw consent you previously gave, on a going-forward basis.
- Nominate another individual to exercise your rights in the event of death or incapacity.
- Raise a grievance with us, and escalate to the relevant data protection authority if you are not satisfied with our response.
To exercise any of these, write to us at the address in section 14. We may need to verify your identity before acting. Where the request concerns records controlled by your society, we will direct it to your managing committee and support them in responding.
10. Children's information
The Platform is intended for use by adults. Information about children — such as a child's name linked to a unit for the child-exit notification feature — is provided and controlled by the parent, guardian or the managing committee.
We do not knowingly collect personal data directly from children, and we do not use children's data for tracking or targeted advertising. If you believe a child's information has been provided to us improperly, contact us and we will remove it.
12. Where your information is stored
Neighbium primarily stores and processes personal data on cloud infrastructure. Where a service provider processes data outside India, we take steps to ensure the transfer is permitted under applicable law and that the provider is bound by appropriate contractual protections.
13. Changes to this policy
We may update this policy as the Platform, our practices or the law change. When we do, we will revise the date at the top of this page, and we will give notice within the Platform where the change is significant.
Continuing to use the Platform after a change takes effect means you accept the updated policy.
14. Contact and grievances
If you have a question about this policy, want to exercise a right, or wish to raise a complaint about how your personal data has been handled, write to us:
- Email: support@neighbium.com
We aim to acknowledge grievances promptly and resolve them within the period required by applicable law. If you are not satisfied with our response, you may escalate the matter to the relevant data protection authority in India.
Questions about this document?
Write to us and we will get back to you.
See also: Terms of Service · Trust & Security