Privacy Notice & Policy
Last updated: 20 August 2026
1. Who we are (Data Fiduciary)
This Privacy Notice & Policy (“Notice”) explains how Casa Rio & Casa Rio CHS Fed. Ltd. (“we”, “us”, “our”), acting as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), processes digital personal data when you use the Casa Rio community website and related digital services (the “Platform”).
This Notice is a standalone disclosure. It is separate from our Terms of Use and is meant to be read on its own so you can give informed consent where consent is required.
Registered address: F Wing, Riverdale, Casa Rio, Kalyan-Shil Road, Dombivli East, Palava City, Maharashtra 421204
Business contact for data questions (Rule 9): Helpdesk / Grievance Officer (designated contact) — +91-89768-58001
Hours: Tuesday to Sunday, 10 AM to 6 PM (except public holidays)
This Notice is provided in English. If you need it in any other language listed in the Eighth Schedule to the Constitution of India, contact the helpdesk above and we will arrange access as reasonably practicable.
2. Scope and how to use this Notice
This Notice applies to personal data we process in connection with:
- Browsing or using the Platform (community information, events, stories, gallery, and related pages)
- Signing in with mobile OTP authentication
- Registering for community events and programmes, including time-slot selection and custom registration answers
- Communications with our helpdesk about the Platform, events, or data rights
- Authorised administrator access (invites, roles, and moderation tools)
It does not replace statutory notices that individual cooperative housing societies (CHS) or other entities may be required to issue under other laws. It covers only processing by Casa Rio & Casa Rio CHS Fed. Ltd. for the Platform.
Communication links for rights and complaints: you may use this Platform (including this page at /privacy and our Terms of Use) and the helpdesk number above to withdraw consent, exercise Data Principal rights, or ask how to complain to the Data Protection Board of India (“Board”).
3. Personal data we collect (itemised)
Depending on how you use the Platform, we may process the following categories of personal data:
- Identity data — full name and any other identity-related fields you submit on an event registration form (for example society / wing, flat or unit reference, age band, or other answers configured for that event)
- Contact data — mobile number (required for OTP sign-in and registrations); email address if you provide it on a form
- Account / authentication data — mobile number in E.164 format, OTP verification status, Firebase Auth unique user identifier (UID), and session / auth tokens managed by our authentication provider
- Event participation data — event identifier, chosen time slot (id and label), registration answers, registration status, and timestamps
- Administrator / invite data — for authorised administrators only: invite status, role or permission flags, and linkage to a verified mobile number
- Organiser application data — when you show interest in registering a standing organiser: the organiser’s full name, chosen public handle, formal email, phone number, registered number, editor names and mobile numbers, and records of your agreement to the Terms of Use and Organiser Terms
- Technical and security data — limited device and security signals needed for OTP / Google reCAPTCHA, fraud and abuse prevention, and service reliability (which may include IP address, user-agent / browser type, and provider security logs)
- Communications data — information you voluntarily share when you contact the helpdesk about the Platform, an event, or a data request
- Content metadata — if an authorised administrator uploads images or media to gallery / stories features, file names, storage paths, and publish status associated with that upload
We do not intentionally seek special categories of sensitive personal data (for example health, biometrics, or financial account numbers) beyond what you choose to type into a free-text registration field. Please avoid submitting unnecessary sensitive information. If an event form asks for optional details, provide only what you are comfortable sharing for that event.
We do not operate payment checkout on the Platform. We do not intentionally collect precise GPS location. We do not currently use third-party advertising cookies or sell personal data.
4. Purposes of processing and services enabled
We process personal data only for these specified purposes. Against each purpose we describe the service or use that processing enables:
- Account access — to create and maintain your signed-in session so you can use account-gated features (for example event registration). Data used: contact and authentication data; technical / security data.
- Event organisation — to accept, store, and manage event registrations, allocate or enforce slot capacity, and coordinate with authorised organisers. Data used: identity, contact, event participation, and (if provided) email / form answers.
- Organiser applications — to receive, review, and (if approved) set up standing organiser teams. Data used: organiser application data; if approved, invite / account data for the organiser contact.
- Service communications — to contact you about your registration, event changes (cancellation, reschedule, slot updates), or helpdesk requests you initiate. Data used: contact data and relevant event / request details.
- Platform operation and security — to host, operate, secure, troubleshoot, and improve the Platform, including OTP / reCAPTCHA checks, abuse prevention, backup, and audit. Data used: authentication, technical / security, and relevant account or registration records.
- Administration — to allow authorised administrators to manage content, events, registrations, and access controls. Data used: administrator / invite data and registration records they are authorised to view.
- Legal compliance and rights — to comply with applicable law, respond to lawful requests, establish or defend legal claims, and respond to Data Principal rights or grievances. Data used: as relevant to the request or obligation.
We do not sell your personal data. We do not use your registration data for unrelated marketing, advertising, or profiling for commercial targeting unless we first give a fresh notice and obtain a separate, specific consent for that purpose.
5. Consent and other lawful grounds
Where the DPDP Act requires consent, we process your personal data based on your free, specific, informed, unconditional, and clear affirmative consent — for example when you submit an event registration, show interest as an organiser, or complete OTP sign-in after this Notice (or a short consent summary linking here) has been made available.
Consent for one purpose is not treated as consent for another unrelated purpose. You may refuse consent; if you do, we may be unable to provide the related service (for example registration or account access).
Separately, we may process certain personal data for legitimate uses recognised under the DPDP Act (including where processing is necessary for compliance with any law for the time being in force, for employment or similar organisational purposes applicable to authorised staff / office-bearers, for medical emergency or disaster situations if ever applicable, or other uses expressly permitted by the Act and rules), to the extent those grounds apply. Where we rely on a legitimate use, we will still honour applicable rights and safeguards under the Act.
6. How to withdraw consent
You may withdraw consent at any time with ease comparable to giving it:
- Call or message the helpdesk at the number above and state that you withdraw consent for Platform / event processing, quoting the mobile number used for OTP or registration
- For a specific event registration, ask us to cancel that registration and erase related registration data where no lawful retention need applies
- Delete your account from Profile, or call or message the helpdesk to deactivate or delete your Platform account after identity verification
Withdrawal does not affect processing completed lawfully before withdrawal. After withdrawal we will stop processing for the consented purpose(s), except where we must retain or process data to comply with law, resolve disputes, or meet security / audit obligations (including minimum log retention under the DPDP Rules). Withdrawal may mean we can no longer keep an active registration or signed-in account.
7. Sharing, Data Processors, and recipients
We use trusted service providers (Data Processors) to host and operate the Platform on our instructions. We do not allow them to use your personal data for their own unrelated purposes.
Major recipients / processors include:
- Google Firebase / Google Cloud (Google LLC and its affiliates) — authentication (Firebase Auth / phone OTP), database (Cloud Firestore), file storage (Firebase Storage), and related security features including reCAPTCHA
- Authorised Casa Rio organisers, office-bearers, and administrators — limited access to registration and operational data needed to run events and manage the Platform
- Professional advisers or service providers (for example IT, legal, or audit support) — only under confidentiality and need-to-know arrangements when required
- Courts, regulators, law-enforcement, or other authorities — when required by applicable law or lawful process
If we engage additional processors that materially change how your data is handled, we will update this Notice and, where required, seek fresh consent.
8. Cross-border transfer
Our processors (in particular Google Firebase / Google Cloud) may store or process personal data on infrastructure located outside India.
Where such transfer occurs, we rely on applicable Indian law, including the DPDP Act and DPDP Rules (including any notified restricted territory list and contractual / platform safeguards). We will not transfer personal data to a country or territory that is restricted by the Central Government for such transfers, except as permitted by law.
9. Retention and erasure
We keep personal data only for as long as needed for the purposes above, or as required by law. Indicative periods:
- Account / authentication records — while your account remains active; after last meaningful use or upon verified deletion request, we deactivate access and erase or anonymise identity data when no longer needed, subject to the log-retention rules below
- Event registrations — for the event cycle and up to 24 months afterward for organising, resident queries, audit, and dispute handling, unless you request earlier erasure and no legal retention need applies
- Helpdesk / grievance communications — typically up to 24 months after closure of the request, or longer if needed for an ongoing dispute or legal requirement
- Administrator invite / role records — while the person remains authorised, then for a reasonable wind-down period for security and audit
- Security, traffic, and processing logs — retained for a minimum of one (1) year from the relevant processing, as required under the DPDP Rules for detection, investigation, remediation, and related purposes specified in law, unless a longer period is required by another law
When retention is no longer necessary, we delete or anonymise the data where reasonably practicable (including instructing processors where applicable). Backups may take a short additional period to rotate.
If a class of processing becomes subject to a prescribed inactivity-based erasure timeline under the DPDP Rules, we will inform affected Data Principals at least 48 hours before erasure, as required, so they can renew engagement or exercise rights.
10. Security safeguards
We implement reasonable technical and organisational measures appropriate to the nature of the data and our processing, aligned with Rule 6 of the DPDP Rules, including where applicable:
- Encrypted transit (HTTPS) for the Platform
- Authentication and access controls for administration
- Provider security features (including OTP verification and reCAPTCHA)
- Need-to-know access for organisers and administrators
- Logging / monitoring measures aimed at detecting and investigating unauthorised access
- Contractual expectations that processors apply reasonable security safeguards
No method of transmission or storage is completely secure. Please protect your OTP, device, and any shared screens. You must not share OTPs with anyone claiming to represent us unless you initiated the contact through official channels.
11. Personal data breach
If we become aware of a personal data breach, we will, to the best of our knowledge and as required under the DPDP Act and Rules:
- Intimate affected Data Principals without delay, in clear language, including the nature, extent, and timing of the breach; likely consequences; mitigation measures; recommended safety steps; and a contact for queries
- Intimate the Data Protection Board of India without delay and provide further details within the timelines prescribed (including the 72-hour follow-up where applicable)
12. Your rights as a Data Principal
Subject to the DPDP Act and applicable rules, you may:
- Right to access information — seek a summary of personal data being processed and of processing activities
- Right to correction and updating — request correction of inaccurate or incomplete personal data
- Right to erasure — request erasure of personal data that is no longer necessary for the stated purpose, subject to lawful retention needs (including mandatory log retention)
- Right to withdraw consent — where processing is based on consent, as described above
- Right of grievance redressal — raise a grievance with us about our processing
- Right to nominate — nominate another individual to exercise rights in the event of your death or incapacity, in the manner prescribed under the Act / Rules
How to exercise rights: contact Helpdesk / Grievance Officer (designated contact) at +91-89768-58001. Please state (1) which right you wish to exercise, (2) the mobile number linked to your account or registration, and (3) enough detail for us to locate your records. We may need to verify your identity (and, for a nominee, the nomination / authority) before acting. We will respond within the timelines prescribed by law and, where no specific timeline applies, within a reasonable period.
13. Duties of the Data Principal
Under the DPDP Act, you also have duties, including to not impersonate another person, not suppress material information while providing personal data for a document / registration / authentication, and not register a false or frivolous grievance or complaint. Misuse may attract consequences under applicable law and may lead to suspension of Platform access under our Terms of Use.
14. Grievance redressal
Grievance contact: Helpdesk / Grievance Officer (designated contact)
Phone: +91-89768-58001
Address: F Wing, Riverdale, Casa Rio, Kalyan-Shil Road, Dombivli East, Palava City, Maharashtra 421204
Hours: Tuesday to Sunday, 10 AM to 6 PM (except public holidays)
We will acknowledge grievances as soon as practicable (and aim to do so within 72 hours of receipt during working hours) and endeavour to resolve them within 30 days, or sooner where a shorter period is mandated by applicable law or rules (including any IT Rules timelines that apply to intermediary-style content complaints).
If you remain dissatisfied after exhausting our grievance process, you may escalate a complaint to the Data Protection Board of India in the manner prescribed under the DPDP Act and Rules (including any portal or process notified by the Board). Ask our helpdesk if you need pointers to the then-current Board complaint channel.
15. Children and persons with disability
The Platform is intended for adult residents and authorised community users (18 years or older). We do not knowingly offer Platform account or registration features to children. Processing personal data of a child requires verifiable consent of a parent or lawful guardian as mandated by the DPDP Act and Rules, and is subject to additional restrictions (including prohibitions on tracking / behavioural monitoring and targeted advertising directed at children).
If you believe a child’s data was submitted in error, contact us for deletion. For persons with disability who require lawful guardian support under applicable law, we will accept verifiable guardian consent and communications as prescribed.
16. Cookies, local storage, and similar technologies
The Platform and its processors may use strictly necessary cookies, local storage, or similar technologies to keep you signed in, complete OTP / reCAPTCHA checks, and remember basic UI preferences. These are used to operate the service securely, not for third-party advertising.
You can control cookies through your browser settings. Blocking essential cookies may prevent sign-in or registration from working.
17. Changes to this Notice
We may update this Notice from time to time. The “Last updated” date at the top will change when we do.
For material changes — such as new categories of personal data, new purposes, or new categories of third-party sharing — we will provide reasonable advance notice through the Platform (for example a banner or updated consent text) and, where we have a usable contact on file and the law requires, through that contact. Where a change requires fresh consent, we will seek it before relying on the new processing. Continued use after non-material clarifications become effective constitutes acknowledgment of the updated Notice.
18. Contact
Casa Rio & Casa Rio CHS Fed. Ltd.
F Wing, Riverdale, Casa Rio, Kalyan-Shil Road, Dombivli East, Palava City, Maharashtra 421204
Helpdesk: +91-89768-58001
For data questions or grievances, ask for Helpdesk / Grievance Officer (designated contact) at +91-89768-58001.