AUTO-KART PRIVATE LIMITED
CIN: U45200TS2026PTC209701
PRIVACY POLICY
Effective Date:
Auto-Kart
Private Limited ("Auto-Kart", "we", "us",
or "our") operates a technology-enabled marketplace connecting
vehicle owners with mechanics and roadside assistance providers across India
(the "Platform"). This Privacy Policy ("Policy")
governs how we collect, use, store, share, and protect your personal data when
you access or use our Platform.
This
Policy applies to: (a) Customers who book services through the Platform;
(b) Mechanics/Garages who register and subscribe to the Platform; (c) website
visitors; and (d) applicants seeking to join the Platform as Mechanics
(together, "Data Principals" or "you").
|
Important Notice:
By registering with or using the Platform,
you agree to be bound by this Policy. If you do not agree with any part of
this Policy, please do not access or use the Platform. |
This
Policy is issued in compliance with the Digital Personal Data Protection
Act, 2023 (DPDPA), the Information Technology Act, 2000, the IT
(Reasonable Security Practices and Procedures and Sensitive Personal Data or
Information) Rules, 2011 (SPDI Rules), and the IT (Intermediary
Guidelines and Digital Media Ethics Code) Rules, 2021. Auto-Kart acts as a Data
Fiduciary within the meaning of the DPDPA.
In this
Policy, the following terms have the meanings given below. Capitalised terms
not defined here shall bear the meaning assigned to them under the DPDPA or the
IT Act, as applicable.
"Consent" means a free, specific, informed,
unconditional, and unambiguous indication of your agreement to the processing
of your Personal Data for a specified purpose, given by a clear affirmative
action, as defined under section 2(6) of the DPDPA.
"Data
Fiduciary" means a person who
alone or in conjunction with other persons determines the purpose and means of
processing Personal Data — in this context, Auto-Kart Private Limited.
"Data
Principal" means the
individual to whom Personal Data relates — in this context, you, the user of
the Platform.
"Data
Processor" means any person
who processes Personal Data on behalf of, and under the instructions of, a Data
Fiduciary, including third-party service providers engaged by Auto-Kart.
"Personal
Data" means any data about an individual who is
identifiable by or in relation to such data, as defined under section 2(t) of
the DPDPA.
"Processing" means an automated operation or set of
operations performed on Digital Personal Data, including collection, recording,
storage, retrieval, use, sharing, disclosure, or erasure.
"Sensitive
Personal Data" means
personal data revealing passwords, financial data, health data, official
identifiers, sex life, sexual orientation, biometric data, genetic data, caste
or tribe, religious or political belief, or any other category notified as
sensitive by the Central Government under the SPDI Rules.
"Platform" means the Auto-Kart application, website,
and related technology services operated by Auto-Kart Private Limited.
"Significant
Data Fiduciary (SDF)" means
a Data Fiduciary notified by the Central Government under section 10 of the
DPDPA on the basis of volume, sensitivity of data, risk to rights of Data
Principals, or other criteria. Auto-Kart will comply with additional SDF
obligations if and when so notified.
"Purpose
Limitation" means the
principle that Personal Data shall be collected only for a specified, explicit,
and legitimate purpose and shall not be processed in a manner incompatible with
that purpose.
We
collect Personal Data in accordance with the principle of data minimisation
- only such data as is adequate, relevant, and necessary for the purpose for
which it is collected. The information we collect depends on your role on the
Platform.
When
you book a service through Auto-Kart, we collect the following categories of
Personal Data:
2.1 Identity and
Contact Information: your
name, mobile number, and email address.
2.2 Location
Data: your GPS coordinates or the service address
you provide at the time of booking, used solely to identify the nearest
available Mechanic. See Clause 4 for further detail.
2.3 Vehicle
Details: registration number, make, model, year, fuel
type, and nature of the reported issue.
2.4 Transaction
Information: job value, payment
instrument type, payment reference number, and GST details.
2.5 Service
History: past bookings, job status, job photographs
uploaded by either party during the job, and warranty sign-off records.
2.6 Feedback and
Ratings: ratings, written reviews, and complaint
submissions you make regarding a Mechanic.
2.7 Device and
Usage Data: device type,
operating system version, app version, IP address, session timestamps, and
clickstream data, collected automatically when you use our app or website. This
data is used for security, debugging, and analytics.
2.8 Inferred
Data: preferences and behavioural patterns derived
from your usage of the Platform (e.g., preferred service types, frequently used
locations). This inferred data is used only to personalise your experience and
is not shared with third parties for independent profiling.
When
you register and subscribe to the Platform, we collect:
2.9 Identity and
KYC Documents: full name,
photograph, masked Aadhaar (last four digits only — full Aadhaar numbers are
never stored), PAN, and government-issued ID for verification.
2.10 Business
Details: garage or business name, trade licence
number, GSTIN, and operating address.
2.11 Contact
Information: mobile number,
WhatsApp number, and email address.
2.12 Real-Time
Location: GPS coordinates when the app is active and
you are set to "On Duty", used to allocate nearby service leads. See
Clause 4.
2.13 Financial
Information: bank account
number, IFSC code, and UPI ID for processing settlements. This constitutes
Sensitive Personal Data under the SPDI Rules.
2.14 Performance
and Profiling Data: customer
ratings, written reviews, job completion rate, cancellation rate, response time
metrics, and upheld complaint count. This data is used to produce a Performance
Profile that influences lead allocation and subscription enforcement. See
Clause 10.
2.15 Subscription
and Billing Records: subscription
plan tier, payment history, billing dates, invoice records, and penalty
deductions.
2.16 Audit Logs: a timestamped log of all Platform actions
taken by your account (job acceptance, cancellation, status changes) is
maintained for security, fraud detection, and dispute resolution purposes under
the IT Act, 2000.
2.17
Communications Records: records
of all support tickets, chat messages, emails, and complaint submissions you
make to Auto-Kart, retained for grievance and legal compliance purposes.
2.18 Voluntary
Submissions: any additional
information you voluntarily provide to us, including through feedback forms,
surveys, or applications to join the Platform.
We do
not collect, and you must not submit, the following:
2.19 Full Aadhaar card numbers (only the last four
digits of masked copies are stored).
2.20 Biometric data such as fingerprints, iris
scans, or facial recognition data.
2.21 Health, medical, or genetic data.
2.22 Data revealing caste, religion, political
opinion, or trade union membership.
2.23 Children's
data: the Platform is not directed at persons under
18 years of age. We do not knowingly collect Personal Data from minors. Persons
under 18 must not use the Platform without the supervision of a parent or
guardian who accepts this Policy on their behalf.
Under
the DPDPA, every instance of processing Personal Data must rest on a lawful
basis. Auto-Kart processes your Personal Data on one or more of the following
bases, depending on the specific processing activity:
3.1 Consent
(DPDPA s.6): where you have
given us free, specific, informed, unconditional, and unambiguous consent.
Consent is obtained at the point of registration via affirmative click-through
acceptance of this Policy and, where required, separately for specific
activities (e.g., location tracking, marketing communications). You may
withdraw consent at any time (see Clause 11.4).
3.2 Legitimate
Use (DPDPA s.7): where
processing is necessary for the performance of a function of the State,
compliance with law, or for purposes reasonably expected by the Data Principal,
including safety and security functions, employment-related processing, and
research or archiving in the public interest.
3.3 Legal
Obligation: where processing is
required by applicable law, including retention of financial records under the
CGST Act, 2017 (8 years), TCS compliance, and responding to valid orders of
courts or regulatory authorities.
3.4 Contract
Performance: where processing is
necessary to perform our contractual obligations to you under the Terms of Use
or the Mechanic Subscription Agreement.
The
table below maps key processing activities to their lawful basis:
|
Processing Activity |
Lawful Basis (DPDPA) |
Data Category Involved |
|
Account creation and management |
Consent (s.6) |
Identity, contact, KYC |
|
Service lead allocation |
Consent / Legitimate Use (s.7) |
Location, performance data |
|
Payment processing and GST invoicing |
Legal Obligation (s.7(b)) |
Transaction, financial data |
|
KYC and identity verification |
Consent / Legal Obligation |
KYC documents, PAN, Aadhaar |
|
Operational communications (OTPs, alerts) |
Consent / Contract Performance |
Contact information |
|
Marketing communications |
Consent (s.6) — opt-in only |
Contact information |
|
Fraud and revenue leakage detection |
Legitimate Use (s.7) |
Location, transaction, usage |
|
Grievance and dispute resolution |
Legal Obligation / Legitimate Use |
All relevant categories |
|
Analytics and Platform improvement |
Consent / Legitimate Use |
Pseudonymised usage data |
|
Compliance with court/statutory orders |
Legal Obligation (s.7(b)) |
As directed by authority |
4.1 Purpose
Limitation: Personal Data collected
for a specified purpose shall not be processed for any purpose incompatible
with the original purpose, without obtaining fresh consent or establishing a
separate lawful basis. We will not use your vehicle data for insurance
marketing, your location history for advertising, or your financial information
for any purpose other than settlement processing, without your explicit
consent.
4.2 Data
Minimisation: We collect only
such Personal Data as is adequate, relevant, and not excessive in relation to
the purpose for which it is processed. Each data category described in Clause 2
is collected because it is necessary for a specific, identified function of the
Platform.
4.3 Accuracy
Obligation: Auto-Kart shall
take reasonable steps to ensure that the Personal Data we hold is accurate,
complete, and kept up to date, having regard to the purpose for which it is
being processed (DPDPA s.8(3)). You are responsible for keeping your account
information current. We provide in-app tools for you to correct your own
information at any time.
4.4 Storage
Limitation: Personal Data shall
not be retained for longer than is necessary for the purpose for which it was
collected, subject to applicable legal retention obligations. Specific
retention periods are set out in Clause 6.
5.1 Customers. We collect your location at the time of booking only to
identify the nearest available Mechanic and to dispatch them to your vehicle.
We do not persistently track or store your location data after the job is
marked complete or cancelled.
5.2 Mechanics. We collect your real-time GPS coordinates when the app is
active and your status is "On Duty". This data is used to: (a)
allocate service leads based on proximity; (b) display your estimated arrival
time to the Customer during an active job; and (c) verify job-completion
location for audit and dispute purposes. Location tracking ceases automatically
when you switch to "Off Duty" or close the application. Raw location
data is retained for 30 days from the relevant job date and then permanently
deleted; aggregated and anonymised location metrics may be retained for
Platform analytics.
5.3 Consent and Revocation. Location access is sought via your device's
operating system permission prompt and requires your affirmative grant. You may
revoke location permission at any time through your device settings. Revocation
will: (i) for Mechanics - prevent lead allocation while Off Duty status cannot
be verified; (ii) for Customers - may prevent booking completion where a
service address cannot be confirmed. Revocation does not affect Personal Data
already collected prior to revocation.
5.4 No Background Tracking. We do not collect location data when the app
is running in the background and you are not actively using the Platform or
assigned to a live job.
6.1 General Principle. Personal Data shall be retained only for so
long as is necessary for the purpose for which it was collected, unless a
longer retention period is required or permitted by law. On expiry of the
applicable retention period, data will be securely deleted or irreversibly
anonymised.
6.2 Customer
Account Data: duration of your
active account plus 3 years after account closure or last activity, whichever
is later.
6.3 Mechanic
Account Data: duration of your
active subscription plus 5 years after subscription termination.
6.4 Job and
Service Records (including photographs and sign-offs): 5 years from the date of job completion.
6.5 Payment and
GST Records: 8 years, as
mandated by section 35 of the CGST Act, 2017 and section 44AA of the Income Tax
Act, 1961.
6.6 KYC Documents
(Mechanic): 5 years after
subscription termination, in compliance with applicable anti-money laundering
and KYC norms.
6.7 Location Data (raw GPS logs): 30 days from the relevant job date, then
permanently deleted. Aggregated, anonymised analytics derived from location
data: 36 months.
6.8 Customer
Support and Complaint Records: 3
years from the date of resolution.
6.9 Audit Logs
(IT Act compliance): 180
days (6 months), as required under Rule 3(1)(j) of the IT Intermediary
Guidelines Rules, 2021; extended to 365 days where a grievance or investigation
is pending.
6.10 Website
Visitor and Cookie Data: 13
months from the date of collection.
6.11 Consent
Records: retained for the duration of the relationship
plus 3 years, as evidence of the lawful basis for processing.
6.12 Deletion on Request. We will process a valid deletion request
within 90 days of receipt, subject to legal retention obligations. Data subject
to a mandatory retention period will be flagged as 'deletion pending' and
deleted promptly upon expiry of that period. We will confirm completion of
deletion to you in writing.
6.13 Anonymisation. Where we anonymise Personal Data (rendering it no longer
capable of identifying you), such anonymised data falls outside the scope of
this Policy and may be retained and used indefinitely for analytics, research,
and Platform improvement.
7.1 No Sale of Data. We do not sell, trade, rent, or otherwise transfer your
Personal Data to any third party for their independent commercial use. Any
sharing is strictly limited to what is described in this Clause 7.
When a
booking is confirmed, we share limited information between the parties solely
to enable service delivery:
7.2 Customers may
see: the Mechanic's name, photograph, rating
score, garage name, approximate distance, and real-time GPS location during the
active job only.
7.3 Mechanics may
see: the Customer's name, masked mobile number
(where technically possible), vehicle details, service address, and job
description.
This
sharing ceases automatically on job completion or cancellation. Neither
party may use the other party's Personal Data for any purpose other than the
immediate service engagement, and any such misuse constitutes a breach of this
Policy and applicable law.
We
engage Data Processors who process Personal Data on our behalf and under our
written instructions. Auto-Kart remains responsible as Data Fiduciary for all
processing by its Data Processors. All Data Processors are bound by written
data processing agreements that require: (a) processing only on documented
instructions from Auto-Kart; (b) equivalent security standards; (c)
confidentiality obligations; and (d) assistance with Data Principal rights
requests.
7.4 Cloud Hosting
Providers: for secure storage
and processing of Platform data within India.
7.5 Payment
Aggregators (e.g., Razorpay, PhonePe): for processing Customer payments and Mechanic settlement
disbursements. Financial data shared with these providers is governed by their
own PCI-DSS compliant privacy frameworks.
7.6 KYC and
Identity Verification Partners: for
document verification, PAN validation, and GSTIN lookup during Mechanic
onboarding.
7.7 Communication
Service Providers: SMS
gateways, WhatsApp Business API providers, and email delivery services, used
for OTPs, booking confirmations, invoices, and renewal reminders.
7.8 Analytics
Providers: for understanding
navigation patterns on the Platform. Only pseudonymised data is shared with
analytics providers; no directly identifying information is transmitted.
7.9 Legal and
Audit Advisors: where necessary for
litigation support, regulatory compliance, or statutory audits, subject to
professional confidentiality obligations.
We may
disclose Personal Data when: (a) required by a court order, statutory
obligation, or direction of a competent authority; (b) necessary to protect the
rights, property, or safety of Auto-Kart, our users, or the public; or (c)
required to assist law enforcement under applicable law. Where legally
permissible, we will notify you before making such disclosure so that you may
seek a protective order.
If
Auto-Kart undergoes a merger, acquisition, sale of assets, or corporate
restructuring, your Personal Data may be transferred to the successor entity.
The successor will be contractually required to assume obligations equivalent
to those in this Policy. We will notify you at least 30 days before any such
transfer takes effect, where legally permissible.
7.10 As of the effective date of this Policy, all
Personal Data is stored and processed on servers located within India.
7.11 If we propose to transfer Personal Data
outside India in the future, we will do so only in compliance with section 16
of the DPDPA and any applicable cross-border transfer rules notified by the
Central Government.
7.12 Permitted transfer mechanisms may include:
(a) transfer to countries notified as adequate by the Central Government; (b)
transfer subject to standard contractual clauses approved under the DPDPA; or
(c) transfer with the explicit consent of the Data Principal. We will update
this Policy at least 30 days before any cross-border transfer takes effect.
We use
cookies and similar tracking technologies (collectively, "Cookies")
on our website to operate the Platform, remember your preferences, and analyse
usage patterns.
8.1 Strictly
Necessary Cookies: essential
for the Platform to function (login session management, CSRF security tokens,
load balancing). These Cookies cannot be disabled as they are technically
required for service delivery.
8.2 Functional
Cookies: remember your preferences such as language
selection, login state, and display settings. Active for up to 12 months.
8.3 Analytics
Cookies: used to understand how visitors navigate the
website, which pages are most visited, and how users arrive at the Platform.
These Cookies are activated only upon your affirmative consent and are retained
for 13 months.
8.4 Marketing and
Targeting Cookies: used to
display relevant advertisements on third-party platforms (e.g., Google, Meta).
These Cookies require your explicit opt-in consent and are retained for 13
months. You may opt out at any time.
8.5 Consent Mechanism. On your first visit to our website, a Cookie
consent banner is displayed. Your consent choices are recorded with a timestamp
and can be reviewed or changed at any time via the Cookie Settings link in the
website footer. Consent records are retained for 3 years (see Clause 6.11).
8.6 Managing Cookies. You may also manage Cookies through your
browser settings. Note that disabling Strictly Necessary Cookies will prevent
the Platform from functioning. Disabling Analytics or Marketing Cookies will
not affect core Platform functionality.
8.7 Do Not Track. Our Platform currently does not respond to browser
"Do Not Track" signals. We will update this Policy if our practice
changes.
9.1 Security Measures. We implement appropriate technical,
organisational, and physical safeguards to protect Personal Data against
unauthorised access, disclosure, alteration, or destruction, including:
9.2 Encryption of Personal Data in transit using
TLS 1.2 or higher and at rest using AES-256 or equivalent.
9.3 Role-based access controls (RBAC) ensuring
that only authorised personnel can access Personal Data strictly on a
need-to-know basis.
9.4 Multi-factor authentication (MFA) for all
Platform administrative accounts.
9.5 Regular automated vulnerability scanning and
periodic third-party penetration testing (at least annually).
9.6 Secure deletion and irreversible
anonymisation protocols applied at the end of the applicable retention period.
9.7 Mandatory confidentiality and data protection
obligations in all employment contracts, contractor agreements, and third-party
service provider agreements.
9.8 A documented Information Security Policy,
reviewed at least annually or on any material change to our processing
activities.
|
🔔 Personal Data Breach Notification: In the event of a Personal Data breach that is likely
to result in a risk to your rights, we will notify you and report the breach
to the Data Protection Board of India as soon as reasonably practicable, and
in any event within the timeframe prescribed by the DPDPA and the Rules
thereunder (Rules not yet in force as of the effective date of this Policy;
we will update this notice when prescribed timelines are published).
Notification will include the nature of the breach, categories of data
affected, and remedial steps taken. |
9.9 Your Responsibility. You are responsible for maintaining the
confidentiality of your account credentials (username and password). You must
not share your login credentials with any third party. You agree to notify us
immediately at privacy@autokart.in if you become aware of any unauthorised use
of your account. Auto-Kart is not liable for losses arising from your failure
to safeguard your credentials.
9.10 Security Limitation. No method of internet transmission or
electronic storage is completely secure. While we implement all commercially
reasonable security measures, we cannot guarantee absolute security against
factors beyond our reasonable control, including sophisticated cyberattacks or
force majeure events.
10.1 Profiling of Mechanics. Our Platform generates a Performance Profile
for each Mechanic comprising: customer ratings, review sentiment, job completion
rate, cancellation rate, response time, and upheld complaint count. This
Performance Profile influences lead allocation priority, enforcement of the
Mechanic Subscription Agreement, and — in cases of threshold breach — may
trigger a review process.
10.2 Automated Systems. Our Platform uses automated systems for: (a)
lead allocation — assigning jobs to Mechanics based on proximity, availability,
and Performance Profile score; (b) performance threshold monitoring —
automatically flagging accounts where defined thresholds are breached; and (c)
fraud and revenue leakage detection — identifying unusual patterns such as
off-platform job diversion or unusually high cancellation rates.
|
Human Review Guarantee:
No significant decision that adversely affects
your subscription benefits — including suspension, demotion, or termination
of subscription — is taken by automated means alone. Every adverse action
involves a mandatory human review step by Auto-Kart personnel, and you will
receive written notice with an opportunity to respond before any action is
finalised, in accordance with the Mechanic Subscription Agreement. |
10.3 Right to Contest Automated Decisions. If you believe that an automated decision
affecting your account is incorrect or unfair, you may contact our support team
at privacy@autokart.in. We will arrange a human review of the relevant decision
within 15 working days and communicate the outcome to you in writing.
10.4 Customer Profiling. We derive limited inferences from Customer
usage data (e.g., preferred service types, frequently visited areas) solely to
personalise service recommendations. This inferred data is not shared with
third parties and is not used to make decisions that adversely affect your
access to the Platform.
Under
the DPDPA and other applicable law, you have the rights described in this
Clause 11. To exercise any of these rights, contact us at privacy@autokart.in.
We will acknowledge your request within 48 hours and respond substantively
within 30 days (or such shorter period as may be prescribed). We will
verify your identity before acting on any rights request.
11.1 Right to Access. You may request: (a) confirmation of whether we hold
Personal Data about you; (b) a summary of the Personal Data we hold and the
purposes for which it is being processed; and (c) a list of the entities or
categories of entities with whom your Personal Data has been shared. We will
provide this information in a clear, readable format.
11.2 Right to Correction and Completion. You may request correction of inaccurate
Personal Data and completion of incomplete Personal Data. You may update most
information directly in your account settings. Where a correction has legal
implications (e.g., correcting KYC data), we may require supporting
documentation before acting.
11.3 Right to Erasure. You may request deletion of your Personal
Data where: (a) the purpose for which it was collected is no longer served; (b)
you have withdrawn consent and there is no other lawful basis for retention; or
(c) the data is being processed unlawfully. Erasure will be subject to any
mandatory legal retention obligations (see Clause 6). We will delete data
within 90 days of a valid erasure request and confirm completion to you.
11.4 Right to Withdraw Consent. Where processing is based on your consent,
you may withdraw that consent at any time through your in-app settings or by
emailing privacy@autokart.in. Withdrawal is prospective only — it does not
affect the lawfulness of processing carried out before withdrawal. Withdrawal
may affect your ability to access certain features of the Platform (e.g.,
revoking location consent will affect lead allocation for Mechanics).
11.5 Right to Data Portability. To the extent required by the DPDPA and Rules
thereunder (when notified), you may request that we provide your Personal Data
in a commonly used, machine-readable format to enable transfer to another
service provider.
11.6 Right to Grievance Redressal. You have the right to a prompt and effective
remedy for any privacy-related concern. Please refer to Clause 17 for the
grievance redressal process. If your complaint is not resolved within 30 days,
you may escalate to the Data Protection Board of India.
11.7 Right to Nominate. You may nominate another individual to
exercise your data rights on your behalf in the event of your death or
incapacity. To register a nominee, please contact privacy@autokart.in for the
nomination form.
|
Identity Verification:
To protect against unauthorised access to
your data, all rights requests must be accompanied by identity verification.
We may request: (a) confirmation of your registered email or mobile number
via OTP; (b) a scanned copy of a government-issued ID for requests of a
sensitive nature; or (c) any other verification reasonably required. We will
not process rights requests that cannot be verified. |
12.1 The
Platform may contain hyperlinks to third-party websites, payment gateways, and
social media platforms. Auto-Kart is not responsible for the privacy practices,
security, or content of those third-party services.
12.2 Your
financial information entered on third-party payment platforms (e.g., Razorpay,
PhonePe) is processed under their own PCI-DSS compliant privacy frameworks. We
encourage you to review their privacy policies before completing any payment.
12.3 Once
you navigate away from the Auto-Kart Platform, our obligations under this
Policy do not extend to any third-party service or website you visit.
12.4 Auto-Kart
is not liable for any loss or damage arising from your interaction with
third-party services linked from our Platform.
13.1 Ratings,
reviews, and comments you post on the Platform may be visible to other users
and, where indicated, to the general public. Your first name and last initial
may be displayed alongside your review.
13.2 You
must not include Sensitive Personal Data or the Personal Data of third parties
in your public reviews or comments. Auto-Kart is not liable for Personal Data
you choose to disclose publicly on the Platform.
13.3 To
request removal of a review or public comment, contact us at
privacy@autokart.in. We will process the request within 30 days, subject to our
content moderation policies and any applicable legal requirements.
We may
contact you by SMS, WhatsApp, email, or in-app notification for the following
purposes:
14.1
Transactional Communications (cannot be opted out of): booking confirmations, job updates, OTPs,
receipts, GST invoices, subscription renewal reminders, payment receipts,
account security alerts, and Policy change notifications.
14.2 Promotional
Communications (consent required; opt-out available): offers, discounts, new feature announcements,
and marketing campaigns. These are sent only where you have given prior consent
and may be unsubscribed from at any time.
14.3 Opt-Out. You may withdraw consent for promotional communications
at any time by: (a) using the unsubscribe link in any marketing email; (b)
adjusting your notification preferences in-app; or (c) emailing
privacy@autokart.in. Opt-out will take effect within 10 working days.
Transactional messages will continue while your account is active, as they are
necessary for service delivery.
14.4 DND Compliance. Where you have registered your mobile number on the TRAI
Do Not Disturb (DND) registry, we will respect DND preferences for promotional
SMS communications. Transactional SMS messages are exempt from DND restrictions
under TRAI regulations.
15.1 The
Platform is not directed at persons under 18 years of age. We do not knowingly
collect Personal Data from minors.
15.2 If
you are under 18, you must not register on or use the Platform independently.
If you use the Platform with the assistance of a parent or guardian, that
parent or guardian accepts this Policy on your behalf and is responsible for
all data submitted through the account.
15.3 If
a parent or guardian believes that their child has independently submitted
Personal Data to us, they should contact privacy@autokart.in immediately. We
will delete such data without undue delay upon verification of the request.
15.4 Verifiable Parental Consent. Section 9 of the
DPDPA requires Data Fiduciaries to obtain verifiable consent of a parent or
lawful guardian before processing a child's Personal Data, once this provision
is brought into force and the manner of verification is prescribed by the
Central Government. Ahead of this provision taking effect, we are developing a
verification mechanism (which may include OTP-based confirmation of the
parent's or guardian's identity, or such other method as may be prescribed) to
confirm that consent given on behalf of a child has genuinely been given by a
parent or lawful guardian. We will implement this mechanism, and update this
Policy accordingly, by the date on which Section 9 of the DPDPA comes into
force.
16.1 We
may update this Policy from time to time to reflect changes in applicable law,
our data processing practices, or the services we offer. All updated versions
will be posted on our Platform with the revised effective date and version
number.
16.2 For
material changes - those that significantly affect how we process your
Personal Data, expand the categories of data collected, add new sharing
arrangements, or reduce your rights — we will provide at least 15 days'
prior notice by email or in-app notification. Where required by the DPDPA,
we will seek fresh consent before any material change takes effect.
16.3 For
non-material changes (e.g., corrections, clarifications, or
administrative updates), the revised Policy will take effect on the posted
effective date without advance notice.
16.4 Your
continued use of the Platform after the effective date of any revised Policy
constitutes your acceptance of the updated terms to the extent permitted by
applicable law. If you do not agree to a material change, you must stop using
the Platform before the change takes effect and may request deletion of your
data under Clause 11.3.
16.5 An
archive of prior versions of this Policy will be maintained and made available
upon request by contacting privacy@autokart.in.
In the
event of any discrepancy, concern, or grievance relating to your Personal Data
or the manner in which it is handled, you may contact our Grievance Officer.
The Grievance Officer is a senior individual appointed pursuant to Rule 3(2) of
the IT Intermediary Guidelines Rules, 2021 and the DPDPA.
|
Grievance Officer |
|
|
Designation |
Grievance Officer / Data Protection Contact, Auto-Kart
Private Limited |
|
Email |
privacy@autokart.in |
|
Phone |
+91-___________ (Monday to Friday, 10:00 AM – 6:00 PM
IST) |
|
Postal Address |
Auto-Kart Private Limited, H.No 2-41, Near Hanuman
Temple, Keesara, Nagaram, Hyderabad – 500083, Telangana |
|
Acknowledgement Timeline |
Within 48 hours of receipt of grievance |
|
Resolution Timeline |
Within 30 days of receipt, or such shorter period as may
be prescribed |
17.1 Grievance Process. On receipt of a grievance, the Grievance
Officer will: (a) acknowledge receipt within 48 hours; (b) investigate the
matter and provide a substantive response within 30 days of receipt; and (c)
where the grievance is upheld, take appropriate remedial action and notify you
of the steps taken.
17.2 Escalation to the Data Protection Board. If your grievance is not resolved to your
satisfaction within 30 days, you may escalate the matter to the Data Protection
Board of India (Board) established under section 18 of the DPDPA. Details of
the Board's complaint mechanism will be updated on this page once the Board is
constituted and its procedures are published.
17.3 Escalation to CERT-In. For matters involving a data security
incident or breach, you may also report to the Indian Computer Emergency
Response Team (CERT-In) under the IT Act, 2000.
18.1 By
registering with and using the Platform, you expressly consent to our
collection, processing, storage, and sharing of your Personal Data as described
in this Policy. Your consent is specific, informed, and voluntarily given by
your affirmative act of registration and use.
18.2 Where
separate consent is required for specific processing activities (e.g., location
tracking, marketing communications, Analytics Cookies), such consent is sought
separately at the relevant point of interaction and is independent of your
general consent to this Policy.
18.3 You
may withdraw consent at any time as described in Clause 11.4. Withdrawal of
consent does not affect any processing lawfully carried out prior to
withdrawal.
19.1 This
Policy is governed by the laws of the Republic of India, including the Digital
Personal Data Protection Act, 2023, the Information Technology Act, 2000, and
all regulations and rules made thereunder.
19.2 Subject
to Clause 19.3, any dispute arising from or in connection with this Policy
shall be subject to the exclusive jurisdiction of the courts of competent
jurisdiction at Hyderabad, Telangana.
19.3 Nothing
in this Clause 19 limits your right to bring a complaint before the Data
Protection Board of India or any other regulatory authority having jurisdiction
under applicable law.
20.1 Entire Agreement. This Policy, together with the Terms of Use
and the Mechanic Subscription Agreement (where applicable), constitutes the
entire agreement between Auto-Kart and you with respect to the collection,
processing, and protection of your Personal Data.
20.2 Conflict. In the event of any conflict between this Policy and the
Terms of Use or the Mechanic Subscription Agreement with respect to privacy and
data protection matters, this Policy shall prevail.
20.3 Assignment. You may not assign your rights or obligations under this
Policy to any third party without Auto-Kart's prior written consent. Auto-Kart
may transfer its rights under this Policy to a successor entity in connection
with a corporate restructuring, without requiring your separate consent,
provided the successor assumes equivalent data protection obligations.
20.4 Severability. If any provision of this Policy is found by a court of
competent jurisdiction to be unlawful, void, or unenforceable, that provision
shall be severed from the remaining provisions, which shall continue in full
force and effect.
20.5 Waiver. Any failure or delay by Auto-Kart to enforce any
provision of this Policy shall not constitute a waiver of that provision or any
other provision of this Policy.
20.6 Language. This Policy is drafted in English. If translated into any
other language for convenience, the English version shall prevail in the event
of any inconsistency.
20.7 Notices. All notices to Auto-Kart under this Policy should be
addressed to privacy@autokart.in or to the registered address set out in Clause
17.
20.8 Force Majeure. Auto-Kart is not liable for any failure to comply with
this Policy to the extent such failure is caused by a force majeure event,
including acts of God, cyberattacks by state or non-state actors, natural
disasters, government orders, or other circumstances beyond our reasonable
control, provided we take all commercially reasonable steps to mitigate the
impact.
This
Policy has been prepared for Auto-Kart Private Limited | CIN:
U45200TS2026PTC209701
Effective from the date first stated
above |
Version 2.1 | Supersedes Version 2.0
© Auto-Kart Private Limited. All Rights Reserved.