01Overview
Two kinds of people appear in this policy. Operators are our customers: owners, managers and staff who sign in to Dormingo. Residents are the tenants whose details an operator enters. Residents do not have Dormingo accounts.
Dormingo operates in India, the United Kingdom and the United States, and privacy law differs in each. Rather than publish three policies we describe one standard of handling, then set out the country-specific rights in sections 10, 11 and 12. Read the section for your country in addition to the rest of this policy, not instead of it.
This policy covers the Dormingo mobile app for Android and iOS, the Dormingo web dashboard, and the backend services behind them (together, the "Service").
02Our role: processor or controller
This distinction decides who is responsible for what. The words differ by country; the split is the same one.
| Role | India (DPDP Act) | UK & EU | United States |
|---|---|---|---|
| Decides why and how data is used | Data Fiduciary | Controller | Business |
| Acts only on instructions | Data Processor | Processor | Service provider |
| The individual | Data Principal | Data subject | Consumer |
- For resident data — the details an operator enters about residents, applicants, guarantors, emergency contacts and contractors — the operator is the Data Fiduciary / Controller and Dormingo is the Data Processor. We act only on the operator's documented instructions and do not decide what that data is used for.
- For operator account data — registration details, sign-in and security records, billing information, support correspondence and diagnostics — Dormingo is the Data Fiduciary / Controller.
Where we act as processor we sign a written data processing agreement containing the terms required by section 8(2) of India's Digital Personal Data Protection Act 2023, Article 28 of the UK and EU GDPR, and the service-provider terms required by the California Consumer Privacy Act as amended by the CPRA.
03What we collect
Information operators give us
- Account details — name, email address, phone number, job title, profile photo if uploaded, theme preference, and the organisation you work for. Passwords are stored only as a salted hash; if you sign in with Google we receive your Google email, name and profile picture and a signed identity token, never your Google password.
- Organisation details — registered business name, registration and tax numbers (CIN, GSTIN or PAN in India; company and VAT number in the UK; EIN in the United States), trading address, and the bank details you want printed on receipts and invoices the Service generates.
- Billing details — company name, tax registration number, billing address. Subscription card details go directly to our payment processor; Dormingo never stores full card numbers.
- Support messages you send us, and anything you include in them.
Resident and property data entered by operators
- Identity and contact details — name, date of birth, gender, nationality, phone, email, permanent and correspondence address.
- Tenancy details — property, floor, room and bed, joining and vacating dates, notice, transfers, rent amount, billing cycle, lock-in period, scheduled visits.
- Financial records — rent charged, payments received and the method used, security deposits held, retained and refunded, forfeitures, tokens and advances, electricity meter readings and utility charges, expenses, refunds, and generated receipts and invoices. Every entry records who recorded it and when.
- Study or employment details — university, college, course, year of study, or employer and designation.
- Emergency and next-of-kin contacts — name, relationship, phone, email. These people have usually not dealt with the operator directly, so the operator must have a lawful basis for holding their details.
- Identity documents (KYC) — see section 04.
- Maintenance and complaint records — reported faults, photographs of the fault, assignee and resolution.
- Enquiry and visit records for prospective residents.
- Property photographs of buildings, rooms and amenities, which may incidentally include people.
Information collected automatically
- Device and log data — device model, operating system, app version, language, IP address, the endpoint or database function called, response status and timestamp. An IP address is personal data in the UK and the EEA, and under the DPDP Act where it is linked to an identifiable person.
- Security records — sign-in attempts, session refreshes, sign-outs, permission changes, account closures.
- Crash reports, where your device or app store is configured to send them.
- Push notification token, if you allow notifications.
Location
The app asks for location permission at two points only: when you set up a property, and when you pick or confirm an address. It is used to centre a map and turn a chosen point into a postal address. It runs only while the app is in the foreground and only on those screens. We do not collect location in the background and do not track you between sessions. Refusing the permission only means you type the address yourself.
04Identity documents
Identity documents carry more risk than most other data, so they are handled separately. Operators may upload images of a passport, Aadhaar, PAN card, driving licence, voter identity card, national identity card, residence permit, visa or student card, together with the document number, expiry date and the outcome of the check.
- Documents upload directly from the device to Cloudflare R2 object storage over a presigned URL valid for five minutes and for a single object key. The key is derived from the owner identity inside your signed session token, never from anything the app sends, so one account cannot write into another's namespace. The file never passes through our application servers.
- Only team members holding the identity-check permission can view them, and only for properties they are assigned to. Every verification decision records who made it and when.
- The outcome is recorded as verified, rejected or expired, with a reason for rejection. There is no automated decision-making and no profiling.
- Some documents reveal data the UK and EU GDPR treat as a special category, and that Indian law treats as sensitive personal data under the IT (Reasonable Security Practices) Rules 2011. The operator must identify a valid condition — under Article 9 GDPR, usually substantial public interest or compliance with employment, social security or housing law — and collect no more than the checking obligation requires.
- Aadhaar. Under the Aadhaar Act 2016 an Aadhaar number must not be published or displayed publicly, and only the last four digits should remain visible on a retained copy. A masked copy or offline verification is preferable to a full image. Dormingo supports recording an alternative document instead.
05How we use it, and our legal basis
Where we are the Data Fiduciary / Controller, these are the bases we rely on. In India processing rests either on your consent or on a "legitimate use" listed in section 7 of the DPDP Act; in the UK and EEA on an Article 6 basis.
| Purpose | India — DPDP basis | UK & EU — GDPR basis |
|---|---|---|
| Providing the Service, keeping you signed in, honouring settings | Consent, given for a specified purpose at sign-up | Performance of a contract |
| Billing and tax compliance | Legitimate use — compliance with law | Legal obligation |
| Security, fraud prevention, abuse detection | Legitimate use — compliance with law; consent | Legitimate interests; legal obligation |
| Diagnosing faults, improving reliability | Consent | Legitimate interests |
| Responding to support requests | Legitimate use — voluntarily provided for that purpose | Contract; legitimate interests |
| Service announcements about outages and security | Legitimate use — necessary to provide the service sought | Legitimate interests |
| Product and marketing emails | Consent — withdrawable any time | Consent — withdrawable any time |
| Establishing or defending legal claims | Legitimate use — compliance with law or judgment | Legitimate interests |
Where we rely on legitimate interests we have carried out a balancing assessment and concluded our interests do not override your rights; ask and we will send a summary. Where we rely on consent you may withdraw it at any time, as easily as you gave it, without affecting processing already carried out.
Where we act as processor, the operator is responsible for its own lawful basis for resident data. In practice that is usually performance of the tenancy agreement, compliance with a legal obligation — police tenant verification and state paying-guest or lodging-house registration in India, right-to-rent checks in England, fair-housing record-keeping in the United States — or the operator's legitimate interests in running the building safely.
07Where your data lives
Dormingo runs on Supabase in more than one region. Which region holds your data is fixed when your account is provisioned, from the country you select at sign-up. It is a property of the account, not of an individual building or user.
| Market | Database region | File storage | Governing framework |
|---|---|---|---|
| India | Mumbai (ap-south-1) | R2, Asia-Pacific jurisdiction | Digital Personal Data Protection Act, 2023 |
| United Kingdom | London (eu-west-2) | R2, European Union jurisdiction | UK GDPR & Data Protection Act 2018 |
| United States | Northern Virginia (us-east-1) | R2, North America | Applicable state privacy laws |
Within a region, data is replicated across availability zones for durability, and backups stay in the same jurisdiction as the primary database. Setting the R2 bucket jurisdiction restricts object storage to data centres inside that region.
Some processing crosses borders even when your database does not: push notifications go through Google's global messaging infrastructure, email through Resend, map tiles and geocoding through Google, and our engineers support you from where they are based. Those transfers are limited to what the feature requires.
- Out of India — the DPDP Act permits transfer to any country the Central Government has not restricted by notification. We monitor those notifications and will re-provision affected data if one is issued.
- Out of the United Kingdom — an adequacy regulation, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum.
- Out of the EEA — an adequacy decision or the EU Standard Contractual Clauses, with supplementary measures where needed.
- For any destination without equivalent protection we run a transfer risk assessment, and encryption in transit and at rest plus strict access control apply in every case.
08How long we keep it
| Category | Retention |
|---|---|
| Account and profile data | While the account is open, then up to 12 months |
| Tenancy, rent, deposit and payment records | India: 8 years (Companies Act 2013) and 6 years (GST Act) · UK: 6 years · US: as state and federal tax law requires |
| Identity check records | The statutory period applying to the operator, then deleted |
| Maintenance and complaint records | While the tenancy runs, then up to 6 years |
| Security and access logs | Up to 12 months |
| Diagnostic logs | Up to 90 days |
| Support correspondence | Up to 3 years after the matter is closed |
| Database backups | Rolling 35-day cycle, then overwritten |
| Files on Cloudflare R2 | Deleted with their parent record, subject to the retentions above |
What closing an account actually does
Dormingo's financial ledger is append-only by design, because an operator's rent history is their bookkeeping and has to stay trustworthy. So closing an account does not erase the books. It signs you out of every device, revokes every session, disables push notifications, and strips the personal details out of profiles and tenant records, leaving amounts and dates attached to nobody. The account is then marked closed.
A genuine erasure request — Article 17 GDPR, section 12(3) of the DPDP Act, or a US state deletion right — is answered by a separate audited purge, the only operation in our system able to delete ledger rows. It cannot be reached from the app or from any client. Ask at privacy@dormingo.app and we will run it, subject only to records the law requires us to keep, which are then held for that purpose alone and for the period above.
09How we protect it
- Encryption in transit (TLS 1.2+) and at rest (AES-256) for databases, backups and object storage.
- Row-level security in the database itself, so a request that should not see a row cannot see it even if the app has a bug. Permissions are granular and further restricted by a per-property allow-list.
- Passwords stored only as salted hashes — never in readable form, never visible to our staff.
- Sign-in tokens are short-lived; refresh tokens rotate on every use and are revoked immediately when a session ends or an account closes.
- On your device, tokens live in the iOS keychain or the Android keystore-backed store, never in ordinary preferences.
- File uploads use presigned URLs expiring in five minutes, scoped to a single object key derived from your session rather than from client input.
- Rate limiting on authentication endpoints; throttling of verification and password-reset email.
- Least-privilege internal access, granted only where needed, logged and reviewed. Regular dependency patching, code review and independent security testing.
If a breach happens
No system is perfectly secure. If a breach affects personal data we act on the timetable that applies:
- India — notification to the Data Protection Board and to every affected Data Principal without delay under the DPDP Act and its Rules. This duty has no risk threshold, so an Indian breach is reported even where a European one might not be. Incidents of the types listed in the CERT-In directions of 28 April 2022 are reported to CERT-In within six hours.
- UK & EEA — notification to the ICO or lead supervisory authority within 72 hours where the breach is likely to result in a risk to rights and freedoms, and to affected individuals without undue delay where the risk is high.
- United States — notification under the applicable state breach-notification statutes.
- Where we are the processor we notify the operator without undue delay so it can meet its own duties, and we help it do so.
Choose a strong, unique password and remove staff accounts promptly when people leave.
10Your rights · India
The Digital Personal Data Protection Act 2023 gives you these rights against the Data Fiduciary. For your Dormingo account, that is us. For resident records, that is the operator — we will assist them.
- Access — a summary of the personal data being processed, the processing activities undertaken, and the identities of other Data Fiduciaries and Processors it has been shared with.
- Correction, completion, updating and erasure — erasure must be granted unless retention is necessary for the specified purpose or for compliance with law.
- Grievance redressal — use our grievance mechanism before approaching the Board. Write to grievance@dormingo.app; we acknowledge within 48 hours and resolve within the period the DPDP Rules prescribe.
- Nomination — nominate another individual to exercise your rights if you die or become incapacitated. Send a nomination to privacy@dormingo.app.
- Withdraw consent at any time, as easily as it was given. Withdrawal does not affect processing already carried out; processing stops within a reasonable time afterwards.
Your duties under section 15 also apply: do not impersonate another person when giving personal data, do not suppress material information where the law requires it, do not register a false or frivolous grievance, and give only authentic information when seeking correction or erasure.
If our response does not satisfy you, complain to the Data Protection Board of India. The Information Technology Act 2000 and the SPDI Rules 2011 continue to apply to sensitive personal data alongside the DPDP Act; we maintain a documented security programme consistent with the "reasonable security practices" those rules require.
11Your rights · United Kingdom & Europe
Free to exercise. We respond within one month, extendable by two further months for complex requests, and we tell you if we extend.
- Access — confirmation of whether we hold your data, and a copy of it.
- Rectification — inaccurate data corrected, incomplete data completed.
- Erasure — deletion where no overriding reason to keep it exists.
- Restriction — processing paused while a dispute about accuracy or lawfulness is resolved.
- Portability — the data you gave us in a structured, commonly used, machine-readable format, transmitted to another provider where technically feasible.
- Objection — to processing based on legitimate interests, and to direct marketing at any time, which we always honour.
- Withdraw consent where consent is the basis, without affecting earlier processing.
- No solely automated decisions producing legal or similarly significant effects. We make none.
Write to privacy@dormingo.app. We may ask you to confirm your identity so we do not disclose data to the wrong person. You may complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113) or, in the EEA, to the supervisory authority where you live, work, or where the issue arose. We would appreciate the chance to resolve it first.
12Your rights · United States
State privacy laws now apply in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and elsewhere. Rather than check which state you are in, we extend all of the following to everyone in the United States.
- Know what personal information we collect, its sources, the purposes, and who we disclose it to.
- Copy — in a portable format where technically feasible.
- Correct inaccurate personal information.
- Delete, subject to exceptions such as completing a transaction, complying with a legal obligation, or detecting security incidents.
- Opt out of sale, sharing and targeted advertising. We do none of those, so there is nothing to opt out of.
- Limit use of sensitive personal information. We use it only to provide the Service you asked for.
- Opt out of profiling with legal or similarly significant effects. We do not profile.
- No discrimination for exercising a right — no denial of service, different price or lower quality.
- Appeal a refusal. Any refusal explains how; we answer an appeal within 45 days.
Write to privacy@dormingo.app with the subject "Privacy request". We confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 where reasonably necessary. An authorised agent may act for you with written permission we can verify.
US housing operators should note that the Fair Housing Act, the Fair Credit Reporting Act and state tenant-screening laws impose obligations on them, not on Dormingo. Dormingo performs no screening, scoring or adverse-action decisioning.
13Notifications and marketing
- Push notifications are optional. Control them in device settings; turning them off costs you no feature.
- Transactional email — verification, password reset, staff invitations, welcome messages — is essential to running an account and is not marketing.
- Service announcements about outages, security and significant changes go to account holders and cannot be switched off while the account is open, because you need them to use the Service safely.
- Marketing email is sent only with consent, carries a one-click unsubscribe in every message, and unsubscribing never affects your account. Where India's TCCCP Regulations apply to a message, we honour registered preferences and the required identifiers.
- We honour Global Privacy Control and similar browser opt-out signals on our website.
15Children's data
Dormingo is a business tool and is not directed at children. Accounts must be held by an adult, and we do not knowingly collect personal data from anyone under 18 for their own account.
Operators may record resident details for residents under 18 where lawful. In that case the operator carries the additional duties: verifiable parental consent, no tracking and no targeted advertising under section 9 of the DPDP Act, and the equivalent obligations under the UK and EU GDPR and COPPA. If you believe a child gave information directly to us, write to privacy@dormingo.app and we will delete it.
16App store disclosures
The Google Play Data Safety declaration and the Apple App Store privacy label for Dormingo describe the same collection and use as this policy. If you find a discrepancy, this policy is the accurate statement and we will correct the store listing — tell us at privacy@dormingo.app.
17Changes to this policy
We may update this policy as the Service or the law changes. The version and effective date always appear at the top of this page. For any change that materially affects your rights or how we use your information we will tell you in the app and by email at least 30 days before it takes effect, unless the law requires it sooner. Continuing to use the Service after the effective date means you accept the update. Superseded versions are available on request.
18Contact us
| Data Fiduciary / Controller | Dwellerin Network Pvt. Ltd. (trading as Dormingo) |
| Privacy and data rights | privacy@dormingo.app |
| Grievance Officer (India) | grievance@dormingo.app |
| Data Protection Officer (UK/EU) | dpo@dormingo.app |
| Security reports | security@dormingo.app |
| Support | support@dormingo.app |
We aim to acknowledge every message within two business days. For a request about your own data, include enough detail for us to find your records.