Privacy Policy

Effective Date: May 16, 2026 · Last Updated: July 29, 2026 · Version: 2.1

Preamble

This Privacy Policy ("Policy") is an electronic document published in accordance with Rule 3(1) of the Information Technology (Intermediaries Guidelines and Digital Media Ethics Code) Rules, 2021, and Section 43A of the Information Technology Act, 2000 ("IT Act"), and constitutes a legally binding agreement between Waadi Tax & Insurance Solutions (Proprietorship managed by JAFRIDA; GSTIN: 06CBFPJ8826H1ZH; Udyam Number: UDYAM-HR-21-0030370) ("Firm", "we", "us", "our") and any person who accesses, registers upon, or uses our information services and platform.

Waadi Tax & Insurance Solutions is a proprietorship firm with its Registered Office at Kherla Nuh, Delhi Road, Nuh, Haryana - 122107, India.

This Policy must be read in conjunction with our Terms and Conditions. By accessing or using the App, you expressly consent to the collection, use, storage, and disclosure of your personal data as described herein.

Part I: Legal Framework

This Policy is published in strict compliance with the following statutes and regulations:

Primary Legislation

  • Digital Personal Data Protection Act, 2023 (DPDPA) — The principal data protection legislation in India, prescribing obligations on Data Fiduciaries
  • Information Technology Act, 2000 (IT Act) — Sections 43A, 66, 66C, 72, and 72A govern data protection, computer offences, breach of confidentiality, and unauthorized disclosure
  • IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules) — Prescribes specific obligations on body corporates handling sensitive personal data

Supporting Regulations

  • IT (Intermediaries Guidelines and Digital Media Ethics Code) Rules, 2021 — Rule 3(1)(b) mandates intermediaries to publish their privacy policy
  • RBI Master Direction on Digital Payment Security Controls, 2021 — Governs security standards for payment data
  • RBI Circular on Storage of Payment System Data (2018) — Mandates storage of all payment data within India
  • Payment and Settlement Systems Act, 2007 — Governs payment systems and security obligations
  • Google Play Developer Program Policies (2024) — Applicable to Apps distributed through Google Play Store
  • Apple App Store Review Guidelines (Section 5.1 - Privacy) — Applicable to Apps distributed through Apple App Store

Constitutional Basis:The right to privacy in India is constitutionally guaranteed as a fundamental right under Article 21 of the Constitution of India, as affirmed by the Supreme Court in Justice K.S. Puttaswamy (Retd.) & Anr. v. Union of India & Ors., (2017) 10 SCC 1. This Policy acknowledges and respects this constitutional right.

Part II: Data Fiduciary Information

Under the DPDPA 2023, Waadi Tax & Insurance Solutions (Proprietorship managed by JAFRIDA) is the "Data Fiduciary" — the entity that determines the purpose and means of processing your personal data.

Entity NameWaadi Tax & Insurance Solutions
ProprietorJAFRIDA
GSTIN06CBFPJ8826H1ZH
Udyam NumberUDYAM-HR-21-0030370
Registered OfficeKherla Nuh, Delhi Road, Nuh, Haryana - 122107
Principal BusinessInformation Services, Tax & Insurance Solutions
Emailjaveskhan27@gmail.com
Grievance Officer Emailjaveskhan27@gmail.com

Part III: Personal Data Collection

We collect personal data under the framework established by Schedule I of the SPDI Rules, 2011 and the DPDPA 2023. The categories are:

3.1 Personal Data You Provide Voluntarily

Identity and Contact Information (Mandatory)

  • Full legal name and date of birth
  • Mobile phone number (used for OTP-based authentication per RBI 2FA mandate)
  • Email address

Vehicle and Compliance Information (Mandatory for Service Delivery)

  • Vehicle Registration Number (VRN)
  • Vehicle category (LMV, HMV, commercial, tourist, etc.)
  • Vehicle specifications (seating capacity, fuel type, engine capacity)
  • Chassis number and engine number (for permit applications)

Document Uploads (User-Controlled)

  • Registration Certificate (RC) — issued under Section 41 of the Motor Vehicles Act, 1988
  • Insurance Policy Certificate — mandatory under Section 146 of the Motor Vehicles Act, 1988
  • Pollution Under Control (PUC) Certificate — required under Rule 115 of the Central Motor Vehicles Rules, 1989
  • Fitness Certificate — issued under Section 56 of the Motor Vehicles Act, 1988
  • National Permit — granted under Section 88 of the Motor Vehicles Act, 1988
  • Any other compliance document uploaded at your discretion

Payment Reference Information (Transaction Records Only)

  • PayU Transaction ID and Payment ID
  • Transaction amount and status
  • Order reference numbers

IMPORTANT: We do NOT collect, store, or process credit card numbers, debit card numbers, CVV, PINs, net banking credentials, or UPI PINs. All such sensitive financial data is handled exclusively by PayU Payments Private Limited, our PCI-DSS certified Payment Aggregator, under their separate privacy framework.

Communication Records

  • Support queries, messages, and feedback submitted through the App or email

3.2 Data Collected Automatically

  • Device Identifiers: Device model, OS version, app version number
  • Usage Analytics: Feature usage frequency, session duration, navigation patterns (anonymized)
  • Log Data: Server-side access logs including IP address, timestamps, API response codes

We do NOT collect real-time GPS location data. Any geographic reference is limited to the state/region selected by you for service processing.

3.3 Sensitive Personal Data or Information (SPDI)

Under Rule 3 of the SPDI Rules, 2011, certain categories constitute "sensitive personal data." The following categories, if collected, are treated with heightened protection:

  • Biometric data (if collected for future identity verification features)
  • Financial information to the extent of transaction records

Part IV: Lawful Basis and Purpose of Processing

We process your personal data on the following lawful bases under Section 4 of the DPDPA 2023:

Lawful BasisExamples
Consent (Section 6, DPDPA 2023)Registration, document upload, marketing communications
Legitimate Uses (Section 7, DPDPA 2023)Service delivery, payment processing, legal compliance
Legal ObligationTax records, court orders, government directives
Vital InterestsEmergency situations requiring processing to protect life

Specific purposes of processing include:

PurposeLegal BasisData Categories Used
User account creation and authenticationConsentIdentity, Contact
Processing border tax payments on Parivahan portalLegitimate UseVehicle, Identity
Processing challan payments on e-Challan portalLegitimate UseVehicle, Identity
Uploading official VAHAN receipts to your accountLegitimate UseVehicle, Transaction
Document expiry monitoring and alertsConsentDocument Data
Payment processing via PayULegitimate UseTransaction Reference
GST invoice generation (per GST Act, 2017)Legal ObligationIdentity, Transaction
Customer support and grievance resolutionLegitimate UseCommunication
Fraud detection and preventionLegitimate UseAll categories
Compliance with court orders or government directionsLegal ObligationAs directed
Tax record maintenance (8 years, per Income Tax Act, 1961)Legal ObligationTransaction Records

Part V: Data Sharing and Disclosure

We share your personal data only with the following categories of recipients and only to the extent necessary:

6.1 Government Portals (Essential for Service)

  • Parivahan Sewa (parivahan.gov.in) — Vehicle registration data and tax payment submissions are processed on this Ministry of Road Transport portal. This sharing is inherent to and inseparable from our core service.
  • State Transport Department Portals — State-specific tax and permit applications

6.2 Payment Processor

PayU Payments Private Limited — Our sole Payment Aggregator, authorized by RBI. PayU operates under the RBI Master Directions on Payment Aggregators and Payment Gateways (2020). Their data handling is governed by their own Privacy Policy and PCI-DSS certification.

6.3 Cloud Infrastructure

Our servers are hosted on secure VPS infrastructure within India, in compliance with the RBI Circular on Storage of Payment System Data (April 6, 2018), which mandates storage of payment data within Indian territory.

6.4 Legal Authorities

We may disclose personal data to law enforcement or judicial authorities when:

  • Required by a valid court order under Section 91 of the Code of Criminal Procedure, 1973 (CrPC)
  • Required under Section 69 of the IT Act, 2000 (government direction for interception/monitoring)
  • Required under Section 67C of the IT Act, 2000 (preservation and retention of data)
  • Required to comply with any other applicable law

We do NOT sell, rent, licence, or transfer your personal data to any third party for commercial, marketing, or advertising purposes. Any unauthorized disclosure of personal data constitutes a criminal offence under Section 72A of the IT Act, 2000, punishable with imprisonment up to three years and/or a fine up to Rs. 5,00,000 (Five Lakh Rupees).

Part VI: Data Security

As mandated by Section 43A of the IT Act, 2000 read with Rule 8 of the SPDI Rules, 2011, we implement and maintain "reasonable security practices and procedures" comprising an internationally accepted information security programme, including:

  • Encryption in Transit: All data exchanged between your device and our servers is encrypted using TLS 1.2/1.3 protocols
  • Encryption at Rest: Database encryption for all stored personal data
  • Access Controls: Role-based access control (RBAC) with principle of least privilege; administrative access protected by multi-factor authentication (MFA)
  • Authentication: JWT-based token authentication with OTP verification for all user login events
  • Secure Storage: Document files stored in sandboxed Nginx server environments with strict access controls
  • Data Minimization: We collect only what is strictly necessary for service delivery
  • Retention Controls: Automated deletion of receipts after service expiry + 2-day buffer period
  • Audit Logs: Server-side access logs maintained for security audit purposes

Legal Note: In the event of a data breach, we are obligated under the DPDPA 2023 to notify the Data Protection Board of India and affected Data Principals in the prescribed manner.

Part VII: Data Retention

Data CategoryRetention PeriodLegal Basis
Account and identity dataDuration of account + 90 days post deletion requestDPDPA 2023
Payment transaction recordsMinimum 8 yearsIncome Tax Act, 1961; GST Act, 2017
Vehicle compliance documentsUntil document expiry + 2 daysService requirement
Communication/support records3 yearsLimitation Act, 1963
Server access logs90 daysIT (Intermediary) Rules, 2021
GST invoices and credit notes6 yearsGST Act, 2017 (Section 36)

Upon expiry of the applicable retention period, personal data will be permanently deleted or anonymized so that it can no longer identify you.

Part VIII: Your Rights as Data Principal

9.1 Right to Access Information (Section 11, DPDPA 2023)

You have the right to obtain confirmation of whether your personal data is being processed, a summary of the processing activities undertaken, and the identities of all Data Fiduciaries and Data Processors with whom your data has been shared.

9.2 Right to Correction and Erasure (Section 12, DPDPA 2023)

You may request correction of inaccurate or misleading personal data, completion of incomplete personal data, and erasure of personal data no longer necessary for the purpose for which it was collected (subject to legal retention requirements).

9.3 Right to Grievance Redressal (Section 13, DPDPA 2023)

You have the right to have your grievances addressed expeditiously and effectively by our Grievance Officer.

9.4 Right to Nominate (Section 14, DPDPA 2023)

You may nominate any individual to exercise your rights in the event of your death or incapacity.

9.5 Right to Withdraw Consent

You may withdraw consent for processing at any time. However, withdrawal shall not affect the lawfulness of processing based on consent before its withdrawal, and may result in inability to access certain Services.

To exercise any of the above rights, email us at javeskhan27@gmail.com with your registered mobile number and a description of your request.

Part IX: Cookies, Children, and Changes

10. Cookies

The Waadi Tax & Insurance Solutions platform may use cookies to improve user experience, verify MSME/GST status, and provide informational updates. We implement robust technical measures to protect all such data.

11. Children's Privacy (Section 9, DPDPA 2023)

Waadi App is not directed at children under 18 years of age. Section 9 of the DPDPA 2023 imposes additional obligations on Data Fiduciaries processing children's personal data, including obtaining parental consent. We do not knowingly collect personal data from anyone under 18. If we discover that we have collected data from a child without verifiable parental consent, we will delete it promptly.

12. Changes to This Policy

We reserve the right to modify this Policy. Material changes will be communicated through an in-App notification at least 15 days before taking effect. Continued use of the App after the effective date of revised Policy constitutes your acceptance thereof, as recognized under the Indian Contract Act, 1872 (Section 7 — acceptance of proposals).

Part X: Grievance Redressal

In accordance with Rule 5(9) of the SPDI Rules, 2011, Section 13 of the DPDPA 2023, and Rule 3(2) of the IT (Intermediary) Rules, 2021, we have designated a Grievance Officer:

Grievance Officer: Jafrida
Email: javeskhan27@gmail.com
Acknowledgement: Within 24 hours of receipt
Resolution: Within 30 (thirty) days of receipt

If dissatisfied with our resolution, you may approach:

  • The Data Protection Board of India — established under Section 18 of the DPDPA 2023
  • The Adjudicating Officer under Section 46 of the IT Act, 2000
  • The appropriate Consumer Forum under the Consumer Protection Act, 2019

14. Governing Law and Jurisdiction

This Policy is governed by the laws of the Republic of India. Subject to the arbitration clause in our Terms of Service, any dispute arising under this Policy shall be subject to the exclusive jurisdiction of courts at Nuh, Haryana, India.

Contact Us for Privacy Queries

Kherla Nuh, Delhi Road, Nuh, Haryana - 122107