Compliance with Digital Personal Data Protection Act (DPDP Act, 2023)
DropJet Technologies (Proprietorship) adheres strictly to the statutory guidelines of the Digital Personal Data Protection Act, 2023 (DPDP Act) of India. We act as a responsible Data Fiduciary, ensuring that personal data belonging to customers (Data Principals) and delivery partners is processed lawfully, securely, and transparently.
Core Data Governance Principles
1. Explicit Consent & Opt-In
Users and pilot partners provide unambiguous, affirmative consent during onboarding for specific operational purposes.
2. Purpose Limitation
Data is strictly utilized for dispatch matching, live road telemetry, invoicing, and safety verification. Zero secondary sale.
3. Data Minimization
Only strictly essential fields are collected (sender name, phone, pickup/drop coordinates, vehicle preferences).
4. Right to Erasure
Customers and drivers can initiate complete account deactivation and personal data deletion with a 30-day turnaround.
1. Purpose of Data Collection
Personal data is processed exclusively for specified, legitimate purposes:
- Hyperlocal Dispatching: Algorithmic matching between senders and the nearest available delivery pilot.
- Live GPS Telemetry: Generating second-by-second road transit ETA for senders and recipients.
- Delivery Verification: Transmitting 4-digit secret delivery handover OTPs to authenticate final receipt.
- Statutory Invoicing: Generating tax-compliant invoices and computing TDS deductions for commercial partners.
- Platform Security: Preventing fraudulent bookings, route tampering, and identity impersonation.
2. Aadhaar, Driving License & Partner KYC Handling
In accordance with Aadhaar Regulations and the DPDP Act:
- Masked Aadhaar: Only the last 4 digits of Aadhaar numbers are stored in application databases after successful verification. Full Aadhaar numbers are never logged in plain text.
- Driving License & RC Vault: Scanned driver licenses and vehicle registration certificates are stored inside encrypted private cloud buckets accessible only by authorized compliance personnel via multi-factor authentication (MFA).
- Zero Resale: Partner identification records are never leased, monetized, or shared with third-party marketing brokers.
3. Location & GPS Telemetry Governance
- Customer Location: Accessed only while the app is actively used in the foreground or while tracking an assigned live order.
- Driver Background GPS: Telemetry is collected in the background strictly while the pilot is marked "On Duty". Tapping "Go Offline" immediately terminates all background coordinate polling.
- Masked Calling: Telephone communications between senders and drivers are connected via proxy masked calling where technically supported, keeping personal phone numbers private.
4. Data Retention & Archival Schedule
- Real-time GPS Breadcrumbs: Archived to cold storage after 90 days and purged automatically after 180 days.
- Chat / Support Logs: Retained for 12 months for quality and dispute resolution.
- Financial & Invoice Records: Retained for 7 years in mandatory compliance with Section 128 of the Companies Act and Indian GST & Income Tax statutory auditing rules.
5. Data Deletion & Right to be Forgotten
Users and delivery partners may request complete deletion of their account and personal data at any time:
- Email our Data Protection Desk at support@dropjet.in with subject line "Account & Data Deletion Request".
- Verify account ownership via one-time SMS OTP on the registered phone number.
- All personal identifiers, profile photos, and saved addresses are permanently wiped from production databases within 30 calendar days.
6. Mandatory Data Breach Response Protocol
In strict compliance with Section 8(6) of the Digital Personal Data Protection Act, 2023, DropJet maintains an automated, rapid-response incident protocol:
- Containment & Forensics: Immediate isolation of affected servers, rotation of all API keys, and revocation of active JWT authentication tokens within 2 hours of detection.
- Regulatory Notification (72 Hours): In the event of a verified data breach compromising personal data, DropJet will notify the Data Protection Board of India (DPBI) within seventy-two (72) hours of becoming aware.
- User Notification: Impacted data principals (customers/pilots) will receive electronic notification detailing the nature of the breach, potential consequences, and corrective actions taken.
Data Protection Contact
For inquiries regarding personal data processing or to exercise your statutory DPDP rights:
Data Protection Desk: DropJet Technologies (Proprietorship)
Location: Lucknow, Uttar Pradesh, Bharat
Official Email: support@dropjet.in
Operations Helpline: +91 96704 99919