Legal

GDPR & data protection

Our network runs in India, but agencies and brands headquartered in the EU and UK still need clear answers on roles, rights and transfers. This page gives them.

This statement supplements our Privacy Policy for clients subject to the EU General Data Protection Regulation, the UK GDPR, or India's Digital Personal Data Protection Act. It describes the roles we take, the rights individuals can exercise, and how to request a data processing agreement.
01

Controller and processor roles

  • For our own business contacts, advertiser accounts and website visitors, DP Ad Spaces is the controller.
  • For personal data contained inside creatives or audience lists you supply, you are the controller and we act as processor on your documented instructions.
  • For fleet-partner and driver data, DP Ad Spaces is the controller and shares limited reporting with the fleet operator as a separate controller.
02

Data minimisation by design

The in-cab format is inherently low-risk: screens broadcast, they do not observe. There are no cameras, microphones, audience sensors or device-identifier capture in our players. The only continuous data streams are device health telemetry and vehicle GPS, both tied to a vehicle rather than to a person. That keeps the personal-data footprint of a campaign close to zero.

03

Exercising data-subject rights

Individuals may request any of the following, free of charge:

  • Access — a copy of the personal data we hold about you.
  • Rectification — correction of inaccurate or incomplete records.
  • Erasure — deletion where we no longer need the data or consent is withdrawn.
  • Restriction and objection — pausing or objecting to specific processing.
  • Portability — a machine-readable export of data you provided to us.

Send requests to dpads.india@gmail.com with enough detail to identify your records. We acknowledge within 5 business days and respond within 30 days. Where a request relates to data we process on behalf of a client, we forward it to that client and assist them in responding.

04

International transfers

Our platform and media storage are hosted with cloud providers that operate globally. Where personal data of EU or UK individuals is transferred outside those regions, we rely on the European Commission's Standard Contractual Clauses together with the UK Addendum, supported by encryption in transit and access controls scoped per tenant.

05

Sub-processors

We use a small set of sub-processors for hosting, database, media storage, authentication, email delivery and payments. The current list, with entity names and processing locations, is provided on request and attached to every signed DPA. We give clients advance notice of changes so they can object.

06

Requesting a DPA

Agencies and brands that need a signed data processing agreement, security questionnaire response, or records-of-processing summary can request one from dpads.india@gmail.com. Include your legal entity, the campaigns in scope, and any specific clauses your procurement team requires.

07

Incident response

We maintain a documented incident procedure covering detection, containment, assessment and notification. Where we act as processor and become aware of a personal-data breach, we notify the affected controller without undue delay and provide the information they need to meet their own 72-hour regulatory obligations.