आरंभ Legal Documents

Data Processing Agreement

Formal data processing terms for B2B corporate clients and business partners working with आरंभ.

Last updated: August 2026Effective: 1 September 2026
§1

Parties & Definitions

This Data Processing Agreement (DPA) applies to corporate clients, travel agents, and business partners who share customer personal data with आरंभ Tours & Travels for the purpose of booking or managing tours and rentals. Individual consumers are covered by our Privacy Policy.
Controller
The corporate client or business partner who determines the purposes and means of processing personal data.
Processor
आरंभ Tours & Travels, which processes personal data on behalf of the Controller for service delivery.
Data Subject
The individual whose personal data is being processed (e.g., a corporate employee or client travelling with आरंभ).
Personal Data
Any information relating to an identified or identifiable natural person, as defined under IT Act 2000 Rules and GDPR.
Processing
Any operation performed on personal data — collection, storage, use, disclosure, deletion.
§2

Subject Matter & Purpose of Processing

आरंभ processes personal data provided by the Controller exclusively for the following purposes:

  • Booking and coordinating tour packages and vehicle rentals for the Controller's clients
  • Issuing invoices and managing payment records
  • Verifying driver eligibility for self-drive bookings
  • Customer communication related to booked services
  • Legal and regulatory compliance

We will not use personal data received from the Controller for our own marketing purposes without separate written consent.

§3

Processor Obligations

As a Data Processor, आरंभ commits to:

  • Process personal data only on documented instructions from the Controller.
  • Ensure all personnel with access to personal data are subject to confidentiality obligations.
  • Implement appropriate technical and organisational security measures (see §6).
  • Not engage sub-processors without prior written authorisation from the Controller (see §4).
  • Assist the Controller in responding to data subject requests.
  • Delete or return all personal data upon termination of the service relationship.
  • Make available all information necessary to demonstrate compliance with this DPA.
§4

Approved Sub-Processors

आरंभ uses the following sub-processors for service delivery. Controllers are notified of any new sub-processors with 30 days notice:

MongoDB Atlas
Database hosting and storage (India/Asia Pacific region).
Razorpay
Payment processing (PCI-DSS Level 1 certified, India).
Render.com
Backend API hosting (cloud infrastructure).
Google (Analytics)
Anonymised website analytics — only if consent is obtained.
Email Provider
Transactional email for booking confirmations and communications.
Controllers who object to a new sub-processor may terminate the service agreement in accordance with the notice period in their service contract.
§5

Cross-Border Data Transfers

Personal data is primarily processed within India. Where data is transferred outside India (e.g., through cloud infrastructure with global data centres), we ensure:

  • Transfers are subject to standard contractual clauses or equivalent safeguards.
  • Sub-processors maintain equivalent data protection standards.
  • Indian IT Act 2000 SPDI Rules are complied with for all sensitive personal data.
§6

Security Measures

आरंभ implements the following technical and organisational measures to protect personal data:

  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption for data at rest (MongoDB Atlas)
  • bcrypt 12-round password hashing
  • Role-based access control and least-privilege access
  • Multi-layer authentication (JWT + token version revocation)
  • Regular security audits and vulnerability assessments
  • Employee access logging and audit trails

Full details are available in our public Security Policy.

§7

Personal Data Breach Notification

In the event of a personal data breach affecting Controller-provided data:

  • आरंभ will notify the Controller within 72 hours of becoming aware of the breach.
  • Notification will include: nature of the breach, categories and volume of data affected, likely consequences, and measures taken or proposed.
  • The Controller is responsible for notifying affected data subjects and regulatory authorities as required by applicable law.
  • आरंभ will provide full cooperation and information to support the Controller's response.
§8

Assisting with Data Subject Rights

आरंभ will assist the Controller in fulfilling data subject requests (access, correction, deletion, portability) by:

  • Providing relevant data extracts within 5 business days of a verified Controller request.
  • Deleting or anonymising specific data records within 10 business days of a Controller instruction, subject to legal retention requirements.
  • Flagging any data subject requests received directly by आरंभ to the Controller for handling.
§9

Termination & Data Deletion

Upon termination of the service relationship or DPA:

  • आरंभ will, at the Controller's choice, either return all personal data in a machine-readable format or securely delete it within 30 days of termination.
  • Data retained by legal obligation will be clearly documented and deleted upon expiry of the legal retention period.
  • A written confirmation of deletion will be provided upon request.
§10

Contact for DPA Enquiries

To enter into a formal DPA, request a signed copy, or discuss corporate data processing arrangements:

Email
support@aarambhatravels.in (subject: "DPA Request")
Response time
We respond to DPA enquiries within 5 business days.
This page provides a summary of our standard DPA terms. A full legally executed DPA is available upon request for corporate clients with formal data sharing requirements.