BandobastBandobast
ProductAboutPricingStoriesContact

PRIVACY POLICY

BANDOBAST Effective Date: 31st July 2026 Last Revised: 31st July 2026


ARTICLE 1 - INTRODUCTION AND SCOPE

1.1 Who We Are. Bandobast ("Company", "we", "us", or "our") operates a cloud-based software-as-a-service platform for event service vendors, accessible at bandobast.app ("Platform"). This Privacy Policy explains how we collect, use, store, share, and protect personal data in connection with the Platform.

1.2 Scope of This Policy. This Privacy Policy applies to:

(a) Vendors - businesses and individuals who register for and use the Platform to manage their event services operations; and

(b) End Clients - third-party customers of Vendors whose personal data is entered into the Platform by or on behalf of Vendors.

This Policy does not apply to the data practices of Vendors in their capacity as Data Fiduciaries in relation to their End Clients. Vendors are independent businesses subject to their own privacy obligations. Please refer to the relevant Vendor's privacy practices for information about how they handle your personal data.

1.3 Legal Framework. We are committed to compliance with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and all other applicable data protection and privacy laws. Where we process personal data of individuals outside India, we apply standards no less protective than those required by the DPDP Act.

1.4 Relationship to Our Terms. This Privacy Policy is incorporated into and should be read alongside our Terms and Conditions. Capitalised terms not defined in this Policy have the meanings given to them in the Terms and Conditions.


ARTICLE 2 - DEFINITIONS

In this Privacy Policy:

"Consent" has the meaning given under the DPDP Act - a free, specific, informed, unconditional, and unambiguous indication of agreement by a Data Principal for the processing of their personal data for a specified purpose.

"Data Fiduciary" means a person (including a company or firm) who, alone or in conjunction with others, determines the purpose and means of processing personal data, as defined under the DPDP Act.

"Data Principal" means the individual to whom personal data relates.

"Data Processor" means a person who processes personal data on behalf of a Data Fiduciary.

"End Client" means a third-party customer of a Vendor whose personal data is stored in the Vendor's Workspace on the Platform.

"End Client Personal Data" means personal data relating to an End Client entered into the Platform by or on behalf of a Vendor.

"Personal Data" means any data about an individual who is identifiable by or in relation to such data.

"Platform Data" means aggregated, anonymised statistical and operational data derived from use of the Platform that does not identify any individual or Vendor.

"Processing" means any operation or set of operations performed on personal data, including collection, storage, use, sharing, disclosure, and deletion.

"Sensitive Personal Data" means personal data revealing financial information, health data, biometric data, or other categories designated as sensitive under applicable law.

"Vendor" means a business or individual who holds an approved account on the Platform.

"Vendor Account Data" means personal data relating to a Vendor or its Authorised Users collected directly by the Company for the purpose of providing the Platform.

"Workspace" means the isolated, tenant-specific environment provisioned for each Vendor on the Platform.


ARTICLE 3 - DATA WE COLLECT AND HOW WE COLLECT IT

We collect personal data in two distinct capacities depending on whose data is involved.

3.1 Data We Collect as Data Fiduciary (Vendor Account Data)

When a Vendor registers for, accesses, or uses the Platform, we collect and process the following categories of personal data in our capacity as Data Fiduciary:

3.1.1 Registration and Account Data

CategoryExamplesHow Collected
Identity dataFull name, business name, designationProvided by Vendor at registration
Contact dataEmail address, phone numberProvided by Vendor at registration
Authentication dataHashed password, session tokensGenerated at registration and login
Business dataVendor category, service descriptionProvided by Vendor during onboarding
Account statusApproval status, plan type, subscription datesGenerated by the Platform

We do not store plaintext passwords. Passwords are processed using industry-standard cryptographic hashing before storage.

3.1.2 Team Member Data

Where a Vendor invites Team Members to their Workspace, we collect:

  • Name and email address of each Team Member;
  • Role and permission levels assigned by the Vendor;
  • Date of invitation and acceptance; and
  • Login and activity records within the Workspace.

The Vendor is responsible for ensuring that each Team Member has been informed of and consents to their personal data being processed by the Company as described in this Policy.

3.1.3 Billing and Payment Data

CategoryExamplesHow Collected
Subscription dataPlan type, billing date, subscription historyGenerated by Platform
GST registrationGSTIN, business address for invoicingProvided by Vendor
Payment recordsAmount, date, status of each transactionProvided by payment processor

We do not directly collect, store, or process full payment card numbers. All payment card data is processed exclusively by our third-party payment processor (see Article 6). We receive only transaction status, reference numbers, and summary data.

3.1.4 Usage and Technical Data

We automatically collect the following data when a Vendor or Authorised User accesses the Platform:

CategoryExamplesSource
Log dataRequest ID, user ID, tenant ID, API endpoint accessed, HTTP status code, response timeOur application servers
Device and browser dataIP address, browser type and version, operating system, device typeCloudflare (edge layer)
Session dataLogin timestamps, session duration, "remember this device" token (30-day validity)Our application servers
Error dataError messages and stack traces where errors occurOur application servers

This data is collected for security monitoring, system performance, abuse prevention, and troubleshooting. It is not used for behavioural advertising.

3.1.5 Communications Data

If you contact us by email, through in-app support chat, or by any other channel, we retain records of that correspondence, including your name, contact details, and the content of your communications.

3.2 Data We Process as Data Processor (End Client Personal Data)

When Vendors use the Platform to manage their bookings, the Vendor inputs End Client Personal Data into their Workspace. In relation to End Client Personal Data, we act exclusively as a Data Processor on behalf of the Vendor, who is the Data Fiduciary.

End Client Personal Data typically includes:

CategoryExamples
Identity dataFull name
Contact dataPhone number, email address, postal address
Event dataEvent date, event type, location, booking notes
Financial dataAgreed booking amounts, payment instalments, outstanding balances
CommunicationsNotes recorded by the Vendor regarding the client
ImagesPhotographs uploaded to client galleries (Studio Plan only)

We process End Client Personal Data solely on the instructions of the relevant Vendor and for the purpose of providing the Platform services to that Vendor. We do not use End Client Personal Data for our own purposes, including marketing, analytics, or product improvement. We do not sell, share, or disclose End Client Personal Data to any third party except as required to provide the Platform or as required by law.

If you are an End Client and wish to know how your personal data is used, you should contact the Vendor who booked your event. That Vendor - not Bandobast - is responsible for the collection and use of your data in connection with your event engagement.


ARTICLE 4 - PURPOSES AND LEGAL BASIS FOR PROCESSING

4.1 Processing of Vendor Account Data

We process Vendor Account Data on the following legal bases under the DPDP Act and applicable law:

PurposeLegal Basis
Creating and managing Vendor accountsPerformance of contract (Terms and Conditions)
Reviewing and approving Vendor registration applicationsLegitimate interest in ensuring the Platform is used by legitimate businesses
Providing, maintaining, and improving the PlatformPerformance of contract
Processing subscription payments and issuing invoicesPerformance of contract; compliance with tax laws
Sending account and service notifications (e.g. billing alerts, security alerts, maintenance notices)Performance of contract; legitimate interest in communicating service-related information
Security monitoring, fraud prevention, and abuse detectionLegitimate interest in protecting the Platform and its users
Responding to support queries and complaintsPerformance of contract; legitimate interest
Complying with legal obligations (e.g. tax record-keeping, responding to lawful requests)Compliance with law
Sending product updates, feature announcements, and promotional communicationsConsent (where required); legitimate interest (for existing Vendors)
Generating anonymised Platform Data for product analytics and business improvementLegitimate interest (no individual is identified)

We do not use Vendor Account Data for automated decision-making that produces legal or similarly significant effects.

4.2 Processing of End Client Personal Data

We process End Client Personal Data solely:

(a) to provide the Platform services to the Vendor as instructed;

(b) to maintain system security, including backup, logging, and monitoring; and

(c) as required by applicable law.

The legal basis for our processing as Data Processor is the contract we have with the Vendor (our Terms and Conditions). The Vendor is responsible for establishing and maintaining a lawful basis for the original collection of End Client Personal Data.


ARTICLE 5 - COOKIES AND SIMILAR TECHNOLOGIES

5.1 What We Use. The Platform uses the following cookies and local storage mechanisms:

Name / TypePurposeDuration
Authentication token (JWT)Maintains your login session on the PlatformSession (until logout)
"Remember this device" tokenKeeps you logged in across browser sessions when you opt in30 days
Security cookiesCSRF protection and related security functionsSession

5.2 What We Do Not Use. We do not use:

  • Third-party advertising or tracking cookies;
  • Analytics tracking cookies from third-party services (e.g. Google Analytics);
  • Cross-site tracking technologies; or
  • Fingerprinting technologies.

5.3 Managing Cookies. You can control cookies through your browser settings. Disabling authentication cookies will prevent you from logging into the Platform.


ARTICLE 6 - DATA SHARING AND THIRD PARTIES

We do not sell, rent, or trade personal data. We share personal data only as described below.

6.1 Sub-Processors

We engage the following categories of third-party sub-processors to operate the Platform:

CategoryPurposeLocation
Cloud infrastructure providerHosting of application servers and databaseHetzner (Germany)
Cloud storage and CDNStorage of photos, thumbnails, and static assets; content deliveryCloudflare R2 (global CDN)
Edge network and DDoS protectionTraffic routing, security, and performanceCloudflare (global)
Payment processorProcessing Subscription paymentsIndia (to be confirmed)
Email service providerTransactional emails (account notifications, invitations, billing)To be confirmed
Security monitoringHost-level security event monitoring and alertingInternal (Wazuh, on private network)

All sub-processors are bound by data processing agreements that require them to maintain appropriate security measures and process personal data only on our instructions.

6.2 Legal Disclosures

We may disclose personal data to governmental authorities, regulatory bodies, courts, or law enforcement agencies where we are required to do so by applicable law, court order, or legal process. Where permissible, we will notify the affected Vendor or individual before making such a disclosure.

6.3 Business Transfers

In the event of a merger, acquisition, restructuring, sale of assets, or similar corporate transaction involving Bandobast, personal data held by us may be transferred to the successor entity. We will notify affected Vendors by email and provide an opportunity to export or delete their data before any such transfer takes effect, where practicable.

6.4 With Your Consent

We may share personal data with third parties for purposes not described in this Policy where we have obtained your prior, explicit consent.

6.5 No Cross-Vendor Data Sharing

Personal data belonging to one Vendor's Workspace - including all End Client Personal Data in that Workspace - is never shared with, or made accessible to, any other Vendor. Each Workspace is logically isolated at the database level. There is no shared customer directory across Vendors on the Platform.


ARTICLE 7 - DATA RETENTION

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law.

Data CategoryRetention PeriodBasis
Vendor Account Data (active account)For the duration of the accountContractual necessity
Vendor Account Data (after account deletion)90 days from deletion requestTo allow data export; DPDP Act compliance
Billing records and invoices7 years from the date of the invoiceIndian tax law (GST record-keeping requirements)
Application logs (request logs, error logs)90 daysSecurity and debugging; in line with our monitoring policy
Security event logs (Wazuh SIEM)90 days queryable; archived thereafterSecurity monitoring and incident response
End Client Personal Data (active Workspace)Until the Vendor deletes the record, or until the Workspace is closedData Processor - retained per Vendor instruction
End Client Personal Data (after Workspace deletion)90 days from Workspace deletion, then permanently deletedTo allow Vendor data export; DPDP Act compliance
Photo Originals (Studio Plan)30 days from the date of upload, then auto-deletedStorage lifecycle policy; see Article 8
Photo Thumbnails and PreviewsUntil the Vendor's Workspace is permanently deletedContractual necessity
Support correspondence3 years from the date of correspondenceLegitimate interest in maintaining records of interactions

After the applicable retention period, personal data is permanently deleted or irreversibly anonymised. Billing records retained for tax compliance purposes are stored in a segregated archive, not accessible within the active Platform.


ARTICLE 8 - PHOTO TOOL AND IMAGE DATA (STUDIO PLAN)

8.1 Original Images. When a Vendor uploads original photographs ("Originals") through the Photo Tool:

(a) Originals are stored in a private, access-controlled storage bucket and are not publicly accessible;

(b) Compressed previews and thumbnails are generated for use in client galleries;

(c) Originals are automatically and permanently deleted thirty (30) days after upload, regardless of whether the Vendor has downloaded them. This deletion is irreversible and cannot be paused or extended.

8.2 Previews and Thumbnails. Compressed previews and thumbnails remain accessible within the Vendor's Workspace for the duration of the Workspace. They are served over a secure content delivery network.

8.3 Client Gallery Access. Client gallery share links are protected by unique, cryptographically generated access tokens. Accessing a gallery via its share link does not require the End Client to create an account or provide personal data to Bandobast. We do not track the identity of individuals who access client galleries.

8.4 Images of Individuals. Photographs uploaded to the Platform may depict identifiable individuals. The Vendor - as Data Fiduciary - is responsible for ensuring that all necessary consents have been obtained from individuals depicted in uploaded images in accordance with the DPDP Act and applicable law. Bandobast processes such images solely as Data Processor on the Vendor's instruction.


ARTICLE 9 - DATA SECURITY

9.1 Technical Measures. We implement and maintain the following technical security measures to protect personal data:

MeasureDescription
Encryption in transitAll data transmitted between users and the Platform is encrypted using TLS (HTTPS). All data transmitted between internal services is encrypted over a private network (Tailscale).
AuthenticationJWT-based session authentication with short token expiry. Password hashing using industry-standard algorithms.
Multi-tenancy isolationRow-Level Security (RLS) enforced at the database level ensures each Vendor's data is inaccessible to other Vendors.
Access controlRole-based access controls limit which Authorised Users can access which data within a Workspace.
Infrastructure securityApplication and database servers are hosted on dedicated cloud virtual machines, not shared hosting. Network access between servers is restricted.
BackupsThe database is backed up daily via automated exports shipped to encrypted cloud storage.
Security monitoringHost-level security monitoring (authentication events, file integrity, vulnerability scanning, anomaly detection) is operated 24/7 via a SIEM platform.
Private storagePhoto Originals are stored in a private storage bucket. Access is controlled by short-lived presigned URLs (1-hour expiry).

9.2 Organisational Measures. We implement the following organisational security measures:

  • All personnel with access to personal data are subject to confidentiality obligations;
  • Access to production systems is restricted to authorised personnel only, via multi-factor authenticated private network access;
  • Security policies and this Privacy Policy are reviewed periodically and updated as required.

9.3 No Absolute Guarantee. Despite these measures, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security of personal data. In the event of a security incident affecting personal data, we will take prompt remedial action and notify affected parties as required by applicable law.

9.4 Data Breach Notification. In the event of a confirmed personal data breach:

(a) we will notify the Data Protection Board of India within seventy-two (72) hours of becoming aware of the breach, as required by the DPDP Act;

(b) we will notify affected Vendors without undue delay, including a description of the nature of the breach, the categories of personal data affected, and the steps we have taken or propose to take in response; and

(c) where End Client Personal Data is affected, we will assist affected Vendors in meeting their own notification obligations to their End Clients.


ARTICLE 10 - YOUR RIGHTS AS A DATA PRINCIPAL

10.1 Rights of Vendors and Authorised Users

If you are a Vendor or an Authorised User, you have the following rights in respect of your personal data held by us, subject to applicable law:

Right of Access. You have the right to request confirmation of whether we hold personal data about you, and to receive a summary of such data and the purposes for which it is processed.

Right to Correction. You have the right to request that we correct any inaccurate or incomplete personal data we hold about you. You may update most account data directly from your account settings.

Right to Erasure. You have the right to request deletion of your personal data where: (i) the data is no longer necessary for the purposes for which it was collected; (ii) you withdraw consent (where processing was based on consent); or (iii) you object to processing and there is no overriding legitimate ground for us to continue. We may decline erasure requests where retention is required by law (e.g. billing records) or for the establishment, exercise, or defence of legal claims.

Right to Withdraw Consent. Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

Right to Grievance Redressal. You have the right to have your grievance regarding the processing of your personal data addressed by us in accordance with our grievance procedure (see Article 12).

Right to Nominate. Under the DPDP Act, you have the right to nominate another individual who shall exercise your rights on your behalf in the event of your death or incapacity.

10.2 Rights of End Clients

If you are an End Client whose personal data has been entered into the Platform by a Vendor, the relevant Vendor - not Bandobast - is the Data Fiduciary in respect of your data. Your rights under the DPDP Act should be exercised by contacting the Vendor directly.

Where a Vendor informs us of an End Client's request to access, correct, or erase their personal data, we will assist the Vendor in fulfilling that request within the Platform.

If you are unable to reach the Vendor, or if you believe your personal data has been processed unlawfully by a Vendor using the Platform, you may contact us at [email protected] and we will endeavour to assist where we are able to do so.

10.3 How to Exercise Your Rights

To exercise any of the rights set out in Article 10.1, please submit a written request to [email protected] with the subject line "Data Rights Request". Please include sufficient information to allow us to identify you and your account. We will respond within the timeframe required by applicable law (currently thirty (30) days under the DPDP Act, subject to any permitted extensions).

We will not charge a fee for handling rights requests unless requests are manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or decline to act on the request.


ARTICLE 11 - INTERNATIONAL DATA TRANSFERS

11.1 Infrastructure Location. Our primary application servers and database are hosted on cloud infrastructure located in Germany (Hetzner). Photo and file storage, as well as content delivery, is provided through Cloudflare's global network, which operates data centres across multiple jurisdictions including the European Union and the United States.

11.2 Transfers Outside India. By using the Platform, you acknowledge that your personal data may be transferred to and stored in jurisdictions outside India. We ensure that any such transfers are subject to appropriate safeguards, including contractual protections with sub-processors, and that the receiving parties are bound by data protection obligations no less stringent than those imposed under the DPDP Act.

11.3 Future Changes. As the DPDP Act's cross-border transfer rules are operationalised by the Government of India (including any notification of "trusted" countries or approved transfer mechanisms), we will update our transfer practices accordingly.


ARTICLE 12 - CHILDREN'S PRIVACY

The Platform is intended for use by business operators and is not directed at individuals under the age of eighteen (18). We do not knowingly collect personal data from anyone under eighteen. If we become aware that we have inadvertently collected personal data from a minor, we will take steps to delete that data promptly. If you believe we may hold personal data of a minor, please contact us immediately at [email protected].


ARTICLE 13 - LINKS TO THIRD-PARTY SERVICES

The Platform may contain links to third-party websites, applications, or services. This Privacy Policy does not apply to those third parties. We are not responsible for the privacy practices of third-party services and encourage you to review their privacy policies before providing them with any personal data.


ARTICLE 14 - CHANGES TO THIS PRIVACY POLICY

14.1 Right to Amend. We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or Platform features.

14.2 Notification. We will notify Vendors of material changes to this Policy by:

(a) sending an email to the registered account email address; and

(b) displaying a prominent notice within the Platform.

We will provide at least fourteen (14) days' notice before material changes take effect, except where changes are required by law or to address an urgent security risk, in which case we will provide as much notice as is reasonably practicable.

14.3 Continued Use. Continued use of the Platform after the effective date of a revised Privacy Policy constitutes acceptance of the revised Policy. If you do not agree to the revised Policy, you must cease using the Platform and may request deletion of your data in accordance with Article 10.

14.4 Version History. Prior versions of this Privacy Policy are available upon written request to [email protected].


ARTICLE 15 - GRIEVANCE OFFICER AND CONTACT

In accordance with the DPDP Act and applicable rules, you may direct any grievances, complaints, or queries relating to this Privacy Policy or our data processing practices to:

Grievance Officer Bandobast K Dommasandra, Belathur Main Road Bangalore - 560047 India

Email: [email protected] Subject line: "Privacy Grievance" or "Data Rights Request"

We will acknowledge receipt of your grievance within forty-eight (48) hours and endeavour to resolve it within thirty (30) days of receipt. If you are not satisfied with our response, you may lodge a complaint with the Data Protection Board of India, once it is constituted and operational under the DPDP Act.


This Privacy Policy was last updated on 31st July 2026 and supersedes all prior versions.

© 2026 Bandobast. All rights reserved.

BandobastBandobast

Studio OS for India’s event vendors.

Product
  • Bookings
  • Calendar
  • Photo Tool
  • Invoicing
For vendors
  • Photographers
  • Caterers
  • Decorators
  • Planners
Company
  • About
  • Pricing
  • Help centre
  • Contact
© 2026 Bandobast Technologies Pvt. Ltd.
TermsPrivacy