Our commitment
Towigo Mobility Pvt. Ltd. (“Towigo”) is committed to protecting personal data in accordance with the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023 (DPDPA), and applicable rules and guidelines issued thereunder.
This Data Protection Policy describes how we implement technical, organisational, and procedural safeguards across our towing and roadside assistance platform.
Scope
This policy applies to personal data processed by Towigo relating to:
- Customers booking towing or recovery services;
- Drivers, crane operators, and fleet partners;
- Website visitors and app users;
- Employees and contractors with access to systems handling personal data.
Data protection principles
We aim to process personal data in line with the following principles:
- Lawfulness & fairness: processing only where we have a valid legal basis and informing individuals appropriately;
- Purpose limitation: collecting data for specified, legitimate purposes;
- Data minimisation: collecting only what is necessary for the service;
- Accuracy: keeping data correct and up to date where practicable;
- Storage limitation: retaining data only as long as needed (see our Data Retention Policy);
- Integrity & confidentiality: protecting data against unauthorised access, loss, or misuse.
Security measures
We implement measures including, where appropriate:
- Encryption in transit (TLS/SSL) for data transmitted over networks;
- Access controls and role-based permissions for internal systems;
- Authentication mechanisms including OTP for customer accounts;
- Logging and monitoring of critical infrastructure;
- Vendor due diligence for subprocessors handling personal data;
- Employee training on data handling and incident reporting.
Data processors & transfers
We engage trusted service providers (payment gateways, cloud hosting, SMS/email, maps) who process data on our instructions and under contractual confidentiality and security obligations. Personal data is primarily processed and stored in India unless otherwise disclosed and permitted by law.
Data breach response
We maintain procedures to detect, investigate, and respond to suspected personal data breaches. Where required by law, we will notify affected individuals and relevant authorities within prescribed timelines.
Individual rights
Subject to applicable law, you may have rights to access, correct, erase, or restrict processing of your personal data, and to withdraw consent for optional processing. See our Privacy Policy for details on exercising these rights.
Grievance officer
For data protection concerns, contact our Grievance Officer: