Trust, Security & Data Privacy at ADDA
Protecting Your Data, Privacy, and Trust.
ADDA is well known in the Indian CommunityTech Segment, for its commitment to Data Privacy. Unlike other companies in this segment, ADDA has stayed true to the SaaS model, avoiding Business Models that leverage User data.
At ADDA, trust is not a marketing statement. It is the foundation of how our platform is designed, how our business operates, and how we build long-term relationships with housing societies, apartment communities, and management committees.

Built on the Highest Standards of Security
ADDA follows globally recognised security practices to protect community data against unauthorised access, misuse, and cyber threats. Security is built into the platform's architecture, infrastructure, and operating processes.
Key security measures implemented across ADDA include:
Strong encryption for data in transit and at rest, ensuring resident data, documents, conversations, and financial records remain protected at all times.
Continuous infrastructure monitoring to detect, prevent, and respond to security threats.
Layered security controls designed to ensure availability, integrity, and confidentiality of data.
Certified for Global Compliance
Compliance at ADDA is proactive and ongoing. Our systems and processes are aligned with recognised global standards and Indian regulatory requirements to ensure responsible handling of personal and community data.

ISO/IEC 27001:2022 Certification
Validating that ADDA maintains an audited Information Security Management System (ISMS) covering risk management, access control, incident response, and continuous improvement.
Issued
June 17, 2025
Valid Till
June 16, 2028
Cert No.
25RN06EV

Digital Personal Data Protection (DPDP) Act Certification
Confirming alignment with India's DPDP Act through documented policies, processes, and governance controls.
Issued
10 Jan, 2026
Valid Till
09 Jan, 2027
Cert No.
TT2026003D
Independent Security Validation
Awarded after successful third-party security audits conducted by independent cybersecurity experts.
These certifications require periodic audits and reviews, ensuring that compliance is continuously maintained rather than treated as a one-time exercise.
Frequent VAPT & Security Audits
ADDA conducts regular security testing to identify and address potential vulnerabilities before they can be exploited.
This includes:
- Internal Vulnerability Assessment and Penetration Testing (VAPT) conducted at least once every month.
- Annual third-party security audits performed by independent cybersecurity experts.
The findings from these assessments are tracked, remediated, and reviewed as part of ADDA's ongoing security governance program.
Controlled Access & Credential Protection
Safeguarding community data also requires strict control over who can access it and under what conditions.
ADDA enforces:
- Role-based access controls, ensuring that data access is limited strictly to authorised personnel.
- Access to user data is controlled through script access management. They are logged and monitored.
- Mandatory security training and non-disclosure agreements for employees handling sensitive information.
Unless unavoidable, customer support is delivered through guided workflows or screen-sharing, reducing the need for direct data access.
Backup & Disaster Recovery
ADDA maintains defined backup and disaster recovery processes to ensure data availability and business continuity.
Data Backup and Recovery
These include:
- Daily backups for critical systems, including payment-related data.
- Periodic backups for non-critical systems as per documented policies.
- Encrypted backup storage using Amazon Glacier for long-term durability.
ADDA maintains a maximum 24-hour Recovery Point Objective (RPO), ensuring minimal data loss in the event of a system failure or incident.
Hosted on AWS – Secure Cloud Infrastructure
ADDA's infrastructure is hosted entirely on Amazon Web Services (AWS), a globally trusted cloud platform.
AWS provides:
- Built-in DDoS protection and network-level security controls.
- Encryption at rest and in transit.
- Continuous threat detection using services such as GuardDuty.
- Detailed audit logging through CloudTrail.
- 24×7 infrastructure monitoring and auto-scaling for performance and uptime.
AWS infrastructure used by ADDA aligns with internationally recognised standards including ISO 27017, ISO 27701, and ISO 27018.
Secure Payment Processing
ADDA enables secure online payments through trusted, PCI-DSS compliant payment gateways.
ADDA integrates with providers such as Razorpay, Cashfree, Stripe, PayFort, and Braintree. All payment data is encrypted and transmitted only through secure, validated channels, and ADDA does not store sensitive card or banking information on its systems.
A Clear Philosophy: Subscription SaaS, Not Advertising
Many digital platforms operate advertising-driven business models that rely on user data to generate revenue. Such models inherently require access to personal information and usage patterns.
ADDA follows a different approach. Our business is based entirely on software subscriptions paid by communities. This means:
- ADDA has no commercial incentive to monetise resident or community data.
For Indian Management Committees: Risk, Responsibility & Choice
Management Committees in India, today carry a heightened responsibility when it comes to resident data. Under evolving data protection laws such as India's DPDP Act, committees are expected to exercise due care in how personal data is collected, processed, and shared through technology platforms.
Choosing a community management platform is therefore not just a technology decision—it is a risk decision. Advertising-led platforms inherently depend on resident data to sustain their business models, which can increase long-term privacy and compliance exposure for committees.
ADDA's subscription-based SaaS model is deliberately designed to minimise this risk. Because ADDA does not rely on advertising revenue, resident data is used strictly for legitimate community operations, helping Management Committees meet their governance and compliance responsibilities with greater confidence.
Your Data Belongs to You. Always.
ADDA believes that communities must retain full control over their data.
- Data processing follows principles of purpose limitation and data minimisation.
- Data retention and access are governed by documented policies aligned with legal and operational requirements.
Our platform is designed to provide transparency, accountability, and peace of mind for both management committees and residents.
Transparency, Accountability & Ongoing Commitment
Cybersecurity threats and data protection regulations continue to evolve. ADDA regularly reviews and strengthens its policies, controls, and technical safeguards to stay aligned with regulatory requirements and emerging risks.
