Data protection

Privacy Policy

Effective date: 29 July 2026 · Applies to the CommCorner mobile application (Android & iOS) and this website · Governed by Indian law, including the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000

1. Who we are

Aarvin Ventures ("we", "us", "our") is the Data Fiduciary responsible for personal data processed through CommCorner, a community operations mobile application used by residential societies and gated communities. This policy explains what we collect, why, and what rights you have over it, whether you use CommCorner as a Resident, a Super Admin, or a prospective resident submitting an access request.

2. Personal data we collect

CommCorner is designed to collect only what is operationally necessary to run staff attendance, gate security, facility operations, and task management for a residential community.

CategoryExamplesCollected from
Identity & accountPhone number, name, role (Super Admin / Resident), device identifiers used for session trustYou, at registration / access request
Authentication metadataDevice-trust status, session and token metadata (never the token itself, once expired)Automatically, on login
Staff & attendance recordsStaff names, categories/zones, attendance marks, edit history and who made each changeEntered by Residents / Super Admins
Gate & visitor dataVisitor name, purpose of visit, unit/flat being visited, pre-approval and blacklist entriesEntered by Residents / gate/security staff
Facility operations dataDG/EB/water meter readings, occupancy counts, CCTV status, operational notes — generally not personal data, but logged with the staff member who recorded itEntered by facility staff / admins
Notification dataPush notification tokens (FCM / APNs), read/unread status of notificationsAutomatically, from your device

We do not collect passwords — CommCorner has no password field anywhere in the system.

3. Why we process it

  • To authenticate you and maintain per-device session security (phone-number identity, device trust).
  • To operate the features you or your community's Super Admin use: attendance marking, gate/visitor approvals, facility operations logging, and task tracking.
  • To maintain an accurate, timestamped audit trail for attendance and gate decisions, as required for dispute resolution and operational accountability.
  • To send you push and in-app notifications relevant to your role.
  • To detect and prevent misuse, fraud, or unauthorized access (e.g. blacklist checks, rate limiting, device-trust enforcement).
  • To generate daily and monthly reports for your community's administrators.

4. Legal basis for processing

Under the Digital Personal Data Protection Act, 2023, we process your personal data on the basis of: (a) your consent, given when you register, submit an access request, or are added to a community by your Super Admin; and (b) legitimate operational use reasonably expected within a community-management relationship, such as maintaining attendance and security audit trails. You may withdraw consent at any time by contacting us, subject to the effect this may have on your ability to use the service (see Section 8).

5. Who we share data with

We do not sell personal data. Data is shared only as follows:

  • Within your own community: your community's Super Admin can see data within their administrative scope (e.g. attendance, gate requests) as part of the service's core function.
  • Infrastructure & hosting providers: our backend (Django REST Framework + PostgreSQL) runs on third-party cloud infrastructure that stores data on our behalf, under contractual confidentiality obligations.
  • Push notification providers: Google Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS), solely to deliver notifications to your device.
  • Legal requirements: where required by law, regulation, or a valid order from a competent Indian authority.

6. Data retention

Account and profile data is retained while your account remains active. Attendance and gate-approval audit records are retained for as long as your community's Super Admin maintains the account, to preserve the integrity of the audit trail, and are deleted or anonymised on verified deletion requests where retention is not otherwise required by law. You may request deletion of your personal data at any time (see Section 8), subject to records your community is legally required to retain.

7. How we secure your data

CommCorner is built with security as a first-class concern, not an afterthought:

  • Passwordless authentication — phone number + per-device trust, removing an entire class of password-related risk.
  • Per-device session trust — a new device must be approved by your community's Super Admin before it can access account data.
  • Short-lived JWT access tokens (15 minutes) and refresh tokens (30 days), validated against live session and device state on every request.
  • Sensitive credentials on the mobile app are stored in the device's secure enclave (iOS Keychain / Android Keystore), never in plain local storage.
  • Full audit logging of authentication events and attendance/gate mutations.
  • Rate limiting and structured logging on the backend to detect anomalous access patterns.

8. Your rights

As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the right to:

  • Access a summary of the personal data we hold about you.
  • Correct or update inaccurate or incomplete personal data.
  • Erase personal data that is no longer necessary for the purpose it was collected, subject to your community's legitimate recordkeeping needs.
  • Withdraw consent at any time, understanding this may limit or end your ability to use CommCorner.
  • Nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
  • Grievance redressal through our Grievance Officer (Section 13) before escalating to the Data Protection Board of India.

To exercise any of these rights, email sannagiriraviteja@gmail.com from your registered contact details. We will respond within a reasonable time and in any case within the period prescribed by applicable law.

9. Children's data

CommCorner is intended for use by adult residents and administrators (18 years or older). We do not knowingly collect personal data directly from children. Staff or dependent records entered by an adult Resident or Super Admin are the responsibility of the person who enters them.

10. Cross-border data transfer

Where our infrastructure or service providers (including push notification services) process data outside India, we take reasonable steps to ensure such processing is subject to equivalent safeguards, consistent with the Digital Personal Data Protection Act, 2023 and applicable rules.

11. Cookies & tracking on this website

This marketing website stores a single local preference (light/dark theme choice) in your browser's local storage. It does not use tracking cookies, third-party advertising pixels, or analytics scripts that identify you personally.

12. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or legal obligations. Material changes will be notified within the CommCorner app or via the contact details on your account. The "Effective date" above reflects the latest revision.

This policy is written to reflect CommCorner's actual data flows as implemented (passwordless phone-number + device-trust auth, attendance/gate/facility modules). If you significantly change what the app collects or how it's processed, this document should be reviewed and updated to match before publishing an update.

13. Grievance Officer & contact

In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, our Grievance Officer is:

Sannagiri Raviteja
Aarvin Ventures
Villa 24, Plot No 24, Affluence Villas, Haris Pranava Township, Manneguda, 501510, RangaReddy, Telangana, India
Email: sannagiriraviteja@gmail.com