Legal

DPDP Statement

India's Digital Personal Data Protection Act, 2023 (DPDP Act) establishes a framework for the processing of personal data, giving individuals (referred to as Data Principals) certain rights over their information and placing obligations on organisations that collect and process it. This statement explains how SafetyConnect, operated by IoT RL Connect Private Limited in India, handles personal data as a Data Fiduciary under the DPDP Act, and outlines the rights available to you.

This statement supplements our Privacy Policy, which provides the full detail of what data is collected and how it is used. Where this statement is silent, the Privacy Policy applies.

1. Purpose and Scope

This statement applies to personal data processed by SafetyConnect through our mobile and web applications, websites, and related services. It covers data collected from users, customers, and visitors in connection with our driving safety, process safety, incident management, and fleet safety products. IoT RL Connect Private Limited (India) acts as the Data Fiduciary responsible for the processing of personal data within the scope of the DPDP Act.

2. Legal Basis for Processing

We process personal data on the basis of consent that is free, specific, informed, unconditional, and unambiguous. Consent is given through a clear affirmative action, such as signing up for an account or agreeing to our terms, and is never obtained through pre-ticked boxes or inaction.

Before we request consent, we provide a clear notice describing what data is collected, the purpose for processing it, and your rights as a Data Principal. You may withdraw your consent at any time, in the same way it was originally given. Withdrawal does not affect the lawfulness of any processing that occurred before the withdrawal took effect.

3. Data Principal Rights

Under the DPDP Act, you have the following rights:

  • Right to access: You may request a summary of the personal data we hold about you and the processing activities we perform on it.
  • Right to correction: You may request correction of any inaccurate or incomplete personal data.
  • Right to erasure: You may request deletion of personal data that is no longer necessary for the purpose for which it was collected, or where consent has been withdrawn and no other legal basis applies.
  • Right to grievance redressal: You may raise a complaint through our designated grievance channel and receive a response within a defined timeframe.
  • Right to nominate: You may nominate another individual to exercise your rights under the DPDP Act on your behalf in the event of your death or incapacity.

4. Grievance Officer

To exercise any of the rights described above, or to raise a grievance, please contact our designated Grievance Officer at:

  • Email: support@safetyconnect.io or support@iotrl.io

We will acknowledge your request promptly and aim to respond within 30 days. If additional time is needed to address a complex request, we will inform you of the delay and the reason within that period.

5. Data Retention and Erasure

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law. By default, data is stored for one year or as per the customer's specific requirement. Once the retention period ends, or when data is no longer needed, it is securely deleted or anonymized so that it can no longer be linked to you.

6. Data Security

We implement reasonable security safeguards designed to prevent unauthorized access, use, or disclosure of personal data. SafetyConnect is ISO 27001 certified and employs 256-bit encryption for data in transit and at rest. Our security practices are subject to regular audits and continuous improvement.

In the event of a personal data breach that is likely to cause harm, we will notify affected Data Principals and the Data Protection Board of India in accordance with applicable law.

7. Cross-Border Data Transfer

Personal data may be transferred to, and processed in, jurisdictions outside India, including the United States, where IoT Research Labs Inc. maintains operations. Such transfers are carried out in compliance with applicable law. We do not transfer personal data to any jurisdiction that the Central Government of India has restricted under the DPDP Act.

8. Children's Data

SafetyConnect's products are not directed at children and we do not knowingly collect personal data from individuals under 18 without verifiable parental or guardian consent. For users under 16, our Privacy Policy applies additional protections and no data is collected under any circumstances. If you believe we have collected personal data from a minor without proper consent, please contact our Grievance Officer so that we may delete it promptly.

9. Relationship to the Privacy Policy

This DPDP Statement provides an overview of our obligations and your rights under India's Digital Personal Data Protection Act, 2023. It does not replace our Privacy Policy, which contains the full detail of what personal data is collected, how it is used, and the measures we take to protect it. In the event of any inconsistency between this statement and the Privacy Policy, the Privacy Policy prevails for all matters governed by it.

10. Updates to This Statement

We may update this DPDP Statement from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will post the updated statement on this page and, where appropriate, notify you by email or through a prominent notice on our website. We encourage you to review this page periodically.