Data processing overview
For most of the personal data flowing through Iyerxpress, the operating company is the controller and we are the processor. This page describes how the processor relationship works in practice - the roles, the flows, the subprocessors, and the ways to review it.
Who is the controller
The operating company that runs the fleet - the Customer - is the controller for operational, rider, and recipient data flowing through the platform. The Customer sets the purpose of processing (running the delivery operation) and decides which orders, riders, and clients are onboarded.
Who is the processor
Iyerxpress is the processor. We process personal data only on documented instructions from the Customer, as set out in the commercial agreement and the platform documentation.
Categories of data
- Operations users - identity, contact details, role, and audit logs.
- Riders - identity, live position during active shifts, shift and performance history.
- Recipients - name, phone number, delivery address, and delivery instructions.
Purpose of processing
- Assigning orders to riders and continuously optimising their routes.
- Predicting realistic delivery windows and adjusting them as conditions change.
- Reallocating orders between riders to keep windows honest.
- Sending status notifications and providing live tracking to recipients.
- Producing operational analytics for the Customer.
Subprocessors
We use a small number of subprocessors to operate parts of the platform. Categories currently include:
- Infrastructure hosting.
- Transactional email delivery.
- SMS and WhatsApp delivery.
- Application monitoring and error tracking.
The current list of named subprocessors is available on request through the contact page. We notify Customers before adding a subprocessor in a way that materially changes where personal data is processed.
International transfers
Personal data is primarily processed in India. Where a subprocessor operates outside India, we use contractual safeguards and encryption in transit and at rest to protect the transfer, and we describe the transfer to the Customer on request.
Security
Full details are on the security page. In summary - TLS 1.2 or higher end-to-end, AES-256 at rest, role-based access, least-privilege internal access, and audit logging on reassignment and access-elevation events.
Assisting the Customer
We assist the Customer with rights requests it receives from data subjects - typically recipients - by providing the operational data we hold about them, correcting it, or removing it once it is no longer needed for a legitimate operational or statutory purpose.
Notification of a personal data incident
If we become aware of a personal data incident affecting a Customer's operational data, we notify the Customer without undue delay and share what we know and what we are doing about it. Details of our incident response are documented in the security page.
End of processing
On exit from the platform, operational data is exportable in standard formats for the window described in the security page, then removed - except where a statutory obligation requires retention, which is called out explicitly.
Formal data-processing addendum
For Customers on the Growth and Enterprise plans, a formal data-processing addendum is available and forms part of the commercial agreement. Ask through the contact page.