EstateDeck Visitor Management turns the paper register into a real verified-entry workflow — resident pre-approval from the app, OTP confirmation, photo capture at the gate, Aadhaar masked per UIDAI circular, and a shareable WhatsApp gate pass.
DPDP Act 2023-ready · UIDAI Aadhaar masking · Number masking · §65B-admissible log · Event-mode bulk passes.
EstateDeck Visitor Management is the gate-level visitor workflow for Indian housing societies, RWAs, and apartment owners' associations. Residents pre-approve expected visitors from the app; on arrival, the guard captures the visitor's photo, captures their Aadhaar in masked form (XXXX-XXXX-1234) per UIDAI Circular K-11020/217/2018-UIDAI, sends an OTP to the resident, and on approval generates a digital gate pass. Guard-to-resident calls are routed through the EstateDeck server so the resident's mobile number is never exposed — honouring the right to privacy recognised in Justice K.S. Puttaswamy v Union of India 2017. Every entry-and-exit record is preserved under IT Act 2000 §65B with DPDP Act 2023 §6 notice and consent.
Anjali Mehta is visiting Flat C-1204 at Mahaveer Tulip Residency. The hosts pre-approved her at lunch. Here's every event from pre-approval creation to exit stamp — including the UIDAI-masked Aadhaar moment, the OTP dispatch, and the DPDP §6 consent.
| Time | Event | Status |
|---|---|---|
| Mon 13:42 | Resident creates pre-approval: Anjali Mehta · Tue 18:30-19:30 · Lunch guest | ▶ Pre-approved |
| Mon 13:42 | Shareable invite link generated · WhatsApp pre-write composed | ✓ Link ready |
| Tue 18:47 | Visitor at Tower C gate · Guard taps "Match pre-approval" | ↗ Arrived |
| Tue 18:47 | Guard captures visitor photo · Visitor consents to DPDP §6 notice | ✓ Photo + consent |
| Tue 18:48 | Aadhaar scanned · Stored as XXXX-XXXX-4421 (last 4 only) per UIDAI | ✓ Masked Aadhaar |
| Tue 18:48 | OTP push to resident app + IVR call routed via server (number masked) | ↗ OTP sent |
| Tue 18:49 | Resident sees photo + pre-approval match + taps Approve | ✓ Approved |
| Tue 18:49 | Digital gate pass generated · Entry stamp logged · Tower C lift unlocked | ✓ Entry |
| Tue 20:34 | Exit stamp captured at Tower C gate | ✓ Exit |
| Tue 20:34 | Total stay: 1 hr 45 min · Record sealed · §65B-admissible | ✓ Sealed |
| Tue 20:35 | Resident's mobile number never exposed to guard or visitor | → Puttaswamy 2017 |
The register says Mr Sharma visited Flat 1204 at 19:30. Which Sharma? Which 1204 — Tower A, B, or C? The guard wrote what he heard. Audit trail: zero. Accountability: zero.
Resident phone numbers sit in the guard register, visible to every shift change, every visitor with a glance at the desk. Six months in, your number is in three WhatsApp groups you didn't join.
The guard insists on a "photo ID copy." A Xerox of your visitor's full Aadhaar sits in a drawer that anyone can open. UIDAI explicitly prohibits this. The society liability is real.
The guard calls four times in twenty minutes. You're in the kitchen. Two guests are waiting in the rain. The party started without you because you were on the intercom.
EstateDeck splits gate-related work into specialised modules with clean boundaries. Visitor Management owns the one-off visitor entry workflow — anything that's not a one-off visitor is somewhere else.
Tell the gate they're coming. The intercom goes silent.
Fifty wedding guests. Fifty passcodes. One WhatsApp share.
Last 4 digits only. Never the full number. Per UIDAI circular, not optional.
App push for the connected. Phone call for the offline. No resident left out.
Your number stays yours. The guard never gets it.
First visit: the visitor sees what's collected, agrees, and we remember.
A minor cannot walk out alone unless a parent says so.
Patterns the Hon. Secretary needs to see. Without seeing names.
EstateDeck Visitor Management is in production with three distinct gate patterns. The workflow flexes; the audit log stays the same.
One gate, two shifts, a steady stream of one-off visitors — food delivery, family, friends. Pre-approval + OTP handles 90% of entries in seconds. The Hon. Secretary uses the monthly committee report to spot late-night anomalies.
Main gate plus per-tower secondary entries. Multi-family approval routing matters because someone is always at home. Event-mode bulk passes used 4-6 times a month for cultural and family events. Number masking is a hard requirement.
Heavy contractor visits for snag-list fixes. Vendor visitor flag auto-routes carpenter, electrician, painter records to Vendor Management. Each contractor visit becomes an audit-friendly record for the defect-liability claim later.
The Unique Identification Authority of India circular K-11020/217/2018 specifies that entities holding Aadhaar information must mask the first 8 digits and display only the last 4. EstateDeck stores only the masked form (XXXX-XXXX-1234) — full Aadhaar never enters our database. This eliminates the society's liability exposure under the Aadhaar Act 2016.
The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act 2016, Section 29, restricts the sharing and use of Aadhaar number and biometric information. Housing societies are not authorised users of full Aadhaar. EstateDeck's masking approach keeps the society on the right side of this restriction.
The Digital Personal Data Protection Act 2023 (Phase I notified 13 Nov 2025; full compliance window 13 May 2027) requires notice and consent before processing personal data. EstateDeck captures DPDP §6 consent at the visitor's first visit with a one-screen notice — purpose, retention, access — and persists it for subsequent visits.
The 9-judge Supreme Court bench in Justice K.S. Puttaswamy (Retd.) v Union of India 2017 recognised the right to privacy as a constitutional fundamental right under Article 21. EstateDeck's number masking, masked Aadhaar storage, and DPDP §6 consent flow are designed to honour this right at the gate — where it would otherwise be most casually violated.
Section 65B of the Information Technology Act 2000 governs the admissibility of electronic records in Indian courts. Every visitor entry, exit timestamp, photo, OTP delivery, and approval action in EstateDeck Visitor Management is preserved as §65B-compliant electronic evidence — admissible at police investigation, society dispute resolution, or insurance claim.
State-specific Apartment Ownership Acts (Maharashtra AOA 1970, West Bengal AOA 1972, Karnataka AOA 1972, TN AOA 1994, Delhi AOA 1986, UP Apartment Act 2010, Haryana AOA 1983) and registered society bye-laws frequently require visitor logging as part of resident-safety obligations. EstateDeck's log structure satisfies these requirements for AOAs and CHSes across India.
"I took over the Security & Vigilance portfolio in 2024 and the first thing I discovered was a drawer behind the guard desk with about three hundred Aadhaar photocopies in it. Visitors from the last six months. The previous arrangement was 'show ID, we'll Xerox it for the records.' Nobody on the committee had thought about UIDAI's masking circular, or about what would happen if that drawer was photographed. We moved to EstateDeck the next month. Fourteen months in: zero Aadhaar copies anywhere, last four digits only on every record, ninety-two thousand visitor entries logged with photo and OTP, zero phone numbers leaked. The DPDP Act phase-one came in November '25 and we were already compliant. The Hon. Auditor at our AGM in March specifically called out the visitor log as the cleanest record he'd seen in a Noida AOA."
| What you need at the gate | Paper register | Basic visitor app | EstateDeck VMS |
|---|---|---|---|
| Pre-approval before arrival | None | Sometimes | One-tap + regular list + bulk |
| Resident phone number safe | Open to everyone | Visible to guard | End-to-end masked |
| Aadhaar handling | Xerox in drawer | Full number stored | Last 4 digits only (UIDAI) |
| OTP / IVR for offline residents | Phone call to landline | App only | App + IVR fallback |
| Bulk gate passes for events | "Tell the guard names" | Manual one-by-one | Event mode · up to 200 guests |
| Child exit verification | Guard's judgement | Usually none | Parent OTP required |
| DPDP §6 consent capture | Not possible | Rarely | One-screen at first visit |
| §65B-admissible audit log | Loose pages | Basic timestamps | Full per-event sealed log |
The questions every Hon. Secretary, MC Security Member, and worried parent asks before replacing the paper register at the gate.
We'll walk you through the pre-approval flow, the UIDAI-masked Aadhaar capture, the IVR fallback, and the DPDP §6 consent — in a 20-minute demo built for your society's gate profile.
Book the Visitor Demo →