Legal

Privacy Policy

We are committed to protecting the privacy of every individual who interacts with DaaS, from tenant administrators to their end clients. This policy explains exactly what we collect, why we collect it, and how we protect it.

Effective date: July 26, 2026|AmityEdge Technologies Pvt. Ltd.

Overview

DaaS is operated by AmityEdge Technologies Pvt. Ltd.(“AmityEdge”, “we”, “us”). We provide a multi-tenant SaaS platform that allows diet and wellness businesses (“Tenants”) to manage their operations, clients, diet plans, and analytics on shared infrastructure.

This Privacy Policy applies to all users of DaaS, including Tenant administrators, branch staff, and end clients who access a Tenant's client portal. It describes our practices for collecting, using, storing, sharing, and protecting personal data.

Data Controller vs. Processor: For most health and client data processed through Tenant portals, the Tenant (your diet business) acts as the Data Controller, and AmityEdge acts as the Data Processor. AmityEdge acts as Data Controller for platform-level data such as Tenant account information and billing.

Data We Collect

We collect different categories of data depending on your role:

Tenant Account Data

  • Full name, business name, email address, phone number
  • Business address and jurisdiction
  • Subscription plan and billing information (processed by our payment provider)
  • Branch and staff structure

Client Health Data (PHI)

  • Full name, date of birth, gender, contact details
  • Physical measurements: height, weight, BMI, body composition
  • Medical history, conditions, and dietary restrictions
  • Assigned diet plans, meal logs, and nutritional targets
  • Progress records, consultant notes, and activity logs

Usage & Technical Data

  • IP addresses, browser and device type, operating system
  • Pages accessed, features used, session duration and frequency
  • Authentication events: logins, logouts, failed attempts
  • API request logs processed through Vercel's serverless infrastructure

Enquiry & Communication Data

  • Enquiry form submissions (name, email, phone, business details, plan interest)
  • Support communications and correspondence

How We Use Your Data

PurposeLawful BasisData Used
Provide and operate DaaSContract performanceAccount, usage, health data
Authenticate users and manage sessionsContract performanceEmail, session tokens
Display and process health/dietary dataContract + legitimate interestsClient health data
Process subscription billingContract performanceBilling data
Send service notifications and updatesContract + legitimate interestsEmail, name
Analyze platform usage to improve featuresLegitimate interestsAggregated usage data
Comply with legal obligationsLegal obligationAs required by law
Respond to your enquiriesLegitimate interestsContact form data
Security monitoring and fraud preventionLegitimate interestsLogs, IP, auth events

We never sell personal data to third parties, use it for advertising, or share it with third parties for their own marketing purposes.

Infrastructure & Data Storage

DaaS is built on enterprise-grade cloud infrastructure. Understanding where your data lives is important:

Supabase

Our primary database, authentication, and file storage provider. Data is stored in PostgreSQL on AWS infrastructure. Supabase enforces Row-Level Security (RLS) policies that logically isolate each Tenant's data at the database level: no Tenant can access another Tenant's data, even on shared infrastructure.

Region: AWS ap-south-1 (Mumbai, India).

Vercel

Application hosting, serverless API functions, and CDN delivery. All data transmitted through Vercel is encrypted in transit via TLS 1.3. Vercel processes request/response data ephemerally to serve your application; it does not retain your business or client data.

SOC 2 Type II certified. Global edge network for low-latency delivery.

Encryption at rest is applied to all data stored in Supabase (AES-256). Encryption in transit is enforced on all connections via TLS 1.3. Authentication tokens are stored in httpOnly, Secure, SameSite cookies, not accessible via JavaScript.

Third-Party Services

We use a limited number of carefully selected sub-processors to operate the platform:

Sub-processorPurposeDPA / Compliance
Supabase Inc.Database, authentication, storageDPA available; SOC 2
Vercel Inc.Hosting, serverless compute, CDNDPA available; SOC 2 Type II
Resend, Inc.Transactional email delivery, no health dataDPA available; SOC 2 Type II
Cloudflare, Inc.Bot protection (Turnstile)DPA available; SOC 2 Type II
RazorpayTenant subscription billing (INR)PCI DSS Level 1

We do not share personal data with analytics platforms that track individuals across the web, social media companies, or advertising networks. All sub-processors are bound by Data Processing Agreements (DPAs) that restrict their use of your data to providing services to us.

Security Measures

We take security seriously given the sensitive health data processed through our platform. Our technical and organizational measures include:

AES-256 Encryption

All data at rest is encrypted using AES-256 via Supabase's storage encryption. Free-text medical answers are additionally encrypted with AES-256-GCM by the application before they are written.

TLS in Transit

All connections are encrypted in transit. Outdated protocols (TLS 1.0/1.1) are disabled.

Row-Level Security

PostgreSQL RLS policies prevent cross-tenant data access at the database engine level, and restrict branch staff to their own branch.

Secure Auth Cookies

Session tokens are stored in httpOnly, Secure, SameSite cookies, not readable by JavaScript. Idle sessions are signed out automatically.

Health-Record Access Logging

Opening a client or lead health record writes an append-only audit entry: who, what, when, and from which IP. Entries cannot be edited or deleted for at least one year.

Privileged Fields Are Not Self-Editable

A user’s role, tenant, branch and account status can only be changed by a server-side administrative operation, enforced by database grants and a trigger.

If you discover a security vulnerability, please report it responsibly to security@dietasaservice.com. We operate a responsible disclosure program.

Cookies & Tracking

DaaS uses a minimal set of cookies strictly necessary to provide the service:

Cookie NameTypePurposeDuration
sb-<project>-auth-token (may be split across numbered chunks)EssentialSupabase authentication session and refresh tokenRotating; cleared on sign-out
daas-seenEssentialRecords last activity so an idle session can be signed outRotating; cleared on sign-out

We do not set third-party advertising cookies, social media tracking pixels, or cross-site analytics cookies. We do not use Google Analytics, Meta Pixel, or similar tracking tools.

Authentication cookies are httpOnly and cannot be read by JavaScript. They are required for the platform to function: the service cannot be used if these cookies are blocked.

Data Retention

Data is retained for as long as the Tenant maintains its account with us and the client relationship the record belongs to. Health-record access logs are retained for a minimum of one year and cannot be altered or deleted within that period.

We do not publish a retention schedule yet. Automated scheduled deletion is still being built, and publishing periods we do not enforce would be misleading. A specific schedule will appear here once the deletion job is running and has been verified. Until then, export and deletion requests are actioned manually. Write to grievance@dietasaservice.com.

Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data. We honor these rights for all users regardless of location:

Right of Access

Request a copy of all personal data we hold about you, in a portable machine-readable format.

Right to Rectification

Request correction of inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data where we have no ongoing lawful basis to retain it.

Right to Data Portability

Receive your data in a structured, commonly used format (JSON or CSV) to transfer to another service.

Right to Restriction

Request that we limit processing of your data in certain circumstances.

Right to Object

Object to processing based on legitimate interests, including profiling.

Right to Withdraw Consent

Where processing is based on consent, withdraw it at any time without affecting past processing.

To exercise any of these rights, contact us at privacy@dietasaservice.com. We will respond within 30 days. We may request identity verification before processing sensitive requests.

Health Data

DaaS stores health information about our Tenants' clients: medical history, medications, allergies, body measurements, dietary habits and nutrition goals. The Tenant is the Data Fiduciary for that information under India's Digital Personal Data Protection Act, 2023; AmityEdge processes it on the Tenant's instructions.

Each Tenant's health data is isolated by PostgreSQL Row-Level Security, enforced by the database rather than by application code. Free-text medical answers, covering past surgeries, current medications, allergies, food preferences and dislikes, and cravings notes, are additionally encrypted with AES-256-GCM before storage. Traffic is encrypted in transit. Opening a client or lead health record writes an audit entry recording who accessed it, when, and from which IP address.

HIPAA does not apply to this service, and we do not offer a Business Associate Agreement as a standard term. See our Data Protection page for the full position, the safeguards we do and do not implement, and the arrangement available to US Covered Entities.

International Data Transfers

Client and Tenant data is stored in India (AWS ap-south-1, Mumbai, via Supabase). Application hosting and content delivery run on Vercel's global network, which means request and response data may transit servers outside India while a page is being served; it is not stored there.

Both Supabase and Vercel maintain Data Processing Agreements covering cross-border transfers. Copies are available on request from legal@dietasaservice.com. We do not currently offer a choice of hosting region.

Children's Privacy

The DaaS administrative interface is not directed at individuals under 18 years of age. We do not knowingly collect personal data from children under 18 through our platform sign-up process.

Tenants (healthcare businesses) may manage health records for minor clients. In such cases, the Tenant is responsible as Data Controller for ensuring appropriate parental or guardian consent has been obtained in accordance with applicable law (e.g., COPPA, GDPR Article 8).

Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will:

  • Update the effective date at the top of this policy
  • Post a notice on the DaaS dashboard for active Tenants
  • Send an email notification to registered Tenant administrators at least 30 days before the changes take effect

Your continued use of the platform after the effective date of material changes constitutes your acceptance of the updated policy. If you do not agree with the changes, you may terminate your subscription before the effective date.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out:

Privacy Enquiries

privacy@dietasaservice.com

Response within 5 business days

Registered Address

AmityEdge Technologies Pvt. Ltd.
India

Our full position under India's DPDP Act, including the Grievance Officer, your rights as a Data Principal, and the safeguards we do and do not implement, is on the Data Protection page. If you are in the EU/EEA, see our GDPR page.