Our Position
AmityEdge Technologies Pvt. Ltd. is incorporated in India. DaaS is sold to and used by businesses in India, is billed in Indian Rupees, and stores its data in India. The regime we build to is India's Digital Personal Data Protection Act, 2023.
We do not currently market to, or target our services at, individuals in the EU or EEA. We have not appointed a Data Protection Officer or an Article 27 EU Representative, because on our present activities the GDPR does not require one. If that changes, for example if we take on EU Tenants or an EU establishment, we will appoint both and say so here before we do.
Controller and Processor
The Tenant is the Controller
The diet kitchen or nutrition practice decides why and how its clients’ data is processed. It obtains consent, answers data-subject requests, and decides retention.
AmityEdge is the Processor
We process client data only on the Tenant’s documented instructions. We do not use it for our own purposes, sell it, or use it to train machine-learning models.
AmityEdge is Controller for account data
For the Tenant’s own business, billing and enquiry data, AmityEdge determines the purposes and is the Controller.
Sub-processor changes
If we add or replace a sub-processor that handles client data, we will notify Tenants by email before the change takes effect.
Lawful Basis for Health Data
Health data is a special category of personal data under Article 9. The basis this platform actually relies on is Article 9(2)(a), explicit consent: the client ticks each declaration on the intake form, and we store the exact wording shown, whether it was accepted, and the IP address it was submitted from.
We do not rely on Article 9(2)(h) (health or social care management). That basis requires a professional bound by a statutory obligation of secrecy, which a diet kitchen is not. For ordinary contact and account data, the basis is Article 6(1)(b), performance of a contract, and Article 6(1)(f) legitimate interests for security logging and fraud prevention.
Your Rights
Where the GDPR applies, data subjects have rights of access, rectification, erasure, restriction, portability and objection, plus the right not to be subject to solely automated decisions with legal or similarly significant effects.
Sub-Processors
| Provider | Purpose | Receives client health data? |
|---|---|---|
| Supabase Inc. | Database, authentication, file storage | Yes |
| Vercel Inc. | Application hosting and delivery | In transit, during request processing |
| Razorpay | Tenant subscription billing (INR) | No |
| Resend, Inc. | Transactional email | No |
| Cloudflare, Inc. | Bot protection on public forms | No. IP address and challenge token only |
Data Processing Agreements with Supabase and Vercel are available on request. The “No” against Resend is enforced by an automated test that fails our build if a client name, contact detail or health answer is ever added to an outbound email.
International Transfers
Client and Tenant data is stored in India (AWS ap-south-1, Mumbai). Application hosting runs on Vercel's global network, so request and response data may transit servers outside India while a page is served; it is not stored there. We do not offer a choice of hosting region.
What We Have Not Built
Stated plainly, so that no one relies on something that does not exist:
- No appointed Data Protection Officer and no Article 27 EU Representative.
- No self-service data-subject request portal; requests are handled manually.
- No automated retention or erasure schedule yet, so we publish no retention table. Access logs are retained for a minimum of one year and cannot be altered within that period.
- No EU data-residency option.
- No cookie consent banner; we set only strictly necessary cookies and no trackers.
- Consents on the intake form are currently collected together rather than individually; separating them is scheduled work.
Contact
AmityEdge Technologies Pvt. Ltd., India
Privacy and data-subject requests: grievance@dietasaservice.com
Legal and contractual: legal@dietasaservice.com
If your data is held by a business using DaaS, contact that business first. They are the Controller for your record and can act on it directly.