EU/EEA

GDPR

DaaS is an India-based service for Indian diet kitchens and nutrition practices. This page states honestly where we stand in relation to the GDPR.

Effective date: August 14, 2026|AmityEdge Technologies Pvt. Ltd.

Our Position

AmityEdge Technologies Pvt. Ltd. is incorporated in India. DaaS is sold to and used by businesses in India, is billed in Indian Rupees, and stores its data in India. The regime we build to is India's Digital Personal Data Protection Act, 2023.

We do not currently market to, or target our services at, individuals in the EU or EEA. We have not appointed a Data Protection Officer or an Article 27 EU Representative, because on our present activities the GDPR does not require one. If that changes, for example if we take on EU Tenants or an EU establishment, we will appoint both and say so here before we do.

Many of the GDPR's substantive requirements and the DPDP Act's overlap closely: purpose limitation, explicit consent for health data, data-subject rights, breach notification, and security safeguards. The controls described on our Data Protection page are built to satisfy both, and an EU/EEA individual whose data ends up here gets the benefit of them regardless of whether the GDPR technically applies.

Controller and Processor

The Tenant is the Controller

The diet kitchen or nutrition practice decides why and how its clients’ data is processed. It obtains consent, answers data-subject requests, and decides retention.

AmityEdge is the Processor

We process client data only on the Tenant’s documented instructions. We do not use it for our own purposes, sell it, or use it to train machine-learning models.

AmityEdge is Controller for account data

For the Tenant’s own business, billing and enquiry data, AmityEdge determines the purposes and is the Controller.

Sub-processor changes

If we add or replace a sub-processor that handles client data, we will notify Tenants by email before the change takes effect.

Lawful Basis for Health Data

Health data is a special category of personal data under Article 9. The basis this platform actually relies on is Article 9(2)(a), explicit consent: the client ticks each declaration on the intake form, and we store the exact wording shown, whether it was accepted, and the IP address it was submitted from.

We do not rely on Article 9(2)(h) (health or social care management). That basis requires a professional bound by a statutory obligation of secrecy, which a diet kitchen is not. For ordinary contact and account data, the basis is Article 6(1)(b), performance of a contract, and Article 6(1)(f) legitimate interests for security logging and fraud prevention.

Your Rights

Where the GDPR applies, data subjects have rights of access, rectification, erasure, restriction, portability and objection, plus the right not to be subject to solely automated decisions with legal or similarly significant effects.

How these are handled today: requests are fulfilled by your Tenant, who is the Controller. There is no self-service portal yet. Write to your Tenant, or to the address below and we will route it. We aim to respond within 30 days. We do not carry out profiling or automated decision-making that produces legal effects; any nutrition plan drafted with software assistance is reviewed and approved by a qualified human before it reaches a client.

Sub-Processors

ProviderPurposeReceives client health data?
Supabase Inc.Database, authentication, file storageYes
Vercel Inc.Application hosting and deliveryIn transit, during request processing
RazorpayTenant subscription billing (INR)No
Resend, Inc.Transactional emailNo
Cloudflare, Inc.Bot protection on public formsNo. IP address and challenge token only

Data Processing Agreements with Supabase and Vercel are available on request. The “No” against Resend is enforced by an automated test that fails our build if a client name, contact detail or health answer is ever added to an outbound email.

International Transfers

Client and Tenant data is stored in India (AWS ap-south-1, Mumbai). Application hosting runs on Vercel's global network, so request and response data may transit servers outside India while a page is served; it is not stored there. We do not offer a choice of hosting region.

What We Have Not Built

Stated plainly, so that no one relies on something that does not exist:

  • No appointed Data Protection Officer and no Article 27 EU Representative.
  • No self-service data-subject request portal; requests are handled manually.
  • No automated retention or erasure schedule yet, so we publish no retention table. Access logs are retained for a minimum of one year and cannot be altered within that period.
  • No EU data-residency option.
  • No cookie consent banner; we set only strictly necessary cookies and no trackers.
  • Consents on the intake form are currently collected together rather than individually; separating them is scheduled work.

Contact

AmityEdge Technologies Pvt. Ltd., India

Privacy and data-subject requests: grievance@dietasaservice.com

Legal and contractual: legal@dietasaservice.com

If your data is held by a business using DaaS, contact that business first. They are the Controller for your record and can act on it directly.