Privacy Policy
Your privacy matters to us. This policy explains how we collect, use, and protect personal data when you use the Nandy website and platform, in line with Indian law.
Last Updated: 2026-07-12
Introduction
Nandy is the AI-native operating system for housing societies, operated by Lexifyr Technologies Pvt. Ltd. ("Nandy," "we," "us," or "our"). This Privacy Policy describes how we collect, use, share, and protect personal data when you visit nandyai.com (the "Site") or use the Nandy platform (the "Services").
We process personal data as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), read with the Information Technology Act, 2000 and applicable rules. Where we process data on the documented instructions of a housing society (for example, resident records the society's committee uploads), we act as a Data Processor on that society's behalf.
Information We Collect
Account and committee information. When a society signs up, we collect the names, email addresses, phone numbers, and roles of committee members and administrators.
Society and resident records. To run the Services we process the society's flat list, occupancy details, resident names and contact details, dues and billing history, notices, and bookings, as provided by the society's committee or by residents who claim their flats.
Payment and reconciliation data. Nandy Reconcile processes records of maintenance payments, including UPI transaction references, cheque details, and bank statement entries that the society uploads or connects, so that each payment can be matched to the right flat and bill. We do not store your full bank account credentials or card numbers.
Visitor and gate records. Where a society uses gate management, we process visitor names, phone numbers, photographs captured at the gate, and entry/exit logs, on behalf of that society.
Support and communications. If you contact us through the Site's contact form, by email, or in-app, we collect your name, email address, society name, and the contents of your message.
Technical information. Our servers log standard request metadata (IP address, user agent, timestamp, referring URL) for security and operational purposes for a limited period. We do not currently run third-party advertising pixels or cross-site trackers on the Site.
How We Use Information
We use personal data for the following purposes:
- Providing the Services: reconciling payments, maintaining committee-grade books, generating statements and reports, publishing notices, managing bookings, and answering residents' questions through the Nandy AI Assistant;
- Gate and visitor management: pre-approvals, entry logs, and real-time arrival alerts for the society that enabled them;
- Support and communication: responding to enquiries, onboarding societies, and sending service-related notifications;
- Security and integrity: authenticating users, scoping access by role, detecting fraud or abuse, and maintaining audit logs;
- Legal compliance: meeting our obligations under applicable law, including tax, accounting, and cooperative housing regulations.
We do not use your personal data for third-party advertising, and we do not sell personal data.
Consent & Legal Basis
Under the DPDP Act we process personal data on the basis of consent, or for certain legitimate uses recognised by the Act, for example where you voluntarily provide data for a specified purpose, or where processing is required to comply with law or a court order.
Where consent is the basis, it is requested in clear and plain language, and you may withdraw it at any time with effect for the future. Withdrawing consent may mean parts of the Services no longer work for you. For instance, we cannot send arrival alerts without processing your contact details.
Where a society's committee provides residents' data, the committee is responsible for ensuring it is entitled to share that data with us for the operation of the society's account.
Data Security
We take reasonable security safeguards as required by Section 8 of the DPDP Act to prevent personal data breaches. Your data is encrypted in transit and at rest, access is scoped to your society and to each user's role, and administrative actions are logged.
In the event of a personal data breach affecting you, we will notify the Data Protection Board of India and affected Data Principals in the form and manner prescribed under the DPDP Act and its rules.
No method of transmission or storage is completely secure; where we rely on third-party infrastructure, we choose providers with strong, independently audited security practices.
Data Retention
We retain personal data only for as long as it is needed for the purposes described in this policy: for the duration of your society's account, and thereafter for the period required by applicable law, such as statutory retention periods for books of account and society records.
When data is no longer required and no legal obligation requires us to keep it, we erase it or irreversibly anonymise it. Societies can export their books at any time before closing their account.
Your Rights
As a Data Principal under the DPDP Act, you have the right to:
- Access: obtain a summary of the personal data we process about you and the processing activities undertaken;
- Correction and erasure: have inaccurate or misleading data corrected, incomplete data completed, and data that is no longer necessary erased;
- Grievance redressal: have a readily available means to register a grievance and receive a timely response (see below);
- Nominate: nominate another individual to exercise your rights in the event of death or incapacity;
- Withdraw consent: withdraw previously given consent at any time, with effect for the future.
To exercise any of these rights, email us at [email protected] with the subject line "Privacy Request", from the email address associated with your account. We will verify your identity before acting on the request. Where your data was provided by your society's committee, we may route the request through the committee where the DPDP Act requires it.
Grievance Redressal
If you have a concern about how your personal data is handled, contact our Grievance Officer:
Grievance Officer
Lexifyr Technologies Pvt. Ltd.
Email: [email protected] (subject line "Grievance")
We acknowledge grievances promptly and aim to resolve them within the timelines prescribed under the DPDP Act and applicable rules. If you are not satisfied with our response, you may approach the Data Protection Board of India.
Children's Data
The Site and Services are intended for adults and are not directed at children. We do not knowingly process the personal data of a child (an individual under 18 years of age) except as part of a society's resident records provided by the society with verifiable parental consent, as required by Section 9 of the DPDP Act.
We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child's data has been provided to us improperly, contact us and we will delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page, and for material changes we will notify you through the Site, the platform, or by email.
Your continued use of the Site or Services after an updated policy takes effect constitutes acceptance of the updated policy, to the extent permitted by law.
Contact Us
If you have questions about this Privacy Policy or our data practices, contact us:
Lexifyr Technologies Pvt. Ltd.
Email: [email protected]