DPDP Act Declaration
This declaration is issued by Greatminds Retail Private Limited (“GoWith”) in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the rules and notifications issued thereunder. It sets out our commitments as a Data Fiduciary, the specific rights of Data Principals (Users) whose personal data we process, and the contact channels through which those rights may be exercised.
Please read this together with our Privacy Policy, which contains the operational detail of how we collect, process, share, and retain personal data.
1. Data Fiduciary Notice (Section 5, DPDP Act)
For the purposes of the DPDP Act, the Data Fiduciary is:
2. Purposes for Which Personal Data Is Processed
Personal data of Users is processed for the following specified purposes only:
- Creating and operating User accounts on the Platform;
- Completing Know-Your-Customer (KYC) verification of Companions (government ID, live selfie, bank verification);
- Matching Bookers with verified Companions;
- Facilitating Bookings and payments through Escrow;
- Verifying Meets via GPS check-in and providing safety features (dispute resolution, ratings);
- Complying with tax, anti-money-laundering, and other legal obligations;
- Sending transactional and safety-related communications;
- Sending marketing communications, only where the User has provided free, specific, informed, and unambiguous consent.
3. Legal Bases for Processing
Under the DPDP Act, we process personal data on the following bases:
- Consent (Section 6): for KYC document upload, marketing communications, and other processing not covered by legitimate uses. Consent is recorded at the time of collection and can be withdrawn at any time.
- Legitimate uses (Section 7): for performing the Platform contract you enter into upon signup; for compliance with legal obligations; for responding to medical or safety emergencies; for the fulfilment of employment-related obligations to Companions where applicable.
4. Rights of Data Principals (Chapter III, DPDP Act)
As a Data Principal, you have the following rights under the DPDP Act:
- Section 11 — Right to information about personal data: to receive a summary of the personal data being processed and the activities undertaken with respect to it.
- Section 12 — Right to correction and erasure: to have inaccurate or misleading data corrected, incomplete data completed, outdated data updated, and to request erasure of data that is no longer necessary for the purposes for which it was collected.
- Section 13 — Right of grievance redressal: to raise a complaint about our processing of your personal data, addressed to our Grievance Officer.
- Section 14 — Right to nominate: to nominate another individual to exercise your rights in the event of your death or incapacity.
- Right to withdraw consent: at any time, subject to lawful consequences.
Requests may be submitted through the app under Settings → Privacy, or by email to our Data Protection Officer.
5. Duties of Data Principals (Section 15)
The DPDP Act also imposes duties on Data Principals. You agree to:
- Comply with all applicable laws while exercising your rights under the DPDP Act;
- Not impersonate another person while providing personal data for a specified purpose;
- Not suppress any material information while providing personal data;
- Not register a false or frivolous grievance or complaint with a Data Fiduciary or the Data Protection Board;
- Furnish only such information as is verifiably authentic.
6. Reasonable Security Safeguards (Section 8(5))
GoWith has implemented and shall continue to implement reasonable security safeguards to prevent personal data breaches, including:
- Encryption of personal data in transit (TLS 1.2 or higher);
- Encryption at rest for sensitive personal data (KYC documents, payment tokens);
- Role-based access controls with need-to-know principle;
- Multi-factor authentication for internal systems;
- Regular vulnerability assessments and penetration testing;
- Documented incident response and breach notification procedures;
- Employee training on data protection principles.
7. Personal Data Breach Notification (Section 8(6))
In the event of a personal data breach that is likely to result in harm to any Data Principal, GoWith shall notify:
- The Data Protection Board of India, without undue delay; and
- Each affected Data Principal, in the manner and within the timelines prescribed under the DPDP Act and rules.
8. Data Retention and Erasure (Section 8(7))
Personal data is retained only for as long as necessary to fulfil the purpose for which it was collected, or as required by law. Categories of retention period are set out in Section 7 of our Privacy Policy. On account closure, personal data not required for legal retention is erased or anonymised within thirty (30) days.
9. Cross-Border Transfer
Personal data is primarily stored on servers located within India (AWS ap-south-1, Mumbai region). Where any processor requires access from outside India, transfers are made only to jurisdictions permitted under the DPDP Act and applicable Central Government notifications, subject to contractual safeguards equivalent to Indian data protection standards.
10. Personal Data of Children
The Platform is not intended for use by, and does not knowingly collect personal data from, individuals under 18 years of age. Any such data discovered will be deleted without delay in accordance with Section 9 of the DPDP Act.
11. Consent Manager (Section 6(7))
GoWith does not currently integrate with an accredited Consent Manager. Where such integrations are enabled in future, Users will be notified and given the option to manage consent through the Consent Manager of their choice.
12. Grievance Officer and Data Protection Officer
Any grievance or query relating to the processing of your personal data may be raised with our Grievance Officer / Data Protection Officer:
If you are dissatisfied with our response, or if your grievance is not resolved within thirty (30) days, you may lodge a complaint with the Data Protection Board of India established under Chapter V of the DPDP Act, once operational.
13. Changes to this Declaration
This Declaration may be updated to reflect changes in applicable law, regulator guidance, or our processing activities. Material changes will be notified via in-app notice or email at least fourteen (14) days prior to taking effect.
This declaration is intended as a good-faith notice to Data Principals under the DPDP Act, 2023 and does not constitute legal advice. Final content is subject to legal review prior to public launch.