Privacy Policy
Turag — a product of Blessing Softtech (OPC) Private Limited
BST-WEB-02 · Last updated: [DD Month YYYY] · Version 0.2 — Draft
1. Who we are
1.1 Blessing Softtech (OPC) Private Limited (CIN U62099PN2024OPC235937), registered office A 102, Sky Belvedere, Viman Nagar, Pune, Maharashtra [PIN], India, operates the Turag platform. In this policy we are “the Company”, “we” or “us”, and you are “you”.
1.2 For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Company is the Data Fiduciary in respect of the personal data described in this policy. Where we process personal data on behalf of another entity, we act as a Data Processor and that entity’s notice applies.
1.3 This policy also serves as the privacy policy required under Rule 3(1)(a) of the IT Rules, 2021 and under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”) to the extent those rules continue to apply.
2. Scope
This policy applies to personal data we collect through the Turag website, mobile applications, inspection operations, customer support channels, and any other service that links to it. It does not apply to third-party websites or to a Seller’s or Buyer’s own handling of your data.
3. What we collect
| Category | Examples | Source |
|---|---|---|
| Identity data | Name, date of birth, photograph | You |
| Contact data | Mobile number, email, postal address | You |
| Account data | Username, hashed password, preferences, support history | You / generated |
| KYC data | PAN, identity document number and image, address proof, selfie/liveness capture | You / KYC provider |
| Vehicle data | Registration number, chassis and engine number, RC particulars, insurance and challan status | You / public and authorised sources |
| Inspection data | Checkpoint results, photographs and video of the vehicle, diagnostic (OBD) output, inspector notes, geolocation of the inspection, score and grade | Our inspector / equipment |
| Transaction data | Bookings, invoices, amounts, payment status, refund records | You / payment aggregator |
| Technical data | IP address, device identifiers, browser type, operating system, crash logs | Automatic |
| Usage data | Pages viewed, listings viewed, search terms, session duration | Automatic |
| Communications | Call recordings with support, chat transcripts, emails | You / us |
3.1 Financial information. We do not collect or store complete card numbers, CVV, UPI PIN, or net-banking credentials. Those are collected directly by our RBI-authorised payment aggregator.
3.2 Children. The Platform is not intended for persons under 18. We do not knowingly process the personal data of a child. Where the DPDP Act requires verifiable parental consent before processing a child’s data, we will not proceed without it, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
3.3 Data of persons with disabilities. Where a lawful guardian has been appointed, we will process personal data only on verifiable consent of that guardian.
4. Why we process it, and on what basis
| Purpose | Categories used | Lawful basis under the DPDP Act |
|---|---|---|
| Creating and operating your account | Identity, contact, account | Consent |
| Publishing a listing and connecting Buyer and Seller | Identity, contact, vehicle | Consent |
| Carrying out an inspection and issuing a report | Vehicle, inspection, identity | Consent |
| Verifying identity and ownership; fraud prevention | KYC, vehicle, transaction | Consent; and certain legitimate uses under s.7 |
| Taking and settling payments; issuing invoices | Transaction, identity | Consent; performance of the service requested |
| Customer support and grievance handling | All, as relevant | Consent; s.7 legitimate uses |
| Meeting legal, tax and regulatory obligations | Transaction, KYC, identity | Compliance with law (s.7(b)) |
| Security, logging, and abuse detection | Technical, usage | Consent; s.7 legitimate uses |
| Service communications | Contact | Consent |
| Marketing and promotional communication | Contact, usage | Consent — separately obtained and separately withdrawable |
| Analytics and product improvement | Usage, technical, de-identified | Consent |
4.1 We will not use your personal data for a materially new purpose without first giving you notice and, where required, obtaining fresh consent.
5. Notice and consent
5.1 Before or at the time of collecting personal data on the basis of consent, we give you a notice in clear and plain language setting out the personal data sought, the purposes, how to withdraw consent, how to exercise your rights, and how to complain to the Data Protection Board of India.
5.2 The notice is available in English and, on request, in any language listed in the Eighth Schedule to the Constitution of India.
5.3 Your consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and is limited to the personal data necessary for the stated purpose.
5.4 Withdrawing consent is as easy as giving it. Use the privacy controls in your account, or write to privacy@turag.ai. On withdrawal we will stop the relevant processing within a reasonable time and require our processors to do the same. Withdrawal does not affect the lawfulness of processing already carried out, and we may retain data where another lawful ground — such as a statutory retention obligation — applies.
5.5 Consent Managers. Once the Consent Manager framework under the DPDP Rules, 2025 becomes operative, you may give, manage, review and withdraw consent through a Consent Manager registered with the Data Protection Board. We will accept and act on consent artefacts received through a registered Consent Manager.
6. Inspection data — specific notice
6.1 A Turag inspection produces a detailed record of the vehicle, including photographs and video that may incidentally capture the surroundings, the inspection location, and in some cases the face or voice of a person present.
6.2 We use inspection data to produce and deliver the inspection report, to substantiate the “Turag Verified” mark, to handle disputes and complaints, to train and audit our inspectors, and — in de-identified form — to improve our inspection methodology.
6.3 Inspection reports are shared with the person who commissioned the inspection and, where the vehicle is listed, with prospective Buyers in the form published on the listing.
6.4 A separate consent notice is presented on the account before an inspection is carried out.
7. Who we share it with
We share personal data only as set out below, and only to the extent necessary:
- Data Processors engaged by us under written contract — hosting, cloud storage, analytics, communication (SMS/email), call-centre, KYC verification and document-storage providers. They may process personal data only on our instructions.
- Payment aggregators and banks, to process payments and refunds.
- Sellers and Buyers, to the limited extent needed to complete a transaction you have initiated.
- Financing partners, insurers or RTO service providers, only where you ask us to connect you.
- Professional advisers — auditors, lawyers, insurers — under duties of confidentiality.
- Government agencies, courts, or law enforcement, where required under a lawful order or to comply with law.
- An acquirer, in a merger, amalgamation or transfer of business, subject to this policy continuing to apply.
We do not sell personal data.
8. Cross-border transfer
Personal data may be stored or processed outside India by our service providers. We transfer personal data outside India only in accordance with section 16 of the DPDP Act and any restriction notified by the Central Government, and under contractual safeguards binding the recipient to standards no less protective than this policy. Where a sectoral law requires data to be held in India, we comply with that requirement.
9. How long we keep it
| Record | Indicative retention |
|---|---|
| Account and profile data | For the life of the account, then [180] days |
| Inspection reports and media | [3] years from the inspection date |
| Transaction, invoice and tax records | [8] years from the end of the relevant financial year |
| KYC records | [5] years from the end of the relationship or transaction |
| Support recordings and transcripts | [12] months |
| Server, access and security logs | [180] days |
| Marketing consent records | For the life of the consent, then [3] years |
| Grievance records | [3] years from closure |
9.1 We erase personal data, and require our processors to erase it, when the purpose is no longer being served and retention is not required by law — including where you have not contacted us or exercised any right for the period specified under the DPDP Rules. We will give you notice before erasing on that ground.
10. Security
10.1 We implement reasonable security safeguards, including: encryption in transit (TLS) and at rest; role-based access control and least privilege; multi-factor authentication for administrative access; logging and monitoring; secure software development and change control; vendor due diligence and written processing contracts; periodic vulnerability assessment and penetration testing; and staff training.
10.2 No system is completely secure. In the event of a personal data breach we will notify each affected Data Principal and the Data Protection Board of India in the form and within the timelines prescribed under the DPDP Act and Rules.
11. Your rights
Subject to the DPDP Act, you have the right to:
- Access — obtain a summary of the personal data we process about you, the processing activities, and the identities of other Data Fiduciaries and Processors with whom it has been shared;
- Correction, completion and updating — have inaccurate or misleading data corrected and incomplete data completed;
- Erasure — have personal data erased where it is no longer necessary and no law requires it to be kept;
- Nominate — nominate another individual to exercise your rights in the event of your death or incapacity;
- Grievance redressal — have a complaint answered by us before approaching the Board; and
- Withdraw consent at any time, as described in clause 5.4.
11.1 How to exercise them. Use the privacy controls in your account, or write to the Grievance Officer at grievance@turag.ai. We may ask for information to verify your identity. We will respond within [30] days, or such shorter period as may be prescribed.
11.2 Your duties. Under section 15 of the DPDP Act you must not impersonate another person when providing data, must not suppress material information where legally required to disclose it, must not register a false or frivolous complaint, and must provide authentic information when seeking correction or erasure.
12. Cookies and similar technologies
12.1 We use strictly necessary cookies to operate the Platform, and — where you consent — preference, analytics and marketing cookies.
12.2 You may manage non-essential cookies through the cookie banner or your browser settings. Disabling strictly necessary cookies may prevent parts of the Platform from working.
13. Grievance Officer and complaints
| Role | Details |
|---|---|
| Grievance Officer / Data Protection contact | [Name] |
| Address | Blessing Softtech (OPC) Private Limited, A 102, Sky Belvedere, Viman Nagar, Pune, Maharashtra [PIN], India |
| grievance@turag.ai | |
| Phone | +91 70205 29191 |
| Response timeline | Acknowledgement within 24 hours; resolution within 15 days |
If you are not satisfied with our response, you may complain to the Data Protection Board of India in the manner prescribed under the DPDP Act.
14. Changes to this policy
We will post any change on this page with a revised “Last updated” date, and will notify you of a material change by email or in-app notice before it takes effect.