SmartMy Garage SmartMy Garage
  1. Home
  2. Legal
  3. Privacy policy

Privacy policy

Draft. This text has not been reviewed by a lawyer yet and may change. The signed agreement with each customer takes precedence.

Last updated: 10 October 2026

This notice explains what personal data the SmartMy products and websites handle, why, with whom it is shared, how long it is kept, and what you can ask of us. It is written for everyone the products touch: the organisations that use SmartMy, their staff, and the students, parents, residents, guests, visitors, members and customers whose records those organisations keep.

1. Who we are

SmartMy is made by Hadoopt Technologies Private Limited, a company incorporated in India ("Hadoopt", "we", "us"). The SmartMy products are HRMS, Campus (schools and colleges), Placement, Hostel, Stay (PGs and co-living), Desk (helpdesk and maintenance), VMS (visitor management), Society (apartments), Events, Facility (facility booking), Transit (transport), Grievance, Feast (food service), POS (point of sale) and Garage, with their websites and mobile apps.

Contact for anything in this notice: Grievance Officer, Hadoopt Technologies Private Limited, [email protected].

2. Two roles: whose data is it?

The Digital Personal Data Protection Act, 2023 ("DPDP Act") separates the Data Fiduciary, who decides why and how personal data is used, from the Data Processor, who processes it on the fiduciary's behalf.

  • The organisation is in charge of its records. When a school, employer, hostel, PG, apartment society, office, caterer, garage or any other organisation uses SmartMy, it decides what to record about its people and why. It is the Data Fiduciary for that data, and we are its Data Processor: we keep and process the data only to run the service for it, under our agreement and our data processing addendum. If your record is kept by such an organisation (your employer, your child's school, your hostel or society), it is the organisation you should ask first about your data. It should also give you its own privacy notice.
  • We are in charge of our own data. For the data we collect for ourselves, we are the Data Fiduciary: our websites and contact forms, sign-up and trial details, billing and accounts of our customers, the account directory that lets our apps find your organisation's workspace (section 6), and the support conversations customers have with us.

3. What each product handles

Each organisation chooses which products and features to use, so a given organisation may hold less than the list below. This is what the products are able to record.

Common to all products

  • Users and people: name, photo (optional), e-mail, mobile number, the organisation, entity and role, sign-in history, device and app version, push-notification token, language and time zone.
  • Messages and notifications the organisation sends through the product (in-app, e-mail, push, and WhatsApp or SMS where it turns them on), with their delivery status.
  • Chat: messages between the people the organisation allows to chat (for example a parent and a class teacher), and reports of misuse.
  • Approvals, comments and the history of who changed what, kept as an audit trail.
  • Files the organisation uploads (documents, photos, attachments).

By product

4. Children's data

Campus, Hostel, Feast, Transit and Events are used by schools, hostels and caterers for people under 18. For children:

  • The organisation must obtain verifiable consent from a parent or lawful guardian before processing a child's data, except where the DPDP Act and its rules exempt it (for example an educational institution's attendance and safety duties). The products support this: parents sign in to their own account, consents are recorded with who, how and when, and a paper consent can be recorded by the office with its scan.
  • Parents see their child's records and act for the child in the apps.
  • We do not use children's data for advertising, profiling or behavioural monitoring, and do not let the products track a child beyond the service the organisation runs: a bus's location is shown to the parents of its riders only while a trip is running, and a gate entry is recorded at the gate, not followed elsewhere.
  • No AI feature reads a child's records (section 8).

5. Sensitive areas

Face recognition (optional)

Some organisations turn on face recognition for staff attendance, student attendance, hostel entry and exit, or meals at the counter.

  • Templates, not photos. From 3 to 5 photos taken at enrolment, the device makes a face template (128 numbers). The photos stay in the device's memory only while the template is made and are never stored or sent. The HRMS phone check sends a fresh template of that moment to the server, which compares it and keeps neither.
  • Consent first, purpose by purpose. No one is enrolled without consent for a named purpose, given in the app, at the device in person, or on paper recorded by the office; for a child, by a parent or guardian. Withdrawing is as easy as giving consent.
  • Enrolment is done by the organisation's office or at its own device, never by us.
  • Who can see it. No user, of the organisation or of Hadoopt, can read a template through the product; only the server process uses it. You can see what you agreed to and your own match history in the app.
  • Retention. A template is deleted at once when the last consent is withdrawn or "Remove face data" is used, when the person leaves (exit, leaving school, check-out), or after 12 months without a match (the organisation can change this). Match logs are kept 12 months. Devices keep templates in encrypted storage and wipe them after 7 days without a sync, at sign-out and when the device is blocked.
  • Google ML Kit. Face detection on the device uses Google's ML Kit. Pictures and results stay on the device, but ML Kit sends Google usage and performance metrics about the feature and may contact Google for model updates. The recognition model itself runs on the device and sends nothing.

Grievances and anonymous reports

Grievance reports are visible only to the committee or officers the organisation appoints for that kind of complaint, not to the organisation's other administrators; the statement is stored encrypted. Where the organisation allows anonymous reporting, the report is filed without any link to the reporter's account, even from a device where they are signed in: the reporter follows it with a code and a PIN that only they hold. A report by e-mail or telephone keeps the sender's address or number only if the organisation chose to keep them.

Employment, pay and identity numbers

Bank details, salary, payroll and identity numbers in HRMS are visible only to the HR and payroll roles the employer sets; an employee sees their own records.

Residents and visitors

Society, Hostel, Stay and VMS hold where people live and who visits them. Visitor photos and ID details are seen by the gate and the host or resident concerned and the organisation's administrators. Residents' contact numbers are shown to others only as the society allows.

6. What we collect for ourselves

This website. We do not run analytics on this site. It sets no advertising cookies and we do not sell or share visitor data for advertising. Our web servers keep a security log (IP address, browser, page) for 30 days.

We do not sell personal data, and we do not use it for advertising.

7. How the apps work with your data

  • You sign in with your organisation's account; the app asks the SmartMy directory which workspace your e-mail or mobile belongs to, then signs in to that workspace.
  • The apps ask for the camera only for scanning QR codes, taking a photo you choose, and face screens; for location only where a feature needs it (an attendance punch from the phone, a technician's site visit, a guard's patrol round, or a bus crew sharing the bus's position during a trip) and only while that screen is in use, never in the background; for notifications to deliver messages from your organisation.
  • Push notifications are delivered through Google Firebase Cloud Messaging and Apple Push Notification service. The notification text (for example that your child boarded the bus, or that a visitor is waiting) passes through them to reach your phone and may show on its lock screen; you can turn notifications off in the phone's settings.
  • Tokens that keep you signed in are stored in the phone's secure storage. Signing out removes them.
  • The apps carry no advertising and no third-party analytics or tracking SDKs. Google ML Kit's metrics (section 5) are the only data an SDK sends on its own.

8. AI features

Some products offer AI help, through our own gateway to Google's Gemini service: reading a résumé into a candidate profile and matching it to a job (HRMS), sorting and summarising a helpdesk ticket and suggesting a reply (Desk), and answering questions about how to use the product from the user manual (all products).

  • What is sent: only what that one request needs: the résumé of that candidate; the ticket's text and conversation (e-mail addresses and phone numbers removed); the question typed. No AI feature reads students' or children's records, face templates, photos of people, identity numbers, bank or salary data, or grievance reports. Please do not type such details into a question to the help assistant.
  • Consent: a résumé is sent only for a candidate who gave consent when applying or whose consent the recruiter recorded.
  • Not used for training: we use Gemini under Google's paid terms, under which prompts and answers are not used to train Google's models. Our gateway does not store what is sent or answered; it keeps a count of use for billing (section 6).
  • Your organisation decides: AI is off until the organisation switches it on, product by product, and for each person who may use it. It can switch it off at any time.

9. Service providers we use

We use the following providers to run the service. Each is bound by a contract to use the data only for the service it provides to us. Some are used only if the organisation turns on the feature that needs them.

Some services are chosen and contracted by the organisation itself, not by us, and work under its own terms: its own e-mail server, its GPS tracking server (Traccar) and route planner, the telephony provider of a grievance hotline, background-verification agencies an employer sends cases to, and the booking channels (iCal calendars) of a hostel or PG.

10. Where your data is stored

Data may be stored and processed in India or in other countries where we or our providers operate, chosen for reliability and cost. It is never transferred to a country to which the Government of India has restricted transfers under section 16 of the DPDP Act (none has been notified as of the date of this notice). The same safeguards in this notice apply wherever it is kept, and we tell our customers before their data is moved to another country.

We store no card data. Online payments are handled by Razorpay or Stripe, which keep payment data as the Reserve Bank of India requires.

11. How we protect it

  • Encryption in transit (HTTPS/TLS) for every website, portal, app and connection between services.
  • Encryption at rest of server disks, databases, file storage and backups.
  • One database per organisation, so one customer's data never mixes with another's.
  • Roles: inside each workspace, people see only what their role allows.
  • Logs: sign-ins, approvals and changes to records are logged.
  • Backups, encrypted, with restore tests.
  • Support access only on request: our staff look at an organisation's data only when it asks for help with a specific request, only for that request, and every access is logged.
  • Face templates are readable by no user (section 5).

If a breach of personal data happens, we inform the organisation concerned at once, and the Data Protection Board of India and the people affected as the DPDP Act requires.

12. How long data is kept

  • Organisation data is kept while the organisation uses the product and decides to keep it. Some data is deleted automatically, on periods the organisation can change: visitor photos and ID images (180 days), GPS positions of vehicles (90 days), trip-checklist photos (180 days), face templates (12 months without use) and their match logs (12 months), help-assistant conversations (90 days), one-time codes (minutes).
  • When a product is given up, its data is deleted 30 days later. When an organisation leaves, its whole workspace is deleted 30 days after the end. Copies in our backups expire within a further 35 days.
  • Our own data: as in the table in section 6.

13. Your rights

Under the DPDP Act you may:

  • know what personal data is processed about you and with whom it has been shared;
  • correct, complete or update it;
  • have it erased when it is no longer needed for the purpose, or when you withdraw consent, unless the law requires it to be kept;
  • withdraw consent at any time, as easily as you gave it (this does not undo what was done before);
  • nominate another person to exercise your rights if you die or become unable to;
  • have a grievance redressed.

How to use them. If your data is in an organisation's SmartMy workspace (your employer, school, hostel, society, caterer, garage), ask that organisation: it is the Data Fiduciary, and the products give it the tools to answer you. Many of these you can do yourself in the app (your profile, your consents, withdrawing face recognition). If the organisation asks us, we help it. For data we hold for ourselves (section 6), write to our Grievance Officer. We reply within 30 days.

14. Grievance Officer and complaints

Grievance Officer, Hadoopt Technologies Private Limited · [email protected]

If you are not satisfied with our answer, you may complain to the Data Protection Board of India under the DPDP Act, after first using our grievance process.

15. Changes to this notice

We will publish any change on this page with a new date. If a change affects how we use data we hold for ourselves, we will tell the people concerned before it takes effect; customers are told as the data processing addendum says.