DPDP Act, 2023

DPDP Compliance

Maintained by TraWe. Reflects the controls we operate today. Not a legal certification.

Our role

For agency and team data: TraWe is the data fiduciary. For traveller data your agency uploads: your agency is the fiduciary, TraWe is the processor.

Rights we honour

  • Right to access and copy your personal data.
  • Right to correction, completion and updation.
  • Right to erasure once the processing purpose is complete.
  • Right to nominate another individual to exercise rights on your behalf.
  • Right to grievance redressal — acknowledged in 48 hours, resolved within 30 days.

Requests: dpo@trawe.in. From the app: Settings → Privacy → Request my data.

Consent

We collect only what's needed. Optional processing (marketing, product analytics) is opt-out from Settings → Privacy.

Security safeguards

  • TLS 1.2+ in transit, AES-256 at rest.
  • Row-level security isolating every agency's data.
  • Least-privilege role model; MFA for admin access.
  • Daily encrypted backups, 30-day retention.
  • Immutable audit log of every meaningful action.

Sub-processors

Minimum data shared with a small number of vetted providers. Changes are notified at least 15 days in advance.

Managed Postgres (India region)
Database, auth, storage
Mumbai, India
Cloudflare Workers
Application hosting, edge compute
India edge PoPs
Razorpay
Payment collection & reconciliation
India
Meta WhatsApp Cloud API
WhatsApp Business messaging
Global (Meta)
Google Gemini via AI Gateway
AI copilot & itinerary drafting
Global

Grievance officer (India)

TraWe Technologies Pvt. Ltd. · grievance@trawe.in · Acknowledgement 48h, resolution 30 days.

Data breach notification

We notify the Data Protection Board and affected principals as required, with facts, likely consequences, and mitigation applied.