Parties & Definitions
Subject Matter & Purpose of Processing
आरंभ processes personal data provided by the Controller exclusively for the following purposes:
- Booking and coordinating tour packages and vehicle rentals for the Controller's clients
- Issuing invoices and managing payment records
- Verifying driver eligibility for self-drive bookings
- Customer communication related to booked services
- Legal and regulatory compliance
We will not use personal data received from the Controller for our own marketing purposes without separate written consent.
Processor Obligations
As a Data Processor, आरंभ commits to:
- Process personal data only on documented instructions from the Controller.
- Ensure all personnel with access to personal data are subject to confidentiality obligations.
- Implement appropriate technical and organisational security measures (see §6).
- Not engage sub-processors without prior written authorisation from the Controller (see §4).
- Assist the Controller in responding to data subject requests.
- Delete or return all personal data upon termination of the service relationship.
- Make available all information necessary to demonstrate compliance with this DPA.
Approved Sub-Processors
आरंभ uses the following sub-processors for service delivery. Controllers are notified of any new sub-processors with 30 days notice:
Cross-Border Data Transfers
Personal data is primarily processed within India. Where data is transferred outside India (e.g., through cloud infrastructure with global data centres), we ensure:
- Transfers are subject to standard contractual clauses or equivalent safeguards.
- Sub-processors maintain equivalent data protection standards.
- Indian IT Act 2000 SPDI Rules are complied with for all sensitive personal data.
Security Measures
आरंभ implements the following technical and organisational measures to protect personal data:
- TLS 1.2+ encryption for all data in transit
- AES-256 encryption for data at rest (MongoDB Atlas)
- bcrypt 12-round password hashing
- Role-based access control and least-privilege access
- Multi-layer authentication (JWT + token version revocation)
- Regular security audits and vulnerability assessments
- Employee access logging and audit trails
Full details are available in our public Security Policy.
Personal Data Breach Notification
In the event of a personal data breach affecting Controller-provided data:
- आरंभ will notify the Controller within 72 hours of becoming aware of the breach.
- Notification will include: nature of the breach, categories and volume of data affected, likely consequences, and measures taken or proposed.
- The Controller is responsible for notifying affected data subjects and regulatory authorities as required by applicable law.
- आरंभ will provide full cooperation and information to support the Controller's response.
Assisting with Data Subject Rights
आरंभ will assist the Controller in fulfilling data subject requests (access, correction, deletion, portability) by:
- Providing relevant data extracts within 5 business days of a verified Controller request.
- Deleting or anonymising specific data records within 10 business days of a Controller instruction, subject to legal retention requirements.
- Flagging any data subject requests received directly by आरंभ to the Controller for handling.
Termination & Data Deletion
Upon termination of the service relationship or DPA:
- आरंभ will, at the Controller's choice, either return all personal data in a machine-readable format or securely delete it within 30 days of termination.
- Data retained by legal obligation will be clearly documented and deleted upon expiry of the legal retention period.
- A written confirmation of deletion will be provided upon request.
Contact for DPA Enquiries
To enter into a formal DPA, request a signed copy, or discuss corporate data processing arrangements:
