Which Law Applies
AmityEdge Technologies Pvt. Ltd. is incorporated in India and operates DaaS for diet kitchens and nutrition practices in India. The binding regime for personal data on this platform is the Digital Personal Data Protection Act, 2023 (DPDP) and the Digital Personal Data Protection Rules, 2025.
The DPDP Rules take effect in stages. Consent Manager registration opens on 13 November 2026, and the remaining obligations, covering consent notices, Data Principal rights, breach notification and Significant Data Fiduciary duties, apply from 13 May 2027. We are building toward that date and this page will state our position honestly as each control ships.
Who Is Responsible for What
The Tenant is the Data Fiduciary
The diet kitchen or nutrition practice decides why and how its clients’ data is collected and used. It is responsible for obtaining consent, answering its clients’ requests, and deciding when a record is deleted.
AmityEdge is the Data Processor
We store and process client data on the Tenant’s instructions. We do not use client health data for our own purposes, we do not sell it, and we do not use it to train machine-learning models.
AmityEdge is a Data Fiduciary for account data
For the Tenant’s own account, billing and enquiry data, meaning the business owner’s name, email, phone and payment records, AmityEdge is the Data Fiduciary.
The client is the Data Principal
The individual whose health data is on the platform holds the rights described below. Clients do not have accounts on DaaS; they interact through public forms and links.
What We Process, and On What Basis
When a client submits the intake questionnaire, we record each consent separately, storing the exact wording shown on screen, whether it was given, and the IP address it was given from. These are the five statements presented today:
The categories collected are: contact and identity details; date of birth; body measurements; medical history (including diabetes, hypertension, thyroid, PCOS/PCOD, cardiac, kidney, liver, gastrointestinal and mental-health answers); medications, allergies and past surgeries; dietary and lifestyle habits; nutrition goals and food preferences; and optionally a profile photograph.
The third of these, consent to be contacted about services and offers, is optional. It is a separate purpose from providing the service, so declining it does not stop you signing up, and your answer is recorded either way: we store “said no” rather than simply storing nothing. The other four are necessary to provide the service and are required.
Security Safeguards
The following are implemented in the platform today. We have deliberately not listed controls we intend to build.
Field-level encryption of free-text medical answers
AES-256-GCM encryption at rest, applied before storage, to past surgeries, current medications, allergies, food preferences and dislikes, and cravings/emotional-eating notes. The structured Yes/No condition answers are stored unencrypted so they remain filterable; they are protected by the database access controls below, not by field encryption.
Tenant isolation enforced by the database
PostgreSQL Row-Level Security scopes every tenant table to the Tenant that owns it, resolved from the signed-in user rather than from anything the browser sends. Anonymous database access to tenant tables is revoked outright; public forms are written by a server-side service account only.
Privileged fields are not self-editable
A user’s role, tenant, branch and account status can only be changed by a server-side administrative operation, enforced by column-level database grants plus a trigger, not by application code alone.
Private storage for profile photographs
Photographs are held in a private bucket with no public URL and no direct browser access. Staff views are served through a signed link that expires after ten minutes.
Health-record access is logged
Opening a client or lead health record writes an audit entry recording who accessed it, which record, when, and from which IP address.
Public forms are protected against automated abuse
Cloudflare Turnstile challenges plus server-side, database-backed rate limiting and payload size caps on every public submission endpoint.
Transport and browser hardening
TLS for all traffic, HSTS with a two-year max-age and preload, X-Frame-Options, X-Content-Type-Options: nosniff, a strict Referrer-Policy, and a Permissions-Policy denying camera, microphone and geolocation. Session tokens are held in httpOnly, Secure cookies that JavaScript cannot read.
Idle session timeout
Staff sessions are signed out automatically after a period of inactivity.
Sub-Processors
These providers process data on our behalf. Each is bound by its own data processing terms.
| Provider | Purpose | Receives health data? |
|---|---|---|
| Supabase Inc. | Database, authentication, file storage | Yes |
| Vercel Inc. | Application hosting and delivery | In transit, during request processing |
| Vercel AI Gateway and the connected model provider | Drafting a diet plan for your nutritionist to review | Partly, see the note below |
| Razorpay | Tenant subscription billing (INR) | No. Tenant business and payment data only |
| Resend, Inc. | Transactional email | No |
| Cloudflare, Inc. | Bot protection on public forms | No. IP address and challenge token only |
The “No” against Resend is enforced in code, not just by policy: notification emails carry counts and links only, never a client name, contact detail or health answer, and an automated test in our build pipeline fails if that ever stops being true. Open and click tracking are disabled, so no tracking pixels are embedded.
Your Rights as a Data Principal
Under the DPDP Act you have the following rights over your personal data. Because your data is held by the Tenant you deal with, requests are fulfilled by that Tenant; we provide them the means to do so and will assist where needed.
Right to access
A summary of the personal data we hold about you and how it has been processed.
Right to correction and completion
Correction of inaccurate data, completion of incomplete data, and updating of data that has changed.
Right to erasure
Deletion of your personal data, unless it must be retained to comply with a legal obligation.
Right to grievance redressal
A readily available way to raise a complaint, answered by the Grievance Officer below.
Right to nominate
Nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
Children's Data
The DPDP Act requires verifiable parental consent before processing the personal data of anyone under 18, and prohibits tracking, behavioural monitoring and targeted advertising directed at children.
When the date of birth entered on the intake form is under 18, the form requires a parent or guardian's name and contact number before it can be submitted, and records their consent as its own auditable entry alongside the others. We do not carry out behavioural tracking or targeted advertising on any client, of any age.
Breach Notification
A personal data breach is any unauthorised or accidental compromise of the confidentiality, integrity or availability of personal data. We maintain a written incident runbook with named owners, and on becoming aware of a breach affecting data on this platform AmityEdge will:
- Contain the incident and determine which Tenants and Data Principals are affected.
- Notify the affected Tenants without delay, with the facts they need to act.
- Support notification of the Data Protection Board of India and the affected Data Principals without delay, followed by a detailed report to the Board within 72 hours.
As Data Fiduciary, the Tenant makes the notification to its own clients; as Processor we provide the underlying facts and act on the Tenant's instructions.
Retention
Data is retained for as long as the Tenant maintains the client relationship and its account with us. Health-record access logs are retained for a minimum of one year and cannot be altered or deleted within that period.
HIPAA & US Customers
HIPAA applies to US Covered Entities, meaning health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically in connection with covered transactions, and to the Business Associates who handle Protected Health Information on their behalf.
DaaS today serves Indian diet kitchens and nutrition practices, bills in Indian Rupees, and has no US Covered Entity customers. We therefore neither claim HIPAA compliance nor offer a Business Associate Agreement as a standard term, and we ask that Protected Health Information subject to HIPAA is not stored on the platform without a prior written agreement.
Grievance Officer
The DPDP Act requires every Data Fiduciary to publish the contact details of a person who answers questions about the processing of personal data. For AmityEdge:
Grievance Officer, AmityEdge Technologies Pvt. Ltd.
Email: grievance@dietasaservice.com
Legal and contractual: legal@dietasaservice.com
We acknowledge grievances within 2 business days and aim to resolve them within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
If your data is held by a Tenant using DaaS, please contact that business first. They are the Data Fiduciary for your record and can act on it directly.