Legal
Privacy Policy
Effective date: October 7, 2026
1. Data We Process
Gandala processes business data including appointments, transactions, staff information, and client records. This data is owned by the workspace Customer and stored in tenant-isolated PostgreSQL schemas with Row-Level Security enforcement.
2. Data Security
Personally identifiable information (PII) stored in profiles is encrypted using AES-256-GCM at rest. Access is gated by Row-Level Security and role-based permissions. All API routes enforce tenant isolation.
3. Data Sharing
We do not sell or share tenant data with third parties beyond the payment gateway (PayMongo) and infrastructure providers required to operate the Platform. Payment processing is handled by PayMongo under their own privacy policy.
4. Data Retention
Tenant data is retained for the duration of the subscription. Upon cancellation, data is soft-deleted and purged after 30 days of inactivity. Active subscriptions maintain full data access.
5. Your Rights
Tenants may request a data export or deletion by contacting support or using the Platform's data request feature. Exported data is provided in standard formats (CSV, JSON).
6. Cookies & Analytics
Gandala uses session cookies for authentication. No third-party analytics or tracking cookies are used on the Platform.
7. Changes
We may update this Privacy Policy from time to time. Material changes will be communicated through the Platform or via email. Continued use after changes constitutes acceptance.