Privacy by Design
Privacy is not an add-on to AccessHub — it is built into the architecture. Every data handling decision starts with the question: what gives residents the most control?

ADDA AccessHub is built around one belief — residents should never have to choose between security and privacy. You get both. By design, not by accident.
Our Philosophy
Most access control systems collect biometric data, store it on local devices, and never give residents any visibility or control over what happens to it. Paper consent forms are signed and filed away. Data sits on devices indefinitely. Residents have no way to know what is stored, where it is stored, or how to remove it.
ADDA AccessHub is built on the opposite principle. Residents control their biometric data — not the community management, not the technology vendor. Every collection, every use, and every deletion of biometric data is transparent, consent-driven, and resident-initiated.

Privacy is not an add-on to AccessHub — it is built into the architecture. Every data handling decision starts with the question: what gives residents the most control?
Residents always know what data is held about them, where it is active, and how it is being used. No hidden data collection. No silent activations.
No biometric data is collected without explicit, informed, resident-initiated consent. The community cannot override a resident's data decision.
Your Rights
ADDA AccessHub is built to give every resident full exercise of their data rights — not as a compliance checkbox, but as a genuine feature of the platform.
You decide whether your biometric is collected. No one else — not the Management Committee, not the property manager — can activate biometric collection on your behalf.
You can see exactly what biometric data is held about you and which access points it is active on — from the ADDA app, at any time.
You can update your biometric registration at any time — if you want to re-register or update your face data, you do it yourself from the ADDA app.
You can delete your biometric data at any time. One action in the ADDA app — data deleted from every server and device immediately and permanently.
Every consent action — activation, review, update, withdrawal — is logged with a timestamp. You can request a complete history of your biometric data interactions.
Compliance & Certifications
Privacy and data protection regulations are tightening worldwide — India's DPDP Act, Europe's GDPR, and equivalent frameworks across the Middle East and Asia-Pacific all place specific obligations on organisations that collect and process personal data, including biometrics. ADDA AccessHub is built to meet and exceed these requirements — not just in one market, but across every geography where our communities operate.

Biometric activation requires explicit, informed, resident-initiated consent — meeting the requirements of DPDP, GDPR, and equivalent frameworks for lawful data processing.
Biometric data collected through AccessHub is used only for access control — never for any other purpose, never shared, never repurposed. A requirement under both DPDP and GDPR.
Only the data necessary for access control is collected — and only for as long as the resident's access is active. No indefinite retention. Compliant with global data minimisation principles.
Residents can exercise their data rights — access, correction, deletion, and grievance — through ADDA's built-in mechanisms. Structured to meet obligations under DPDP, GDPR, and regional equivalents.
Other Data We Handle
ADDA AccessHub handles more than biometric data — it processes access logs, visitor records, staff entry data, and community usage patterns. Each data type is handled with the same principle: collect only what is needed, protect it completely, and give communities full control over it.
Entry and exit logs are stored securely on the ADDA platform. Access is limited to authorised Management Committee members. Logs are retained for a defined period and can be exported or deleted by the community at any time.
Visitor data collected through ADDA Gatekeeper — name, phone, purpose, entry and exit times — is owned by the community, not by ADDA. It is never used for advertising, profiling, or any commercial purpose.
Resident and staff profile data in ADDA is used solely for community management — access control, communication, and billing. It is never shared with third parties or used beyond its stated purpose.
ADDA's Business Model
ADDA's revenue comes entirely from software subscription fees paid by communities. We do not run ads. We do not sell resident data. We do not allow third-party advertisers access to the ADDA platform or to resident attention.
This is not a policy we adopted recently — it is the business model ADDA was built on since 2009. Communities that choose ADDA choose a platform whose commercial interests are fully aligned with their residents' privacy.
ADDA is a profitable company whose revenue comes entirely from software subscriptions — not from advertising or data monetisation.
No advertiser has ever paid to reach residents through the ADDA platform. No resident has ever been targeted with ads based on their community data.
All data generated on the ADDA platform — access logs, visitor records, billing data, communications — belongs to the community. ADDA is the custodian, not the owner.
Talk to our team — we are happy to walk you through our data handling practices, compliance certifications, and privacy architecture in detail.
Explore Technology →