TrackMyWings Technologies Private Limited
Privacy Policy
- Version
- 1.0
- Effective
- 1 August 2026
- Length
- 21,744 words
CHAPTER 1PRELIMINARY
1. Short Title
This Privacy Policy (”Privacy Policy” or “Policy”) governs the collection, use, processing, storage, disclosure, transfer, retention, protection and deletion of Personal Data by TrackMyWings Technologies Private Limited, a company incorporated under the Companies Act, 2013, having its registered office at Flat 1303, Tower 7, Purva Zenium, Hosahalli, Hunasamaranahalli, Bengaluru North, Bengaluru – 562157, Karnataka (hereinafter referred to as “TrackMyWings”, “Company”, “we”, “our”, or “us”).
This Policy applies to all Personal Data processed through the Company’s digital ecosystem, including but not limited to:
- the TrackMyWings mobile applications;
- the TrackMyWings web application;
- desktop applications;
- application programming interfaces (APIs);
- customer support systems;
- websites operated by the Company;
- email communications;
- community features;
- artificial intelligence-powered services;
- flight tracking services;
subscription services; and
all ancillary products and services offered under the TrackMyWings brand.
2. Purpose
The purpose of this Privacy Policy is to:
- (a) explain the categories of Personal Data collected;
- (b) explain the purposes for which such Personal Data is processed;
- (c) specify the legal bases of processing;
- (d) describe the rights available to individuals;
- (e) explain the safeguards adopted by the Company;
- (f) ensure transparency in processing activities;
- (g) establish accountability mechanisms;
- (h) comply with applicable privacy and data protection laws.
3. Applicable Laws
This Privacy Policy has been drafted having regard to, and is intended to operate in compliance with, applicable data protection and privacy laws, including, where applicable:
India
Digital Personal Data Protection Act, 2023
Rules framed thereunder
Information Technology Act, 2000
Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, to the extent applicable until superseded
Applicable directions issued by the Data Protection Board of India or any competent authority.
European Union
Regulation (EU) 2016/679 (General Data Protection Regulation)
European Data Protection Board Guidelines
Applicable decisions of supervisory authorities.
United Kingdom
UK GDPR
Data Protection Act, 2018.
Other Jurisdictions
Where Personal Data of individuals located in other jurisdictions is processed, the Company shall comply with any mandatory legal obligations applicable to such processing.
4. Scope
This Privacy Policy applies to:
- registered users;
- guest users;
- subscribers;
- website visitors;
- applicants for employment;
- contractors;
- vendors;
- airline partners;
- airport partners;
- corporate customers;
- customer support interactions;
- beta testers;
- business partners;
persons whose information is received through lawful third-party integrations.
This Policy applies regardless of the device, operating system or platform through which the Services are accessed.
5. Territorial Application
This Privacy Policy applies to processing activities carried out:
- (a) within India;
- (b) within the European Union;
- (c) within the United Kingdom;
- (d) in any jurisdiction where the Company offers its Services; and
- (e) where applicable law confers extraterritorial effect upon privacy legislation.
6. Guiding Principles
The Company shall process Personal Data in accordance with the following principles:
Lawfulness
Fairness
Transparency
Purpose Limitation
Data Minimisation
Accuracy
Storage Limitation
Integrity
Confidentiality
Accountability
Privacy by Design
Privacy by Default
These principles shall govern every processing activity undertaken by the Company.
7. Relationship with Other Policies
This Privacy Policy shall be read together with, where applicable:
- Terms of Service;
- Cookie Policy;
- Data Retention Policy;
- Information Security Policy;
- Acceptable Use Policy;
- Community Guidelines;
- Data Processing Agreements;
- Enterprise Agreements;
Incident Response Plan; and
any notices provided at the point of data collection.
In the event of any inconsistency, the provision affording the greater level of protection to Personal Data shall prevail, unless otherwise required by applicable law.
8. Binding Effect
By accessing or using the Services, the user acknowledges that they have been provided with this Privacy Policy and, where consent is the lawful basis for processing, expressly consent to the processing of their Personal Data in accordance with this Policy.
Where processing is based on another lawful ground, this Privacy Policy shall operate as the notice required under applicable law.
9. Policy Review
This Privacy Policy shall be reviewed periodically and may be amended to:
- reflect changes in applicable law;
- accommodate technological developments;
- introduce new products or services;
- address identified privacy risks;
- implement recommendations arising from Data Protection Impact Assessments;
improve transparency and accountability.
Material amendments shall be notified through appropriate communication channels prior to becoming effective where required by law.
10. Interpretation
Unless the context otherwise requires:
- words importing the singular include the plural and vice versa;
- references to statutes include amendments, re-enactments and subordinate legislation;
- headings are inserted for convenience only and shall not affect interpretation;
- references to “including” mean “including without limitation”;
references to “Person” include individuals, companies, partnerships, associations and governmental bodies.
CHAPTER 2DEFINITIONS AND INTERPRETATION
2.1 Purpose
The definitions contained in this Chapter shall apply throughout this Privacy Policy unless the context otherwise requires. Capitalised terms not otherwise defined shall have the meanings assigned to them herein.
PART AGeneral Definitions
2.2 “Account”
Means the unique user account created by a User for accessing or using the Services.
2.3 “Affiliate”
Means any entity that directly or indirectly controls, is controlled by, or is under common control with TrackMyWings.
2.4 “Anonymous Information”
Means information that cannot reasonably be used, either alone or in combination with other information, to identify an individual.
Anonymous Information shall not constitute Personal Data for the purposes of this Policy.
2.5 “Applicable Law”
Means any statute, rule, regulation, notification, guideline, judicial decision, directive, ordinance or legally binding governmental requirement applicable to the processing of Personal Data.
2.6 “Artificial Intelligence” or “AI”
Means computational models, algorithms, machine learning systems, predictive analytics, recommendation engines, automation tools, or similar technologies used by the Company for generating insights, predictions, alerts, recommendations or improving the Services.
2.7 “Business Day”
Means any day other than a Saturday, Sunday or public holiday in the jurisdiction where the relevant legal obligation is required to be performed.
2.8 “Company”
Means TrackMyWings Technologies Private Limited together with its successors, assigns and authorised representatives.
2.9 “Consent”
Means any freely given, specific, informed, unconditional and unambiguous indication of the wishes of a Data Principal or Data Subject by which such individual signifies agreement to the processing of Personal Data.
Where applicable, Consent shall satisfy the requirements of:
- the Digital Personal Data Protection Act, 2023;
- the GDPR;
the UK GDPR; and
any other applicable privacy legislation.
2.10 “Controller”
Means the natural or legal person that determines the purposes and means of processing Personal Data.
For the purposes of this Privacy Policy, TrackMyWings shall ordinarily act as the Controller under the GDPR.
2.11 “Cookie”
Means a small data file or similar technology stored on a user’s device for authentication, analytics, preferences, security or other legitimate operational purposes.
2.12 “Cross-Border Transfer”
Means any disclosure, transmission, storage, access or processing of Personal Data outside the jurisdiction in which such Personal Data was originally collected.
2.13 “Customer”
Means any individual or organisation using the Company’s Services under a free or paid subscription.
2.14 “Data”
Means any representation of facts, information, concepts, instructions or records capable of being processed electronically.
PART BDefinitions under the DPDP Act
2.15 “Data Fiduciary”
Shall have the meaning assigned under the Digital Personal Data Protection Act, 2023 and means any person who alone or together with others determines the purpose and means of processing Personal Data.
TrackMyWings acts as a Data Fiduciary in relation to Personal Data processed through its Services.
2.16 “Data Principal”
Means the individual to whom the Personal Data relates.
Where the Data Principal is a child or a person with disability, the term includes the parent, lawful guardian or other authorised representative recognised under applicable law.
2.17 “Consent Manager”
Means a person registered under the Digital Personal Data Protection Act, 2023 who enables a Data Principal to give, manage, review and withdraw Consent through an accessible, transparent and interoperable platform.
2.18 “Processing”
Means a wholly or partly automated operation or set of operations performed on Personal Data, including:
- collection;
- recording;
- organisation;
- storage;
- adaptation;
- alteration;
- retrieval;
- consultation;
- use;
- analysis;
- sharing;
- transmission;
- disclosure;
- restriction;
- anonymisation;
- pseudonymisation;
deletion; and
destruction.
PART CGDPR Definitions
2.19 “Data Processor”
Means any natural or legal person who processes Personal Data on behalf of the Controller.
Examples include cloud hosting providers, notification providers, analytics providers and payment processors engaged by TrackMyWings under written data processing agreements.
2.20 “Data Protection Officer” or “DPO”
Means the individual designated by the Company, where required by applicable law, to oversee compliance with data protection legislation and serve as the point of contact for supervisory authorities and Data Subjects.
2.21 “Data Protection Impact Assessment” or “DPIA”
Means a documented assessment conducted prior to undertaking processing activities that are likely to result in a high risk to the rights and freedoms of natural persons.
A DPIA shall include:
- description of processing;
- assessment of necessity;
- proportionality analysis;
- risk identification;
- mitigation measures;
residual risk assessment; and
periodic review.
2.22 “Data Subject”
Means an identified or identifiable natural person to whom Personal Data relates.
For the purposes of this Policy, the expressions “Data Subject” and “Data Principal” shall be construed according to the applicable law governing the relevant processing activity.
2.23 “Legitimate Interests”
Means the lawful basis under Article 6(1)(f) of the GDPR permitting processing where necessary for the legitimate interests pursued by the Controller or a third party, except where overridden by the interests or fundamental rights and freedoms of the Data Subject.
2.24 “Personal Data”
Means any information relating to an identified or identifiable natural person, whether directly or indirectly identifiable, including but not limited to:
- name;
- email address;
- profile photograph;
- flight itinerary;
- booking reference;
- travel preferences;
- device identifiers;
- IP address;
- approximate location;
- subscription details;
communication records; and
any other information that may reasonably identify an individual.
Anonymous or irreversibly anonymised information shall not constitute Personal Data.
2.25 “Personal Data Breach”
Means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, Personal Data.
2.26 “Profiling”
Means any form of automated processing of Personal Data used to evaluate or predict aspects relating to an individual’s behaviour, preferences, travel patterns or usage characteristics.
2.27 “Pseudonymisation”
Means processing Personal Data in such a manner that it can no longer be attributed to a specific individual without the use of additional information kept separately and protected by appropriate technical and organisational measures.
PART DService-Specific Definitions
2.28 “Flight Data”
Means information relating to air travel, including but not limited to:
- airline;
- flight number;
- departure airport;
- arrival airport;
- gate information;
- departure time;
- arrival time;
- delays;
- cancellations;
- baggage information;
booking reference; and
other itinerary-related details.
2.29 “Location Data”
Means geographical information obtained from a user’s device solely for providing location-dependent features such as airport proximity, trip management or contextual travel alerts.
2.30 “Raw Email Content”
Means the original contents of a flight confirmation email received by the Company solely for the purpose of extracting relevant Flight Data.
Unless expressly stated otherwise, Raw Email Content shall not be retained after extraction of the relevant Flight Data necessary to provide the requested Services.
2.31 “Services”
Means the mobile applications, web application, desktop applications, APIs, customer support systems, AI-powered tools, subscription services, community features and all related digital offerings operated by TrackMyWings.
2.32 “User”
Means any individual who accesses or uses the Services, whether as a registered account holder, subscriber, guest user or otherwise.
PART EInterpretation
2.33 Rules of Interpretation
Unless the context otherwise requires:
- words importing the singular include the plural and vice versa;
- references to one gender include every gender;
- headings are inserted for convenience only and shall not affect interpretation;
- references to statutes include amendments, substitutions and subordinate legislation;
- references to “including” shall mean “including without limitation”;
references to “writing” include electronic records and digitally authenticated communications recognised under applicable law.
CHAPTER 3IDENTITY OF THE DATA FIDUCIARY, DATA CONTROLLER AND CONTACT INFORMATION
3.1 Identity of the Company
This Privacy Policy is issued by TrackMyWings Technologies Private Limited, a company incorporated under the provisions of the Companies Act, 2013, and acting as the primary entity responsible for the operation, administration and management of the TrackMyWings platform.
For the purposes of this Privacy Policy, TrackMyWings shall act as:
the Data Fiduciary under the Digital Personal Data Protection Act, 2023;
the Data Controller under the General Data Protection Regulation (EU) 2016/679 (“GDPR”), where applicable; and
the organisation responsible for determining the purposes and means of processing Personal Data.
Where TrackMyWings processes Personal Data solely on behalf of an enterprise customer pursuant to a written agreement, TrackMyWings may act as a Data Processor, and the respective enterprise customer shall act as the Data Controller or Data Fiduciary.
3.2 Corporate Information
Unless otherwise notified, the Company’s corporate details are as follows:
Legal Name
TrackMyWings Technologies Private Limited
Corporate Status
A company incorporated under the Companies Act, 2013.
Registered Office
Flat 1303, Tower 7, Purva Zenium, Hosahalli, Hunasamaranahalli, Bengaluru North, Bengaluru – 562157, Karnataka.
Corporate Identification Number (CIN)
U62013KA2026PTC219769
GST Registration Number
29AANCT0727D1ZA
Official Website
https://www.trackmywings.com
Official Privacy Contact
support@trackmywings.com
The Company may update the above information from time to time without requiring amendment of the substantive provisions of this Policy.
3.3 Role as Data Fiduciary
TrackMyWings determines:
- what Personal Data is collected;
- why Personal Data is collected;
- how Personal Data is processed;
- how long Personal Data is retained;
- which service providers process Personal Data;
- the safeguards applicable to Personal Data;
the lawful basis for processing; and
the rights available to Data Principals and Data Subjects.
Accordingly, the Company acts as the primary Data Fiduciary under the Digital Personal Data Protection Act, 2023.
3.4 Role as Data Controller
For users located in the European Union, European Economic Area, Switzerland, the United Kingdom or any jurisdiction recognising equivalent privacy rights, TrackMyWings acts as the Data Controller within the meaning of Article 4(7) of the GDPR.
As Controller, the Company shall:
- determine lawful purposes of processing;
- ensure transparency;
- maintain records of processing;
- implement appropriate technical and organisational measures;
- facilitate the exercise of statutory rights;
conduct Data Protection Impact Assessments where required; and
cooperate with competent supervisory authorities.
3.5 Appointment of Data Protection Officer
Where required under Article 37 of the GDPR or any equivalent legislation, the Company shall appoint a Data Protection Officer (“DPO”) possessing appropriate professional qualifications and expert knowledge of data protection law.
The DPO shall independently perform the functions assigned under applicable law, including:
- advising the Company regarding compliance;
- monitoring implementation of this Policy;
- conducting internal privacy audits;
- reviewing Data Protection Impact Assessments;
- acting as the contact point for supervisory authorities;
- handling complaints relating to data protection;
monitoring vendor compliance; and
advising on privacy-by-design measures.
Where appointment of a DPO is not legally mandatory, the Company may voluntarily designate a privacy officer to perform substantially similar functions.
3.6 Appointment of Grievance Officer
Pursuant to the Digital Personal Data Protection Act, 2023, the Company shall designate a Grievance Officer responsible for receiving and resolving complaints from Data Principals.
The Grievance Officer shall:
- acknowledge complaints promptly;
- investigate grievances fairly and impartially;
- coordinate with internal departments;
communicate decisions within the timelines prescribed by law; and
maintain records of grievances and resolutions.
The identity and contact details of the Grievance Officer shall be published on the Company’s official website and updated whenever necessary.
3.7 Contact Details
All privacy-related communications may be addressed to:
Privacy Team
TrackMyWings Technologies Private Limited
Email: privacy@trackmywings.com (recommended dedicated address)
Website: https://www.trackmywings.com
Postal Address: Flat 1303, Tower 7, Purva Zenium, Hosahalli, Hunasamaranahalli, Bengaluru North, Bengaluru – 562157, Karnataka.
If a dedicated privacy email is not yet operational, communications may temporarily be addressed to:
support@trackmywings.com
The Company may establish additional channels, including:
- online privacy request forms;
- in-app privacy request portals;
- authenticated account dashboards;
enterprise support portals; and
postal correspondence.
3.8 Verification of Identity
Prior to acting upon any privacy request, the Company may require reasonable verification of the identity of the requester to protect Personal Data against unauthorized disclosure, alteration or deletion.
Verification methods may include:
- authenticated login;
- one-time passwords (OTP);
- confirmation emails;
- government-issued identification, where legally permissible and proportionate;
additional account verification measures.
The Company shall collect only such verification information as is reasonably necessary.
3.9 Authorised Representatives
Where permitted by applicable law, a request relating to Personal Data may be submitted through:
- a legally authorised representative;
- a parent or lawful guardian;
- an attorney acting under a valid power of attorney;
- an executor or legal heir;
a nominee recognised under the DPDP Act; or
any other person authorised by applicable law.
The Company may require documentary evidence of such authority before processing the request.
3.10 Enterprise Customers
Where TrackMyWings provides Services to enterprise customers under contractual arrangements:
- the enterprise customer may determine the purposes of processing;
- TrackMyWings may process Personal Data strictly in accordance with documented instructions;
the rights and obligations of each party shall be governed by the applicable Data Processing Agreement (“DPA”).
Nothing in this Privacy Policy shall override obligations assumed under a valid DPA.
3.11 Regulatory Cooperation
The Company shall cooperate with:
the Data Protection Board of India established under the DPDP Act;
- competent supervisory authorities under the GDPR;
- courts of competent jurisdiction;
law enforcement agencies acting under lawful authority; and
any other regulatory authority empowered by applicable law.
Such cooperation shall be limited to the extent required by law and shall be subject to appropriate safeguards protecting the rights of affected individuals.
3.12 Updates to Contact Information
The Company reserves the right to modify its contact details, corporate information, or designated officers without amending the substantive provisions of this Policy, provided that updated information is published through appropriate official channels.
CHAPTER 4CATEGORIES OF PERSONAL DATA COLLECTED
4.1 Purpose
This Chapter identifies the categories of Personal Data collected, generated, received, inferred, or otherwise processed by TrackMyWings in connection with the Services.
The Company shall collect only such Personal Data as is:
- adequate;
- relevant;
- proportionate;
necessary for the specified purpose; and
processed in accordance with applicable law.
The Company adheres to the principle of Data Minimisation and shall not collect Personal Data that is excessive in relation to the purposes for which it is processed.
PART ACategories of Personal Data
4.2 Identity Information
The Company may collect information necessary to identify a User, including:
Full name
Preferred display name
Username
Profile photograph
Email address
Unique account identifier
Authentication provider identifier (e.g., Google, Apple Sign-In identifier)
Account creation timestamp
Identity Information is primarily used to establish and maintain user accounts and facilitate authentication.
4.3 Contact Information
The Company may process:
Email address
Customer support correspondence
Notification preferences
Communication language preferences
The Company does not require a telephone number unless specifically requested for a particular Service.
4.4 Authentication Information
For secure authentication, the Company may process:
OAuth authentication tokens
Session identifiers
Authentication timestamps
Device authentication records
Multi-factor authentication status (where enabled)
The Company does not receive or store passwords associated with third-party identity providers such as Google Sign-In.
4.5 Flight Information
The Company may collect or generate the following information relating to air travel:
Airline
Flight number
Departure airport
Arrival airport
Departure terminal
Arrival terminal
Boarding gate
Scheduled departure time
Estimated departure time
Actual departure time
Scheduled arrival time
Estimated arrival time
Actual arrival time
Flight status
Delays
Diversions
Cancellations
Aircraft type (where available)
Booking reference (PNR)
Seat number (where voluntarily provided)
Frequent flyer programme information (where voluntarily provided)
Travel class
Travel history maintained within the Service
4.6 Email-Derived Information
Where a User voluntarily forwards flight confirmation emails to the designated Company email address, the Company may automatically extract:
Flight number
Airline
Booking reference
Departure date
Arrival date
Departure airport
Arrival airport
Passenger name (where necessary)
Ticket information relevant to itinerary creation
Raw email bodies, attachments, marketing content, signatures, and unrelated correspondence shall not be retained once the required Flight Information has been extracted, except where retention is required by law or for the resolution of a user-requested support issue.
4.7 Device Information
The Company may collect information relating to the device used to access the Services, including:
Device model
Manufacturer
Operating system
Operating system version
Screen resolution
Application version
Device language
Time zone
Device identifiers (where permitted)
Push notification token
Crash diagnostics
Performance metrics
The Company shall not intentionally collect hardware identifiers where unnecessary.
4.8 Usage Information
The Company may collect information regarding interaction with the Services, including:
Features accessed
User interface interactions
Search history within the Service
Flight tracking activity
Subscription usage
Community participation
Settings preferences
Application performance
Error reports
Diagnostic events
Usage Information is used to improve functionality, security, and user experience.
4.9 Location Information
Subject to user permission, the Company may process:
Approximate location
Airport proximity
Time-zone information
Country or region
Location necessary to provide travel alerts
Unless expressly stated otherwise, precise GPS location shall be processed on-device wherever technically feasible and shall not be stored by the Company beyond what is necessary to provide the requested functionality.
Location processing shall occur only after obtaining any permissions required by applicable law or platform requirements.
4.10 Subscription Information
Where Users subscribe to paid Services, the Company may process:
Subscription tier
Subscription status
Renewal dates
Payment confirmation
Transaction identifier
Subscription history
The Company does not store complete credit card numbers, CVV codes, or payment credentials. Payment processing is performed by PCI-DSS compliant payment processors.
4.11 Community Information
Where Users participate in community features, the Company may process:
Display name
Profile image
Shared itineraries
Friends or connections
Invitations
Shared travel groups
Group activity
Users retain control over the visibility of information shared through community features.
4.12 Customer Support Information
The Company may process information contained in communications with customer support, including:
Support tickets
Emails
Screenshots voluntarily submitted
Device diagnostics voluntarily submitted
Attachments voluntarily submitted
Complaint history
Resolution history
PART BInformation Automatically Generated
4.13 Technical Logs
The Company may automatically generate:
Server logs
Error logs
Authentication logs
API request logs
Security logs
Audit logs
Fraud detection logs
These logs are maintained solely for operational, security, troubleshooting, and legal compliance purposes.
4.14 Analytics Information
The Company may collect aggregated analytics concerning:
Application performance
Feature adoption
Crash frequency
User engagement
System reliability
Where practicable, analytics shall be aggregated or pseudonymised.
PART CInformation Not Collected
4.15 The Company Does Not Intentionally Collect
Unless specifically required by law or voluntarily provided by the User for customer support, the Company does not intentionally collect:
Government-issued identification numbers
Passport scans
Driver’s licence information
Aadhaar numbers
PAN numbers
Biometric identifiers
Fingerprints
Iris scans
Facial recognition templates
Financial account credentials
Debit or credit card numbers
CVV codes
Internet banking credentials
Passwords of third-party accounts
Health records
Medical diagnoses
Genetic data
Political opinions
Religious beliefs
Trade union membership
Sexual orientation
Criminal conviction records
If such information is inadvertently received, the Company shall take reasonable steps to securely delete or anonymise it unless retention is required by law.
PART DMandatory and Optional Data
4.16 Mandatory Information
The following information is generally necessary for providing the Services:
Email address (for registered accounts)
Authentication credentials
Flight information necessary to provide requested features
Technical information necessary for secure operation
Failure to provide mandatory information may result in the inability to create or maintain an account or access certain features.
4.17 Optional Information
The following categories are generally optional:
Profile photograph
Display name
Community profile
Seat preference
Frequent flyer programme details
Optional travel preferences
Voluntarily shared travel information
A User’s decision not to provide optional information shall not affect access to core functionality unless the relevant feature inherently requires such information.
PART EData Minimisation and Accuracy
4.18 Data Minimisation
The Company shall collect only the minimum amount of Personal Data reasonably necessary to fulfil the specified purposes identified in this Policy.
The Company shall periodically review its collection practices to eliminate unnecessary categories of Personal Data.
4.19 Accuracy
Users are encouraged to ensure that the Personal Data they provide is accurate, complete, and up to date.
The Company may provide mechanisms enabling Users to review, update, or correct their Personal Data.
4.20 Changes to Categories of Data
Where the Company proposes to collect additional categories of Personal Data not previously disclosed, it shall:
- update this Privacy Policy or provide a supplemental privacy notice;
- identify the purposes for the new collection;
identify the applicable lawful basis for processing; and
obtain additional consent where required by applicable law.
CHAPTER 5SOURCES OF PERSONAL DATA AND MODES OF COLLECTION
5.1 Purpose
This Chapter describes the various sources from which TrackMyWings collects, receives, generates or otherwise obtains Personal Data and the lawful methods by which such information is collected.
The Company is committed to ensuring that Personal Data is collected fairly, transparently and only through lawful means consistent with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the General Data Protection Regulation (“GDPR”), and other applicable laws.
The Company shall not obtain Personal Data through unlawful, deceptive, fraudulent or covert means.
PART ACategories of Sources
5.2 Information Provided Directly by Users
The primary source of Personal Data is the User.
A User may voluntarily provide Personal Data when:
- creating an account;
- signing in using Google Sign-In or another approved authentication provider;
- manually adding a flight;
- forwarding flight confirmation emails;
- subscribing to premium services;
- joining community features;
- contacting customer support;
- participating in surveys;
- reporting bugs;
- providing feedback;
communicating with the Company through email or other authorised channels.
The Company shall clearly identify mandatory and optional information at the point of collection.
5.3 Information Generated Through Use of the Services
Certain information is automatically generated as a consequence of the User’s interaction with the Services.
Such information may include:
- application usage;
- device diagnostics;
- authentication logs;
- security events;
- API requests;
- feature utilisation;
- application crashes;
- performance statistics;
travel history maintained within the User’s account.
Automatically generated information is used solely for legitimate operational, security and service improvement purposes.
5.4 Information Derived from Flight Confirmation Emails
Where a User voluntarily forwards a flight confirmation email to the Company’s designated email address, the Company shall process the email solely for the purpose of extracting information necessary to provide the requested Services.
The Company may extract:
- airline;
- flight number;
- booking reference;
- departure airport;
- arrival airport;
- scheduled departure;
- scheduled arrival;
- passenger name (where necessary);
ticket information relevant to itinerary creation.
Except where retention is required by law or for the resolution of a customer support request, the Company shall not retain the raw email body, attachments, marketing content, signatures or unrelated communications after extraction of the required Flight Information.
5.5 Information Received from Third-Party Authentication Providers
Where Users choose to authenticate through third-party identity providers, such as Google Sign-In, the Company may receive only the information expressly authorised by the User and made available by the authentication provider.
Such information may include:
- name;
- email address;
- profile photograph;
unique authentication identifier.
The Company does not obtain the User’s password associated with the third-party authentication provider.
5.6 Information Obtained from Third-Party Aviation Data Providers
To provide flight tracking and travel-related Services, the Company may obtain aviation information from reputable third-party providers.
Such information may include:
- flight schedules;
- airport information;
- aircraft status;
- delays;
- cancellations;
- gate information;
- terminal information;
- baggage carousel information (where available);
operational notices.
Where such information is linked to an identified or identifiable User, it shall be treated as Personal Data and processed in accordance with this Policy.
5.7 Information Received from Payment Service Providers
Where Users purchase paid subscriptions, payment-related information may be received from payment processors.
The Company may receive:
- payment confirmation;
- transaction identifier;
- subscription status;
- renewal information;
payment success or failure notifications.
The Company shall not receive or store complete payment card numbers, CVV values or equivalent payment credentials.
5.8 Information Generated Through Community Features
Where Users voluntarily participate in community functionality, the Company may receive information resulting from such participation, including:
- invitations accepted;
- shared itineraries;
- travel groups;
- profile visibility preferences;
- user interactions;
shared travel updates.
The visibility of such information shall remain subject to the privacy controls selected by the User.
PART BAutomatic Collection Technologies
5.9 Device Information
The Company may automatically collect technical information concerning the User’s device to ensure secure and reliable operation of the Services.
Such information may include:
- operating system;
- application version;
- device model;
- language;
- time zone;
- crash diagnostics;
- security identifiers;
push notification token.
5.10 Location Information
Where enabled by the User, the Company may obtain location information from the User’s device to provide travel-related functionality.
Location processing shall occur only:
- after obtaining any permissions required by applicable law;
- to the extent necessary for the requested functionality;
for the duration reasonably required to provide such functionality.
Where technically feasible, location information shall be processed locally on the User’s device rather than transmitted to Company servers.
5.11 Analytics Technologies
The Company may use analytics technologies to understand:
- application performance;
- feature adoption;
- stability;
- service reliability;
aggregated usage patterns.
Analytics information shall, wherever practicable, be aggregated, pseudonymised or anonymised before analysis.
PART CCollection from Other Persons
5.12 Information Shared by Other Users
A User may voluntarily share another individual’s information through certain collaborative features, such as shared itineraries or travel groups.
The User sharing such information represents and warrants that they have the necessary authority or consent to do so.
The Company reserves the right to remove such information where it reasonably believes the disclosure is unlawful or unauthorised.
5.13 Enterprise Customers
Where Services are provided to enterprise customers, Personal Data may be received from authorised administrators acting on behalf of the enterprise customer.
The Company shall process such information only in accordance with the applicable agreement and documented instructions from the enterprise customer.
5.14 Customer Support Representatives
Personal Data may be received from authorised representatives acting on behalf of a User, including legal representatives, parents, guardians, executors or nominees, where permitted by applicable law.
The Company may require reasonable evidence of such authority before processing any request.
PART DLawful Collection Practices
5.15 Fair Collection
The Company shall collect Personal Data fairly and lawfully.
The Company shall not:
- collect Personal Data through deception;
- secretly monitor communications;
- obtain unauthorised access to third-party accounts;
- purchase unlawfully obtained Personal Data;
- circumvent privacy controls;
process Personal Data for undisclosed purposes.
5.16 Notice at the Time of Collection
Where Personal Data is collected directly from a User, the Company shall provide a privacy notice containing, where applicable:
- the categories of Personal Data collected;
- the purposes of processing;
- the lawful basis for processing;
- retention periods or criteria;
- recipients or categories of recipients;
- information regarding cross-border transfers;
- the rights available to the User;
contact details for privacy-related enquiries.
Where required by applicable law, such notice shall be provided before or at the time of collection.
5.17 Data Minimisation at Collection
The Company shall collect only the minimum Personal Data reasonably necessary to achieve the specified purpose.
Business units shall periodically review collection forms, APIs, workflows and onboarding processes to ensure continued compliance with the principle of data minimisation.
5.18 Prohibition on Covert Collection
Except where expressly authorised by applicable law, the Company shall not engage in covert or concealed collection of Personal Data.
This includes, without limitation:
- hidden tracking technologies;
- unauthorised access to emails;
- undisclosed background monitoring;
- collection of clipboard contents unrelated to the requested functionality;
collection of contacts, photographs, microphones or cameras without the User’s explicit permission where required.
5.19 Changes to Sources of Collection
Where the Company proposes to collect Personal Data from a new source not previously disclosed in this Policy, the Company shall:
- assess the lawfulness of the proposed collection;
- update this Privacy Policy or provide a supplemental notice;
- identify the lawful basis for such collection;
conduct a Data Protection Impact Assessment where required; and
obtain additional consent where required by applicable law.
CHAPTER 6PURPOSES OF PROCESSING PERSONAL DATA
6.1 Purpose
This Chapter describes the specific, explicit and legitimate purposes for which TrackMyWings Technologies Private Limited (“TrackMyWings” or the “Company”) processes Personal Data.
The Company shall process Personal Data only for purposes that are:
- lawful;
- fair;
- transparent;
- specific;
- explicit;
legitimate; and
compatible with the purposes communicated to the User at or before the time of collection.
The Company shall not process Personal Data for purposes incompatible with those disclosed in this Privacy Policy unless otherwise permitted by applicable law or with the User’s consent where required.
PART APrimary Service Purposes
6.2 Account Creation and User Authentication
The Company processes Personal Data to:
- create and maintain user accounts;
- authenticate Users through approved identity providers;
- verify user identity;
- maintain account security;
- prevent unauthorized access;
- administer account settings;
restore account access where necessary.
6.3 Flight Tracking Services
Personal Data is processed to enable Users to:
- create itineraries;
- track flights;
- monitor departures;
- monitor arrivals;
- receive real-time flight updates;
- receive cancellation notifications;
- receive delay notifications;
- receive diversion notifications;
- receive gate changes;
- receive terminal updates;
maintain travel history.
6.4 Email-Based Flight Import
Where a User voluntarily forwards a flight confirmation email, the Company processes the email solely for the purpose of:
- extracting itinerary information;
- creating travel records;
- avoiding manual entry;
improving user convenience.
The Company shall not process the forwarded email for advertising, profiling unrelated to the Services, or unrelated commercial purposes.
6.5 Travel Management
The Company processes Personal Data to enable:
- trip organisation;
- itinerary management;
- historical travel records;
- travel statistics;
- journey summaries;
- carbon footprint calculations;
- travel passport features;
- airport information;
travel reminders.
PART BService Improvement
6.6 Product Development
The Company may process Personal Data to:
- improve existing features;
- identify software defects;
- improve user interface design;
- enhance system performance;
- optimise application reliability;
- improve accessibility;
improve customer experience.
Where practicable, such processing shall utilise anonymised or aggregated information.
6.7 Analytics
The Company processes analytics information to understand:
- feature usage;
- user engagement;
- service availability;
- application stability;
- crash frequency;
- response times;
product performance.
Analytics shall not be used to identify individual Users unless strictly necessary for debugging, fraud prevention or legal compliance.
6.8 Artificial Intelligence Features
The Company may process Personal Data for AI-assisted features including:
- delay prediction;
- travel recommendations;
- airport insights;
- travel statistics;
- intelligent notifications;
personalised travel suggestions.
AI processing shall be proportionate to the intended purpose and shall be subject to appropriate human oversight where required by applicable law.
PART CCommunications
6.9 Operational Communications
The Company processes Personal Data to communicate with Users regarding:
- account verification;
- password resets;
- authentication alerts;
- subscription status;
- payment confirmations;
- flight alerts;
- service updates;
- security notifications;
- policy changes;
customer support responses.
These communications constitute essential service communications and are not marketing communications.
6.10 Customer Support
Personal Data may be processed to:
- investigate reported issues;
- resolve technical problems;
- respond to enquiries;
- verify account ownership;
- investigate complaints;
improve support quality.
Support records may be retained in accordance with the Company’s Data Retention Policy.
PART DCommunity Features
6.11 Social and Community Functionality
Where Users voluntarily participate in community features, Personal Data may be processed to:
- create travel groups;
- share itineraries;
- display shared travel updates;
- facilitate invitations;
- manage permissions;
enable collaborative trip planning.
Only information selected by the User for sharing shall be made visible to other Users.
PART ECommercial Purposes
6.12 Subscription Management
Personal Data may be processed to:
- administer subscriptions;
- verify purchases;
- process renewals;
- prevent subscription fraud;
- provide premium functionality;
maintain billing records.
Payment card information shall be processed by authorised payment processors and not stored by the Company except as expressly disclosed.
6.13 Marketing Communications
Where permitted by applicable law and, where required, based upon valid consent, the Company may process Personal Data to:
- send newsletters;
- communicate product updates;
- announce new features;
- provide promotional offers;
invite participation in surveys.
Users may opt out of marketing communications at any time without affecting access to the Services.
6.14 Advertising
Where the Company offers an advertising-supported version of the Services, Personal Data may be processed to:
- display contextual advertisements;
- measure advertisement performance;
- prevent advertising fraud;
manage advertising frequency.
The Company does not sell Personal Data to advertisers or data brokers.
Where behavioural or personalised advertising requires consent under applicable law, such consent shall be obtained before processing.
PART FSecurity and Legal Compliance
6.15 Security
The Company processes Personal Data to:
- detect fraud;
- detect malicious activity;
- prevent unauthorised access;
- secure user accounts;
- investigate security incidents;
- maintain audit logs;
- ensure system integrity;
monitor suspicious behaviour.
Security processing is undertaken to protect both Users and the Company’s infrastructure.
6.16 Compliance with Law
The Company may process Personal Data where necessary to:
- comply with statutory obligations;
- comply with judicial orders;
- respond to lawful governmental requests;
- enforce contractual rights;
- defend legal claims;
- establish legal rights;
exercise legal remedies.
Such processing shall be limited to what is reasonably necessary under applicable law.
6.17 Corporate Transactions
Personal Data may be processed in connection with:
- mergers;
- acquisitions;
- business restructuring;
- financing;
- investment transactions;
sale of assets.
Where Personal Data is transferred as part of such a transaction, the Company shall ensure that the receiving entity is bound by obligations substantially equivalent to those contained in this Privacy Policy.
PART GProhibited Purposes
6.18 Processing the Company Will Not Undertake
Unless expressly authorised by law or with the User’s explicit consent where required, the Company shall not process Personal Data for:
- unlawful discrimination;
- unlawful surveillance;
- sale of Personal Data;
- undisclosed profiling;
- processing unrelated to disclosed purposes;
- deceptive commercial practices;
- unauthorized access to third-party accounts;
any activity prohibited under applicable law.
PART HPurpose Limitation
6.19 Purpose Limitation Principle
Personal Data shall not be processed for any purpose incompatible with the original purpose of collection unless:
- the User has provided fresh consent where required;
- the processing is authorised by applicable law;
the new purpose is compatible with the original purpose under applicable law; or
the processing is necessary to protect the vital interests of an individual or to comply with a legal obligation.
6.20 Review of Processing Purposes
The Company shall periodically review all processing activities to ensure that:
- each processing activity has a documented lawful purpose;
- the purpose remains necessary and proportionate;
unnecessary processing is discontinued; and
this Privacy Policy is updated where new purposes are introduced.
CHAPTER 7LAWFUL BASES FOR PROCESSING PERSONAL DATA
7.1 Purpose
This Chapter sets out the lawful grounds upon which TrackMyWings Technologies Private Limited (“TrackMyWings” or the “Company”) processes Personal Data.
The Company shall not process Personal Data unless such processing is supported by a lawful basis under applicable law, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the General Data Protection Regulation (“GDPR”), the UK GDPR, and other applicable privacy legislation.
Each processing activity undertaken by the Company shall be documented, assigned an appropriate lawful basis, and periodically reviewed to ensure continued compliance.
PART AGeneral Principles
7.2 Principle of Lawfulness
The Company shall process Personal Data only where:
- (a) the Data Principal or Data Subject has provided valid consent;
- (b) processing is necessary for the performance of a contract;
- (c) processing is necessary to comply with a legal obligation;
- (d) processing is necessary to protect the vital interests of an individual;
- (e) processing is necessary for the performance of a task carried out in the public interest, where applicable; or
- (f) processing is necessary for the legitimate interests pursued by the Company or a third party, provided that such interests are not overridden by the rights and freedoms of the Data Subject.
7.3 Documentation of Lawful Basis
For every category of processing activity, the Company shall maintain documented records identifying:
- the processing activity;
- the categories of Personal Data processed;
- the applicable lawful basis;
- the purpose of processing;
- the categories of recipients;
applicable retention periods; and
any additional safeguards implemented.
Such documentation shall form part of the Company’s Record of Processing Activities (“ROPA”) where required by applicable law.
PART BConsent
7.4 Processing Based on Consent
Where consent constitutes the lawful basis for processing, the Company shall ensure that consent is:
- freely given;
- specific;
- informed;
- unambiguous;
affirmative; and
capable of being withdrawn at any time.
Consent shall not be obtained through:
- silence;
- inactivity;
- pre-ticked boxes;
- deceptive interfaces (“dark patterns”);
bundled consent for unrelated purposes; or
coercive practices.
7.5 Examples of Consent-Based Processing
Consent may be relied upon for processing activities including:
- enabling optional location services;
- sending marketing communications;
- participation in optional surveys;
- participation in beta testing programmes;
- community sharing features;
- optional AI-powered personalisation;
enabling non-essential analytics or advertising technologies where legally required.
7.6 Withdrawal of Consent
A User may withdraw consent at any time through:
- in-app privacy settings;
- account settings;
- the Company’s privacy request portal;
written request to the Grievance Officer or Data Protection Officer; or
any other mechanism provided by the Company.
Withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal.
Where consent is withdrawn, the Company shall cease the relevant processing unless another lawful basis applies.
PART CPerformance of a Contract
7.7 Contractual Necessity
The Company may process Personal Data where such processing is necessary to perform a contract with the User or to take steps at the request of the User prior to entering into a contract.
Examples include:
- account creation;
- user authentication;
- maintaining user profiles;
- flight tracking;
- importing flight information;
- providing premium subscriptions;
- delivering notifications;
- customer support;
billing administration.
Processing shall be limited to what is reasonably necessary for contractual performance.
PART DCompliance with Legal Obligations
7.8 Legal Obligations
The Company may process Personal Data where necessary to comply with applicable legal obligations, including obligations relating to:
- taxation;
- accounting;
- corporate governance;
- judicial proceedings;
- law enforcement requests;
- regulatory investigations;
- fraud prevention;
- cybersecurity;
- sanctions compliance;
court orders.
The Company shall process only the minimum Personal Data necessary to fulfil the relevant legal obligation.
PART ELegitimate Interests (GDPR)
7.9 Legitimate Interests
Where permitted under the GDPR, the Company may process Personal Data where such processing is necessary for its legitimate interests or those of a third party, provided such interests are not overridden by the rights and freedoms of the Data Subject.
Legitimate interests may include:
- protecting network security;
- preventing fraud;
- improving application performance;
- conducting internal audits;
- maintaining service reliability;
- defending legal claims;
- business continuity;
- preventing abuse of the Services;
ensuring information security.
7.10 Legitimate Interest Assessment
Before relying upon legitimate interests, the Company shall conduct and document a Legitimate Interest Assessment (“LIA”) that considers:
- the nature of the legitimate interest;
- the necessity of the processing;
- the reasonable expectations of the Data Subject;
- the potential impact on individual rights;
safeguards implemented to mitigate risks.
Where the assessment concludes that the rights and freedoms of individuals override the Company’s interests, another lawful basis shall be identified or the processing shall not proceed.
PART FVital Interests
7.11 Protection of Vital Interests
The Company may process Personal Data where necessary to protect the vital interests of a User or another natural person, including situations involving imminent threats to life, health, or physical safety.
Such processing shall be exceptional, proportionate, and limited to the circumstances giving rise to the emergency.
PART GPublic Interest
7.12 Processing in the Public Interest
Where authorised by applicable law, the Company may process Personal Data for tasks carried out in the public interest or in the exercise of official authority vested in the Company.
TrackMyWings does not ordinarily rely upon this lawful basis in the normal course of its commercial operations.
PART HProcessing of Children’s Personal Data
7.13 Lawful Basis for Children’s Data
Where processing relates to a child and consent is required by applicable law, the Company shall obtain verifiable consent from the child’s parent or lawful guardian before commencing such processing.
The Company shall implement reasonable procedures to verify the identity and authority of the consenting adult.
PART ISpecial Categories of Personal Data
7.14 Processing of Special Categories
The Company does not intentionally collect or process special categories of Personal Data, such as health data, biometric data, genetic data, racial or ethnic origin, political opinions, religious beliefs, or sexual orientation, except where:
- expressly required by law;
- voluntarily provided for a specific support request;
necessary to establish, exercise, or defend legal claims; or
processed with explicit consent where required.
If such data is inadvertently received, it shall be securely deleted or anonymised unless retention is legally required.
PART JPurpose Compatibility
7.15 Further Processing
Where the Company proposes to process Personal Data for a purpose other than that for which it was originally collected, it shall first determine whether the new purpose is compatible with the original purpose.
In assessing compatibility, the Company shall consider:
- the relationship between the original and new purposes;
- the context in which the data was collected;
- the nature of the Personal Data;
- the potential consequences for the User;
the safeguards applied.
Where the new purpose is incompatible, the Company shall obtain fresh consent or identify another lawful basis before proceeding.
PART KAccountability
7.16 Periodic Review
The Company shall periodically review all processing activities to ensure that:
- the lawful basis remains valid;
- the purpose of processing remains necessary;
- any consent relied upon remains valid;
- appropriate documentation is maintained;
technical and organisational safeguards remain effective.
Where a lawful basis ceases to apply, the Company shall discontinue the relevant processing or identify an alternative lawful basis permitted by law.
Schedule 7-A: Lawful Basis Matrix
| Processing Activity | Primary Lawful Basis | Secondary Basis (if applicable) |
|---|---|---|
| Account registration | Contract | Consent |
| Google Sign-In authentication | Contract | Consent |
| Flight itinerary management | Contract | — |
| Flight email parsing | Consent | Contract |
| Flight status notifications | Contract | Legitimate Interests |
| Customer support | Contract | Legal Obligation |
| Subscription billing | Contract | Legal Obligation |
| Fraud prevention | Legitimate Interests | Legal Obligation |
| Information security | Legitimate Interests | Legal Obligation |
| Marketing emails | Consent | — |
| Product analytics | Legitimate Interests (GDPR) / Consent where required | — |
| Community sharing features | Consent | Contract |
| AI travel recommendations | Legitimate Interests or Consent (depending on jurisdiction) | Contract |
| Legal compliance and regulatory reporting | Legal Obligation | — |
| Business continuity and disaster recovery | Legitimate Interests | Legal Obligation |
CHAPTER 8CONSENT MANAGEMENT, PRIVACY NOTICES AND TRANSPARENCY
8.1 Purpose
This Chapter establishes the framework governing the obtaining, recording, management, renewal, withdrawal and verification of Consent by TrackMyWings Technologies Private Limited (“TrackMyWings” or the “Company”).
The Company recognises that Consent is a cornerstone of lawful processing under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and, where applicable, the General Data Protection Regulation (“GDPR”).
The Company shall ensure that every Consent obtained is capable of being demonstrated through documented evidence and is managed throughout its lifecycle in a transparent and user-centric manner.
PART APrivacy Notices
8.2 Privacy Notice at the Time of Collection
Before or at the time of collecting Personal Data, the Company shall provide the User with a clear and easily understandable Privacy Notice containing, where applicable:
- (a) the identity and contact details of the Company;
- (b) the categories of Personal Data being collected;
- (c) the purposes for which the Personal Data will be processed;
- (d) the lawful basis for processing;
- (e) whether provision of Personal Data is mandatory or voluntary;
- (f) the consequences of refusing to provide the requested information;
- (g) categories of recipients of Personal Data;
- (h) information regarding international transfers;
- (i) applicable retention periods;
- (j) the rights available to the User;
- (k) procedures for exercising such rights;
- (l) contact details of the Grievance Officer and Data Protection Officer, where applicable.
The Privacy Notice shall be concise, transparent, intelligible and easily accessible.
8.3 Layered Privacy Notices
Where appropriate, the Company may provide privacy information using a layered approach consisting of:
- a short-form notice displayed at the point of collection;
- a detailed Privacy Policy;
contextual notices explaining specific features; and
just-in-time notices for new processing activities.
8.4 Language
Privacy notices shall be drafted in clear, plain and easily understandable language.
Where commercially appropriate or legally required, notices may be provided in multiple languages.
Legal terminology shall be avoided where simpler language adequately conveys the required information.
PART BConsent Requirements
8.5 Valid Consent
Consent shall be regarded as valid only if it is:
- freely given;
- specific;
- informed;
- unconditional;
- unambiguous;
obtained through an affirmative action.
Consent shall never be inferred from:
- inactivity;
- silence;
- continued browsing;
- default settings;
- pre-selected checkboxes;
deceptive interface designs.
8.6 Separate Consent for Separate Purposes
Where multiple processing purposes exist, the Company shall obtain separate Consent for each materially distinct purpose, including, where applicable:
- account creation;
- location processing;
- marketing communications;
- personalised recommendations;
- community sharing;
- participation in surveys;
- beta programmes;
- optional analytics;
advertising technologies.
Consent for one purpose shall not be treated as Consent for another unrelated purpose.
8.7 Granularity of Consent
The Company shall, wherever practicable, provide Users with granular controls enabling them to selectively consent to individual categories of processing.
Users shall not be compelled to consent to optional processing as a condition of receiving core Services unless such processing is objectively necessary for the requested functionality.
PART CRecording and Management of Consent
8.8 Consent Records
The Company shall maintain secure records demonstrating that valid Consent has been obtained.
Such records may include:
- identity of the User;
- date and time of Consent;
- version of the Privacy Notice;
- version of the Privacy Policy;
- processing purposes;
- method by which Consent was obtained;
- IP address or equivalent device identifier where appropriate;
record of subsequent modifications or withdrawal.
Consent records shall be protected against unauthorised alteration.
8.9 Version Control
Where the wording of any Consent request is materially changed, the Company shall maintain historical records identifying:
- previous versions;
- effective dates;
- revised wording;
Users to whom each version applied.
8.10 Auditability
Consent management systems shall be designed to enable internal and external audits demonstrating compliance with applicable law.
PART DWithdrawal of Consent
8.11 Right to Withdraw
Users may withdraw Consent at any time.
Withdrawal shall be as easy as giving Consent.
The Company shall not impose unreasonable barriers, unnecessary delays or unjustified charges for withdrawal.
8.12 Methods of Withdrawal
Consent may be withdrawn through:
- application settings;
- account settings;
- privacy dashboard;
- email request;
- privacy request portal;
written communication to the Company.
The Company may introduce additional withdrawal mechanisms from time to time.
8.13 Effect of Withdrawal
Upon withdrawal of Consent:
- (a) the Company shall cease the relevant processing unless another lawful basis applies;
- (b) processing already carried out shall remain lawful;
- (c) essential contractual processing may continue where necessary;
- (d) records evidencing the withdrawn Consent may be retained for compliance purposes.
PART EConsent Refresh
8.14 Renewal of Consent
The Company shall seek renewed Consent where:
- processing purposes materially change;
- new categories of Personal Data are collected;
- new categories of recipients are introduced;
- legal requirements change;
existing Consent becomes invalid or insufficient.
8.15 Periodic Review
The Company may periodically review existing Consents to ensure they remain valid and reflective of the User’s expectations.
PART FChildren’s Consent
8.16 Parental Consent
Where processing relates to a child and parental consent is required under applicable law, the Company shall obtain verifiable consent from the child’s parent or lawful guardian before processing the child’s Personal Data.
Reasonable verification measures may include:
- confirmation emails;
- payment verification;
- government-issued identification (where proportionate);
- digital verification services;
other legally recognised methods.
8.17 Revocation by Parent or Guardian
A parent or lawful guardian may withdraw previously granted consent in accordance with applicable law.
Upon verification of authority, the Company shall cease the relevant processing unless otherwise authorised by law.
PART GConsent and Automated Decision-Making
8.18 AI Features
Where AI-powered features require Consent under applicable law, the Company shall clearly explain:
- the purpose of the processing;
- the categories of Personal Data used;
- the expected outcomes;
- significant effects, if any, on the User;
available safeguards.
Users shall be informed where decisions are based solely on automated processing and of any rights to request human intervention where required by law.
PART HTransparency Obligations
8.19 Transparency
The Company shall maintain transparency throughout the lifecycle of Personal Data by:
- publishing this Privacy Policy;
- maintaining an accessible privacy centre;
- providing timely notices of material changes;
- responding to privacy-related enquiries;
making available appropriate contact details.
8.20 No Dark Patterns
The Company shall not employ interface designs or user experience techniques intended to:
- manipulate Users into providing Consent;
- obscure withdrawal mechanisms;
- mislead Users regarding privacy choices;
impair the exercise of statutory rights.
Privacy choices shall be presented fairly, prominently and without undue influence.
PART IAccountability
8.21 Internal Governance
The Company shall implement appropriate technical and organisational measures to ensure that:
- Consent is managed consistently;
- employees receive privacy training;
- Consent records are periodically audited;
- privacy notices remain accurate;
processing activities remain aligned with disclosed purposes.
8.22 Review
This Chapter shall be reviewed whenever:
- applicable law changes;
- new categories of processing are introduced;
- significant product features are launched;
recommendations arise from audits or Data Protection Impact Assessments.
Schedule 8-A: Consent Matrix
| Processing Activity | Consent Required | Withdrawal Available |
|---|---|---|
| Account Registration | No (Contractual necessity) | Account deletion |
| Google Sign-In | Yes (authentication authorisation) | Disconnect account |
| Flight Email Import | Yes | Stop forwarding emails; delete imported itinerary |
| Location Services | Yes | Disable in app or device settings |
| Push Notifications | Yes | Disable in app or device settings |
| Marketing Emails | Yes | Unsubscribe at any time |
| Community Features | Yes | Disable or leave community features |
| AI Personalisation (where required by law) | Yes | Disable in privacy settings |
| Optional Analytics/Cookies (where required by law) | Yes | Manage through consent preferences |
CHAPTER 9RIGHTS OF DATA PRINCIPALS AND DATA SUBJECTS
9.1 Purpose
This Chapter establishes the rights available to individuals whose Personal Data is processed by TrackMyWings Technologies Private Limited (“TrackMyWings” or the “Company”).
The Company recognises that privacy rights are fundamental legal rights under applicable data protection laws and undertakes to facilitate the effective exercise of such rights in a transparent, timely and non-discriminatory manner.
This Chapter is intended to comply with:
- the Digital Personal Data Protection Act, 2023 (“DPDP Act”);
- the General Data Protection Regulation (“GDPR”);
the UK GDPR; and
other applicable privacy laws.
Where two or more legal regimes apply simultaneously, the Company shall provide the greater protection to the individual unless prohibited by applicable law.
PART AGeneral Principles
9.2 Equal Treatment
No individual shall be denied access to the Services, charged discriminatory prices, provided an inferior level of service, or otherwise subjected to adverse treatment solely because they exercise their privacy rights.
The Company shall not retaliate against any individual for exercising rights conferred by applicable law.
9.3 Free Exercise of Rights
Requests made under this Chapter shall ordinarily be processed without charge.
A reasonable administrative fee may be imposed only where:
- a request is manifestly unfounded;
- a request is excessive;
repeated copies are requested; or
applicable law expressly permits such fee.
The Company shall communicate the reasons for imposing any fee before processing the request.
PART BRights under the DPDP Act
9.4 Right to Access Information
A Data Principal may request confirmation as to whether the Company is processing their Personal Data.
Subject to applicable law, the Company shall provide information regarding:
- categories of Personal Data processed;
- purposes of processing;
- categories of recipients;
- retention periods;
- available rights;
grievance redressal mechanisms.
9.5 Right to Correction
A Data Principal may request correction of inaccurate or incomplete Personal Data.
Upon verification of the request, the Company shall:
- correct inaccurate information;
- complete incomplete information where appropriate;
- update relevant records;
notify affected processors where legally required.
9.6 Right to Erasure
A Data Principal may request deletion of Personal Data where:
- the Personal Data is no longer necessary;
- consent has been withdrawn and no alternative lawful basis exists;
- applicable law requires deletion;
the Data Principal closes their account and no legal retention obligation applies.
The Company may refuse deletion where retention is necessary:
- to comply with law;
- to establish, exercise or defend legal claims;
- to prevent fraud or abuse;
- to maintain information security;
to comply with court orders.
9.7 Right to Grievance Redressal
Every Data Principal shall have the right to submit a grievance concerning the Company’s processing of Personal Data.
The Company shall:
- acknowledge receipt of the grievance;
- investigate the matter impartially;
provide a reasoned response within the period prescribed by applicable law or, where no period is prescribed, within a reasonable time.
9.8 Right to Nominate
Where recognised by applicable law, a Data Principal may nominate another individual to exercise their rights under this Policy in the event of death or incapacity.
The Company may require reasonable evidence of the nominee’s authority before acting upon such request.
PART CRights under the GDPR
9.9 Right of Access
A Data Subject has the right to obtain confirmation as to whether Personal Data concerning them is being processed and, where that is the case, access to such Personal Data together with the information required under Articles 13, 14 and 15 of the GDPR.
9.10 Right to Rectification
A Data Subject has the right to obtain without undue delay the rectification of inaccurate Personal Data and the completion of incomplete Personal Data.
9.11 Right to Erasure (“Right to be Forgotten”)
A Data Subject may request erasure where:
- the Personal Data is no longer necessary;
- consent has been withdrawn;
- the processing is unlawful;
- objection to processing has been upheld;
erasure is required under applicable law.
The Company may decline the request where processing remains necessary for legal compliance, public interest, legal claims or other exceptions recognised by the GDPR.
9.12 Right to Restriction of Processing
A Data Subject may request that processing be restricted where:
- the accuracy of Personal Data is contested;
- processing is unlawful but erasure is opposed;
- the Company no longer requires the data but the Data Subject requires it for legal claims;
an objection to processing is pending determination.
During restriction, the Company shall process the Personal Data only to the extent permitted by applicable law.
9.13 Right to Data Portability
Where technically feasible and required by applicable law, a Data Subject may request a copy of Personal Data they have provided to the Company in a structured, commonly used and machine-readable format.
Where technically feasible, the Company shall facilitate direct transmission to another controller where requested by the Data Subject.
9.14 Right to Object
A Data Subject may object to processing based upon:
- legitimate interests;
- direct marketing;
profiling related to direct marketing; or
other grounds recognised under applicable law.
Upon receipt of a valid objection, the Company shall cease the relevant processing unless compelling legitimate grounds or another lawful basis justifies its continuation.
9.15 Rights Relating to Automated Decision-Making
Where applicable law grants such rights, a Data Subject may:
- request meaningful information about the logic involved in solely automated decisions;
- request human intervention;
- express their point of view;
contest the decision.
TrackMyWings shall ensure that significant decisions producing legal or similarly significant effects are not based solely on automated processing where prohibited by applicable law.
PART DExercising Rights
9.16 Submission of Requests
Privacy requests may be submitted through:
- the in-app privacy centre;
- account settings;
- the Company’s website;
- email to the Grievance Officer or Data Protection Officer;
- postal correspondence;
any other mechanism notified by the Company.
The Company may provide standard request forms for administrative convenience, but shall not require their use where the identity and intent of the requester are otherwise clear.
9.17 Verification of Identity
Before acting on a request, the Company may take reasonable steps to verify the identity of the requester or the authority of an authorised representative.
Verification measures shall be proportionate to the sensitivity of the request and shall minimise the collection of additional Personal Data.
9.18 Time for Response
The Company shall acknowledge and respond to requests within the time periods prescribed by applicable law.
Where no statutory period applies, the Company shall respond without undue delay and, in any event, within a reasonable period.
Where an extension is permitted due to the complexity or volume of requests, the Company shall inform the requester of:
- the reason for the extension;
the anticipated date of completion.
9.19 Refusal of Requests
The Company may refuse a request where:
- the request is manifestly unfounded or excessive;
- compliance would violate applicable law;
- compliance would adversely affect the rights and freedoms of another person;
- retention is legally required;
the request falls within an applicable statutory exemption.
Where a request is refused, the Company shall provide a written explanation, unless prohibited by law, together with information regarding available avenues of review or complaint.
PART ERecord Keeping
9.20 Register of Rights Requests
The Company shall maintain a confidential register recording:
- the date of receipt of each request;
- the nature of the request;
- verification steps undertaken;
- actions taken;
- date of response;
outcome of the request.
Such records shall be retained only for so long as necessary to demonstrate compliance with applicable law.
PART FAccountability
9.21 Training
Employees responsible for handling privacy requests shall receive periodic training regarding:
- applicable legal requirements;
- verification procedures;
- confidentiality obligations;
- response timelines;
escalation procedures.
9.22 Periodic Review
The Company shall periodically review the effectiveness of its rights-handling procedures and update them in light of:
- legislative developments;
- judicial decisions;
- regulatory guidance;
- audit findings;
recommendations arising from Data Protection Impact Assessments.
Schedule 9-A: Summary of Rights
| Right | DPDP Act | GDPR | Available Through |
|---|---|---|---|
| Access | ✔ | ✔ | Privacy Centre / Email |
| Correction | ✔ | ✔ | Account Settings / Request |
| Erasure | ✔ | ✔ | Privacy Centre |
| Grievance | ✔ | — | Grievance Officer |
| Nomination | ✔ | — | Written Request |
| Restriction of Processing | — | ✔ | Privacy Request |
| Data Portability | — | ✔ | Export Tool |
| Objection | — | ✔ | Privacy Request |
| Human Review of Automated Decisions | — | ✔ | Privacy Request |
CHAPTER 10PROCESSING OF PERSONAL DATA OF CHILDREN AND PERSONS WITH DISABILITIES
10.1 Purpose
This Chapter establishes the policy governing the collection, use, disclosure, storage, retention and protection of Personal Data relating to:
- (a) children;
- (b) persons with disabilities whose lawful guardian acts on their behalf; and
- (c) any other vulnerable individuals entitled to enhanced protection under applicable law.
The Company recognises that children and vulnerable persons require a higher standard of privacy protection and shall process their Personal Data only in accordance with applicable law, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the General Data Protection Regulation (“GDPR”), the UK GDPR and other applicable legislation.
PART AGeneral Principles
10.2 Best Interests Principle
The Company shall process Personal Data relating to children only where such processing is demonstrably in the best interests of the child.
Commercial considerations shall never override the privacy rights, dignity, welfare or safety of children.
10.3 Enhanced Protection
Personal Data relating to children shall receive enhanced protection through:
- higher access controls;
- stricter processing limitations;
- additional security safeguards;
- periodic compliance reviews;
restricted disclosure practices.
10.4 Data Minimisation
Only the minimum Personal Data necessary for providing the requested Services shall be collected from or about a child.
The Company shall avoid collecting information that is not strictly necessary for the relevant purpose.
PART BAge Requirements
10.5 Minimum Age
TrackMyWings is not directed toward children unless expressly stated otherwise.
Where applicable law prescribes a minimum age for independent consent to digital services, the Company shall comply with that requirement.
For the purposes of the DPDP Act, a “child” shall have the meaning assigned under that Act, subject to any exemptions or notifications issued by the Central Government.
10.6 Age Verification
Where reasonably necessary, the Company may implement proportionate age verification mechanisms.
Such mechanisms may include:
- self-declaration;
- confirmation through an authenticated account;
- verification by a parent or lawful guardian;
- third-party age verification services;
other lawful and proportionate verification measures.
The Company shall avoid collecting excessive Personal Data solely for age verification purposes.
PART CParental or Guardian Consent
10.7 Requirement of Verifiable Consent
Where consent from a parent or lawful guardian is required by applicable law, the Company shall obtain verifiable consent before collecting or processing the child’s Personal Data.
The Company shall maintain records demonstrating that such consent has been obtained.
10.8 Verification of Authority
Before accepting parental or guardian consent, the Company may require reasonable evidence establishing that the person providing consent has legal authority to do so.
Verification measures shall be proportionate and privacy-preserving.
10.9 Withdrawal of Consent
A parent or lawful guardian may withdraw previously granted consent at any time.
Upon verification of the request, the Company shall cease the relevant processing unless another lawful basis applies or retention is required by law.
PART DProhibited Processing
10.10 Prohibition on Harmful Processing
The Company shall not knowingly undertake processing of a child’s Personal Data in a manner likely to cause:
- physical harm;
- psychological harm;
- emotional harm;
- financial harm;
reputational harm; or
any other material detriment.
10.11 No Behavioural Advertising
The Company shall not knowingly engage in behavioural advertising directed at children where prohibited by applicable law.
Where advertising is displayed within the Services, it shall be contextual rather than behaviourally targeted unless expressly permitted by law and supported by valid consent.
10.12 No Profiling
The Company shall not profile children for the purpose of:
- targeted advertising;
- commercial exploitation;
- behavioural prediction;
marketing segmentation; or
automated decision-making producing legal or similarly significant effects,
unless expressly authorised by applicable law and subject to appropriate safeguards.
10.13 No Sale of Children’s Personal Data
The Company shall not sell, licence or otherwise commercially exploit Personal Data relating to children.
PART EServices Used by Children
10.14 Limited Processing
Where a child lawfully uses the Services, the Company shall process only such Personal Data as is necessary to:
- create and maintain an account (where permitted);
- provide requested travel-related functionality;
- maintain security;
comply with legal obligations; and
respond to customer support requests.
10.15 Community Features
Community features involving children shall be subject to enhanced privacy controls.
By default, the Company shall configure such features to minimise public visibility of the child’s Personal Data, consistent with the principle of Privacy by Default.
10.16 Location Information
The Company shall not knowingly collect or retain precise location information relating to a child except where:
- necessary to provide the requested functionality;
legally permissible; and
supported by the consent required under applicable law.
Where technically feasible, location processing shall occur locally on the child’s device.
PART FPersons with Disabilities
10.17 Lawful Representatives
Where Personal Data relates to a person with a disability whose lawful guardian or authorised representative acts on their behalf, the Company shall recognise requests made by such representative upon verification of their authority.
10.18 Accessibility
Privacy notices, consent requests and rights request mechanisms shall, where reasonably practicable, be designed to be accessible to persons with disabilities.
The Company shall endeavour to provide accessible formats consistent with applicable accessibility standards.
PART GSecurity
10.19 Enhanced Security Measures
Personal Data relating to children and vulnerable persons shall be protected through enhanced safeguards, including:
- role-based access controls;
- encryption in transit and at rest;
- restricted employee access;
- audit logging;
- periodic security reviews;
heightened incident monitoring.
10.20 Personal Data Breaches
Where a Personal Data Breach affects information relating to children or vulnerable persons, the Company shall give particular consideration to:
- the potential impact on affected individuals;
- any enhanced notification obligations under applicable law;
prompt containment and remediation measures.
PART HRights
10.21 Exercise of Rights
A parent, lawful guardian or authorised representative may, where recognised by applicable law:
- request access;
- request correction;
- request erasure;
- withdraw consent;
- submit grievances;
exercise any other applicable statutory rights on behalf of the child or person with disability.
The Company may require reasonable evidence of authority before acting upon such requests.
PART IGovernance
10.22 DPIA Requirement
Before introducing any feature reasonably likely to involve high-risk processing of children’s Personal Data, the Company shall conduct a Data Protection Impact Assessment (DPIA).
The DPIA shall evaluate:
- necessity of processing;
- proportionality;
- potential risks to children;
- mitigation measures;
- residual risks;
ongoing monitoring requirements.
10.23 Periodic Review
The Company shall periodically review:
- age verification procedures;
- parental consent mechanisms;
- safeguards for children;
- accessibility measures;
compliance with applicable legal requirements.
Appropriate amendments shall be made where technological developments, legal changes or audit findings indicate the need for improvement.
Schedule 10-A: Safeguards for Children’s Personal Data
| Processing Activity | Additional Safeguard |
|---|---|
| Account Creation | Age verification where required |
| Location Services | Explicit parental consent where applicable; on-device processing where feasible |
| Community Features | Private by default; restricted visibility |
| Marketing | No direct marketing without lawful basis and required consent |
| Behavioural Advertising | Prohibited where required by law |
| AI Features | Human oversight; no significant automated decisions affecting children |
| Data Sharing | Limited to essential processors under contractual safeguards |
| Data Retention | Minimum necessary retention with periodic review |
CHAPTER 11SHARING, DISCLOSURE AND TRANSFER OF PERSONAL DATA
11.1 Purpose
This Chapter governs the circumstances under which TrackMyWings Technologies Private Limited (“TrackMyWings” or the “Company”) may share, disclose, transfer, provide access to, or otherwise make Personal Data available to third parties.
The Company recognises that disclosure of Personal Data represents a significant privacy risk and shall ensure that every disclosure:
- is lawful;
- is necessary and proportionate;
- is limited to the minimum Personal Data required;
is protected by appropriate contractual, technical and organisational safeguards; and
complies with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the General Data Protection Regulation (“GDPR”), and other applicable laws.
The Company does not sell Personal Data to third parties.
PART AGeneral Principles
11.2 Principle of Restricted Disclosure
Personal Data shall be disclosed only where:
- (a) the disclosure is necessary for providing the Services;
- (b) the User has expressly authorised the disclosure;
- (c) disclosure is required by applicable law;
- (d) disclosure is necessary for the establishment, exercise or defence of legal claims;
- (e) disclosure is necessary to protect the rights, property or safety of the Company, its Users or the public; or
- (f) another lawful basis exists under applicable law.
All disclosures shall be limited to the minimum information reasonably necessary for the relevant purpose.
11.3 No Sale of Personal Data
The Company shall not:
- sell Personal Data;
- rent Personal Data;
- trade Personal Data;
- auction Personal Data;
license Personal Data for unrelated commercial exploitation; or
disclose Personal Data to data brokers.
Nothing in this clause shall prevent the Company from engaging Data Processors or service providers solely for the purpose of providing the Services.
PART BService Providers and Data Processors
11.4 Appointment of Data Processors
The Company may engage carefully selected third-party service providers (“Data Processors”) to process Personal Data on its behalf.
Such Data Processors may include providers of:
- cloud infrastructure;
- databases;
- authentication;
- payment processing;
- subscription management;
- push notifications;
- customer support;
- analytics;
- monitoring;
- cybersecurity;
- aviation data;
- email delivery;
- content delivery networks;
backup and disaster recovery.
Each Data Processor shall process Personal Data only on documented instructions from the Company.
11.5 Data Processing Agreements
Before disclosing Personal Data to a Data Processor, the Company shall execute a written Data Processing Agreement (“DPA”) requiring the Data Processor to:
- process Personal Data only for authorised purposes;
- maintain confidentiality;
- implement appropriate technical and organisational measures;
- assist the Company in fulfilling statutory obligations;
- notify the Company of Personal Data Breaches without undue delay;
- permit audits where contractually required;
- ensure lawful engagement of sub-processors;
securely delete or return Personal Data upon termination of the services.
11.6 Approved Sub-processors
The Company may authorise a Data Processor to engage a sub-processor only where:
- prior authorisation has been obtained where required;
substantially equivalent contractual obligations are imposed upon the sub-processor; and
the Company remains responsible for ensuring compliance with applicable law.
The Company shall maintain and publish, or make available upon request where appropriate, an up-to-date list of its significant sub-processors.
PART CCategories of Third-Party Recipients
11.7 Cloud Service Providers
The Company may disclose Personal Data to cloud service providers solely for the purpose of hosting, storing and securing the Services.
Cloud providers shall not use Personal Data for their own independent purposes except as required by applicable law.
11.8 Payment Service Providers
Subscription-related information may be disclosed to PCI-DSS (Payment Card Industry Data Security Standard) compliant payment service providers for the purposes of:
- processing payments;
- subscription management;
- fraud prevention;
- chargeback handling;
financial reporting.
The Company shall not disclose or store complete payment card details except where expressly authorised by applicable law.
11.9 Aviation Data Providers
Personal Data may be disclosed to aviation data providers where necessary to:
- retrieve flight information;
- verify itinerary details;
- deliver operational updates;
improve travel-related services.
Only the minimum information necessary to perform the requested function shall be disclosed.
11.10 Communication Providers
The Company may disclose limited Personal Data to providers of:
- email services;
- SMS services (where used);
- push notification services;
customer messaging platforms.
Such disclosures shall be limited to information necessary to deliver communications requested by or relating to the User.
11.11 Analytics Providers
Where analytics services are used, the Company shall, wherever reasonably practicable:
- pseudonymise Personal Data before disclosure;
- minimise the amount of information disclosed;
- configure analytics tools to reduce privacy risks;
disable unnecessary identifiers.
PART DCommunity Features
11.12 User-Initiated Sharing
Where a User elects to use community or collaborative features, Personal Data selected by the User may be shared with other authorised Users.
Examples include:
- shared itineraries;
- travel groups;
- flight status updates;
profile information chosen by the User.
The Company shall provide privacy controls enabling Users to manage the visibility of such information.
11.13 Responsibility for Shared Information
Users acknowledge that information voluntarily shared with other Users may be copied, retained or further disclosed by those recipients.
The Company shall not be responsible for subsequent processing undertaken independently by other Users, except to the extent required by applicable law.
PART ECorporate Transactions
11.14 Business Transfers
In connection with:
- mergers;
- acquisitions;
- investments;
- corporate restructuring;
- sale of assets;
insolvency proceedings; or
other corporate transactions,
Personal Data may be disclosed to prospective or actual counterparties, their professional advisers and financing institutions.
Any recipient shall be required to maintain the confidentiality of the Personal Data and use it only for purposes connected with the transaction.
Where required by law, Users shall be notified of any material change in control affecting the processing of their Personal Data.
PART FLegal Disclosures
11.15 Compliance with Law
The Company may disclose Personal Data where reasonably necessary to:
- comply with applicable law;
- comply with judicial orders;
- respond to lawful requests from governmental authorities;
- cooperate with regulatory investigations;
- enforce contractual rights;
establish, exercise or defend legal claims.
The Company shall verify the legal basis and scope of each request before making any disclosure.
11.16 Law Enforcement Requests
Where Personal Data is requested by a law enforcement agency, the Company shall:
- verify the authority of the requesting agency;
- review the legal validity of the request;
- disclose only the information lawfully required;
maintain a record of the disclosure unless prohibited by law.
Where legally permissible, the Company may notify the affected User before disclosing Personal Data.
11.17 Emergency Disclosures
The Company may disclose Personal Data without prior notice where reasonably necessary to:
- protect life or physical safety;
- prevent serious harm;
- respond to imminent cybersecurity threats;
comply with emergency legal obligations.
Such disclosures shall be documented and subject to subsequent review.
PART GInternational Transfers
11.18 Cross-Border Transfers
Where Personal Data is transferred outside the jurisdiction in which it was collected, the Company shall ensure that such transfers are carried out in accordance with:
- the DPDP Act;
- GDPR Chapter V;
the UK GDPR; and
other applicable laws.
Appropriate safeguards may include:
- Standard Contractual Clauses (SCCs);
- adequacy decisions;
- binding corporate rules;
approved certification mechanisms; or
any other lawful transfer mechanism recognised under applicable law.
Transfers from India shall also comply with any restrictions or notifications issued under the DPDP Act.
PART HDisclosure Restrictions
11.19 Prohibited Disclosures
The Company shall not knowingly disclose Personal Data:
- for unlawful purposes;
- to unauthorised third parties;
- beyond what is necessary for the stated purpose;
in a manner inconsistent with this Privacy Policy; or
in violation of applicable law.
11.20 Disclosure Register
The Company shall maintain internal records of categories of disclosures made to third parties, including:
- recipient category;
- purpose of disclosure;
- lawful basis;
- date of disclosure;
applicable safeguards.
Such records shall form part of the Company’s privacy governance programme and, where required, its Record of Processing Activities.
PART IAccountability
11.21 Periodic Review
The Company shall periodically review:
- all third-party disclosures;
- vendor contracts;
- Data Processing Agreements;
- international transfer mechanisms;
sub-processor arrangements; and
disclosure practices.
Where deficiencies are identified, appropriate corrective measures shall be implemented without undue delay.
Schedule 11-A: Categories of Third-Party Recipients
| Recipient Category | Purpose of Disclosure | Safeguards |
|---|---|---|
| Cloud Hosting Providers | Hosting and storage | Data Processing Agreement, encryption, access controls |
| Authentication Providers | User authentication | OAuth, contractual obligations |
| Payment Processors | Subscription billing | PCI-DSS compliance, DPA |
| Aviation Data Providers | Flight information services | Purpose limitation, minimum necessary disclosure |
| Push Notification Providers | Delivery of alerts | Tokenisation, DPA |
| Analytics Providers | Service improvement | Pseudonymisation, data minimisation |
| Customer Support Providers | Resolution of support requests | Confidentiality obligations, access controls |
| Legal and Regulatory Authorities | Compliance with legal obligations | Verified legal process, minimum necessary disclosure |
CHAPTER 12INTERNATIONAL TRANSFERS OF PERSONAL DATA
12.1 Purpose
This Chapter establishes the legal, technical and organisational framework governing the transfer of Personal Data by TrackMyWings Technologies Private Limited (“TrackMyWings” or the “Company”) across national borders.
The Company recognises that cross-border transfers may expose Personal Data to varying levels of legal protection and therefore undertakes to ensure that every international transfer is carried out in a lawful, secure and accountable manner.
This Chapter shall be interpreted in accordance with:
- the Digital Personal Data Protection Act, 2023 (“DPDP Act”);
- the General Data Protection Regulation (“GDPR”), particularly Chapter V;
- the UK GDPR;
applicable national data protection laws; and
legally binding decisions or notifications issued by competent authorities.
PART AGeneral Principles
12.2 Lawful Cross-Border Transfers
The Company may transfer Personal Data outside the jurisdiction in which it was collected only where:
- (a) such transfer is necessary for the provision of the Services;
- (b) an appropriate legal transfer mechanism exists;
- (c) adequate technical and organisational safeguards are implemented;
- (d) the transfer complies with applicable law; and
- (e) the rights of the Data Principal or Data Subject remain protected.
12.3 Equivalent Level of Protection
Where Personal Data is transferred internationally, the Company shall endeavour to ensure that the recipient provides a level of protection that is substantially equivalent to that required under applicable law.
International transfers shall not be used to circumvent privacy protections applicable in the country of collection.
PART BTransfers under the DPDP Act
12.4 Compliance with Indian Law
Where Personal Data originates from India, international transfers shall comply with the DPDP Act and any rules, regulations or notifications issued thereunder.
The Company shall not transfer Personal Data to any jurisdiction that is restricted or prohibited by the Central Government under applicable law.
Where additional safeguards are prescribed by law, the Company shall implement such safeguards before transferring Personal Data.
12.5 Future Regulatory Changes
The Company acknowledges that the legal framework governing international transfers may evolve.
Accordingly, this Chapter shall be interpreted subject to:
- notifications issued by the Central Government;
- regulations framed under the DPDP Act;
- guidance issued by the Data Protection Board of India or any successor authority;
judicial interpretations by competent courts.
PART CTransfers under the GDPR
12.6 Adequacy Decisions
Where Personal Data originating from the European Economic Area (“EEA”) is transferred internationally, the Company may rely upon an adequacy decision adopted by the European Commission where available.
Transfers made pursuant to an adequacy decision shall remain subject to the Company’s internal security and governance requirements.
12.7 Standard Contractual Clauses
Where an adequacy decision is unavailable, the Company may rely upon the European Commission’s Standard Contractual Clauses (“SCCs”) or any successor mechanism recognised under applicable law.
Such clauses shall be incorporated into agreements with the relevant recipient where legally required.
12.8 Binding Corporate Rules
Where Personal Data is transferred within a corporate group, the Company may rely upon Binding Corporate Rules (“BCRs”) approved by the competent supervisory authority, where applicable.
12.9 Other Lawful Transfer Mechanisms
Where permitted by law, the Company may rely upon other recognised transfer mechanisms, including:
- approved codes of conduct;
- approved certification mechanisms;
- contractual safeguards recognised by law;
- explicit consent of the Data Subject where legally permissible;
derogations available under applicable legislation.
PART DTransfer Impact Assessments
12.10 Requirement for Assessment
Before undertaking high-risk international transfers, the Company shall conduct a Transfer Impact Assessment (“TIA”), where required by applicable law.
The assessment shall evaluate whether the recipient jurisdiction provides an adequate level of protection for the transferred Personal Data.
12.11 Matters to be Considered
A Transfer Impact Assessment may consider, among other things:
- the legal framework of the destination jurisdiction;
- government access laws;
- surveillance legislation;
- enforceability of contractual safeguards;
- technical safeguards implemented;
- sensitivity of the Personal Data;
- categories of recipients;
risks to the rights and freedoms of individuals.
12.12 Additional Measures
Where residual risks remain following the assessment, the Company shall implement supplementary safeguards, including, where appropriate:
- end-to-end encryption;
- encryption with customer-controlled keys;
- pseudonymisation;
- anonymisation;
- contractual restrictions;
- enhanced monitoring;
access controls.
PART ETechnical Safeguards
12.13 Secure Transfer Mechanisms
International transfers shall utilise secure communication channels employing industry-recognised encryption and authentication protocols.
Transfers shall not be made through unsecured or unauthorised communication channels.
12.14 Encryption
Where reasonably practicable, Personal Data transferred internationally shall be encrypted:
during transmission; and
while stored by the recipient.
Encryption keys shall be managed in accordance with recognised information security standards.
12.15 Access Controls
Access to internationally transferred Personal Data shall be limited to authorised personnel with a legitimate business need.
Role-based access controls, authentication measures and audit logging shall be implemented to monitor access.
PART FInternational Service Providers
12.16 Selection of Service Providers
Before engaging a service provider located outside the country of collection, the Company shall conduct appropriate due diligence, including an assessment of:
- legal compliance;
- information security practices;
- financial stability;
- incident response capabilities;
- regulatory history;
subcontracting arrangements.
12.17 Contractual Safeguards
Contracts with international service providers shall, where appropriate, include provisions concerning:
- confidentiality;
- security measures;
- breach notification;
- audit rights;
- restrictions on onward transfers;
- data retention;
deletion or return of Personal Data upon termination.
PART GOnward Transfers
12.18 Restrictions on Onward Transfers
A recipient of Personal Data shall not transfer such data to another recipient unless:
- authorised by the Company;
permitted under the applicable contractual arrangement; and
supported by an appropriate legal basis.
The original recipient shall remain responsible for ensuring compliance with applicable contractual obligations where required by law.
PART HUser Information
12.19 Transparency
The Company shall inform Users that their Personal Data may be processed in jurisdictions outside their country of residence where necessary for the operation of the Services.
The Privacy Policy shall describe:
- categories of recipient jurisdictions, where appropriate;
- safeguards implemented;
available mechanisms for obtaining further information.
12.20 User Rights
Where applicable law provides such rights, Users may request information regarding:
- the legal basis for an international transfer;
- applicable safeguards;
- categories of recipients;
mechanisms used to protect transferred Personal Data.
Confidential contractual information may be redacted where permitted by law.
PART IMonitoring and Compliance
12.21 Continuous Review
The Company shall periodically review:
- adequacy decisions;
- Standard Contractual Clauses;
- Transfer Impact Assessments;
- international vendor arrangements;
- applicable regulatory developments;
judicial decisions affecting cross-border transfers.
Where a transfer mechanism ceases to be legally valid, the Company shall suspend or modify the relevant transfers until an alternative lawful mechanism is implemented.
12.22 Record of International Transfers
The Company shall maintain internal records of international transfers, including:
- destination jurisdiction;
- recipient category;
- transfer mechanism relied upon;
- date of transfer;
- categories of Personal Data transferred;
supplementary safeguards implemented.
Such records shall form part of the Company’s privacy governance programme.
Schedule 12-A: International Transfer Mechanisms
| Transfer Scenario | Primary Legal Mechanism | Supplementary Safeguards |
|---|---|---|
| Transfer from India | Compliance with DPDP Act and Government notifications | Encryption, contractual safeguards, vendor due diligence |
| Transfer from EEA to Adequate Jurisdiction | European Commission Adequacy Decision | Security controls and audit rights |
| Transfer from EEA to Non-Adequate Jurisdiction | Standard Contractual Clauses (SCCs) | Transfer Impact Assessment, encryption, pseudonymisation |
| Intra-group Transfers | Binding Corporate Rules (where applicable) or SCCs | Internal governance and audits |
| Emergency Transfer | Applicable legal derogation | Minimum necessary disclosure and documented justification |
CHAPTER 13INFORMATION SECURITY, TECHNICAL AND ORGANISATIONAL MEASURES
13.1 Purpose
This Chapter establishes the Information Security Management Framework adopted by TrackMyWings Technologies Private Limited (“TrackMyWings” or the “Company”) for the protection of Personal Data throughout its lifecycle.
The Company recognises that information security is fundamental to preserving the confidentiality, integrity, availability, authenticity and resilience of Personal Data and shall implement appropriate technical and organisational measures proportionate to the nature, scope, context and purposes of processing, taking into account the risks to the rights and freedoms of individuals.
This Chapter shall be interpreted in accordance with:
- the Digital Personal Data Protection Act, 2023 (“DPDP Act”);
- the General Data Protection Regulation (“GDPR”);
- applicable cybersecurity laws;
internationally recognised information security standards, including ISO/IEC 27001, ISO/IEC 27701, and SOC 2 principles, where adopted by the Company.
PART AInformation Security Governance
13.2 Information Security Programme
The Company shall establish, implement and maintain a comprehensive Information Security Management Programme (“ISMP”) designed to:
- (a) safeguard Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access;
- (b) ensure continuity of essential business operations;
- (c) maintain regulatory compliance;
- (d) support secure software development; and
- (e) facilitate continuous improvement of security controls.
13.3 Risk-Based Security
Security measures shall be proportionate to:
- sensitivity of Personal Data;
- volume of Personal Data processed;
- likelihood of harm;
- technological developments;
- operational environment;
identified cybersecurity threats.
Security controls shall be reviewed periodically and updated where necessary.
13.4 Defence in Depth
The Company shall adopt a multi-layered security architecture incorporating administrative, technical and physical safeguards to minimise the risk of compromise.
No single security control shall be relied upon as the sole mechanism for protecting Personal Data.
PART BConfidentiality
13.5 Access Control
Access to Personal Data shall be granted strictly on a need-to-know and least privilege basis.
Access rights shall be:
- role-based;
- documented;
- periodically reviewed;
promptly revoked upon termination or change of responsibilities.
13.6 Authentication
The Company shall implement secure authentication mechanisms appropriate to the risks involved.
Where reasonably practicable, administrative systems shall require:
- multi-factor authentication;
- strong password policies;
- session management controls;
protection against credential stuffing and brute-force attacks.
13.7 Employee Confidentiality
Employees, contractors and consultants with access to Personal Data shall be bound by legally enforceable confidentiality obligations.
Confidentiality obligations shall continue after termination of employment or engagement.
PART CEncryption
13.8 Encryption in Transit
Personal Data transmitted over public or untrusted networks shall be protected using strong encryption protocols recognised as secure by prevailing industry standards.
13.9 Encryption at Rest
Where appropriate, Personal Data stored within or without Company systems shall be encrypted at rest using recognised cryptographic standards.
Encryption keys shall be securely generated, stored, rotated and managed.
13.10 Key Management
The Company shall maintain documented procedures governing:
- cryptographic key generation;
- storage;
- access;
- rotation;
- revocation;
destruction.
Access to encryption keys shall be strictly limited.
PART DSecure Software Development
13.11 Secure Development Lifecycle
The Company shall adopt a Secure Software Development Lifecycle (“SSDLC”) incorporating security considerations throughout:
- planning;
- design;
- development;
- testing;
- deployment;
maintenance.
Security shall be integrated into product development from inception.
13.12 Secure Coding
Developers shall follow recognised secure coding practices designed to reduce common software vulnerabilities including:
- injection attacks;
- broken authentication;
- insecure deserialisation;
- cross-site scripting;
- cross-site request forgery;
insecure direct object references.
Code shall be reviewed before deployment.
13.13 Security Testing
Applications shall undergo security testing appropriate to their risk profile, including where applicable:
- static application security testing (SAST);
- dynamic application security testing (DAST);
- dependency vulnerability scanning;
- penetration testing;
manual security reviews.
Critical vulnerabilities shall be remediated before production deployment wherever reasonably practicable.
PART EInfrastructure Security
13.14 Network Security
The Company’s infrastructure shall be protected through appropriate security controls including:
- firewalls;
- network segmentation;
- intrusion detection or prevention systems;
- secure gateways;
denial-of-service protections.
13.15 Endpoint Security
Company-managed devices processing Personal Data shall implement appropriate endpoint protection measures, including:
- anti-malware protection;
- operating system updates;
- device encryption;
- remote wipe capabilities where appropriate;
device management controls.
13.16 Cloud Security
Where cloud infrastructure is used, the Company shall implement controls appropriate to the shared responsibility model, including:
- secure configuration;
- identity and access management;
- monitoring;
- encryption;
- logging;
backup controls.
PART FLogging and Monitoring
13.17 Audit Logs
Systems processing Personal Data shall generate audit logs sufficient to record significant security events including:
- authentication events;
- administrative activities;
- access to sensitive Personal Data;
- privilege changes;
security incidents.
Audit logs shall be protected against unauthorised modification.
13.18 Security Monitoring
The Company shall monitor its systems to identify:
- unauthorised access;
- malware activity;
- suspicious network behaviour;
- attempted attacks;
abnormal processing activity.
Monitoring activities shall be proportionate and respectful of applicable privacy laws.
PART GVulnerability Management
13.19 Vulnerability Identification
The Company shall maintain procedures for identifying vulnerabilities affecting:
- applications;
- infrastructure;
- operating systems;
- third-party software;
cloud environments.
13.20 Patch Management
Security patches shall be evaluated and deployed within reasonable timeframes based upon:
- severity of vulnerability;
- exploitability;
- operational impact;
risk to Personal Data.
Critical vulnerabilities shall receive priority remediation.
13.21 Penetration Testing
Where appropriate, the Company shall periodically conduct independent penetration testing of systems processing Personal Data.
Testing findings shall be documented, prioritised and remediated.
PART HBusiness Continuity
13.22 Backup
The Company shall maintain secure backups of critical systems and Personal Data as appropriate.
Backups shall be:
- encrypted where appropriate;
- periodically tested;
- protected from unauthorised access;
retained in accordance with retention policies.
13.23 Disaster Recovery
The Company shall maintain disaster recovery procedures designed to restore critical systems within appropriate recovery objectives.
Disaster recovery plans shall be periodically tested.
13.24 Business Continuity
Business continuity arrangements shall seek to ensure the continued availability of essential Services during significant operational disruptions.
PART IPhysical Security
13.25 Facilities
Where the Company controls physical facilities processing Personal Data, it shall implement appropriate physical safeguards, including:
- controlled access;
- visitor management;
- surveillance where lawful;
- environmental protections;
secure disposal of media.
Where third-party data centres are used, the Company shall exercise reasonable due diligence regarding their physical security.
PART JSecurity Awareness
13.26 Training
Employees shall receive periodic information security and privacy training covering:
- phishing awareness;
- password security;
- secure handling of Personal Data;
- incident reporting;
- acceptable use of Company systems;
confidentiality obligations.
Training shall be refreshed periodically and updated to reflect emerging threats.
PART KVendor Security
13.27 Third-Party Security
Before granting a third party access to Personal Data, the Company shall evaluate the third party’s information security capabilities, taking into account:
- security certifications;
- technical controls;
- regulatory compliance;
- incident response capabilities;
contractual commitments.
Where appropriate, the Company may conduct periodic reassessments of vendors processing Personal Data.
PART LContinuous Improvement
13.28 Security Audits
The Company shall periodically conduct internal or external assessments of its information security programme to evaluate the effectiveness of implemented safeguards.
13.29 Review
Security controls shall be reviewed following:
- significant changes to processing activities;
- major technology changes;
- security incidents;
- regulatory developments;
- audit findings;
identified vulnerabilities.
Corrective actions shall be implemented within a reasonable timeframe.
Schedule 13-A: Core Security Controls
| Security Domain | Representative Controls |
|---|---|
| Identity & Access Management | Role-based access control (RBAC), least privilege, multi-factor authentication (MFA) |
| Encryption | Encryption in transit, encryption at rest, secure cryptographic key management |
| Application Security | Secure SDLC, code reviews, SAST, DAST, dependency scanning |
| Infrastructure Security | Firewalls, network segmentation, intrusion detection/prevention, endpoint protection |
| Monitoring & Logging | Security event logging, audit trails, continuous monitoring, anomaly detection |
| Vulnerability Management | Vulnerability scanning, patch management, penetration testing |
| Business Continuity | Encrypted backups, disaster recovery planning, business continuity testing |
| Vendor Security | Due diligence, contractual security obligations, periodic security reviews |
| Governance | Security policies, employee training, audits, continuous improvement |
CHAPTER 14PERSONAL DATA BREACH MANAGEMENT AND INCIDENT RESPONSE
14.1 Purpose
This Chapter establishes the framework for the prevention, identification, reporting, assessment, containment, investigation, remediation and notification of Personal Data Breaches by TrackMyWings Technologies Private Limited (“TrackMyWings” or the “Company”).
The Company recognises that timely and effective management of security incidents is essential to protecting the rights and freedoms of Data Principals and Data Subjects, maintaining the integrity of the Services, and complying with applicable legal obligations.
This Chapter shall be interpreted in accordance with:
- the Digital Personal Data Protection Act, 2023 (“DPDP Act”);
- the General Data Protection Regulation (“GDPR”), particularly Articles 33 and 34;
- applicable cybersecurity laws;
contractual obligations owed to enterprise customers and business partners.
PART AGeneral Principles
14.2 Incident Response Objectives
The Company’s Incident Response Programme shall be designed to:
- (a) rapidly detect security incidents;
- (b) minimise harm to affected individuals;
- (c) preserve the confidentiality, integrity and availability of Personal Data;
- (d) restore normal operations as quickly as reasonably practicable;
- (e) comply with applicable notification obligations; and
- (f) implement corrective measures to prevent recurrence.
14.3 Scope
This Chapter applies to all incidents affecting:
- Personal Data;
- confidential business information;
- production systems;
- cloud infrastructure;
- employee devices processing Personal Data;
third-party processors acting on behalf of the Company.
PART BDefinition of Personal Data Breach
14.4 Personal Data Breach
For the purposes of this Policy, a Personal Data Breach means a security incident leading to the accidental or unlawful:
- destruction;
- loss;
- alteration;
- unauthorised disclosure;
unauthorised access; or
unavailability,
of Personal Data processed by or on behalf of the Company.
14.5 Examples
Examples of Personal Data Breaches include:
- unauthorised access to user accounts;
- accidental disclosure of Personal Data;
- ransomware attacks;
- phishing compromises;
- cloud storage misconfigurations;
- lost or stolen devices containing Personal Data;
- malware infections;
- insider misuse of Personal Data;
- accidental deletion of Personal Data;
credential compromise.
PART CDetection and Reporting
14.6 Duty to Report
Every employee, contractor, consultant and authorised user who becomes aware of an actual or suspected Personal Data Breach shall report the incident immediately through the Company’s designated incident reporting mechanism.
Failure to report a known breach may result in disciplinary action, subject to applicable law.
14.7 Reporting Channels
Security incidents may be reported through:
- the internal incident response portal;
- the designated security email address;
- the Information Security Team;
- the Data Protection Officer;
- the Grievance Officer;
emergency escalation procedures established by the Company.
Reports should include all available information concerning the nature, timing and impact of the incident.
PART DIncident Classification
14.8 Initial Assessment
Upon receipt of an incident report, the Company shall conduct an initial assessment to determine:
- whether a Personal Data Breach has occurred;
- the categories of Personal Data involved;
- the number of affected individuals;
- the likely consequences;
the urgency of containment measures.
14.9 Severity Classification
Incidents may be classified as:
Critical
High
Medium
Low
Classification shall consider:
- sensitivity of the Personal Data;
- number of affected individuals;
- likelihood of harm;
- operational disruption;
- regulatory impact;
reputational impact.
PART EContainment
14.10 Immediate Containment
Upon confirmation of a breach, the Company shall take reasonable steps to contain the incident, including where appropriate:
- isolating affected systems;
- disabling compromised accounts;
- revoking credentials;
- suspending affected services;
- blocking malicious network traffic;
preserving system logs.
14.11 Preservation of Evidence
The Company shall preserve relevant evidence to facilitate:
- forensic investigation;
- regulatory review;
- legal proceedings;
- insurance claims;
internal disciplinary processes.
Evidence shall be handled in accordance with recognised forensic practices to maintain its integrity and admissibility.
PART FInvestigation
14.12 Incident Investigation
The Company shall investigate every confirmed Personal Data Breach to determine:
- the root cause;
- attack vector;
- duration of exposure;
- systems affected;
- categories of Personal Data compromised;
- identity of affected individuals where reasonably ascertainable;
adequacy of existing security controls.
14.13 Cooperation
Employees, contractors, service providers and Data Processors shall cooperate fully with investigations concerning Personal Data Breaches.
PART GNotification Obligations
14.14 Notification to Competent Authorities
Where required by applicable law, the Company shall notify the competent supervisory or regulatory authority without undue delay.
Where the GDPR applies, the Company shall endeavour to notify the competent supervisory authority within 72 hours of becoming aware of a notifiable Personal Data Breach, unless a delay is permitted by law.
Notifications shall include, where available:
- the nature of the breach;
- categories of Personal Data affected;
- approximate number of affected individuals;
- likely consequences;
- measures taken or proposed to address the breach;
contact details of the Data Protection Officer or other appropriate contact.
14.15 Notification to Data Principals or Data Subjects
Where a Personal Data Breach is likely to result in a high risk to the rights and freedoms of individuals, the Company shall notify affected individuals without undue delay, unless an exception under applicable law applies.
Such notification shall be written in clear and plain language and shall include:
- a description of the incident;
- the categories of Personal Data involved;
- the likely consequences;
- measures taken by the Company;
- recommended protective actions for affected individuals;
contact details for further assistance.
14.16 Notification by Data Processors
A Data Processor acting on behalf of the Company shall notify the Company immediately upon becoming aware of a Personal Data Breach affecting Company data.
The Data Processor shall not notify regulators or affected individuals directly unless authorised by the Company or required by applicable law.
PART HRecovery and Remediation
14.17 Recovery
Following containment, the Company shall take appropriate measures to:
- restore affected systems;
- validate data integrity;
- strengthen security controls;
resume normal operations safely.
14.18 Corrective Actions
Following completion of the investigation, the Company shall implement corrective actions appropriate to the circumstances, including:
- software updates;
- security architecture improvements;
- enhanced monitoring;
- employee training;
- policy revisions;
- vendor remediation;
additional access controls.
PART IDocumentation
14.19 Incident Register
The Company shall maintain a confidential Incident Register documenting:
- incident reference number;
- date and time of discovery;
- reporting source;
- systems affected;
- severity classification;
- Personal Data involved;
- investigative findings;
- notifications made;
- corrective actions;
closure date.
The Incident Register shall be retained in accordance with applicable legal and regulatory requirements.
14.20 Lessons Learned
Following significant incidents, the Company shall conduct a post-incident review to identify:
- root causes;
- procedural weaknesses;
- technical deficiencies;
- opportunities for improvement;
required policy updates.
Recommendations arising from such reviews shall be documented and tracked until implementation.
PART JTesting and Preparedness
14.21 Incident Response Exercises
The Company shall periodically conduct incident response exercises, tabletop simulations or technical testing to evaluate the effectiveness of its breach management procedures.
Findings from such exercises shall inform continuous improvement of the Incident Response Programme.
14.22 Employee Awareness
Employees shall receive periodic training concerning:
- identification of security incidents;
- reporting obligations;
- phishing recognition;
- handling of suspected Personal Data Breaches;
confidentiality during incident response.
PART KGovernance and Oversight
14.23 Roles and Responsibilities
The Company shall assign appropriate responsibilities for:
- Information Security Team;
- Data Protection Officer;
- Grievance Officer;
- Legal and Compliance Team;
- Senior Management;
relevant business units.
Major incidents shall be escalated promptly to senior management for oversight and decision-making.
14.24 Periodic Review
The Incident Response Programme shall be reviewed:
- annually;
- following any significant Personal Data Breach;
- after major organisational or technological changes;
- upon changes in applicable law or regulatory guidance;
following internal or external audits.
Schedule 14-A: Incident Severity Matrix
| Severity | Typical Examples | Illustrative Response |
|---|---|---|
| Critical | Large-scale compromise of sensitive Personal Data, ransomware affecting production systems | Immediate executive escalation, containment, regulatory assessment, user notification where required |
| High | Confirmed unauthorised access to user accounts or cloud resources | Rapid containment, forensic investigation, risk assessment, potential notifications |
| Medium | Limited internal exposure with no evidence of misuse | Corrective action, monitoring, documented investigation |
| Low | Minor policy violations or attempted attacks with no confirmed data compromise | Internal remediation, logging, awareness measures |
CHAPTER 15DATA RETENTION, ARCHIVING AND SECURE DISPOSAL
15.1 Purpose
This Chapter establishes the framework governing the retention, review, archival, anonymisation and secure disposal of Personal Data processed by TrackMyWings Technologies Private Limited (“TrackMyWings” or the “Company”).
The Company recognises that Personal Data shall not be retained indefinitely and shall be kept only for so long as is necessary to fulfil the purposes for which it was collected, comply with applicable legal obligations, resolve disputes, enforce legal rights, and meet legitimate business requirements.
This Chapter shall be interpreted in accordance with:
- the Digital Personal Data Protection Act, 2023 (“DPDP Act”);
- the General Data Protection Regulation (“GDPR”), particularly the principle of storage limitation;
- applicable tax, accounting and corporate laws;
applicable judicial or regulatory preservation requirements.
PART AGeneral Principles
15.2 Principle of Storage Limitation
The Company shall retain Personal Data only for the period reasonably necessary to:
- (a) provide the Services requested by the User;
- (b) fulfil contractual obligations;
- (c) comply with statutory and regulatory requirements;
- (d) establish, exercise or defend legal claims;
- (e) prevent fraud and misuse of the Services; or
- (f) fulfil other lawful purposes expressly identified in this Privacy Policy.
Once the applicable retention period expires, the Company shall securely delete, anonymise or irreversibly de-identify the Personal Data unless further retention is authorised or required by law.
15.3 Data Minimisation
Retention periods shall be proportionate to:
- the purpose of processing;
- the sensitivity of the Personal Data;
- legal obligations;
- operational necessity;
risks associated with prolonged retention.
The Company shall avoid retaining duplicate or obsolete Personal Data.
PART BRetention Schedule
15.4 Retention Policy
The Company shall maintain a documented Retention Schedule identifying:
- categories of Personal Data;
- applicable retention periods;
- legal justification;
- disposal method;
responsible business function.
The Retention Schedule shall be reviewed periodically and updated as necessary.
15.5 Periodic Review
Business units responsible for Personal Data shall periodically review retained information to identify:
- expired records;
- duplicate records;
- obsolete information;
unnecessary archives.
Records identified for disposal shall be processed in accordance with this Chapter.
PART CCategories of Retention
15.6 Account Information
Account information shall ordinarily be retained while the User maintains an active account.
Following account closure, Personal Data shall be deleted or anonymised within a reasonable period unless continued retention is required:
- by law;
- for fraud prevention;
- for dispute resolution;
for enforcement of contractual rights.
15.7 Flight Information
Flight itineraries and travel history shall be retained only for the period necessary to provide requested Services and any related customer support, unless the User elects to retain such information within their account or applicable law requires otherwise.
15.8 Customer Support Records
Customer support communications may be retained for:
- quality assurance;
- dispute resolution;
- training;
- legal compliance;
fraud prevention.
Retention periods shall be proportionate to the nature of the support interaction.
15.9 Payment Records
Payment-related records shall be retained for the period required under applicable tax, accounting and financial reporting laws.
The Company shall not retain complete payment card information beyond what is necessary for authorised processing and compliance purposes.
15.10 Security Logs
Security logs, authentication records and audit trails may be retained for as long as reasonably necessary to:
- detect fraud;
- investigate incidents;
- ensure cybersecurity;
demonstrate regulatory compliance.
Retention periods shall be reviewed periodically to ensure proportionality.
PART DArchiving
15.11 Archival Storage
Where Personal Data is retained for legal, regulatory or historical business purposes, it may be transferred to secure archival storage.
Archived Personal Data shall remain subject to this Privacy Policy.
15.12 Access to Archives
Access to archived Personal Data shall be limited to authorised personnel with a legitimate business, legal or regulatory need.
Archived data shall not be routinely restored to active systems unless necessary for a legitimate purpose.
PART EAnonymisation and Pseudonymisation
15.13 Anonymisation
Where Personal Data is no longer required in identifiable form but remains useful for statistical, analytical or research purposes, the Company may irreversibly anonymise such data.
Anonymised information shall no longer be regarded as Personal Data where re-identification is not reasonably possible.
15.14 Pseudonymisation
Where full anonymisation is not feasible, the Company may apply pseudonymisation techniques to reduce privacy risks.
Additional identifying information shall be stored separately and protected by appropriate security measures.
PART FSecure Disposal
15.15 Disposal Methods
Upon expiry of the applicable retention period, Personal Data shall be securely disposed of using methods appropriate to the storage medium, including:
- secure deletion;
- cryptographic erasure;
- overwriting;
- destruction of encryption keys;
- physical destruction of storage media;
certified destruction by authorised vendors.
The selected method shall render the Personal Data inaccessible or irrecoverable using commercially reasonable means.
15.16 Disposal by Service Providers
Where Personal Data is processed by a Data Processor, the Company shall require the Data Processor, upon termination of the processing relationship or expiry of the retention period, to:
securely delete the Personal Data; or
return the Personal Data to the Company,
unless continued retention is required by applicable law.
The Company may require written certification of such deletion or return.
PART GLegal Holds
15.17 Suspension of Disposal
Where the Company reasonably anticipates or becomes involved in:
- litigation;
- arbitration;
- governmental investigation;
- regulatory inquiry;
- audit;
law enforcement proceedings,
the Company may suspend routine deletion of relevant Personal Data by issuing a Legal Hold.
15.18 Removal of Legal Hold
The Legal Hold shall remain in effect until the Legal Department or other authorised function determines that the relevant proceedings have concluded or the preservation obligation has otherwise ceased.
Upon removal of the Legal Hold, the retained Personal Data shall be reviewed and disposed of in accordance with this Chapter.
PART HUser Requests
15.19 Requests for Erasure
Where a User exercises the right to erasure under applicable law, the Company shall evaluate the request in accordance with Chapter 9.
Erasure may be declined where retention remains necessary for:
- compliance with legal obligations;
- exercise or defence of legal claims;
- fraud prevention;
public interest grounds recognised by law.
Where erasure is granted, associated backup and archival copies shall be deleted or rendered inaccessible in accordance with the Company’s backup lifecycle and technical capabilities.
PART IGovernance
15.20 Record of Disposal
The Company shall maintain appropriate records demonstrating the secure disposal of Personal Data, including where appropriate:
- category of data disposed;
- date of disposal;
- disposal method;
- responsible function;
confirmation of completion.
Such records shall not contain the disposed Personal Data itself.
15.21 Review of Retention Practices
The Company shall periodically review:
- retention schedules;
- archival practices;
- anonymisation procedures;
- secure disposal methods;
- legal hold processes;
regulatory developments affecting retention obligations.
Necessary amendments shall be implemented promptly to maintain ongoing compliance.
Schedule 15-A: Illustrative Retention Matrix
| Category of Personal Data | Illustrative Retention Trigger | End of Retention Event | Disposal Method |
|---|---|---|---|
| Account Information | Active user account | Account closure and expiry of applicable legal/business need | Secure deletion or anonymisation |
| Flight Itineraries | Provision of travel services | Completion of service and expiry of support/legal requirements | Secure deletion or anonymisation |
| Customer Support Records | Resolution of support request | Expiry of operational or legal need | Secure deletion |
| Payment and Billing Records | Financial transaction | Expiry of statutory accounting/tax retention requirements | Secure deletion or certified destruction |
| Security Logs | Security monitoring | Expiry of cybersecurity and compliance requirements | Cryptographic erasure or secure deletion |
| Audit Logs | Regulatory compliance | Expiry of audit or legal retention period | Secure deletion |
| Archived Data | Legal or regulatory preservation | Expiry of archival purpose | Secure destruction or anonymisation |
CHAPTER 16
PRIVACY BY DESIGN, PRIVACY BY DEFAULT AND DATA PROTECTION IMPACT ASSESSMENTS (DPIAs)
16.1 Purpose
This Chapter establishes the framework through which TrackMyWings Technologies Private Limited (“TrackMyWings” or the “Company”) embeds privacy and data protection into the design, development, implementation, operation and continuous improvement of its products, services, technologies and business processes.
The Company recognises that privacy is not merely a legal obligation but a core design principle. Accordingly, privacy considerations shall be integrated throughout the entire lifecycle of every processing activity rather than being applied retrospectively.
This Chapter shall be interpreted in accordance with:
- the Digital Personal Data Protection Act, 2023 (“DPDP Act”);
- the General Data Protection Regulation (“GDPR”), particularly Article 25 (Data Protection by Design and by Default) and Article 35 (Data Protection Impact Assessment);
internationally recognised privacy engineering principles; and
applicable regulatory guidance.
PART APrivacy by Design
16.2 Fundamental Principle
The Company shall integrate privacy protections into every stage of:
- business planning;
- product development;
- software engineering;
- procurement;
- vendor selection;
- artificial intelligence initiatives;
operational processes; and
organisational decision-making.
Privacy shall be treated as an essential design requirement and not as an optional feature.
16.3 Objectives
Privacy by Design seeks to ensure that:
- (a) Personal Data is processed lawfully;
- (b) privacy risks are identified before deployment;
- (c) unnecessary processing is avoided;
- (d) security controls are incorporated from inception;
- (e) Users maintain meaningful control over their Personal Data; and
- (f) privacy protections remain effective throughout the lifecycle of processing.
16.4 Core Design Principles
The Company shall be guided by the following principles:
- proactive rather than reactive measures;
- privacy as the default setting;
- privacy embedded into system architecture;
- full functionality without unnecessary compromise;
- end-to-end lifecycle protection;
- transparency;
- accountability;
user-centric design.
PART BPrivacy by Default
16.5 Default Privacy Settings
Products and Services shall, by default, collect and process only the minimum Personal Data necessary for their intended functionality.
Optional processing activities shall remain disabled until enabled by the User where required by applicable law.
16.6 Default Configuration
Unless a User affirmatively chooses otherwise, default settings shall:
- minimise data collection;
- minimise data sharing;
- minimise public visibility of Personal Data;
- limit retention to the shortest appropriate period;
disable optional tracking technologies where legally required.
16.7 User Control
Users shall, where reasonably practicable, be provided with accessible controls enabling them to:
- manage privacy preferences;
- update consent choices;
- control profile visibility;
- manage notification preferences;
- control location sharing;
review connected accounts.
PART CPrivacy Risk Assessments
16.8 Risk-Based Assessment
Before introducing new processing activities, the Company shall assess privacy risks having regard to:
- nature of the Personal Data;
- volume of data;
- sensitivity of processing;
- likelihood of harm;
- potential impact on affected individuals;
applicable legal obligations.
The level of assessment shall be proportionate to the identified risks.
16.9 High-Risk Processing
Processing activities likely to present a high risk to the rights and freedoms of individuals shall receive enhanced review prior to implementation.
Examples may include:
- large-scale profiling;
- deployment of new artificial intelligence systems;
- processing of children’s Personal Data;
- large-scale location tracking;
- processing involving novel technologies;
- large-scale international transfers;
automated decision-making producing legal or similarly significant effects.
PART DData Protection Impact Assessments (DPIAs)
16.10 Requirement to Conduct a DPIA
The Company shall conduct a Data Protection Impact Assessment (“DPIA”) before commencing any processing activity that is likely to result in a high risk to the rights and freedoms of Data Principals or Data Subjects where required by applicable law.
A DPIA shall also be considered where good governance indicates that early assessment would materially reduce privacy risks, even if not expressly required by law.
16.11 Objectives of a DPIA
A DPIA shall seek to:
- identify privacy risks;
- evaluate necessity and proportionality;
- assess legal compliance;
- identify appropriate safeguards;
- document mitigation measures;
support informed decision-making.
16.12 Minimum Contents
A DPIA shall ordinarily include:
- description of the proposed processing;
- business objectives;
- categories of Personal Data involved;
- lawful basis for processing;
- categories of affected individuals;
- data flows;
- technology involved;
- identified risks;
- likelihood and severity of harm;
- mitigation measures;
- residual risks;
implementation recommendations.
16.13 Consultation
Where appropriate, the Company may consult:
- the Data Protection Officer;
- Information Security personnel;
- Legal and Compliance teams;
- business stakeholders;
- relevant Data Processors;
external advisers.
Where required by law, consultation with competent supervisory authorities shall occur before commencing the relevant processing.
PART EPrivacy Engineering
16.14 Engineering Controls
Engineering teams shall incorporate privacy-enhancing technologies where appropriate, including:
- encryption;
- pseudonymisation;
- anonymisation;
- tokenisation;
- role-based access controls;
- secure logging;
- audit trails;
automated retention controls.
16.15 Secure Architecture
Systems shall be designed to:
- segregate sensitive information;
- minimise unnecessary data replication;
- reduce attack surfaces;
- support secure authentication;
facilitate monitoring and auditing.
Privacy requirements shall be incorporated into architectural reviews.
PART FArtificial Intelligence and Emerging Technologies
16.16 Responsible Use of AI
Where artificial intelligence or machine learning technologies are used, the Company shall evaluate:
- fairness;
- transparency;
- explainability;
- bias;
- privacy implications;
- security risks;
human oversight requirements.
AI systems shall not be deployed where unacceptable privacy risks cannot be adequately mitigated.
16.17 Emerging Technologies
Before adopting emerging technologies that involve Personal Data, the Company shall assess:
- legal compliance;
- cybersecurity implications;
- interoperability;
- vendor maturity;
- potential impacts on individuals;
long-term governance requirements.
PART GProcurement and Vendor Management
16.18 Privacy Review of Vendors
Before procuring technologies or engaging vendors that will process Personal Data, the Company shall conduct a privacy review considering:
- categories of Personal Data processed;
- security certifications;
- compliance history;
- international transfer implications;
- subcontracting arrangements;
contractual protections.
No vendor shall be engaged where identified privacy risks cannot be appropriately mitigated.
PART HChange Management
16.19 Material Changes
Where significant changes are proposed to existing processing activities, the Company shall determine whether:
- an updated privacy assessment is required;
- an existing DPIA should be revised;
- additional user notices are necessary;
fresh consent is required.
16.20 Continuous Monitoring
Privacy risks shall be monitored throughout the lifecycle of processing.
Material changes in technology, law or business operations shall trigger reassessment where appropriate.
PART IDocumentation and Accountability
16.21 Documentation
The Company shall maintain appropriate documentation relating to:
- completed DPIAs;
- privacy assessments;
- design decisions;
- implemented safeguards;
- management approvals;
periodic reviews.
Such documentation shall form part of the Company’s privacy governance framework.
16.22 Review
Privacy by Design practices shall be reviewed periodically to ensure continued effectiveness in light of:
- technological developments;
- legislative changes;
- regulatory guidance;
- audit findings;
- security incidents;
lessons learned.
Schedule 16-A: Illustrative Processing Activities Requiring a DPIA
| Proposed Processing Activity | Indicative DPIA Requirement | Illustrative Mitigation Measures |
|---|---|---|
| Deployment of AI-powered travel recommendations | Yes | Bias assessment, transparency, human oversight |
| Large-scale location tracking | Yes | Granular consent, minimisation, encryption |
| Processing children’s Personal Data | Yes | Age verification, parental consent, restricted processing |
| Migration to a new cloud infrastructure | Risk-based assessment | Vendor due diligence, encryption, access controls |
| Large-scale behavioural analytics | Yes | Pseudonymisation, purpose limitation, opt-out mechanisms |
| New cross-border processing arrangement | Risk-based assessment | Transfer Impact Assessment, contractual safeguards |
| Community features involving public profiles | Risk-based assessment | Privacy-by-default settings, user controls |
CHAPTER 17GOVERNANCE, ACCOUNTABILITY, ROLES AND RESPONSIBILITIES
17.1 Purpose
This Chapter establishes the privacy governance framework of TrackMyWings Technologies Private Limited (“TrackMyWings” or the “Company”), including the allocation of responsibilities for compliance with applicable data protection laws, implementation of privacy controls, oversight of processing activities, and continuous improvement of the Company’s privacy programme.
The Company recognises that effective privacy protection requires clear accountability at every organisational level and shall maintain an enterprise-wide governance framework to ensure that Personal Data is processed lawfully, fairly, securely and transparently.
This Chapter shall be interpreted in accordance with:
- the Digital Personal Data Protection Act, 2023 (“DPDP Act”);
- the General Data Protection Regulation (“GDPR”), including the accountability principle under Article 5(2);
- applicable corporate governance laws;
recognised international standards for privacy governance.
PART AGovernance Principles
17.2 Accountability
The Company shall be responsible for, and capable of demonstrating, compliance with this Privacy Policy and applicable data protection laws.
Accountability shall include:
- documented policies and procedures;
- allocation of responsibilities;
- internal oversight;
- periodic audits;
- training programmes;
- maintenance of appropriate records;
continuous monitoring and improvement.
17.3 Privacy Governance Framework
The Company shall maintain an integrated Privacy Governance Framework comprising:
- Board oversight;
- executive management supervision;
- the Data Protection Officer (where appointed or required);
- the Grievance Officer;
- Information Security governance;
- Legal and Compliance functions;
- business unit accountability;
internal audit and assurance mechanisms.
PART BBoard of Directors
17.4 Strategic Oversight
The Board of Directors, or an appropriately authorised committee thereof, shall exercise strategic oversight over the Company’s privacy and data protection programme.
The Board shall, as appropriate:
- approve significant privacy policies;
- oversee enterprise privacy risks;
- review major privacy incidents;
- ensure adequate allocation of resources;
promote a culture of privacy and compliance.
17.5 Reporting
Senior Management shall periodically report to the Board regarding:
- significant privacy risks;
- material Personal Data Breaches;
- regulatory investigations;
- audit findings;
- major compliance initiatives;
remediation progress.
PART CSenior Management
17.6 Executive Responsibility
Senior Management shall be responsible for implementing the Company’s privacy governance programme and ensuring that adequate organisational, financial and technical resources are available.
Responsibilities include:
- implementing Board-approved policies;
- integrating privacy into business operations;
- approving major privacy initiatives;
- supporting compliance programmes;
ensuring corrective actions are implemented.
PART DData Protection Officer
17.7 Appointment
Where required by applicable law or determined appropriate by the Company, a Data Protection Officer (“DPO”) shall be appointed.
The DPO shall possess appropriate professional knowledge of privacy law and data protection practices.
17.8 Independence
The DPO shall perform duties independently and shall not receive instructions regarding the exercise of statutory responsibilities.
The Company shall ensure that the DPO:
- has adequate resources;
- has direct access to Senior Management;
- is not penalised for performing official duties;
is able to maintain confidentiality.
17.9 Responsibilities
The DPO may be responsible for:
- monitoring compliance;
- advising on DPIAs;
- advising management;
- monitoring legislative developments;
- cooperating with supervisory authorities;
- responding to privacy enquiries;
- maintaining privacy documentation;
conducting awareness programmes.
PART EGrievance Officer
17.10 Appointment
The Company shall appoint a Grievance Officer where required under applicable law.
Contact details of the Grievance Officer shall be published in the Privacy Policy and made readily available to Users.
17.11 Responsibilities
The Grievance Officer shall:
- receive privacy-related complaints;
- acknowledge grievances;
- coordinate investigations;
- facilitate timely responses;
- maintain grievance records;
coordinate with the DPO and Legal Team where appropriate.
PART FInformation Security Team
17.12 Responsibilities
The Information Security Team shall be responsible for implementing and maintaining technical safeguards including:
- access controls;
- encryption;
- network security;
- monitoring;
- vulnerability management;
- incident response;
- disaster recovery;
security awareness.
The Information Security Team shall work closely with the DPO to ensure that security measures support privacy compliance.
PART GLegal and Compliance Function
17.13 Legal Responsibilities
The Legal and Compliance function shall:
- monitor applicable legislation;
- advise on legal risks;
- review contractual arrangements;
- support regulatory engagement;
- oversee legal holds;
- advise on international transfers;
assist with investigations and disputes.
PART HBusiness Units
17.14 Operational Responsibility
Each business unit processing Personal Data shall be responsible for:
- complying with this Privacy Policy;
- maintaining accurate records;
- implementing approved controls;
- reporting privacy incidents;
- cooperating with audits;
participating in privacy training.
Managers shall ensure that employees understand their privacy responsibilities.
PART IEmployees and Personnel
17.15 Individual Responsibility
Every employee, contractor, consultant and temporary worker who processes Personal Data shall:
- comply with this Privacy Policy;
- process Personal Data only for authorised purposes;
- maintain confidentiality;
- report suspected security incidents promptly;
- participate in required training;
protect Company information assets.
Failure to comply may result in disciplinary action, including termination of employment or engagement, subject to applicable law.
PART JData Processors and Third Parties
17.16 Third-Party Accountability
Data Processors and third-party service providers processing Personal Data on behalf of the Company shall:
- comply with applicable contractual obligations;
- implement appropriate security measures;
- process Personal Data only on documented instructions;
- cooperate with audits where contractually required;
notify the Company of Personal Data Breaches without undue delay.
The Company shall remain responsible for ensuring that its processors meet applicable legal and contractual requirements.
PART KTraining and Awareness
17.17 Privacy Training
The Company shall establish a privacy awareness programme providing periodic training appropriate to the responsibilities of personnel.
Training may include:
- privacy principles;
- lawful processing;
- information security;
- phishing awareness;
- incident reporting;
- handling privacy requests;
- confidentiality obligations;
emerging legal developments.
New personnel shall receive privacy training within a reasonable period after joining the Company.
PART LInternal Audits and Monitoring
17.18 Internal Audits
The Company shall conduct periodic internal audits of its privacy programme to evaluate:
- compliance with this Privacy Policy;
- effectiveness of technical controls;
- implementation of organisational measures;
- vendor compliance;
- documentation;
records of processing activities.
Audit findings shall be documented and appropriate corrective actions tracked to completion.
17.19 Compliance Monitoring
The Company shall establish ongoing monitoring mechanisms to assess:
- adherence to privacy policies;
- effectiveness of security controls;
- implementation of corrective actions;
- legislative developments;
emerging risks.
PART MReporting and Escalation
17.20 Internal Reporting
Material privacy issues shall be reported through established governance channels.
Matters requiring escalation may include:
- significant Personal Data Breaches;
- regulatory investigations;
- high-risk processing activities;
- repeated policy violations;
significant audit findings.
Escalation shall occur without undue delay.
PART NContinuous Improvement
17.21 Periodic Review
The Company shall periodically review and update its privacy governance programme to reflect:
- changes in law;
- technological developments;
- organisational restructuring;
- audit recommendations;
- regulatory guidance;
lessons learned from security incidents.
Updates shall be approved in accordance with the Company’s governance processes.
17.22 Culture of Privacy
The Company shall promote a culture in which privacy protection is recognised as a shared organisational responsibility.
All personnel are expected to act with integrity, transparency and accountability when handling Personal Data.
Schedule 17-A: Privacy Governance Responsibility Matrix
| Function | Primary Responsibilities |
|---|---|
| Board of Directors | Strategic oversight, approval of policies, review of major risks and incidents |
| Senior Management | Implementation of privacy programme, allocation of resources, executive oversight |
| Data Protection Officer | Compliance monitoring, DPIAs, regulatory liaison, privacy advice, awareness |
| Grievance Officer | Handling grievances, coordinating responses, maintaining complaint records |
| Information Security Team | Technical safeguards, incident response, vulnerability management, monitoring |
| Legal & Compliance | Legal advice, contractual review, regulatory monitoring, legal holds |
| Business Units | Operational compliance, record maintenance, reporting incidents |
| Employees & Contractors | Lawful processing, confidentiality, incident reporting, policy compliance |
| Data Processors | Processing under instructions, security controls, breach notification, contractual compliance |
| Internal Audit | Independent assessment of privacy governance and control effectiveness |
CHAPTER 18COOKIES, TRACKING TECHNOLOGIES AND ONLINE PRIVACY
18.1 Purpose
This Chapter establishes the policy governing the use of cookies and other online tracking technologies by TrackMyWings Technologies Private Limited (“TrackMyWings” or the “Company”) in connection with its websites, mobile applications, web portals, APIs and other digital services.
The Company is committed to ensuring that tracking technologies are used in a transparent, lawful and proportionate manner, consistent with the privacy rights of Users and applicable data protection laws.
This Chapter shall be interpreted in accordance with:
- the Digital Personal Data Protection Act, 2023 (“DPDP Act”);
- the General Data Protection Regulation (“GDPR”);
- the ePrivacy Directive and any successor legislation, where applicable;
applicable browser, platform and mobile ecosystem requirements.
PART AGeneral Principles
18.2 Transparency
The Company shall clearly inform Users regarding:
- (a) the categories of tracking technologies used;
- (b) their purposes;
- (c) the duration of storage;
- (d) whether third parties have access to collected information;
- (e) available user controls.
Information concerning tracking technologies shall be provided through:
- this Privacy Policy;
- the Company’s Cookie Notice;
- consent banners where legally required;
contextual notices within the Services.
18.3 Data Minimisation
Tracking technologies shall collect only the information reasonably necessary for their intended purpose.
The Company shall periodically review tracking technologies to eliminate unnecessary collection of information.
PART BCategories of Tracking Technologies
18.4 Cookies
Cookies are small text files placed on a User’s browser or device to enable recognition of returning Users and improve the functionality of the Services.
Cookies may be:
- session cookies;
- persistent cookies;
- first-party cookies;
third-party cookies.
18.5 Similar Technologies
The Company may also use technologies including:
- Software Development Kits (“SDKs”);
- web beacons;
- tracking pixels;
- local storage;
- session storage;
- application caches;
- API tokens;
- device identifiers;
similar technologies performing substantially equivalent functions.
PART CCategories of Cookies
18.6 Strictly Necessary Cookies
Strictly Necessary Cookies are essential for the operation of the Services.
These cookies may be used for:
- user authentication;
- session management;
- security;
- fraud prevention;
- load balancing;
maintaining user preferences necessary for core functionality.
Because these cookies are necessary for providing the requested Services, they may be used without separate consent where permitted by applicable law.
18.7 Functional Cookies
Functional Cookies improve the User experience by remembering preferences such as:
- language selection;
- regional settings;
- display preferences;
- accessibility options;
user interface customisation.
Where required by applicable law, Functional Cookies shall be activated only after obtaining the necessary consent.
18.8 Analytics Cookies
Analytics Cookies help the Company understand how Users interact with the Services by collecting aggregated or pseudonymised information concerning:
- application performance;
- navigation patterns;
- feature usage;
- crash reports;
service reliability.
Where reasonably practicable, analytics information shall be pseudonymised or aggregated.
18.9 Performance Cookies
Performance Cookies assist in:
- identifying performance bottlenecks;
- measuring response times;
- improving application stability;
monitoring system availability.
These cookies shall not be used to identify Users unless necessary and lawful.
18.10 Advertising Cookies
Where advertising technologies are used, Advertising Cookies may assist in:
- measuring campaign effectiveness;
- limiting repeated advertisements;
understanding advertising performance.
The Company shall not deploy advertising cookies without obtaining any consent required under applicable law.
PART DMobile Technologies
18.11 Mobile Identifiers
Mobile applications may use platform-provided identifiers to support:
- authentication;
- security;
- application integrity;
- crash diagnostics;
subscription management.
The Company shall not use persistent mobile identifiers for behavioural advertising without the consent required under applicable law.
18.12 Device Information
Limited technical information regarding a device may be collected to:
- ensure compatibility;
- maintain security;
- diagnose technical issues;
improve performance.
Such information shall be processed in accordance with this Privacy Policy.
PART EThird-Party Technologies
18.13 Third-Party Providers
The Company may utilise third-party technologies supplied by providers of:
- analytics services;
- authentication services;
- payment processing;
- cloud infrastructure;
- customer support;
- content delivery;
security monitoring.
The Company shall conduct appropriate due diligence before integrating third-party tracking technologies.
18.14 Third-Party Policies
Where third-party technologies collect information independently, the processing of such information may also be governed by the respective third party’s privacy policy.
The Company encourages Users to review the privacy practices of such providers where appropriate.
PART FConsent Management
18.15 Cookie Consent
Where applicable law requires consent before storing or accessing information on a User’s device, the Company shall obtain valid consent before activating non-essential tracking technologies.
Consent shall be:
- informed;
- specific;
- freely given;
- unambiguous;
capable of being withdrawn at any time.
18.16 Cookie Preference Centre
The Company may provide a Cookie Preference Centre allowing Users to:
- accept all cookies;
- reject non-essential cookies;
- customise preferences by category;
withdraw previously granted consent.
Preference changes shall be implemented within a reasonable period.
18.17 Withdrawal of Consent
Users may withdraw consent relating to non-essential tracking technologies at any time.
Withdrawal shall not affect the lawfulness of processing undertaken before consent was withdrawn.
PART GBrowser Controls
18.18 Browser Settings
Most internet browsers permit Users to:
- block cookies;
- delete cookies;
- restrict third-party cookies;
receive notifications before cookies are stored.
Users should note that disabling certain cookies may affect the functionality of the Services.
18.19 Mobile Platform Controls
Mobile operating systems may permit Users to manage:
- advertising identifiers;
- location permissions;
- application permissions;
- notification settings;
tracking authorisations.
The Company encourages Users to review and manage these settings according to their privacy preferences.
PART HDo Not Track and Similar Signals
18.20 Browser Privacy Signals
Where technically feasible and legally required, the Company shall endeavour to recognise browser-based privacy signals or similar user preference mechanisms.
The Company’s response to such signals may vary depending upon applicable law, technical feasibility and the standards adopted by the relevant browser or platform.
PART IRetention
18.21 Retention of Cookie Data
Information collected through tracking technologies shall be retained only for as long as necessary to fulfil the purposes for which it was collected or as otherwise required by applicable law.
Retention periods shall be periodically reviewed to ensure compliance with the principle of storage limitation.
PART JSecurity
18.22 Protection of Tracking Data
Information obtained through cookies and similar technologies shall be protected using appropriate technical and organisational safeguards, including:
- encryption where appropriate;
- access controls;
- audit logging;
- secure transmission protocols;
periodic security assessments.
PART KGovernance
18.23 Review
The Company shall periodically review:
- categories of cookies used;
- third-party tracking technologies;
- consent mechanisms;
- retention periods;
legal developments relating to online tracking.
Obsolete or unnecessary tracking technologies shall be removed without undue delay.
Schedule 18-A: Illustrative Cookie Categories
| Cookie / Technology Category | Primary Purpose | Consent Requirement* |
|---|---|---|
| Strictly Necessary | Authentication, security, session management | Not generally required where permitted by law |
| Functional | Remember user preferences and accessibility settings | Jurisdiction-dependent |
| Analytics | Usage statistics and service improvement | Required where mandated by applicable law |
| Performance | Performance monitoring and diagnostics | Jurisdiction-dependent |
| Advertising | Advertising measurement and personalisation | Required under applicable law |
| SDKs & Mobile Identifiers | Mobile application functionality and diagnostics | Depends on purpose and applicable law |
*Consent requirements vary depending on the applicable legal framework and jurisdiction.
CHAPTER 19RECORDS OF PROCESSING ACTIVITIES (ROPA), DOCUMENTATION AND COMPLIANCE AUDITS
19.1 Purpose
This Chapter establishes the framework for maintaining Records of Processing Activities (“ROPA”), compliance documentation, audit records and accountability evidence by TrackMyWings Technologies Private Limited (“TrackMyWings” or the “Company”).
The Company recognises that accountability requires not only compliance with applicable privacy laws, but also the ability to demonstrate such compliance through accurate, complete and contemporaneous documentation.
Accordingly, the Company shall maintain appropriate records evidencing compliance with:
- the Digital Personal Data Protection Act, 2023 (“DPDP Act”);
- the General Data Protection Regulation (“GDPR”), including Article 30;
- contractual obligations;
recognised international privacy and information security standards.
PART AAccountability Through Documentation
19.2 Principle of Documented Compliance
The Company shall maintain written records demonstrating compliance with this Privacy Policy and applicable law.
Documentation shall be:
- accurate;
- current;
- complete;
- securely maintained;
- readily retrievable;
periodically reviewed.
Documentation shall be retained only for so long as necessary to demonstrate compliance or satisfy legal obligations.
19.3 Categories of Compliance Documentation
The Company’s privacy governance programme may include documentation relating to:
- Records of Processing Activities;
- Privacy Policies;
- Data Processing Agreements;
- Data Protection Impact Assessments;
- Transfer Impact Assessments;
- consent records;
- security policies;
- incident response records;
- training records;
- audit reports;
- vendor assessments;
- risk assessments;
- legal holds;
regulatory correspondence.
PART BRecords of Processing Activities (ROPA)
19.4 Maintenance of ROPA
Where required by applicable law or considered appropriate as a matter of good governance, the Company shall maintain a Record of Processing Activities (“ROPA”).
The ROPA shall provide an accurate description of the Company’s processing operations and shall be updated whenever material changes occur.
19.5 Minimum Contents of the ROPA
The ROPA may include:
- (a) name and contact details of the Company;
- (b) contact details of the Data Protection Officer, where applicable;
- (c) categories of processing activities;
- (d) purposes of processing;
- (e) categories of Data Principals or Data Subjects;
- (f) categories of Personal Data;
- (g) categories of recipients;
- (h) categories of international transfers;
- (i) lawful basis for processing;
- (j) applicable retention periods;
- (k) technical and organisational safeguards.
19.6 Responsibility
Each business function responsible for processing Personal Data shall provide accurate and timely information necessary for maintaining the ROPA.
The Legal, Compliance and Privacy functions shall coordinate periodic updates.
PART CProcessing Inventories
19.7 Data Mapping
The Company shall maintain an inventory identifying:
- data collection points;
- systems processing Personal Data;
- storage locations;
- internal data flows;
- external disclosures;
- retention schedules;
deletion mechanisms.
Data mapping shall support:
- DPIAs;
- security assessments;
- incident response;
compliance reporting.
19.8 System Register
The Company may maintain an inventory of systems processing Personal Data, identifying:
- system owner;
- categories of Personal Data;
- security classification;
- hosting environment;
- applicable vendors;
retention obligations.
PART DConsent Documentation
19.9 Consent Records
Where processing relies upon consent, the Company shall maintain evidence demonstrating:
- identity of the consenting individual;
- date and time of consent;
- version of the applicable privacy notice;
- processing purposes;
withdrawal of consent, where applicable.
Consent records shall be protected against unauthorised alteration.
PART EDPIA and Privacy Assessments
19.10 DPIA Register
The Company shall maintain a register of completed Data Protection Impact Assessments.
The register may include:
- assessment reference number;
- project name;
- business owner;
- assessment date;
- identified risks;
- mitigation measures;
- approval status;
review date.
19.11 Risk Register
Privacy risks identified through audits, DPIAs, Transfer Impact Assessments or security assessments shall be recorded within the Company’s Privacy Risk Register.
Each risk entry shall identify:
- risk description;
- likelihood;
- impact;
- risk owner;
- mitigation measures;
implementation status.
PART FVendor Documentation
19.12 Vendor Register
The Company shall maintain records relating to Data Processors and significant third-party service providers processing Personal Data.
The Vendor Register may include:
- vendor name;
- processing activities;
- categories of Personal Data;
- geographic location;
- applicable contracts;
- security assessments;
review dates.
19.13 Contract Repository
Executed agreements relating to privacy and data protection, including Data Processing Agreements, Standard Contractual Clauses and confidentiality agreements, shall be securely maintained.
PART GAudit Programme
19.14 Internal Privacy Audits
The Company shall periodically conduct internal audits to evaluate compliance with:
- this Privacy Policy;
- internal procedures;
- applicable legislation;
- contractual obligations;
recognised standards adopted by the Company.
19.15 Scope of Audit
Privacy audits may examine:
- processing activities;
- access controls;
- consent management;
- retention practices;
- breach management;
- vendor compliance;
- international transfers;
- training records;
privacy documentation.
19.16 External Assessments
Where appropriate, the Company may engage qualified independent professionals to conduct:
- privacy compliance reviews;
- information security assessments;
- certification audits;
- penetration testing reviews;
governance evaluations.
PART HAudit Findings
19.17 Corrective Actions
Audit findings shall be documented together with:
- identified deficiencies;
- associated risks;
- recommended actions;
- responsible owners;
- target completion dates;
implementation status.
Corrective actions shall be tracked until completion.
19.18 Follow-up Reviews
The Company shall conduct follow-up reviews to verify that agreed corrective actions have been effectively implemented.
PART IRegulatory Cooperation
19.19 Regulatory Requests
Where requested by a competent authority, the Company shall provide documentation demonstrating compliance, subject to applicable legal restrictions and confidentiality obligations.
Documentation provided shall be accurate, complete and proportionate to the request.
19.20 Preservation of Records
Where regulatory investigations, litigation or audits are anticipated or ongoing, relevant documentation shall be preserved in accordance with the Company’s Legal Hold procedures.
PART JContinuous Monitoring
19.21 Periodic Review
Privacy documentation shall be reviewed periodically to ensure that it remains:
- accurate;
- complete;
- consistent with operational practices;
compliant with evolving legal requirements.
Material changes shall be reflected promptly in the relevant records.
19.22 Continuous Improvement
The Company shall use information obtained from:
- audits;
- incidents;
- complaints;
- DPIAs;
- vendor reviews;
- regulatory developments;
employee feedback,
to strengthen its privacy governance programme and improve compliance maturity.
Schedule 19-A: Illustrative Privacy Documentation Register
| Document | Purpose | Responsible Function | Review Frequency |
|---|---|---|---|
| Privacy Policy | Public privacy notice | Legal / Privacy | At least annually or upon material change |
| Records of Processing Activities (ROPA) | Document processing operations | Privacy / Business Units | Ongoing; formal review annually |
| Data Protection Impact Assessments | Assess high-risk processing | Privacy / Business Owner | Before implementation; periodic review |
| Transfer Impact Assessments | Assess international transfers | Legal / Privacy | Prior to relevant transfers and upon legal changes |
| Vendor Register | Track processors and third parties | Procurement / Privacy | At least annually |
| Consent Register | Evidence of valid consent | Privacy / Engineering | Continuous |
| Incident Register | Record security and privacy incidents | Information Security | Continuous |
| Privacy Risk Register | Track identified privacy risks | Risk & Compliance | Quarterly or upon material change |
| Training Records | Demonstrate employee awareness | Human Resources / Privacy | Continuous |
| Audit Reports | Evidence of compliance reviews | Internal Audit | As scheduled |
CHAPTER 20POLICY ADMINISTRATION, AMENDMENTS, GOVERNING LAW AND MISCELLANEOUS PROVISIONS
20.1 Purpose
This Chapter constitutes the final administrative provisions of the Privacy Policy of TrackMyWings Technologies Private Limited (“TrackMyWings” or the “Company”). It establishes the framework governing the ownership, interpretation, implementation, review, amendment and enforcement of this Privacy Policy.
This Chapter also specifies the governing law, jurisdiction, severability, conflict resolution, publication, version control and effective date of the Privacy Policy.
PART AOwnership and Administration
20.2 Policy Owner
The Company shall designate an appropriate function, department or officer responsible for the ownership and administration of this Privacy Policy.
The Policy Owner shall be responsible for:
- (a) maintaining the Privacy Policy;
- (b) coordinating periodic reviews;
- (c) ensuring legal compliance;
- (d) recommending amendments;
- (e) maintaining version history;
- (f) coordinating publication of updated versions.
20.3 Administrative Responsibility
Implementation of this Privacy Policy shall be a shared responsibility of:
- Senior Management;
- Legal Department;
- Compliance Function;
- Information Security Team;
- Human Resources;
- Business Units;
- Information Technology;
Data Protection Officer, where appointed; and
all employees and authorised personnel.
PART BInterpretation
20.4 Interpretation
This Privacy Policy shall be interpreted:
- consistently with applicable law;
- in a manner promoting protection of Personal Data;
- harmoniously with the Company’s contractual obligations;
in accordance with recognised principles of privacy governance.
Headings are inserted for convenience only and shall not affect interpretation.
20.5 References
Unless the context otherwise requires:
- references to legislation include amendments and successor legislation;
- references to the singular include the plural;
- references to one gender include every gender;
references to “including” mean “including without limitation.”
PART CReview and Amendments
20.6 Periodic Review
The Company shall periodically review this Privacy Policy to ensure that it remains:
- accurate;
- legally compliant;
- operationally effective;
- consistent with technological developments;
aligned with business operations.
Formal reviews shall ordinarily occur at least annually or sooner where circumstances require.
20.7 Amendment
The Company reserves the right to amend this Privacy Policy from time to time.
Amendments may be made where necessary to reflect:
- changes in applicable law;
- judicial decisions;
- regulatory guidance;
- technological developments;
- security enhancements;
- operational changes;
- new products or services;
organisational restructuring.
20.8 Material Changes
Where amendments materially affect the processing of Personal Data or the rights of Users, the Company shall take reasonable steps to notify affected Users by one or more appropriate means, including:
- publication on the Company’s website;
- notification through the mobile application;
- email communication;
- account notifications;
other lawful communication channels.
Where required by applicable law, fresh consent shall be obtained before implementing material changes affecting consent-based processing.
PART DPublication
20.9 Availability
The current version of this Privacy Policy shall be made available through appropriate Company platforms, including:
- the official website;
- mobile applications;
- customer portals;
other digital services operated by the Company.
The Privacy Policy shall be presented in a manner that is reasonably accessible and understandable.
20.10 Historical Versions
The Company may retain previous versions of this Privacy Policy for:
- regulatory compliance;
- historical reference;
- legal proceedings;
audit purposes.
Archived versions may be made available upon reasonable request where appropriate and permitted by law.
PART EGoverning Law
20.11 Governing Law
This Privacy Policy shall be governed by and construed in accordance with the laws of the Republic of India.
Where Personal Data is processed in jurisdictions outside India, the Company shall additionally comply with mandatory privacy laws applicable to such processing to the extent required.
20.12 Jurisdiction
Subject to any mandatory rights available under applicable law, disputes arising out of or relating to this Privacy Policy shall be subject to the jurisdiction of the competent courts having jurisdiction over the Company’s registered office or competent Courts at Shimla, Himachal Pradesh, India, unless otherwise required by law.
Nothing in this clause shall prevent the Company from cooperating with competent regulatory authorities in any jurisdiction where applicable privacy laws require such cooperation.
PART FSeverability
20.13 Severability
If any provision of this Privacy Policy is held to be invalid, unlawful or unenforceable by a court or competent authority, such provision shall, to the extent necessary, be deemed severed.
The remaining provisions shall continue in full force and effect.
PART GWaiver
20.14 No Waiver
Failure by the Company to enforce any provision of this Privacy Policy shall not constitute a waiver of that provision or any other provision.
Any waiver shall be effective only if expressly made in writing by an authorised representative of the Company.
PART HEntire Privacy Policy
20.15 Entire Privacy Policy
This Privacy Policy constitutes the Company’s comprehensive statement regarding the processing of Personal Data through its Services.
Nothing in this Privacy Policy shall limit any additional rights provided to Data Principals under applicable law.
Where specific services require supplementary privacy notices, such notices shall be read together with this Privacy Policy.
PART IContact Information
20.16 Privacy Contact
Questions regarding this Privacy Policy or the Company’s privacy practices may be directed to the Company’s designated privacy contact, Grievance Officer or Data Protection Officer, as applicable.
The Company shall publish updated contact information through its official communication channels.
20.17 Regulatory Complaints
Nothing contained in this Privacy Policy shall prevent any individual from exercising any statutory right to submit complaints or seek remedies before a competent authority, tribunal or court in accordance with applicable law.
PART JEffective Date and Version Control
20.18 Effective Date
This Privacy Policy shall become effective on the date specified below and shall remain in force until amended or replaced.
20.19 Version Control
The Company shall maintain version records including:
- version number;
- approval date;
- effective date;
- summary of material amendments;
approving authority.
Only the latest approved version shall govern the processing of Personal Data unless otherwise required by applicable law.
Schedule 20-A: Policy Administration Register
| Item | Description |
|---|---|
| Policy Name | Privacy Policy |
| Policy Owner | TrackMyWings Technologies Private Limited |
| Approved By | Board of Directors / Authorised Management |
| Effective Date | 1st August, 2026 |
| Version | 1.0 |
| Review Frequency | At least annually or upon material legal, operational or technological change |
| Governing Law | Laws of the Republic of India |
| Jurisdiction | Competent courts having jurisdiction over the Company’s registered office, subject to applicable law |
| Superseded Versions | As recorded in the Version Control Register |