Trust Center

Trust, Security & Data Privacy at ADDA

Protecting Your Data, Privacy, and Trust.

ISO 27001:2022
DPDP Aligned
AWS Hosted
No Ad Tracking
Why ADDA

ADDA is well known in the Indian CommunityTech Segment, for its commitment to Data Privacy. Unlike other companies in this segment, ADDA has stayed true to the SaaS model, avoiding Business Models that leverage User data.

At ADDA, trust is not a marketing statement. It is the foundation of how our platform is designed, how our business operates, and how we build long-term relationships with housing societies, apartment communities, and management committees.

ADDA community trust and certifications
Security

Built on the Highest Standards of Security

ADDA follows globally recognised security practices to protect community data against unauthorised access, misuse, and cyber threats. Security is built into the platform's architecture, infrastructure, and operating processes.

Key security measures implemented across ADDA include:

Strong encryption for data in transit and at rest, ensuring resident data, documents, conversations, and financial records remain protected at all times.

Continuous infrastructure monitoring to detect, prevent, and respond to security threats.

Layered security controls designed to ensure availability, integrity, and confidentiality of data.

Certifications

Certified for Global Compliance

Compliance at ADDA is proactive and ongoing. Our systems and processes are aligned with recognised global standards and Indian regulatory requirements to ensure responsible handling of personal and community data.

ISO/IEC 27001:2022 Certification

ISO/IEC 27001:2022 Certification

Validating that ADDA maintains an audited Information Security Management System (ISMS) covering risk management, access control, incident response, and continuous improvement.

Issued

June 17, 2025

Valid Till

June 16, 2028

Cert No.

25RN06EV

Digital Personal Data Protection (DPDP) Act Certification

Digital Personal Data Protection (DPDP) Act Certification

Confirming alignment with India's DPDP Act through documented policies, processes, and governance controls.

Issued

10 Jan, 2026

Valid Till

09 Jan, 2027

Cert No.

TT2026003D

Independent Security Validation

Awarded after successful third-party security audits conducted by independent cybersecurity experts.

These certifications require periodic audits and reviews, ensuring that compliance is continuously maintained rather than treated as a one-time exercise.

Audits

Frequent VAPT & Security Audits

ADDA conducts regular security testing to identify and address potential vulnerabilities before they can be exploited.

This includes:

  • Internal Vulnerability Assessment and Penetration Testing (VAPT) conducted at least once every month.
  • Annual third-party security audits performed by independent cybersecurity experts.

The findings from these assessments are tracked, remediated, and reviewed as part of ADDA's ongoing security governance program.

Access

Controlled Access & Credential Protection

Safeguarding community data also requires strict control over who can access it and under what conditions.

ADDA enforces:

  • Role-based access controls, ensuring that data access is limited strictly to authorised personnel.
  • Access to user data is controlled through script access management. They are logged and monitored.
  • Mandatory security training and non-disclosure agreements for employees handling sensitive information.

Unless unavoidable, customer support is delivered through guided workflows or screen-sharing, reducing the need for direct data access.

Resilience

Backup & Disaster Recovery

ADDA maintains defined backup and disaster recovery processes to ensure data availability and business continuity.

Data Backup and Recovery

These include:

  • Daily backups for critical systems, including payment-related data.
  • Periodic backups for non-critical systems as per documented policies.
  • Encrypted backup storage using Amazon Glacier for long-term durability.

ADDA maintains a maximum 24-hour Recovery Point Objective (RPO), ensuring minimal data loss in the event of a system failure or incident.

Infrastructure

Hosted on AWS – Secure Cloud Infrastructure

ADDA's infrastructure is hosted entirely on Amazon Web Services (AWS), a globally trusted cloud platform.

AWS provides:

  • Built-in DDoS protection and network-level security controls.
  • Encryption at rest and in transit.
  • Continuous threat detection using services such as GuardDuty.
  • Detailed audit logging through CloudTrail.
  • 24×7 infrastructure monitoring and auto-scaling for performance and uptime.

AWS infrastructure used by ADDA aligns with internationally recognised standards including ISO 27017, ISO 27701, and ISO 27018.

Payments

Secure Payment Processing

ADDA enables secure online payments through trusted, PCI-DSS compliant payment gateways.

ADDA integrates with providers such as Razorpay, Cashfree, Stripe, PayFort, and Braintree. All payment data is encrypted and transmitted only through secure, validated channels, and ADDA does not store sensitive card or banking information on its systems.

Philosophy

A Clear Philosophy: Subscription SaaS, Not Advertising

Many digital platforms operate advertising-driven business models that rely on user data to generate revenue. Such models inherently require access to personal information and usage patterns.

ADDA follows a different approach. Our business is based entirely on software subscriptions paid by communities. This means:

  • ADDA has no commercial incentive to monetise resident or community data.
Governance

For Indian Management Committees: Risk, Responsibility & Choice

Management Committees in India, today carry a heightened responsibility when it comes to resident data. Under evolving data protection laws such as India's DPDP Act, committees are expected to exercise due care in how personal data is collected, processed, and shared through technology platforms.

Choosing a community management platform is therefore not just a technology decision—it is a risk decision. Advertising-led platforms inherently depend on resident data to sustain their business models, which can increase long-term privacy and compliance exposure for committees.

ADDA's subscription-based SaaS model is deliberately designed to minimise this risk. Because ADDA does not rely on advertising revenue, resident data is used strictly for legitimate community operations, helping Management Committees meet their governance and compliance responsibilities with greater confidence.

Ownership

Your Data Belongs to You. Always.

ADDA believes that communities must retain full control over their data.

  • Data processing follows principles of purpose limitation and data minimisation.
  • Data retention and access are governed by documented policies aligned with legal and operational requirements.

Our platform is designed to provide transparency, accountability, and peace of mind for both management committees and residents.

Commitment

Transparency, Accountability & Ongoing Commitment

Cybersecurity threats and data protection regulations continue to evolve. ADDA regularly reviews and strengthens its policies, controls, and technical safeguards to stay aligned with regulatory requirements and emerging risks.

Got questions?

Frequently Asked Questions

For questions related to data security, privacy, or compliance, communities may reach out to: