PRIVACY POLICY

    Effective Date: 22.05.2026
    Last Updated: 22.05.2026
    Version: 1.0

    Transfreight Shipping Solutions Private Limited
    Divyashakti Complex, H-No: 7-1, 58, Flat No: 101, 1st Floor,
    Ameerpet, Hyderabad - 500016, Telangana, India
    Website: www.mytransfreight.com | Email: support@transfreight.in

    1. INTRODUCTION AND OVERVIEW

    Transfreight Shipping Solutions Private Limited (“Transfreight,” “we,” “us,” or “our”) is committed to protecting the privacy and security of the personal data entrusted to us by individuals and business entities who access our digital platform at www.mytransfreight.com (the “Platform”).

    In our capacity as a Digital Logistics Intermediary facilitating maritime freight procurement and global logistics services, this Privacy Policy outlines our standards for collecting, processing, storing, sharing, and safeguarding your information.

    This Privacy Policy applies strictly to:

    • Anyone who accesses, browses, or registers an active user account on the Platform.
    • Individuals whose personal identification or professional credentials are submitted during Know-Your-Customer (KYC) validation or freight booking workflows.
    • Directors, partners, trustees, proprietors, and authorized operational representatives of business entities that transact with or through Transfreight.
    • Any individual whose personal or business data we legitimately receive via third-party software integrations, automated supply chain feeds, or professional referrals.

    We reserve the right to modify, amend, or update this Privacy Policy at any time to reflect updates to our operational data practices, platform enhancements, or structural changes in global data protection laws. Any updated or amended version of this Policy will become legally effective immediately upon its publication on the Platform, as indicated by the “Last Updated” date. We encourage you to review this page periodically to remain informed about our data protection commitments.

    This Privacy Policy is executed and authored in the English language. In the event of any discrepancy, ambiguity, or conflict between the English text and any translated version provided for convenience, the English version shall prevail and control in all legal respects.

    This Policy is structured into two regulatory frameworks:

    • Part A – DPDP Act, 2023: Applies to all users in India and persons whose data is processed within India under the Digital Personal Data Protection Act, 2023.
    • Part B – GDPR (EU/EEA): Applies where we process personal data of individuals located in the European Union or European Economic Area, or where EU/EEA law otherwise applies.

    By using the Platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy, as well as our Terms of Service. If you do not agree, please discontinue use of the Platform immediately.

    2. KEY DEFINITIONS

    • Personal Data: Any information relating to an identified or identifiable natural person (‘Data Principal’ under DPDP Act; ‘Data Subject’ under GDPR).
    • Data Fiduciary / Data Controller: Transfreight, which determines the purpose and means of processing personal data.
    • Data Principal / Data Subject: The natural person whose personal data is being processed.
    • Data Processor: A third party that processes personal data on behalf of Transfreight.
    • Processing: Any operation performed on personal data, including collection, storage, use, disclosure, or deletion.
    • Consent: Refers to your voluntary, active, and uncoerced permission to let us handle your data for optional features. It represents a completely open choice.
    • KYC: Know Your Customer process for verifying user identity and business credentials.
    • Platform: The Transfreight digital platform accessible at www.mytransfreight.com and associated applications.
    • Sensitive Personal Data: Data requiring heightened protection, including financial data, government-issued identifiers (PAN, Aadhaar), and other categories defined by applicable law.

    PART A: DIGITAL PERSONAL DATA PROTECTION ACT, 2023 (INDIA)

    This Part A governs the processing of personal data of Indian residents and data processed within India, in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and rules framed thereunder.

    A.1 Identity and Contact Details of the Data Fiduciary

    Company NameTransfreight Shipping Solutions Private Limited
    Role under DPDP ActData Fiduciary
    Registered AddressDivyashakti Complex, H-No: 7-1, 58, Flat No: 101, 1st Floor, Ameerpet, Hyderabad - 500016, Telangana, India
    Websitewww.mytransfreight.com
    Grievance / Privacy Contactsupport@transfreight.in
    Grievance OfficerGovinda Thatikonda

    A.2 Categories of Personal Data Collected

    A.2.1 Identity and Business Registration Data (KYC)

    • Company Information: Legal name, year of establishment, CIN/LLP number, business type
    • Tax Identifiers: PAN, GSTIN, TAN
    • Individual Identifiers: Names and identity proofs of directors, partners, proprietors (including Aadhaar, PAN card copies)
    • Licensing Documents (if required): IEC, CHA License, MTO License
    • Address Proofs: Registered address, operational address, utility bills, lease agreements

    A.2.2 Contact and Communication Data

    • Email addresses (registered and operational)
    • Mobile numbers linked to OTP-based authentication
    • Designated point of contact name, designation, and direct contact details
    • WhatsApp communications via designated corporate channels

    A.2.3 Transactional and Operational Data

    • Booking requests, quote acceptances, and shipment instructions
    • Bill of Lading details, container numbers, and shipping documentation
    • Payment records (invoice data, bank transfer references — note that we do not store card data)
    • VGM declarations, cargo descriptions, and customs documentation

    A.2.4 Platform Usage and Technical Data

    • IP addresses, browser type, device identifiers, and operating system information
    • Log data including pages visited, timestamps, clickstream behaviour, and session duration
    • OTP authentication records
    • API integration logs

    A.3 Purposes and Legal Bases for Processing

    Under the DPDP Act, 2023, Transfreight processes personal data on the following grounds:

    Purpose of ProcessingLegal Basis under DPDP Act, 2023
    User registration and identity verification (KYC)Consent (Section 6); Legitimate use for compliance
    Processing booking requests and issuing quotesConsent and contractual necessity
    Facilitating freight coordination with LinersLegitimate use — performance of services
    Issuing invoices and collecting paymentsLegal obligation (GST Act, 2017; Income Tax Act, 1961)
    Fraud prevention and sanctions screeningLegitimate use; legal obligation
    Platform security, access control, and OTP authenticationLegitimate use
    Customer support and grievance redressalConsent and legitimate use
    Compliance with FEMA, Customs Act, DPDP Act obligationsLegal obligation
    Sending transactional communications and service updatesConsent
    Analytics and platform improvementLegitimate use (aggregated/anonymised wherever possible)

    We will not use personal data for purposes incompatible with those stated above without seeking fresh consent, except where required by law.

    A.4 Consent — Notice and Withdrawal

    A.4.1 Notice

    At the point of data collection, we provide a clear and accessible notice specifying:

    • The personal data being collected and the purpose of collection
    • The manner in which Data Principals may exercise their rights
    • How to file a complaint with the Data Protection Board of India

    This Privacy Policy, accessible at https://www.mytransfreight.com/privacy, constitutes our standing notice under Section 5 of the DPDP Act.

    A.4.2 Withdrawal of Consent

    Data Principals may withdraw consent at any time by writing to support@transfreight.in. Please note:

    • Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.
    • Where consent withdrawal relates to KYC data, we may be required to retain certain records under applicable law, and access to the Platform may be suspended or terminated.
    • We will process withdrawal requests within a reasonable time, not exceeding 30 days.

    A.5 Data Sharing and Disclosure

    Transfreight shares personal data only as necessary, with the following categories of recipients:

    RecipientPurpose / Basis of Sharing
    Shipping Liners and their agentsBooking confirmation, Bill of Lading issuance, vessel operations — contractual necessity
    Port terminals and ICDsContainer gate-in, customs verification — contractual necessity
    Third-party technology providersPlatform hosting, cloud storage, API integrations — data processing agreements in place
    Insurance intermediaries (if applicable)Facilitation of cargo insurance — user consent
    Payment processors / banksSettlement and wire transfer processing — legal requirement
    Legal and professional advisorsDispute resolution, arbitration — legitimate interest / legal obligation
    Sanctions screening providersTrade compliance and AML checks — legal obligation

    Transfreight does not sell personal data to third parties. All third-party Data Processors engaged by us are required to process data only as directed, maintain appropriate security measures, and adhere to contractual obligations aligned with the DPDP Act.

    A.6 Cross-Border Data Transfers

    In the course of facilitating international maritime freight, certain personal data (such as shipper/consignee details on Bills of Lading) is necessarily transmitted to Liners, ports, and logistics entities outside India. Such transfers occur:

    • As required for performance of the freight contract
    • In compliance with applicable export control and customs regulations
    • Subject to appropriate contractual safeguards with overseas parties

    We will comply with any rules framed by the Central Government regarding cross-border data transfers under Section 16 of the DPDP Act once notified.

    A.7 Data Retention

    Category of DataRetention Period
    KYC Documents (PAN, GST, Aadhaar, CIN etc.)As required under applicable law; minimum 5 years from last transaction
    Booking and shipment records7 years (aligned with GST/Income Tax audit requirements)
    Invoice and payment records7 years
    Communication logs (email, WhatsApp, platform)5 years, or as required for dispute resolution
    OTP and authentication logs2 years
    Platform usage logs12 months, or as required by law

    Post the applicable retention period, personal data will be securely deleted or anonymised unless a longer retention period is required by law or regulatory obligation.

    A.8 Rights of Data Principals

    Under the DPDP Act, 2023, Data Principals have the following rights, subject to applicable limitations and legal obligations:

    RightDescription
    Right to Access (Section 11)The right to obtain a summary of personal data being processed and the identities of all Data Fiduciaries and Processors with whom the data has been shared
    Right to Correction and Erasure (Section 12)The right to correct inaccurate or misleading personal data, complete incomplete data, and request erasure where no lawful retention obligation exists
    Right to Grievance Redressal (Section 13)The right to have grievances addressed by the Data Fiduciary, with recourse to the Data Protection Board if unresolved
    Right to Nominate (Section 14)The right to nominate an individual who may exercise rights on the Data Principal’s behalf in the event of incapacity or death

    To exercise any of the above rights, submit a written request to:

    • Email: support@transfreight.in
    • Grievance Officer: Govinda Thatikonda
    • Response Timeframe: We endeavour to respond within 30 days of receiving a verified request

    A.9 Grievance Redressal and Data Protection Board

    If you are not satisfied with our response to your grievance or rights request, you have the right to approach the Data Protection Board of India established under Section 18 of the DPDP Act. Details of the Data Protection Board will be published here once notified by the Government of India.

    A.10 Security Safeguards

    Transfreight implements appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These include:

    • Multi-factor authentication (OTP-based) for Platform access
    • Encryption of data in transit using industry-standard protocols (TLS/SSL)
    • Role-based access controls limiting internal data access to authorised personnel only
    • Regular security audits and vulnerability assessments
    • Contractual obligations on third-party processors to maintain equivalent security standards

    In the event of a personal data breach that is likely to result in harm to Data Principals, we will notify affected individuals and the Data Protection Board in accordance with the DPDP Act and applicable rules.

    A.11 Obligations of Data Principals

    In accordance with Section 15 of the DPDP Act, Data Principals are obligated to:

    • Not impersonate another person when providing personal data for a specified purpose
    • Not suppress material information or provide false particulars
    • Not register a false or frivolous grievance or complaint

    Submission of inaccurate or fraudulent data in the KYC process will result in immediate account suspension and may attract legal consequences under applicable Indian law, as outlined in our Terms of Service.

    A.12 Cookies and Tracking Technologies

    The Platform uses cookies and similar technologies to enable core functionality, maintain session state, and improve user experience. A detailed Cookie Policy is available at https://www.mytransfreight.com/cookies. By continuing to use the Platform after reviewing our Cookie Notice, you consent to our use of cookies in accordance with applicable law.

    A.13 Changes to This Policy (DPDP)

    We may update this Part A from time to time to reflect changes in law, regulatory requirements, or our data processing practices. Material changes will be communicated via the Platform or registered email at least 7 days before coming into effect. Continued use of the Platform after the effective date constitutes acceptance of the revised policy.


    PART B: GENERAL DATA PROTECTION REGULATION (GDPR) — EUROPEAN UNION

    This Part B applies to the processing of personal data of individuals located in the European Union (EU) or European Economic Area (EEA), or where the EU General Data Protection Regulation 2016/679 (“GDPR”) otherwise applies by virtue of the nature of the services or the location of the Data Subject.

    Where both Part A (DPDP Act) and Part B (GDPR) are applicable, the more protective provision shall apply in respect of the relevant individual’s data.

    B.1 Identity and Contact Details of the Data Controller and Representative

    Data ControllerTransfreight Shipping Solutions Private Limited
    Registered AddressDivyashakti Complex, H-No: 7-1, 58, Flat No: 606, 6th Floor, Ameerpet, Hyderabad - 500016, Telangana, India
    Emailsupport@transfreight.in
    EU/EEA Representative (if applicable)Govinda Thatikonda
    Data Protection Officer (if applicable)Govinda Thatikonda

    If Transfreight is required to appoint an EU Representative under Article 27 GDPR, the Representative’s contact details will be inserted above and updated on the Platform.

    B.2 Categories of Personal Data Processed

    When dealing with EU/EEA-based individuals (for example, consignees, agents, or business contacts located in the EU/EEA), we may process the following categories:

    CategoryExamples
    Identification DataFull name, role or position, business identity documents
    Contact DataEmail address, telephone number, business address
    Business and Financial DataCompany registration details, VAT/tax numbers, invoice and payment records
    Transactional DataBooking references, shipment details, Bill of Lading particulars, cargo descriptions
    Communication DataEmail correspondence, platform messages, WhatsApp interactions
    Technical DataIP address, browser type, device identifiers, platform log data

    We do not intentionally collect special categories of personal data (as defined in Article 9 GDPR) from EU/EEA Data Subjects. If such data is inadvertently provided, it will be deleted promptly.

    B.3 Lawful Bases for Processing

    Under Article 6 GDPR, Transfreight relies on the following lawful bases:

    Processing ActivityLawful Basis (Article 6 GDPR)
    Providing freight facilitation services (booking, documentation, coordination)Article 6(1)(b) — Performance of a contract or pre-contractual steps
    User registration and KYC verificationArticle 6(1)(b) — Contract; Article 6(1)(c) — Legal obligation
    Invoicing and payment processingArticle 6(1)(b) — Contract; Article 6(1)(c) — Legal obligation (VAT, accounting)
    Compliance with trade sanctions and export controlsArticle 6(1)(c) — Legal obligation
    Fraud prevention and platform securityArticle 6(1)(f) — Legitimate interests
    Sending transactional/service communicationsArticle 6(1)(b) — Contract
    Marketing communications (if any)Article 6(1)(a) — Consent (separate opt-in required)
    Analytics and platform improvement (aggregated)Article 6(1)(f) — Legitimate interests

    Where we rely on Article 6(1)(f) legitimate interests, we have conducted a balancing assessment confirming that our interests are not overridden by the interests, rights, or freedoms of the Data Subject. Details are available on request from support@transfreight.in.

    B.4 International Transfers of Personal Data

    Transfreight is headquartered in Hyderabad, Telangana, India, which is currently not the subject of an EU adequacy decision under Article 45 GDPR. Transfers of personal data from EU/EEA Data Subjects to Transfreight in India are made on the basis of:

    • Standard Contractual Clauses (SCCs) adopted by the European Commission, incorporated into our agreements with EU-based counterparties; and/or
    • Necessity for the performance of a contract to which the Data Subject is party or for the implementation of pre-contractual measures taken at the Data Subject’s request (Article 49(1)(b) GDPR), where applicable in the context of maritime freight services.

    In the course of providing freight services, personal data (e.g., shipper and consignee details on Bills of Lading) may be further transmitted to Liners, ports, or logistics entities located in third countries outside the EU/EEA/India. Such transfers are made as necessary for the performance of the freight contract. We will seek to ensure appropriate safeguards are in place to the extent practicable.

    For further details on the appropriate safeguards used, or to obtain a copy of the SCCs, please contact support@transfreight.in.

    B.5 Data Retention

    Personal data of EU/EEA Data Subjects is retained only for as long as necessary for the purposes set out in this Policy, and in any event:

    Data CategoryRetention Period
    KYC and identity documentsDuration of business relationship plus 5 years
    Contractual records (bookings, invoices, correspondence)10 years from date of transaction (in line with applicable commercial limitation periods)
    Accounting and financial records10 years
    Communication records5 years from last interaction
    Technical/log data12 months
    Marketing consent recordsUntil consent is withdrawn, plus 3 years thereafter

    At the end of the applicable retention period, personal data will be securely deleted or anonymised.

    B.6 Rights of Data Subjects under GDPR

    EU/EEA Data Subjects have the following rights under the GDPR, which may be exercised by contacting support@transfreight.in:

    RightDescription
    Right of Access (Article 15)The right to obtain confirmation of whether we process your personal data, and if so, to receive a copy, along with information about how it is used
    Right to Rectification (Article 16)The right to have inaccurate personal data corrected and incomplete data completed without undue delay
    Right to Erasure / ‘Right to be Forgotten’ (Article 17)The right to request deletion of personal data where it is no longer necessary, consent is withdrawn, or processing is unlawful, subject to our legal retention obligations
    Right to Restriction of Processing (Article 18)The right to request that we limit processing of your data in certain circumstances (e.g., while accuracy is contested)
    Right to Data Portability (Article 20)The right to receive personal data provided to us in a structured, commonly used, machine-readable format, and to transmit it to another controller, where processing is based on consent or contract and carried out by automated means
    Right to Object (Article 21)The right to object at any time to processing based on legitimate interests, including profiling; and to object to direct marketing at any time
    Rights related to Automated Decision-Making (Article 22)The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects
    Right to Withdraw Consent (Article 7(3))Where processing is based on consent, the right to withdraw consent at any time without affecting the lawfulness of prior processing

    We will respond to rights requests within one (1) calendar month of receipt. This period may be extended by a further two months where the request is complex or we receive a number of requests. We will notify you of any such extension within the initial one-month period.

    We will not charge a fee for rights requests unless requests are manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee or decline to act.

    B.7 Right to Lodge a Complaint with a Supervisory Authority

    If you are located in the EU/EEA and believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the relevant supervisory authority in the EU/EEA Member State where you are habitually resident, where you work, or where the alleged infringement took place.

    We encourage you to contact us first at support@transfreight.in so that we may address your concerns directly.

    B.8 Security Measures

    Transfreight implements appropriate technical and organisational security measures as required under Article 32 GDPR, taking into account the state of the art, the nature of the data, and the risks of processing. These include:

    • Encryption of personal data in transit (TLS/SSL) and at rest
    • Multi-factor authentication for Platform access
    • Role-based access controls and the principle of least privilege
    • Regular security assessments, penetration testing, and patch management
    • Contractual data processing agreements with all sub-processors
    • Internal data protection training for personnel handling EU/EEA personal data

    B.8.1 Personal Data Breaches

    In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of EU/EEA Data Subjects, Transfreight will:

    • Notify the relevant supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach (Article 33 GDPR)
    • Where the breach is likely to result in a high risk, notify affected Data Subjects without undue delay (Article 34 GDPR)
    • Maintain internal records of all data breaches in accordance with Article 33(5) GDPR

    B.9 Data Protection by Design and by Default

    Consistent with Article 25 GDPR, Transfreight integrates data protection principles into the design of our Platform and processing activities. We apply appropriate technical and organisational measures to ensure that, by default, only personal data necessary for each specific purpose of processing is collected, stored, and used.

    B.10 Data Processing Agreements and Sub-processors

    Where Transfreight engages third-party service providers to process EU/EEA personal data on our behalf, we enter into Data Processing Agreements (DPAs) compliant with Article 28 GDPR. A list of sub-processors can be made available on request to support@transfreight.in. We will provide prior written notice of any intended changes to our list of sub-processors and afford Data Subjects and controllers the opportunity to object.

    B.11 Automated Decision-Making and Profiling

    Transfreight does not currently carry out solely automated decision-making that produces legal or similarly significant effects for EU/EEA Data Subjects. Sanctions screening is conducted with human oversight. If this changes, we will update this Policy accordingly and ensure compliance with Article 22 GDPR.

    B.12 Changes to This Policy (GDPR)

    We may update this Part B to reflect changes in applicable law, regulatory guidance, or our processing activities. We will provide clear notice of any material changes, including the date of the update, via the Platform and by email to registered users. Where required by GDPR, we will seek fresh consent for any materially different processing.


    3. PROVISIONS APPLICABLE UNDER BOTH FRAMEWORKS

    3.1 Minors and Children

    The Platform is intended exclusively for business users and individuals who are at least 18 years of age (or the age of majority in their jurisdiction). We do not knowingly collect personal data from children. If we become aware that personal data of a minor has been submitted, we will delete it promptly.

    3.2 Third-Party Links and Services

    The Platform may contain links to third-party websites or integrate with third-party services (such as payment processors, insurance providers, or customs portals). This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services you access through our Platform.

    3.3 Marketing Communications

    We will only send marketing communications with your prior consent. You may opt out of marketing communications at any time by:

    • Clicking ‘Unsubscribe’ in any marketing email; or
    • Writing to support@transfreight.in with the subject line ‘Unsubscribe’.

    Transactional and service-related communications are necessary for the provision of our services and are not subject to marketing opt-out preferences.

    3.4 Contact and Exercising Rights

    General Privacy Queriessupport@transfreight.in
    Exercising Data Rights (DPDP / GDPR)support@transfreight.in
    Grievance Redressal (India)support@transfreight.in
    Legal Noticessupport@transfreight.in
    Postal AddressTransfreight Shipping Solutions Private Limited, Divyashakti Complex, H-No: 7-1, 58, Flat No: 101, 1st Floor, Ameerpet, Hyderabad - 500016, Telangana, India
    Response TimeframeWithin 30 days (DPDP) / within 1 month (GDPR), with right of extension in complex cases

    3.5 Governing Law

    This Privacy Policy and any disputes arising therefrom shall be governed by and construed in accordance with the laws of Hyderabad, Telangana, India. For EU/EEA residents, nothing in this clause limits any rights you may have under applicable EU data protection law, including the GDPR.


    ACKNOWLEDGEMENT

    By accessing or using the Transfreight Platform, you confirm that you have read, understood, and agree to this Privacy Policy in its entirety, including both Part A (DPDP Act, 2023) and Part B (GDPR), as applicable to your jurisdiction.

    For questions, please contact: support@transfreight.in


    — END OF PRIVACY POLICY —
    Transfreight Shipping Solutions Private Limited | www.mytransfreight.com | Hyderabad, Telangana, India

    Last Updated: 22 May 2026 — Transfreight Shipping Solutions Private Limited