Legal
Data Processing Agreement
Last updated: 20 August 2026
This Data Processing Agreement (“DPA”) applies where Dhruv Shah (India (contact by email at hello@railroute.in)), operating RailRoute (the “Processor”), processes personal data on behalf of an organisation (the “Controller”) that uses RailRoute — for example an employer, travel desk or partner arranging journeys for other people. It forms part of the agreement between the parties. Individuals using RailRoute for their own travel should read the Privacy Policy instead.
RailRoute is an independent service. It is not affiliated with, endorsed by, or operated by Indian Railways, IRCTC, or any Government of India entity. Train names and station codes are used for identification only.
RailRoute does not sell tickets and never takes a payment. Fares are estimates and seat availability changes continuously; the exact fare and the actual booking are confirmed on IRCTC.
1. Roles
The Controller determines the purposes and means of processing and is responsible for the lawfulness of the instructions it gives. The Processor processes personal data only on the Controller’s documented instructions, which include the use of the Service as configured by the Controller, and as otherwise required by applicable law.
2. Subject matter, nature and duration
Subject matter: provision of journey-search results across railway timetable and seat-availability information.
Nature and purpose: receiving search parameters, querying timetable and availability information, computing journey options, returning results, and operating, securing and supporting the Service.
Duration: for as long as the Controller uses the Service, plus any period required to comply with law.
3. Categories of data subjects and personal data
Data subjects: the Controller’s personnel and the travellers on whose behalf searches are run.
Categories of personal data: search parameters (origin and destination stations, travel dates, quota and class); technical data (IP address, browser and device information, timestamps); and diagnostic logs.
Data not processed: the Service takes no payment and stores no payment instrument data, and does not require passenger names, ages, identity document numbers or PNRs. Special categories of personal data must not be submitted to the Service.
4. Processor obligations
- Process personal data only on documented instructions from the Controller.
- Ensure that personnel authorised to process personal data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (clause 5).
- Assist the Controller, so far as reasonably possible, with data subject requests and security obligations.
- Make available information reasonably necessary to demonstrate compliance with this DPA.
5. Security measures
- Encryption of data in transit over public networks.
- Access to production systems restricted on a least-privilege basis and protected by strong authentication.
- All access to external data sources performed server side; credentials are never exposed to the browser.
- Logging and monitoring of access to production systems.
- Retention limits, with logs deleted or anonymised once they are no longer needed.
- Periodic review of dependencies and of the measures in this clause.
6. Sub-processors
The Controller gives general authorisation for the Processor to engage sub-processors. The Processor uses sub-processors in the following categories:
- cloud hosting and infrastructure providers;
- third-party providers of railway timetable and seat-availability information;
- web analytics, session-recording and error-monitoring providers;
- email and communications providers.
A current list of the specific sub-processors engaged is available on request from hello@railroute.in. The Processor imposes data protection obligations on each sub-processor no less protective than those in this DPA and remains liable for their performance. The Controller will be notified of an intended addition or replacement of a sub-processor and may object on reasonable data protection grounds.
7. International transfers
Personal data may be processed or stored outside the country in which it was collected, including where hosting or sub-processor infrastructure is located abroad. Where that occurs, the Processor will ensure an appropriate transfer mechanism recognised under applicable law is in place.
8. Data subject requests
If the Processor receives a request from a data subject relating to personal data processed on behalf of the Controller, it will not respond directly other than to confirm receipt, and will forward the request to the Controller without undue delay and assist with responding to it.
9. Personal data breach
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA, with the information reasonably available to it, and will cooperate with the Controller in investigating and mitigating the breach.
10. Deletion and return
On termination of the Service, and at the Controller’s choice, the Processor will delete or return personal data processed on the Controller’s behalf, and delete existing copies, unless applicable law requires storage for longer.
11. Audit
The Processor will, on reasonable written notice and no more than once in any twelve-month period (unless required by a supervisory authority), provide information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits conducted in a manner that does not compromise the security or confidentiality of other customers’ data.
12. Liability and governing law
The liability provisions of the Terms of Service apply to this DPA. This DPA is governed by the laws of India, with the courts at India having exclusive jurisdiction. In the event of a conflict between this DPA and the Terms of Service in respect of the processing of personal data, this DPA prevails.
Questions? See the contact details.