Skip to content

Data Processing Agreement

The terms under which RentJinie processes personal data on behalf of your business — scope, security, sub-processors, breach notification and deletion.

Last updated

When you use RentJinie to store information about your own customers, you decide why and how that data is processed. In the language of the Digital Personal Data Protection Act, 2023 you are the Data Fiduciary and we are your Data Processor.

This Data Processing Agreement (DPA) sets out how we handle that data. It forms part of our Terms & Conditions and applies automatically to every account — you do not need to sign a separate copy, though we are happy to execute one on request.

1. Scope and roles

You (Data Fiduciary)
Determine what customer data you collect, why you collect it, how long you keep it, and the lawful basis for it. You are responsible for giving your customers any notice and obtaining any consent required.
Us (Data Processor)
Process that data only to provide the Service, on your documented instructions — which include your configuration of the platform and your use of its features.

2. What we process

The categories are determined by you, but in normal use include: your customers' names, phone numbers, addresses, ID-proof documents you choose to capture, their rental history, outstanding dues and payment records.

The data subjects are your customers and your staff. Processing lasts for as long as your account is active, plus the retention period below.

3. Our obligations

  • Process personal data only for the purpose of providing the Service, and only on your instructions.
  • Not sell personal data, and not use it for our own unrelated purposes or for advertising.
  • Ensure our personnel with access are bound by confidentiality and are trained on their obligations.
  • Apply appropriate technical and organisational security measures — see below.
  • Assist you, so far as reasonably practicable, in responding to data-principal requests and to regulators.
  • Tell you without undue delay if we become aware of a personal data breach affecting your data.

4. Security measures

  • Encryption of data in transit using current TLS.
  • Passwords stored using a strong one-way hash, never in recoverable form.
  • Multi-tenant isolation, so one organisation cannot read another's records.
  • Role-based access control within your organisation — owner, manager and staff.
  • Access to production systems limited to authorised personnel on a need-to-know basis, with logging.
  • Regular backups, and restoration procedures that are tested.

5. Sub-processors

We use a small number of sub-processors — principally infrastructure hosting, storage, and transactional email and notification delivery — to run the Service. Each is bound by written terms no less protective than this DPA.

You consent to our use of sub-processors. We will give you notice before adding a new one, and you may object on reasonable data-protection grounds; if we cannot resolve your objection you may terminate the affected part of the Service. A current list is available on request.

6. International transfers

Where personal data is processed outside India, we do so only in jurisdictions not restricted by the Government of India, and under contractual safeguards requiring protection equivalent to that provided here.

7. Data-principal requests

If one of your customers contacts us directly to access, correct or erase their data, we will not respond substantively. We will refer them to you and tell you promptly, because you are the fiduciary for that relationship.

The platform's own features — editing and deleting customer records, and exporting data — are the primary way you fulfil such requests.

8. Breach notification

If we become aware of a personal data breach affecting data we process for you, we will notify you without undue delay with the information we have: what happened, the categories and approximate volume of data affected, the likely consequences and the steps we are taking.

We will assist you in meeting your own notification obligations to affected individuals and to the Data Protection Board of India.

9. Audit

On reasonable written notice, and no more than once a year unless required by a regulator, we will provide the information reasonably necessary to demonstrate our compliance with this DPA. We may satisfy this through documentation and written responses rather than on-site access, to protect the security of other customers.

10. Return and deletion

You can export your data at any time while your account is active, and we recommend you do so before closing it.

After termination we retain your data for a limited grace period so it can be restored or exported, then delete or irreversibly anonymise it — except where law requires us to keep it longer, in which case we continue to protect it under this DPA for as long as we hold it.

11. Liability and precedence

Liability under this DPA is subject to the limitations in our Terms & Conditions. Where this DPA conflicts with those Terms on the processing of personal data, this DPA prevails.