1. Why this document exists
When a hotel puts its guests' names, phone numbers and identity documents into Digilight PMS, the hotel decides what happens to that data and Digilight India merely acts on its instructions.
Under the Digital Personal Data Protection Act 2023 ("DPDP Act") the hotel is the Data Fiduciary and Digilight India is its Data Processor, and the Act requires that relationship to be governed by a contract.
This addendum is that contract. It forms part of the Terms of Service and applies automatically to every subscriber — there is nothing to sign and nothing to request.
2. Definitions
Data Fiduciary, Data Processor, Data Principal, Personal Data, Processing and Personal Data Breach carry the meanings given to them in the DPDP Act. For subscribers whose auditors expect the equivalents, Data Fiduciary is comparable to a Controller and Data Principal to a Data Subject. Guest Data means personal data about the Subscriber's guests, entered into the Service by the Subscriber. Sub-processor means a third party we engage to process Guest Data.
3. The roles, stated exactly
3.1 The hotel is the Data Fiduciary
You decide why guest data is collected and what is done with it. You are responsible for having a lawful basis to hold it, and for giving your guests whatever notice the law requires. See your warranty at Terms §9.1.
3.2 Digilight India is the Data Processor
We process Guest Data only on your documented instructions — which, in the ordinary course, are the instructions you give by using the product's features.
3.3 Where we are a Fiduciary in our own right
For your own account data — your staff, their logins, your billing records — and for the records we generate ourselves, such as audit and security logs, Digilight India decides the purposes and is therefore a Data Fiduciary. The Privacy Policy governs that data.
4. Scope of processing
- Subject matter: provision of the Digilight PMS hotel management service.
- Duration: the term of the subscription, plus any retention period agreed at §11.
- Nature and purpose: as set out at §5.
- Categories of Data Principal: your guests, and your own staff.
- Categories of personal data: as enumerated in Privacy Policy §3 — including, today, identity-document numbers.
5. What we do with the data
We store bookings and stays; produce invoices; run the reports you ask for; send the communications you trigger; back the data up; and provide support when you ask for it.
We do not sell it, share it for advertising, or use it to train machine-learning models. No AI or LLM service is integrated into Digilight PMS.
6. Support access
Digilight India's staff can enter your account to provide support. We are telling you this rather than letting you discover it, because concealing a capability that demonstrably exists in the software would be the single most damaging thing this document could do.
The safeguards are built into the mechanism, not promised in prose:
- A support session is time-limited to 30 minutes.
- It requires a written reason, recorded before access begins.
- It can be revoked at any time.
- It is logged, including who accessed the account and why.
7. Sub-processors
You give a general authorisation for Digilight India to engage the sub-processors below. Each sub-processor we contract with is bound to obligations no less protective than those in this addendum.
| Sub-processor | What it does | Where it runs |
|---|---|---|
| Vercel | Application hosting and scheduled jobs | Singapore |
| Neon | Managed PostgreSQL — where Guest Data is stored | Singapore |
| Resend | Transactional email | To be confirmed |
| Razorpay | Subscription payments (not yet enabled) | India |
| OpenStreetMap Foundation | Map tiles on one screen, loaded by the browser | To be confirmed |
| Cloudflare | Map marker icons on the same screen | To be confirmed |
| Overpass API | Nearby-hotel lookup for the same screen, server-side | To be confirmed |
The last three serve a single optional map screen. We will give subscribers at least 30 days' notice before engaging a new sub-processor that processes Guest Data. You may object on reasonable data-protection grounds; we will work with you in good faith to address the objection, and if we cannot, you may terminate the affected subscription as your remedy. This list may change over time; the current sub-processor list published by Digilight India in this addendum is the authoritative version.
8. Cross-border transfer
The application and the database both run in Singapore, so Guest Data — including guests' identity-document numbers — is processed outside India. This is a matter of fact taken from the deployment configuration, and it engages the cross-border transfer provisions of the DPDP Act (s.16). We disclose it here plainly so that you can meet your own obligations as Data Fiduciary. If the Central Government restricts transfers to Singapore, or if we move Guest Data to a different region, we will update this addendum and notify subscribers before the change takes effect.
9. Personal data breach
If Guest Data is exposed, we will notify you without undue delay after we become aware of it, and in any event within 72 hours, and give you what you need to meet your own notification duties to the Data Protection Board and to your guests. Our notice will set out, so far as we know it at the time, what happened, the data affected, and the steps we are taking in response.
10. Our obligations as Processor
We will: process Guest Data only on your instructions; keep it confidential and bind our staff to confidentiality; apply the security measures described in the Security Policy; assist you in responding to your guests' rights requests; assist you with breach notification; and make available the information you need to demonstrate compliance.
11. Return and deletion
At the end of a subscription, you keep read access to your records — check-in, check-out, billing and payment collection continue to work — and your data is not deleted automatically. Bulk data export is available on the Growth plan and above.
On your written request, and in any event within 30 days of it, we will make your Guest Data available to you as an export and then delete it from our live systems, except records we are required by law to keep — principally invoice and tax records, which Indian tax law requires us to retain for several years and which we delete when that period ends. Backup copies are overwritten on our provider's normal backup cycle. See Privacy Policy §9.
12. Liability
The limitation of liability in Terms §14 applies to this addendum, and each party's liability under it counts towards the single aggregate cap set out in those terms. Nothing in this addendum limits any liability that cannot be limited under Indian law.
13. Audits
You may ask us for a written summary of the security measures described in the Security Policy, and we will provide one within a reasonable period. We do not currently hold a third-party audit report or certification (see Security Policy §2). Enterprise subscribers who need a fuller audit may agree further audit arrangements with us in writing, on reasonable notice and no more than once a year.
14. Order of precedence
Where this addendum and the Terms of Service conflict, this addendum prevails in respect of the processing of Guest Data.
15. Contact us
- Business: Digilight India
- Product: Digilight PMS
- Website: www.digilightpms.com
- Support email: support@digilightpms.com
- WhatsApp: +91 95488 38588
- Support hours: Monday to Saturday, 10:00 AM – 6:00 PM IST
- Business address: Meerut, Uttar Pradesh, India