Overview
DaaS is operated by AmityEdge Technologies Pvt. Ltd.(“AmityEdge”, “we”, “us”). We provide a multi-tenant SaaS platform that allows diet and wellness businesses (“Tenants”) to manage their operations, clients, diet plans, and analytics on shared infrastructure.
This Privacy Policy applies to all users of DaaS, including Tenant administrators, branch staff, and end clients who access a Tenant's client portal. It describes our practices for collecting, using, storing, sharing, and protecting personal data.
Data We Collect
We collect different categories of data depending on your role:
Tenant Account Data
- Full name, business name, email address, phone number
- Business address and jurisdiction
- Subscription plan and billing information (processed by our payment provider)
- Branch and staff structure
Client Health Data (PHI)
- Full name, date of birth, gender, contact details
- Physical measurements: height, weight, BMI, body composition
- Medical history, conditions, and dietary restrictions
- Assigned diet plans, meal logs, and nutritional targets
- Progress records, consultant notes, and activity logs
Usage & Technical Data
- IP addresses, browser and device type, operating system
- Pages accessed, features used, session duration and frequency
- Authentication events: logins, logouts, failed attempts
- API request logs processed through Vercel's serverless infrastructure
Enquiry & Communication Data
- Enquiry form submissions (name, email, phone, business details, plan interest)
- Support communications and correspondence
How We Use Your Data
| Purpose | Lawful Basis | Data Used |
|---|---|---|
| Provide and operate DaaS | Contract performance | Account, usage, health data |
| Authenticate users and manage sessions | Contract performance | Email, session tokens |
| Display and process health/dietary data | Contract + legitimate interests | Client health data |
| Process subscription billing | Contract performance | Billing data |
| Send service notifications and updates | Contract + legitimate interests | Email, name |
| Analyze platform usage to improve features | Legitimate interests | Aggregated usage data |
| Comply with legal obligations | Legal obligation | As required by law |
| Respond to your enquiries | Legitimate interests | Contact form data |
| Security monitoring and fraud prevention | Legitimate interests | Logs, IP, auth events |
We never sell personal data to third parties, use it for advertising, or share it with third parties for their own marketing purposes.
Infrastructure & Data Storage
DaaS is built on enterprise-grade cloud infrastructure. Understanding where your data lives is important:
Supabase
Our primary database, authentication, and file storage provider. Data is stored in PostgreSQL on AWS infrastructure. Supabase enforces Row-Level Security (RLS) policies that logically isolate each Tenant's data at the database level: no Tenant can access another Tenant's data, even on shared infrastructure.
Region: AWS ap-south-1 (Mumbai, India).
Vercel
Application hosting, serverless API functions, and CDN delivery. All data transmitted through Vercel is encrypted in transit via TLS 1.3. Vercel processes request/response data ephemerally to serve your application; it does not retain your business or client data.
SOC 2 Type II certified. Global edge network for low-latency delivery.
Third-Party Services
We use a limited number of carefully selected sub-processors to operate the platform:
| Sub-processor | Purpose | DPA / Compliance |
|---|---|---|
| Supabase Inc. | Database, authentication, storage | DPA available; SOC 2 |
| Vercel Inc. | Hosting, serverless compute, CDN | DPA available; SOC 2 Type II |
| Resend, Inc. | Transactional email delivery, no health data | DPA available; SOC 2 Type II |
| Cloudflare, Inc. | Bot protection (Turnstile) | DPA available; SOC 2 Type II |
| Razorpay | Tenant subscription billing (INR) | PCI DSS Level 1 |
We do not share personal data with analytics platforms that track individuals across the web, social media companies, or advertising networks. All sub-processors are bound by Data Processing Agreements (DPAs) that restrict their use of your data to providing services to us.
Security Measures
We take security seriously given the sensitive health data processed through our platform. Our technical and organizational measures include:
AES-256 Encryption
All data at rest is encrypted using AES-256 via Supabase's storage encryption. Free-text medical answers are additionally encrypted with AES-256-GCM by the application before they are written.
TLS in Transit
All connections are encrypted in transit. Outdated protocols (TLS 1.0/1.1) are disabled.
Row-Level Security
PostgreSQL RLS policies prevent cross-tenant data access at the database engine level, and restrict branch staff to their own branch.
Secure Auth Cookies
Session tokens are stored in httpOnly, Secure, SameSite cookies, not readable by JavaScript. Idle sessions are signed out automatically.
Health-Record Access Logging
Opening a client or lead health record writes an append-only audit entry: who, what, when, and from which IP. Entries cannot be edited or deleted for at least one year.
Privileged Fields Are Not Self-Editable
A user’s role, tenant, branch and account status can only be changed by a server-side administrative operation, enforced by database grants and a trigger.
If you discover a security vulnerability, please report it responsibly to security@dietasaservice.com. We operate a responsible disclosure program.
Data Retention
Data is retained for as long as the Tenant maintains its account with us and the client relationship the record belongs to. Health-record access logs are retained for a minimum of one year and cannot be altered or deleted within that period.
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data. We honor these rights for all users regardless of location:
Right of Access
Request a copy of all personal data we hold about you, in a portable machine-readable format.
Right to Rectification
Request correction of inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your personal data where we have no ongoing lawful basis to retain it.
Right to Data Portability
Receive your data in a structured, commonly used format (JSON or CSV) to transfer to another service.
Right to Restriction
Request that we limit processing of your data in certain circumstances.
Right to Object
Object to processing based on legitimate interests, including profiling.
Right to Withdraw Consent
Where processing is based on consent, withdraw it at any time without affecting past processing.
To exercise any of these rights, contact us at privacy@dietasaservice.com. We will respond within 30 days. We may request identity verification before processing sensitive requests.
Health Data
DaaS stores health information about our Tenants' clients: medical history, medications, allergies, body measurements, dietary habits and nutrition goals. The Tenant is the Data Fiduciary for that information under India's Digital Personal Data Protection Act, 2023; AmityEdge processes it on the Tenant's instructions.
Each Tenant's health data is isolated by PostgreSQL Row-Level Security, enforced by the database rather than by application code. Free-text medical answers, covering past surgeries, current medications, allergies, food preferences and dislikes, and cravings notes, are additionally encrypted with AES-256-GCM before storage. Traffic is encrypted in transit. Opening a client or lead health record writes an audit entry recording who accessed it, when, and from which IP address.
International Data Transfers
Client and Tenant data is stored in India (AWS ap-south-1, Mumbai, via Supabase). Application hosting and content delivery run on Vercel's global network, which means request and response data may transit servers outside India while a page is being served; it is not stored there.
Both Supabase and Vercel maintain Data Processing Agreements covering cross-border transfers. Copies are available on request from legal@dietasaservice.com. We do not currently offer a choice of hosting region.
Children's Privacy
The DaaS administrative interface is not directed at individuals under 18 years of age. We do not knowingly collect personal data from children under 18 through our platform sign-up process.
Tenants (healthcare businesses) may manage health records for minor clients. In such cases, the Tenant is responsible as Data Controller for ensuring appropriate parental or guardian consent has been obtained in accordance with applicable law (e.g., COPPA, GDPR Article 8).
Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will:
- Update the effective date at the top of this policy
- Post a notice on the DaaS dashboard for active Tenants
- Send an email notification to registered Tenant administrators at least 30 days before the changes take effect
Your continued use of the platform after the effective date of material changes constitutes your acceptance of the updated policy. If you do not agree with the changes, you may terminate your subscription before the effective date.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out:
Registered Address
AmityEdge Technologies Pvt. Ltd.
India
Our full position under India's DPDP Act, including the Grievance Officer, your rights as a Data Principal, and the safeguards we do and do not implement, is on the Data Protection page. If you are in the EU/EEA, see our GDPR page.