Legal

Privacy Policy

Effective date: October 7, 2026

1. Data We Process

Gandala processes business data including appointments, transactions, staff information, and client records. This data is owned by the workspace Customer and stored in tenant-isolated PostgreSQL schemas with Row-Level Security enforcement.

2. Data Security

Personally identifiable information (PII) stored in profiles is encrypted using AES-256-GCM at rest. Access is gated by Row-Level Security and role-based permissions. All API routes enforce tenant isolation.

3. Data Sharing

We do not sell or share tenant data with third parties beyond the payment gateway (PayMongo) and infrastructure providers required to operate the Platform. Payment processing is handled by PayMongo under their own privacy policy.

4. Data Retention

Tenant data is retained for the duration of the subscription. Upon cancellation, data is soft-deleted and purged after 30 days of inactivity. Active subscriptions maintain full data access.

5. Your Rights

Tenants may request a data export or deletion by contacting support or using the Platform's data request feature. Exported data is provided in standard formats (CSV, JSON).

6. Cookies & Analytics

Gandala uses session cookies for authentication. No third-party analytics or tracking cookies are used on the Platform.

7. Changes

We may update this Privacy Policy from time to time. Material changes will be communicated through the Platform or via email. Continued use after changes constitutes acceptance.