1. Parties and incorporation
This Data Processing Agreement ("DPA") is entered into between the organisation subscribing to Tripkoz ("Customer", "you", the Data Fiduciary) and Tripkoz Technologies ("Tripkoz", "we", the Data Processor).
It is incorporated into, and forms part of, the Tripkoz Terms & Conditions. Where the DPA and the Terms conflict on the processing of personal data, this DPA governs.
It applies for as long as we process personal data on your behalf.
2. Definitions
- "DPDP Act" means the Digital Personal Data Protection Act, 2023 and the rules made under it.
- "Data Principal" means the individual to whom personal data relates — a passenger, guardian, driver or administrator.
- "Data Fiduciary" means the party that determines the purpose and means of processing. For Customer Data, that is you.
- "Data Processor" means the party that processes personal data on the Data Fiduciary’s behalf. For Customer Data, that is us.
- "Personal Data" means any data about an identifiable individual processed through the Service.
- "Processing" has the meaning given in the DPDP Act and includes collection, storage, use, transmission, disclosure and erasure.
- "Personal Data Breach" means any unauthorised processing of, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to, Personal Data.
- "Sub-processor" means a third party engaged by us to process Personal Data in providing the Service.
3. Roles of the parties
You are the Data Fiduciary in respect of Customer Data. You decide which passengers, guardians, drivers and vehicles are recorded, what is recorded about them, who in your organisation can see it, and how long you keep it in the Service.
We are the Data Processor. We process Customer Data only to provide, secure and support the Service, and only on your documented instructions.
We are the Data Fiduciary for a small, separate set of data we hold in our own right: your administrators’ account and billing details, support correspondence, and aggregated, de-identified usage statistics. That processing is described in the Privacy Policy, not here.
You are responsible for having a lawful basis for the processing you instruct — in particular, for obtaining verifiable consent from a parent or lawful guardian before a child’s personal data is recorded in the Service.
4. Subject matter, duration and categories
Subject matter — provision of the Tripkoz transport-management platform: live vehicle tracking, trip and boarding records, safety and maintenance records, notifications, and the associated administration.
Duration — for the term of your subscription, plus the retention period in clause 11.
Categories of Data Principal:
- Passengers, including children transported by schools and colleges;
- Parents, guardians and authorised contacts;
- Drivers and vehicle attendants;
- Your administrators and other staff users.
Categories of Personal Data:
- Identity and contact — name, photograph, phone number, email address, employee or student identifier, class or department;
- Location — device and vehicle GPS coordinates, speed, heading and timestamps collected during trips;
- Trip records — boarding and alighting events, attendance, absence reports, pickup and drop-off points, home or stop location;
- Driver credentials — licence number and expiry, badge and permit details, and uploaded document images;
- Safety and incident records — inspection checklists, incident and SOS reports and any notes attached to them;
- Technical — IP address, device and app version, session and audit records.
We do not require, and ask you not to upload, financial account details, health records, biometric data or government identity numbers of passengers. The Service is not designed to hold them.
5. Processing on your instructions
We process Customer Data only:
- To provide the Service and the features your users invoke;
- On your further documented instructions, where they are consistent with the Service;
- To secure the Service, prevent fraud and abuse, and maintain availability and integrity;
- Where required by law, in which case we will tell you before we act unless the law forbids us from doing so.
We do not sell Customer Data. We do not use it for advertising. We do not use it to train machine-learning models.
If we consider an instruction to breach the DPDP Act or other applicable law, we will tell you promptly and may pause that processing until it is resolved.
6. Confidentiality and personnel
Access to Customer Data is limited to personnel who need it to operate or support the Service. Every such person is bound by a written confidentiality obligation that survives the end of their engagement.
Our personnel are trained on data protection and on the specific sensitivity of children’s location data. Administrative access to production data is role-restricted, logged, and reviewed.
7. Security measures
We implement and maintain appropriate technical and organisational measures, including:
- Encryption of data in transit using current TLS, and encryption of data at rest, including uploaded documents in object storage;
- Logical tenant separation, so one organisation’s records cannot be read from another organisation’s session, enforced in the data layer rather than only in the interface;
- Role-based access control with granular permissions, and short-lived access tokens with an inactivity timeout;
- Password hashing with a salted, industry-standard algorithm; no plaintext credential is ever stored;
- Time-limited signed URLs for document access, so a link cannot be shared indefinitely;
- Audit logging of significant administrative actions, retained for investigation;
- Regular backups, restore testing, and monitoring for availability and anomalies;
- Change control and code review for production changes, and dependency scanning.
Measures are reviewed as the Service evolves. We may change a specific measure provided the overall level of protection is not reduced.
8. Sub-processors
You give general authorisation for us to engage Sub-processors. Each is bound by written terms imposing data-protection obligations no less protective than this DPA, and we remain liable to you for their performance.
The current categories are:
- Cloud hosting and database infrastructure — running the application and storing Customer Data;
- Object storage and content delivery — driver documents, photographs and static assets;
- Mapping and geocoding — rendering maps and converting coordinates to addresses;
- Push notification, SMS and email delivery — sending alerts and account messages;
- Payment processing (Razorpay) — subscription payments and invoicing. Razorpay processes your administrators’ billing details as an independent controller of that data, not on our behalf;
- Error monitoring and application logging — diagnosing faults.
A current list naming each Sub-processor and its processing location is available on request from privacy@tripkoz.com. We will give at least thirty (30) days’ notice before adding or replacing a Sub-processor that processes Customer Data. If you reasonably object on data-protection grounds within that period, we will work with you on an alternative; if none is workable, you may terminate the affected part of the Service and receive a refund of the unused term.
9. Location and transfers
Customer Data is hosted on infrastructure in India, and may be processed in other jurisdictions where our Sub-processors operate, in accordance with section 16 of the DPDP Act and any restrictions notified by the Central Government.
Where data leaves India, we ensure a comparable level of protection through contractual commitments with the Sub-processor, encryption in transit and at rest, and access controls.
10. Data Principal rights
Requests from Data Principals — access, correction, erasure, grievance redressal, or nomination — are answered by you as Data Fiduciary. Most can be satisfied directly in the dashboard, which lets an administrator view, correct, export and delete the records for a passenger, guardian or driver.
Where a request reaches us instead, we will not respond to it on our own account. We will forward it to you promptly and, unless the law directs otherwise, tell the individual to contact you.
We will give you reasonable assistance, at no charge, in responding to such requests and in carrying out any consultation with the Data Protection Board that the DPDP Act requires.
11. Breach notification
We will notify you of a Personal Data Breach affecting Customer Data without undue delay, and in any event within seventy-two (72) hours of becoming aware of it.
The notification will describe, so far as known at the time: the nature of the breach, the categories and approximate number of Data Principals and records affected, the likely consequences, and the measures taken or proposed to address it. Where the full picture is not yet available, we will send what we have and update you as it develops rather than waiting.
We will cooperate with you in meeting your own notification obligations to the Data Protection Board of India and to affected Data Principals, and we will not require you to wait on our internal process before you notify.
12. Retention, return and deletion
We retain Customer Data for the term of your subscription and for thirty (30) days after it ends, so that an account can be reactivated or exported without loss.
On request during that period we will provide an export of your Customer Data in a machine-readable format. On written instruction we will delete it sooner.
After thirty days we may delete Customer Data. We retain only what the law requires us to keep — tax invoices in particular, for the statutory period — and audit records where they are needed to demonstrate compliance.
Deleted records may persist in encrypted backups until those backups expire on their normal cycle, during which they remain protected by the measures in clause 7 and are not restored into the live system except as part of a disaster recovery.
13. Audits and information
We will make available the information reasonably necessary to demonstrate compliance with this DPA, including our security documentation and, where available, third-party assessment reports.
You may audit our compliance, at your own cost, no more than once in any twelve-month period and on at least thirty (30) days’ written notice, or more often if required by a regulator or following a Personal Data Breach affecting your Customer Data. An audit must not disrupt the Service or compromise the confidentiality of another customer’s data.
14. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms & Conditions.
Nothing in this DPA relieves either party of an obligation imposed directly on it by the DPDP Act, and neither party may contract out of a liability the Act places on it.
15. Contact
Data protection questions, Sub-processor lists and countersigned copies of this DPA: privacy@tripkoz.com.
Grievances under the DPDP Act: our Grievance Officer at grievance@tripkoz.com, who acknowledges within 24 hours and aims to resolve within 15 days of receipt.
Related policies
This document sits alongside the rest of our published terms. Together they form the agreement that governs your use of Tripkoz.