Last updated: 31 July 2026
1. Who we are and how to reach us
Movozen Private Limited (CIN U62013RJ2026PTC114286), which operates the MoboSafe platform, is the Data Fiduciary responsible for the personal data described in this policy. Our registered office is at 94/16, Lotus Plaza, 3rd Floor, Madhyam Marg, Mansarovar, Jaipur, Rajasthan 302020, India.
You can contact us at support@movozen.ai or +91 9694232040. Grievances are handled as set out in the Grievance Redressal clause below.
2. Laws this policy is written against
This policy is governed by Indian law. Where any other framework is referred to, it is for the benefit of users outside India and does not displace Indian law.
- Digital Personal Data Protection Act, 2023 ("DPDP Act") and rules made under it.
- Information Technology Act, 2000, in particular section 43A and section 72A.
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").
- Directions issued by the Indian Computer Emergency Response Team (CERT-In) dated 28 April 2022 on cyber incident reporting and log retention.
- Consumer Protection (E-Commerce) Rules, 2020, to the extent we sell online.
3. Terms used in this policy
We use the vocabulary of the DPDP Act so that the meaning of this policy is unambiguous.
- "Data Principal" means the individual the personal data relates to. That is you.
- "Data Fiduciary" means the person who decides why and how personal data is processed. That is us.
- "Data Processor" means a person who processes personal data on our behalf, such as a hosting provider.
- "Personal data" means any data about an individual who is identifiable by or in relation to that data.
- "Processing" means any operation performed on personal data, including collection, storage, use, sharing and erasure.
4. Notice of what we collect and why
Where we rely on your consent, we give you notice under section 5 of the DPDP Act before or at the time of collection, describing the personal data sought, the purpose, how you may exercise your rights, and how you may complain to the Data Protection Board of India. This policy forms part of that notice.
The categories of personal data we process are set out below. Not all of it applies to every user; what we hold depends on whether you are a website visitor, a customer contact, a fleet driver, or a parent or guardian using a tracking view provided by an institution.
- Identity and contact data: name, email address, telephone number, employer or institution, designation.
- Account data: login credentials in hashed form, roles and permissions, preferences, support correspondence.
- Vehicle telematics data: real-time and historical GPS location, speed, route, ignition status, idling, geofence events, fuel and OBD diagnostics. Where a vehicle is linked to an identifiable driver, this is personal data about that driver.
- Camera and driver monitoring data: video and still images from road-facing and cabin-facing cameras, including ADAS and DMS event footage that may capture a driver's face and in-cab behaviour.
- Compliance and verification data: registration numbers, RC and permit details, driving licence particulars, and challan history retrieved from government sources such as VAHAN and Sarathi.
- Billing data: business name, billing address, GSTIN and invoice records. We do not collect or process card, bank or other payment instrument details, and no payment is taken through our website or mobile applications.
- Technical data: IP address, device and browser type, operating system, and usage logs.
5. Why we process personal data
We process personal data only for purposes that are lawful and that we have told you about.
- To provide the platform: tracking, alerts, reporting, electronic proof of delivery, eWay Bill automation and driver verification.
- To supply, install, maintain and support hardware and software.
- To meet regulatory obligations, including transmitting data to State or National Government backend systems where a vehicle is registered under AIS-140.
- To improve safety outcomes through driver behaviour analysis and incident reconstruction.
- To raise invoices and meet tax, accounting and company law obligations.
- To respond to enquiries and provide customer support.
- To send marketing communications, only where you have consented, and always with the ability to withdraw.
- To detect, investigate and prevent fraud, misuse and security incidents.
6. Grounds on which we process
Under the DPDP Act, personal data may be processed on the basis of consent under section 6, or for certain legitimate uses set out in section 7. We do not rely on a general "legitimate interests" ground, because Indian law does not provide one.
Where we rely on consent, that consent is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the stated purpose.
Where we rely on certain legitimate uses, this is typically because you have voluntarily provided data for a purpose you have not indicated you object to, or because processing is required to comply with a law or a judgment, or to respond to a medical emergency or a threat to life or safety.
For business customers, the employing organisation is generally the Data Fiduciary in respect of its own drivers and employees, and we act on its instructions. That organisation is responsible for giving notice to, and where required obtaining consent from, its drivers and staff before vehicles are tracked or cabin-facing cameras are enabled.
7. Withdrawing consent
Where processing rests on your consent, you may withdraw it at any time. Withdrawing consent must be as easy as giving it, and you can do so by writing to support@movozen.ai or using the controls in your account.
Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Where withdrawal means we can no longer provide a service, we will tell you and stop that service. We may continue to retain data where a law requires it, for example transmission and retention obligations attaching to AIS-140 devices or CERT-In log retention.
8. Children and persons with disabilities
Section 9 of the DPDP Act imposes specific obligations where personal data of a child, meaning a person under eighteen years of age, is processed. It requires verifiable consent of a parent or lawful guardian, and it prohibits tracking, behavioural monitoring, and targeted advertising directed at children.
We do not knowingly collect personal data directly from children through our website, and our website is not directed at children.
Where our platform is deployed for school or institutional transport, the institution is the Data Fiduciary in respect of the students it transports. That institution is responsible for obtaining verifiable parental or guardian consent before a student is associated with a vehicle, route or pickup point, and for limiting access to that information to authorised staff and the child's own parent or guardian. We process such data only on the institution's documented instructions and for the safety purpose for which it was collected.
We do not use children's personal data for behavioural monitoring or advertising, and we do not build profiles of children. Where a parent or guardian wishes to exercise rights over a child's data, they should contact the institution in the first instance, and may also contact our Grievance Officer.
The same protections are applied to the personal data of a person with a disability who has a lawful guardian.
10. Where data is stored and transfers outside India
Our production databases and application infrastructure for Indian customers are hosted in India.
Where personal data is transferred outside India, we do so in accordance with section 16 of the DPDP Act, which permits transfer other than to territories restricted by notification of the Central Government. Where a sectoral law imposes a stricter localisation requirement, that stricter requirement applies.
Certain support and communications tools we use may process limited data outside India. We contract with those providers on terms requiring confidentiality and security appropriate to the data.
11. How long we keep personal data
We retain personal data only for as long as necessary for the purpose it was collected for, or for as long as a law requires, whichever is longer. When neither applies, we erase it or anonymise it.
- Account and customer records: for the term of the relationship and thereafter as required by company, tax and accounting law.
- Telematics and location history: for the retention period agreed in the customer's subscription plan, after which it is deleted or aggregated.
- Camera and event footage: retained for the period configured by the customer, typically short, unless preserved for an incident, claim or legal proceeding.
- Information and communication technology logs: retained within India for 180 days, as required by the CERT-In directions of 28 April 2022.
- Invoices and statutory financial records: retained for the period prescribed under Indian tax and company law.
12. Security
We implement reasonable security practices and procedures within the meaning of section 43A of the Information Technology Act, 2000 and Rule 8 of the SPDI Rules, proportionate to the nature of the data we hold.
These include encryption of data in transit, access control on a need-to-know basis, hashed credentials, network and application hardening, logging and monitoring, vendor due diligence, and periodic review. No system can be guaranteed absolutely secure, and we do not claim otherwise.
13. Personal data breaches
If a personal data breach occurs, we will notify the Data Protection Board of India and each affected Data Principal in the form and manner required under the DPDP Act and the rules made under it.
Separately, cyber security incidents falling within the CERT-In directions of 28 April 2022 are reported to CERT-In within six hours of being noticed.
14. Your rights as a Data Principal
Subject to the conditions in the DPDP Act, you have the following rights. To exercise any of them, write to support@movozen.ai from the email address associated with your account, or contact our Grievance Officer.
- Right to access information about processing: a summary of the personal data we hold about you, the processing carried out, and the identities of other Data Fiduciaries and Processors with whom it has been shared.
- Right to correction, completion, updating and erasure of your personal data, subject to any legal obligation requiring us to retain it.
- Right to grievance redressal: to have your complaint answered by us before approaching the Data Protection Board of India.
- Right to nominate: to nominate another individual to exercise your rights under the Act in the event of your death or incapacity.
- Right to withdraw consent, as described above.
15. Your duties as a Data Principal
The DPDP Act also places duties on Data Principals. You must not impersonate another person when providing data, must not suppress material information when providing data for a document or identifier, must not register a false or frivolous grievance, and must furnish only information that is verifiably authentic when exercising the right to correction or erasure.
16. Grievance redressal
If you have a complaint about how your personal data is handled, contact our Grievance Officer: Manil Tongya, Director, Movozen Private Limited, 94/16, Lotus Plaza, 3rd Floor, Madhyam Marg, Mansarovar, Jaipur, Rajasthan 302020, India. Email: manil@movozen.ai.
We acknowledge complaints within twenty-four hours and aim to resolve them within fifteen days of receipt.
If you are not satisfied with our response, or if we do not respond within the period above, you may complain to the Data Protection Board of India in the manner prescribed under the DPDP Act.
17. Driver and employee monitoring
Our platform can record vehicle location, driving behaviour and, where cabin-facing cameras are fitted, in-cab video. Where an employer deploys these features, the employer is responsible for informing its drivers, for obtaining any consent required, and for using the data only for the safety, compliance and operational purposes it has disclosed.
We make configuration options available so that monitoring can be limited to duty hours and to the vehicle rather than the individual. We do not independently use driver footage for any purpose other than providing and supporting the service, and complying with law.
19. Changes to this policy
We may update this policy. The version in force is the one published on this page, and the date it was last updated is shown at the top. Where a change materially affects how we process your personal data, we will bring it to your notice.
20. Governing law and jurisdiction
This policy is governed by the laws of India. Subject to the dispute resolution provisions of our Terms of Service, the courts at Jaipur, Rajasthan have jurisdiction.