Onehub Innovations determines why and how personal data is processed for Ente Karyasthan services. This notice is designed to align with applicable Indian privacy and information-technology law, including the staged implementation of the Digital Personal Data Protection Act, 2023 and Rules, 2025.
This notice should be read with the relevant service agreement and any just-in-time notice shown when sensitive property, identity or payment information is requested.
1. Data we collect
- Identity, account, contact, communication and verification information.
- Property, ownership, occupancy, access, service, maintenance, tenant and authorised-representative information.
- Quotations, approvals, invoices, tax records, transaction references, refunds and loyalty records. Card or banking credentials are handled by approved payment providers; we do not intentionally store complete card credentials.
- Photographs, videos, inspection notes, documents, support conversations and incident reports necessary for the agreed service.
- Device, IP address, login, security, cookie, consent and website-use records.
- Staff, applicant, vendor and deployed-personnel information needed for identity, HR, assignment, safety, attendance and compliance.
2. How we obtain and use data
We obtain data from you, authorised representatives, property owners or occupants, our personnel, service partners, payment providers and lawful public sources. We use it to respond to enquiries, verify authority, deliver and document services, provide access, process payments/refunds, prevent fraud, maintain security, resolve complaints, comply with law, improve operations and communicate service information.
Where consent is the applicable basis, you may withdraw it through the same or an equally practical written channel. Withdrawal is prospective and does not invalidate prior lawful processing or records that must be retained.
3. Sharing and processors
We share only what is reasonably necessary with assigned personnel, vendors, property stakeholders authorised for that property, cloud/hosting providers, communications providers, payment gateways, accountants, auditors, insurers, professional advisers and authorities acting lawfully.
We do not sell personal data. A service provider may process data only for its assigned function, subject to applicable contractual and legal safeguards.
4. Retention
Enquiry records are normally retained while they remain actionable and for up to three years thereafter for service history, fraud prevention and dispute handling. Contract, invoice, tax and accounting records may be retained for at least the legally required period, commonly up to eight financial years where applicable. Verification, property, incident and access records are kept only as long as reasonably necessary for the engagement, safety, claims and legal obligations.
When retention is no longer necessary, data is deleted, anonymised or securely isolated, subject to backup rotation and lawful holds.
5. Security and access control
We use role-based access, property-level authorisation, authentication, audit records, restricted administrative controls, vendor controls and reasonable technical/organisational safeguards. No internet or storage system is guaranteed to be completely secure; suspected incidents should be reported immediately.
6. Your requests
Subject to applicable law and identity verification, you may request access to a summary of data, correction, completion, updating, erasure where retention is not required, withdrawal of consent, and grievance review. Requests may be refused or limited where another person's rights, security, fraud prevention, legal privilege, statutory retention or lawful claims require it.
7. Children and third-party data
Our services are not directed to children for independent purchase. A parent, lawful guardian or authorised adult must provide and manage any child-related information. If you provide another person's data, you confirm that you have authority and have given them appropriate notice.
8. Cookies and external services
Essential cookies may support login, security, preferences and transactions. Analytics or external integrations, if enabled, may have separate notices. Links to third-party services are governed by their policies.
9. Contact and grievance
Send privacy requests to grievance@entekaryasthan.com with the subject Privacy Request. Include enough information to identify the relevant account or service, but do not email passwords, OTPs or complete payment credentials.
Important: These policies are operational legal documents, not a substitute for advice on a specific dispute. Mandatory rights and duties under applicable law prevail over any inconsistent wording.