Legal
Data Processing Agreement
This Data Processing Agreement (DPA) forms part of the agreement between Simplified Management and each customer using the Platform, and governs how we process personal data on their behalf.
Last updated: 19 August 2026
This DPA forms part of the agreement between Simplified Management Private Limited (CIN U62099PN2026PTC254686) ("Processor", "we") and the customer identified in the applicable order form or account signup ("Fiduciary", "you", "Customer") for use of the Simplified Management application (the "Platform"). It should be read alongside our App Privacy Policy and Terms of Use.
1. Roles
The Customer is the Data Fiduciary for all personal data of its guests and staff processed through the Platform, as defined under the Digital Personal Data Protection Act 2023 ("DPDP Act"). The Customer determines the purpose and means of processing that data. The Processor processes that data solely on the Customer's documented instructions, which are given by the Customer's use of the Platform's features and any written instruction the Customer separately provides.
This DPA does not apply to personal data the Processor holds about the Customer's own account users (name, email, login records, billing data) — that relationship is governed by the Terms of Use, under which the Processor acts as Data Fiduciary directly.
2. Scope of processing
| Subject matter | Provision of the Platform: reservation management, housekeeping and staff task routing, laundry and inventory tracking, guest check-in and identity document handling, invoicing and GST documentation, and reporting |
| Duration | The term of the Customer's subscription, plus the retention periods in §6 |
| Nature of processing | Storage, display, computation (occupancy/revenue reporting), transmission (sync with the Customer's PMS), deletion |
| Categories of data subjects | The Customer's guests; the Customer's staff (housekeepers, supervisors, admins) |
| Categories of personal data | See App Privacy Policy §4 — reservation data, guest identity documents, Form C / foreign-national records, invoice and payment data, staff assignment records |
3. Processor obligations
The Processor shall:
- Process personal data only on the Customer's documented instructions, including regarding cross-border transfer — noting that, per App Privacy Policy §7, all processing currently occurs on infrastructure located in India
- Ensure personnel authorized to process the data are bound by confidentiality
- Implement the security measures described in §7 below
- Assist the Customer, at the Customer's reasonable request, in responding to data principal requests (access, correction, erasure) it receives regarding its guests or staff
- Notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data (see §4)
- Delete or return all personal data at the end of the relationship, per §6, unless retention is required by law
- Make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA
- Not engage a sub-processor without the authorization in §5
4. Breach notification
The Processor will notify the Customer within 72 hours of becoming aware of a personal data breach affecting the Customer's data, including: the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed. The Customer remains responsible for any notification obligations it has to the Data Protection Board of India or to affected individuals.
5. Sub-processors
The Customer authorizes the Processor to engage the following sub-processors, each bound by written terms no less protective than this DPA:
| Sub-processor | Purpose |
|---|---|
| Supabase | Database, authentication, and file storage |
| MSG91 | WhatsApp messaging (booking confirmations, check-in links, guest communications) |
| The Customer's own PMS provider (eZee Technosys or iPMS247) | Reservation data source |
| MakeMyTrip / Goibibo | Booking and cancellation sync, where active |
The Processor will notify the Customer of any intended change to this list at least 30 days in advance, giving the Customer the opportunity to object on reasonable data-protection grounds.
6. Retention and deletion
The Processor will retain and delete Customer data in line with the schedule in App Privacy Policy §6. On termination of the Customer's subscription, the Processor will delete all Customer data within 90 days, except data it is required to retain by law (statutory GST/invoice records to 6 years; other categories per the same schedule).
7. Security measures
The Processor maintains: role-based access control differentiating access levels within the Platform; encryption of data in transit; access logging; and restricted internal access on a need-to-know basis. Details available on request.
8. Audit
The Customer may request, no more than once per 12 months, evidence of the Processor's compliance with this DPA (e.g. a summary of security controls or a relevant certification). On-site audits, if required, will be scheduled by mutual agreement.
9. Liability
Governed by the limitation of liability terms in the Customer's Terms of Use, except where the DPDP Act or other applicable law prevents such limitation.
10. Precedence
In the event of conflict between this DPA and the Terms of Use on matters of personal data processing, this DPA controls.
Contact us
Simplified Management Private Limited
Viman Nagar, Pune, Maharashtra, India
privacy@simplifiedmanagement.in
