PRIVACY POLICY
BANDOBAST Effective Date: 31st July 2026 Last Revised: 31st July 2026
ARTICLE 1 - INTRODUCTION AND SCOPE
1.1 Who We Are. Bandobast ("Company", "we", "us", or "our") operates a cloud-based software-as-a-service platform for event service vendors, accessible at bandobast.app ("Platform"). This Privacy Policy explains how we collect, use, store, share, and protect personal data in connection with the Platform.
1.2 Scope of This Policy. This Privacy Policy applies to:
(a) Vendors - businesses and individuals who register for and use the Platform to manage their event services operations; and
(b) End Clients - third-party customers of Vendors whose personal data is entered into the Platform by or on behalf of Vendors.
This Policy does not apply to the data practices of Vendors in their capacity as Data Fiduciaries in relation to their End Clients. Vendors are independent businesses subject to their own privacy obligations. Please refer to the relevant Vendor's privacy practices for information about how they handle your personal data.
1.3 Legal Framework. We are committed to compliance with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and all other applicable data protection and privacy laws. Where we process personal data of individuals outside India, we apply standards no less protective than those required by the DPDP Act.
1.4 Relationship to Our Terms. This Privacy Policy is incorporated into and should be read alongside our Terms and Conditions. Capitalised terms not defined in this Policy have the meanings given to them in the Terms and Conditions.
ARTICLE 2 - DEFINITIONS
In this Privacy Policy:
"Consent" has the meaning given under the DPDP Act - a free, specific, informed, unconditional, and unambiguous indication of agreement by a Data Principal for the processing of their personal data for a specified purpose.
"Data Fiduciary" means a person (including a company or firm) who, alone or in conjunction with others, determines the purpose and means of processing personal data, as defined under the DPDP Act.
"Data Principal" means the individual to whom personal data relates.
"Data Processor" means a person who processes personal data on behalf of a Data Fiduciary.
"End Client" means a third-party customer of a Vendor whose personal data is stored in the Vendor's Workspace on the Platform.
"End Client Personal Data" means personal data relating to an End Client entered into the Platform by or on behalf of a Vendor.
"Personal Data" means any data about an individual who is identifiable by or in relation to such data.
"Platform Data" means aggregated, anonymised statistical and operational data derived from use of the Platform that does not identify any individual or Vendor.
"Processing" means any operation or set of operations performed on personal data, including collection, storage, use, sharing, disclosure, and deletion.
"Sensitive Personal Data" means personal data revealing financial information, health data, biometric data, or other categories designated as sensitive under applicable law.
"Vendor" means a business or individual who holds an approved account on the Platform.
"Vendor Account Data" means personal data relating to a Vendor or its Authorised Users collected directly by the Company for the purpose of providing the Platform.
"Workspace" means the isolated, tenant-specific environment provisioned for each Vendor on the Platform.
ARTICLE 3 - DATA WE COLLECT AND HOW WE COLLECT IT
We collect personal data in two distinct capacities depending on whose data is involved.
3.1 Data We Collect as Data Fiduciary (Vendor Account Data)
When a Vendor registers for, accesses, or uses the Platform, we collect and process the following categories of personal data in our capacity as Data Fiduciary:
3.1.1 Registration and Account Data
| Category | Examples | How Collected |
|---|---|---|
| Identity data | Full name, business name, designation | Provided by Vendor at registration |
| Contact data | Email address, phone number | Provided by Vendor at registration |
| Authentication data | Hashed password, session tokens | Generated at registration and login |
| Business data | Vendor category, service description | Provided by Vendor during onboarding |
| Account status | Approval status, plan type, subscription dates | Generated by the Platform |
We do not store plaintext passwords. Passwords are processed using industry-standard cryptographic hashing before storage.
3.1.2 Team Member Data
Where a Vendor invites Team Members to their Workspace, we collect:
- Name and email address of each Team Member;
- Role and permission levels assigned by the Vendor;
- Date of invitation and acceptance; and
- Login and activity records within the Workspace.
The Vendor is responsible for ensuring that each Team Member has been informed of and consents to their personal data being processed by the Company as described in this Policy.
3.1.3 Billing and Payment Data
| Category | Examples | How Collected |
|---|---|---|
| Subscription data | Plan type, billing date, subscription history | Generated by Platform |
| GST registration | GSTIN, business address for invoicing | Provided by Vendor |
| Payment records | Amount, date, status of each transaction | Provided by payment processor |
We do not directly collect, store, or process full payment card numbers. All payment card data is processed exclusively by our third-party payment processor (see Article 6). We receive only transaction status, reference numbers, and summary data.
3.1.4 Usage and Technical Data
We automatically collect the following data when a Vendor or Authorised User accesses the Platform:
| Category | Examples | Source |
|---|---|---|
| Log data | Request ID, user ID, tenant ID, API endpoint accessed, HTTP status code, response time | Our application servers |
| Device and browser data | IP address, browser type and version, operating system, device type | Cloudflare (edge layer) |
| Session data | Login timestamps, session duration, "remember this device" token (30-day validity) | Our application servers |
| Error data | Error messages and stack traces where errors occur | Our application servers |
This data is collected for security monitoring, system performance, abuse prevention, and troubleshooting. It is not used for behavioural advertising.
3.1.5 Communications Data
If you contact us by email, through in-app support chat, or by any other channel, we retain records of that correspondence, including your name, contact details, and the content of your communications.
3.2 Data We Process as Data Processor (End Client Personal Data)
When Vendors use the Platform to manage their bookings, the Vendor inputs End Client Personal Data into their Workspace. In relation to End Client Personal Data, we act exclusively as a Data Processor on behalf of the Vendor, who is the Data Fiduciary.
End Client Personal Data typically includes:
| Category | Examples |
|---|---|
| Identity data | Full name |
| Contact data | Phone number, email address, postal address |
| Event data | Event date, event type, location, booking notes |
| Financial data | Agreed booking amounts, payment instalments, outstanding balances |
| Communications | Notes recorded by the Vendor regarding the client |
| Images | Photographs uploaded to client galleries (Studio Plan only) |
We process End Client Personal Data solely on the instructions of the relevant Vendor and for the purpose of providing the Platform services to that Vendor. We do not use End Client Personal Data for our own purposes, including marketing, analytics, or product improvement. We do not sell, share, or disclose End Client Personal Data to any third party except as required to provide the Platform or as required by law.
If you are an End Client and wish to know how your personal data is used, you should contact the Vendor who booked your event. That Vendor - not Bandobast - is responsible for the collection and use of your data in connection with your event engagement.
ARTICLE 4 - PURPOSES AND LEGAL BASIS FOR PROCESSING
4.1 Processing of Vendor Account Data
We process Vendor Account Data on the following legal bases under the DPDP Act and applicable law:
| Purpose | Legal Basis |
|---|---|
| Creating and managing Vendor accounts | Performance of contract (Terms and Conditions) |
| Reviewing and approving Vendor registration applications | Legitimate interest in ensuring the Platform is used by legitimate businesses |
| Providing, maintaining, and improving the Platform | Performance of contract |
| Processing subscription payments and issuing invoices | Performance of contract; compliance with tax laws |
| Sending account and service notifications (e.g. billing alerts, security alerts, maintenance notices) | Performance of contract; legitimate interest in communicating service-related information |
| Security monitoring, fraud prevention, and abuse detection | Legitimate interest in protecting the Platform and its users |
| Responding to support queries and complaints | Performance of contract; legitimate interest |
| Complying with legal obligations (e.g. tax record-keeping, responding to lawful requests) | Compliance with law |
| Sending product updates, feature announcements, and promotional communications | Consent (where required); legitimate interest (for existing Vendors) |
| Generating anonymised Platform Data for product analytics and business improvement | Legitimate interest (no individual is identified) |
We do not use Vendor Account Data for automated decision-making that produces legal or similarly significant effects.
4.2 Processing of End Client Personal Data
We process End Client Personal Data solely:
(a) to provide the Platform services to the Vendor as instructed;
(b) to maintain system security, including backup, logging, and monitoring; and
(c) as required by applicable law.
The legal basis for our processing as Data Processor is the contract we have with the Vendor (our Terms and Conditions). The Vendor is responsible for establishing and maintaining a lawful basis for the original collection of End Client Personal Data.
ARTICLE 5 - COOKIES AND SIMILAR TECHNOLOGIES
5.1 What We Use. The Platform uses the following cookies and local storage mechanisms:
| Name / Type | Purpose | Duration |
|---|---|---|
| Authentication token (JWT) | Maintains your login session on the Platform | Session (until logout) |
| "Remember this device" token | Keeps you logged in across browser sessions when you opt in | 30 days |
| Security cookies | CSRF protection and related security functions | Session |
5.2 What We Do Not Use. We do not use:
- Third-party advertising or tracking cookies;
- Analytics tracking cookies from third-party services (e.g. Google Analytics);
- Cross-site tracking technologies; or
- Fingerprinting technologies.
5.3 Managing Cookies. You can control cookies through your browser settings. Disabling authentication cookies will prevent you from logging into the Platform.
ARTICLE 6 - DATA SHARING AND THIRD PARTIES
We do not sell, rent, or trade personal data. We share personal data only as described below.
6.1 Sub-Processors
We engage the following categories of third-party sub-processors to operate the Platform:
| Category | Purpose | Location |
|---|---|---|
| Cloud infrastructure provider | Hosting of application servers and database | Hetzner (Germany) |
| Cloud storage and CDN | Storage of photos, thumbnails, and static assets; content delivery | Cloudflare R2 (global CDN) |
| Edge network and DDoS protection | Traffic routing, security, and performance | Cloudflare (global) |
| Payment processor | Processing Subscription payments | India (to be confirmed) |
| Email service provider | Transactional emails (account notifications, invitations, billing) | To be confirmed |
| Security monitoring | Host-level security event monitoring and alerting | Internal (Wazuh, on private network) |
All sub-processors are bound by data processing agreements that require them to maintain appropriate security measures and process personal data only on our instructions.
6.2 Legal Disclosures
We may disclose personal data to governmental authorities, regulatory bodies, courts, or law enforcement agencies where we are required to do so by applicable law, court order, or legal process. Where permissible, we will notify the affected Vendor or individual before making such a disclosure.
6.3 Business Transfers
In the event of a merger, acquisition, restructuring, sale of assets, or similar corporate transaction involving Bandobast, personal data held by us may be transferred to the successor entity. We will notify affected Vendors by email and provide an opportunity to export or delete their data before any such transfer takes effect, where practicable.
6.4 With Your Consent
We may share personal data with third parties for purposes not described in this Policy where we have obtained your prior, explicit consent.
6.5 No Cross-Vendor Data Sharing
Personal data belonging to one Vendor's Workspace - including all End Client Personal Data in that Workspace - is never shared with, or made accessible to, any other Vendor. Each Workspace is logically isolated at the database level. There is no shared customer directory across Vendors on the Platform.
ARTICLE 7 - DATA RETENTION
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law.
| Data Category | Retention Period | Basis |
|---|---|---|
| Vendor Account Data (active account) | For the duration of the account | Contractual necessity |
| Vendor Account Data (after account deletion) | 90 days from deletion request | To allow data export; DPDP Act compliance |
| Billing records and invoices | 7 years from the date of the invoice | Indian tax law (GST record-keeping requirements) |
| Application logs (request logs, error logs) | 90 days | Security and debugging; in line with our monitoring policy |
| Security event logs (Wazuh SIEM) | 90 days queryable; archived thereafter | Security monitoring and incident response |
| End Client Personal Data (active Workspace) | Until the Vendor deletes the record, or until the Workspace is closed | Data Processor - retained per Vendor instruction |
| End Client Personal Data (after Workspace deletion) | 90 days from Workspace deletion, then permanently deleted | To allow Vendor data export; DPDP Act compliance |
| Photo Originals (Studio Plan) | 30 days from the date of upload, then auto-deleted | Storage lifecycle policy; see Article 8 |
| Photo Thumbnails and Previews | Until the Vendor's Workspace is permanently deleted | Contractual necessity |
| Support correspondence | 3 years from the date of correspondence | Legitimate interest in maintaining records of interactions |
After the applicable retention period, personal data is permanently deleted or irreversibly anonymised. Billing records retained for tax compliance purposes are stored in a segregated archive, not accessible within the active Platform.
ARTICLE 8 - PHOTO TOOL AND IMAGE DATA (STUDIO PLAN)
8.1 Original Images. When a Vendor uploads original photographs ("Originals") through the Photo Tool:
(a) Originals are stored in a private, access-controlled storage bucket and are not publicly accessible;
(b) Compressed previews and thumbnails are generated for use in client galleries;
(c) Originals are automatically and permanently deleted thirty (30) days after upload, regardless of whether the Vendor has downloaded them. This deletion is irreversible and cannot be paused or extended.
8.2 Previews and Thumbnails. Compressed previews and thumbnails remain accessible within the Vendor's Workspace for the duration of the Workspace. They are served over a secure content delivery network.
8.3 Client Gallery Access. Client gallery share links are protected by unique, cryptographically generated access tokens. Accessing a gallery via its share link does not require the End Client to create an account or provide personal data to Bandobast. We do not track the identity of individuals who access client galleries.
8.4 Images of Individuals. Photographs uploaded to the Platform may depict identifiable individuals. The Vendor - as Data Fiduciary - is responsible for ensuring that all necessary consents have been obtained from individuals depicted in uploaded images in accordance with the DPDP Act and applicable law. Bandobast processes such images solely as Data Processor on the Vendor's instruction.
ARTICLE 9 - DATA SECURITY
9.1 Technical Measures. We implement and maintain the following technical security measures to protect personal data:
| Measure | Description |
|---|---|
| Encryption in transit | All data transmitted between users and the Platform is encrypted using TLS (HTTPS). All data transmitted between internal services is encrypted over a private network (Tailscale). |
| Authentication | JWT-based session authentication with short token expiry. Password hashing using industry-standard algorithms. |
| Multi-tenancy isolation | Row-Level Security (RLS) enforced at the database level ensures each Vendor's data is inaccessible to other Vendors. |
| Access control | Role-based access controls limit which Authorised Users can access which data within a Workspace. |
| Infrastructure security | Application and database servers are hosted on dedicated cloud virtual machines, not shared hosting. Network access between servers is restricted. |
| Backups | The database is backed up daily via automated exports shipped to encrypted cloud storage. |
| Security monitoring | Host-level security monitoring (authentication events, file integrity, vulnerability scanning, anomaly detection) is operated 24/7 via a SIEM platform. |
| Private storage | Photo Originals are stored in a private storage bucket. Access is controlled by short-lived presigned URLs (1-hour expiry). |
9.2 Organisational Measures. We implement the following organisational security measures:
- All personnel with access to personal data are subject to confidentiality obligations;
- Access to production systems is restricted to authorised personnel only, via multi-factor authenticated private network access;
- Security policies and this Privacy Policy are reviewed periodically and updated as required.
9.3 No Absolute Guarantee. Despite these measures, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security of personal data. In the event of a security incident affecting personal data, we will take prompt remedial action and notify affected parties as required by applicable law.
9.4 Data Breach Notification. In the event of a confirmed personal data breach:
(a) we will notify the Data Protection Board of India within seventy-two (72) hours of becoming aware of the breach, as required by the DPDP Act;
(b) we will notify affected Vendors without undue delay, including a description of the nature of the breach, the categories of personal data affected, and the steps we have taken or propose to take in response; and
(c) where End Client Personal Data is affected, we will assist affected Vendors in meeting their own notification obligations to their End Clients.
ARTICLE 10 - YOUR RIGHTS AS A DATA PRINCIPAL
10.1 Rights of Vendors and Authorised Users
If you are a Vendor or an Authorised User, you have the following rights in respect of your personal data held by us, subject to applicable law:
Right of Access. You have the right to request confirmation of whether we hold personal data about you, and to receive a summary of such data and the purposes for which it is processed.
Right to Correction. You have the right to request that we correct any inaccurate or incomplete personal data we hold about you. You may update most account data directly from your account settings.
Right to Erasure. You have the right to request deletion of your personal data where: (i) the data is no longer necessary for the purposes for which it was collected; (ii) you withdraw consent (where processing was based on consent); or (iii) you object to processing and there is no overriding legitimate ground for us to continue. We may decline erasure requests where retention is required by law (e.g. billing records) or for the establishment, exercise, or defence of legal claims.
Right to Withdraw Consent. Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Right to Grievance Redressal. You have the right to have your grievance regarding the processing of your personal data addressed by us in accordance with our grievance procedure (see Article 12).
Right to Nominate. Under the DPDP Act, you have the right to nominate another individual who shall exercise your rights on your behalf in the event of your death or incapacity.
10.2 Rights of End Clients
If you are an End Client whose personal data has been entered into the Platform by a Vendor, the relevant Vendor - not Bandobast - is the Data Fiduciary in respect of your data. Your rights under the DPDP Act should be exercised by contacting the Vendor directly.
Where a Vendor informs us of an End Client's request to access, correct, or erase their personal data, we will assist the Vendor in fulfilling that request within the Platform.
If you are unable to reach the Vendor, or if you believe your personal data has been processed unlawfully by a Vendor using the Platform, you may contact us at [email protected] and we will endeavour to assist where we are able to do so.
10.3 How to Exercise Your Rights
To exercise any of the rights set out in Article 10.1, please submit a written request to [email protected] with the subject line "Data Rights Request". Please include sufficient information to allow us to identify you and your account. We will respond within the timeframe required by applicable law (currently thirty (30) days under the DPDP Act, subject to any permitted extensions).
We will not charge a fee for handling rights requests unless requests are manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or decline to act on the request.
ARTICLE 11 - INTERNATIONAL DATA TRANSFERS
11.1 Infrastructure Location. Our primary application servers and database are hosted on cloud infrastructure located in Germany (Hetzner). Photo and file storage, as well as content delivery, is provided through Cloudflare's global network, which operates data centres across multiple jurisdictions including the European Union and the United States.
11.2 Transfers Outside India. By using the Platform, you acknowledge that your personal data may be transferred to and stored in jurisdictions outside India. We ensure that any such transfers are subject to appropriate safeguards, including contractual protections with sub-processors, and that the receiving parties are bound by data protection obligations no less stringent than those imposed under the DPDP Act.
11.3 Future Changes. As the DPDP Act's cross-border transfer rules are operationalised by the Government of India (including any notification of "trusted" countries or approved transfer mechanisms), we will update our transfer practices accordingly.
ARTICLE 12 - CHILDREN'S PRIVACY
The Platform is intended for use by business operators and is not directed at individuals under the age of eighteen (18). We do not knowingly collect personal data from anyone under eighteen. If we become aware that we have inadvertently collected personal data from a minor, we will take steps to delete that data promptly. If you believe we may hold personal data of a minor, please contact us immediately at [email protected].
ARTICLE 13 - LINKS TO THIRD-PARTY SERVICES
The Platform may contain links to third-party websites, applications, or services. This Privacy Policy does not apply to those third parties. We are not responsible for the privacy practices of third-party services and encourage you to review their privacy policies before providing them with any personal data.
ARTICLE 14 - CHANGES TO THIS PRIVACY POLICY
14.1 Right to Amend. We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or Platform features.
14.2 Notification. We will notify Vendors of material changes to this Policy by:
(a) sending an email to the registered account email address; and
(b) displaying a prominent notice within the Platform.
We will provide at least fourteen (14) days' notice before material changes take effect, except where changes are required by law or to address an urgent security risk, in which case we will provide as much notice as is reasonably practicable.
14.3 Continued Use. Continued use of the Platform after the effective date of a revised Privacy Policy constitutes acceptance of the revised Policy. If you do not agree to the revised Policy, you must cease using the Platform and may request deletion of your data in accordance with Article 10.
14.4 Version History. Prior versions of this Privacy Policy are available upon written request to [email protected].
ARTICLE 15 - GRIEVANCE OFFICER AND CONTACT
In accordance with the DPDP Act and applicable rules, you may direct any grievances, complaints, or queries relating to this Privacy Policy or our data processing practices to:
Grievance Officer Bandobast K Dommasandra, Belathur Main Road Bangalore - 560047 India
Email: [email protected] Subject line: "Privacy Grievance" or "Data Rights Request"
We will acknowledge receipt of your grievance within forty-eight (48) hours and endeavour to resolve it within thirty (30) days of receipt. If you are not satisfied with our response, you may lodge a complaint with the Data Protection Board of India, once it is constituted and operational under the DPDP Act.
This Privacy Policy was last updated on 31st July 2026 and supersedes all prior versions.
© 2026 Bandobast. All rights reserved.