Privacy Notice

About this notice

Gateway Distriparks Limited (“GDL”, “we”, “us” or “our”) respects your privacy. This notice explains what personal data we collect, why we use it, who may receive it, how long we keep it and how you can contact us or exercise your rights. Personal data means information about an identifiable individual.

This notice covers GDL’s websites, customer interactions, corporate functions and relevant Inland Container Depot, Container Freight Station, rail, road and warehousing operations. It covers digital personal data, including information collected on paper and subsequently digitised. It is relevant to customers and their representatives, drivers, transport partners, employees, applicants, contractors, suppliers, visitors and individual shareholders.

We act as a Data Fiduciary when we decide the purposes and means of processing. Where we act only on another organisation’s instructions, we assist that organisation with requests relating to its processing. Separate companies within a group may issue their own notices; this notice does not automatically cover them.

A notice supplied with a particular form, service, employment process or premises entry explains the data and purposes relevant to that activity. This general notice does not by itself request or record consent. Reading it, browsing our website or remaining silent does not constitute consent.

Applicable law and transition

This notice is designed for the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, alongside other applicable Indian law. Statutory rights and obligations apply according to their commencement and scope. We accept privacy questions and requests through the contact below during the transition and explain the provisions applicable to your request.

If another jurisdiction’s law applies to a particular activity, we will provide any additional information required for that activity. References to overseas law do not replace the grounds or safeguards required for processing subject to Indian law.

Personal data and purposes

The information we use depends on your interaction with us. We collect only the fields needed for the relevant activity. We may process the categories below for the stated purposes; the notice at collection specifies the fields and purposes applicable to your interaction.

Interaction Personal data where relevant Specified purpose
Inquiries and customer accounts Name, work contact details, role, organisation, account identifier and correspondence Answer an inquiry, create and administer an account, arrange a requested service and provide service updates.
Transport and terminal services Driver name, phone, licence details, vehicle association, authorisation, gate and delivery records; trip location where tracking is used Verify the person authorised to collect or deliver cargo, coordinate movement, record entry and delivery, and resolve service issues.
Employment and recruitment CV, qualifications, employment history and contact details; for employees, payroll, bank, tax, attendance and benefit information Assess a stated application, administer employment, pay remuneration and provide applicable benefits.
Suppliers and contractors Individual contact, authorised representative, sole proprietor, payment and relevant tax details Onboard and communicate with suppliers, authorise work, pay for services and maintain required records.
Premises access and safety Visitor identity and host, entry and exit records, images from CCTV where installed Manage access, protect people and premises and investigate specified safety or security incidents.
Website and portal use IP address, browser or device information, account and security logs; cookie identifiers where used Operate and secure digital services; provide optional analytics or personalisation only on the applicable ground.
Investor and privacy services Shareholder or nominee identifiers and contact details; request details and proportionate verification information Administer investor communications and entitlements, and resolve privacy requests and complaints.

Health information, dependant details, identity documents or biometric identifiers, if required for a specific process, need a separate explanation of the fields, necessity, purpose and applicable safeguards. We do not require such information simply because you visit our website. Please do not send passwords, OTPs or full payment credentials in an inquiry.

Sources of information

We may receive data directly from you; from your employer or an authorised representative arranging services; from recruitment, logistics or service partners; and from systems used during your interaction with us. Third-party receipt is not treated as your consent. We establish the applicable processing ground and provide notice where required. We do not assume that all information found online is exempt from data protection law.

Grounds for processing

For processing governed by DPDP, we rely on your consent or a specific use permitted by section 7 where its conditions are satisfied. The purpose of a transaction or a commercial preference is not, by itself, a separate legal ground.

Consent

Where consent is needed, we explain the specific data and purpose before asking you to agree. We use a clear affirmative choice, separate optional purposes from necessary service information, and do not require agreement to unrelated processing. We retain evidence of the notice and your choice. We provide the language options required by applicable law, including English or an Eighth Schedule language for DPDP notices and consent requests.

Certain legitimate uses

Where you voluntarily give us information for a specified request, and have not indicated that you do not agree to that use, we may use it for that request where section 7(a) applies. This does not automatically permit unrelated marketing or reuse of information received from someone else.

For employment and related purposes, we assess the use under section 7(i), including applicable employment administration, benefits and protection against loss or liability. Employment is not a blanket justification for unrelated monitoring or publicity. Optional uses require their own ground.

Where relevant, we may process information for a legally required disclosure to an Indian public authority, compliance with a qualifying judgment or order, or a qualifying medical emergency or disaster response. We assess the conditions of the relevant provision rather than treating all business administration as a legal obligation.

Your choices and withdrawal

You may withdraw consent for a particular purpose at any time by emailing dpo@gatewaydistriparks.com, calling the contact in section 14 or writing to us. Where you gave consent through an electronic control, we will provide a withdrawal route with comparable ease. Tell us which purpose you wish to stop; withdrawing marketing consent does not cancel an unrelated service request.

We will stop the relevant consent-based use and instruct processors acting for us to stop within a reasonable time, unless continued processing is required or authorised by applicable law. Withdrawal does not invalidate earlier lawful processing. We will explain if the requested service can no longer be provided without the data, and any information that must still be retained.

We will distinguish mandatory fields from optional fields at collection and explain the consequence of not providing mandatory information. You can decline optional marketing without losing the core service. To stop promotional messages, use an unsubscribe facility provided with the message or contact our DPO. Essential service communications may continue on the applicable ground.

Sharing and international processing

We may share relevant information with authorised GDL personnel and, where necessary for the specified purpose, logistics partners, transporters, customs brokers, shipping-line representatives, banks, payment providers, professional advisers, registrars and public authorities. The information shared depends on your transaction and the recipient’s role.

Service providers acting as our processors may support hosting, applications, payroll, communications or other defined services. We require appropriate contracts covering authorised use, confidentiality, security and assistance with requests and incidents. We remain responsible for processing undertaken on our behalf. Recipients that determine their own purposes are responsible for their processing under applicable law.

A restructuring or transfer of business may require limited disclosure to advisers or a prospective successor, subject to a valid ground and appropriate safeguards. This notice does not authorise unrestricted sharing with affiliates or third parties.

If an activity involves hosting, access or support outside India, we apply the restrictions and conditions imposed under applicable Indian law and assess the recipient’s safeguards. Contact the DPO for information about the locations and recipients relevant to your interaction. Any additional overseas privacy requirements are addressed where they apply.

Retention and erasure

We retain data for the period needed for its specified purpose and any applicable legal retention requirement. Relevant factors include completion of the transaction, employment or benefit administration, statutory records, limitation periods and a specific legal hold. Retention is assessed by record category; a general business preference is not a reason to retain every record indefinitely.

When the purpose has ended or consent is withdrawn, we assess what can be erased and what must be retained. Where operative, the retention requirements in Rules 6 and 8 apply, including the relevant one-year periods for data and logs. Records retained only for a legal requirement are restricted to that use. We erase records, or irreversibly anonymise them where permitted, when retention is no longer justified, and address copies held by processors.

Backups and archives are subject to controlled retention and restoration procedures. Data retained in them is protected and is not restored to ordinary use in disregard of an approved erasure decision. You may ask the DPO about the retention period and exceptions applicable to your records.

Security and personal data breaches

We apply reasonable technical and organisational safeguards appropriate to the data and processing. These include access restrictions, protection during storage and transmission, monitoring, recovery arrangements and controls over service providers. No system can eliminate every risk; please notify us promptly of a suspected compromise involving your data.

Where a personal data breach occurs, we investigate and take corrective action. When the applicable DPDP notification provisions are in force, we notify affected individuals and initially inform the Data Protection Board without delay, and provide the required detailed Board information within 72 hours unless an extension is allowed. Other applicable reporting obligations are addressed separately.

Cookies and similar technologies

Cookies and similar technologies can support website operation, remember choices, measure use or enable optional content. Where they process personal data, the purpose and processing ground must be established. Necessary security or session functions are distinguished from optional analytics and advertising.

Where optional tracking relies on consent, we request your choice before that tracking begins. We will make it possible to change that choice with comparable ease. Browser settings can also help you remove or restrict stored cookies, although some functions may be affected. Contact dpo@gatewaydistriparks.com for help with privacy choices.

Information about the cookies used for a particular website, including their purposes, providers and duration, is provided with the relevant cookie notice or preference choices. You can contact our DPO for assistance. Continuing to browse does not by itself authorise consent-based tracking.

Children and lawful guardians

Our business website and commercial services are not directed at children. If a particular activity involves a child under 18, such as a dependant benefit or an authorised visit, we provide the relevant information and obtain verifiable parental or lawful guardian consent where required. We apply applicable restrictions on detrimental processing, behavioural monitoring and targeted advertising directed at children, subject to lawful exemptions.

If a person with a disability has a lawful guardian and guardian consent is required, we verify the relevant authority. Disability alone does not mean that a person lacks capacity or must act through a guardian. If you believe a child’s information has been supplied inappropriately, contact our DPO.

Your rights

Subject to the commencement, scope and applicable exceptions of the DPDP framework, you may exercise the following rights in relation to your data. We also consider requests under other applicable law.

Right or choice What you can request
Access to information A summary of personal data and processing, and information about sharing as provided by applicable law.
Correction and completion Correction of inaccurate or misleading information, completion of incomplete data and updating of your records.
Erasure Deletion where retention is not necessary for the specified purpose or compliance with law.
Withdrawal Withdrawal of consent for a specified use, as explained in section 6.
Grievance redressal Review of a concern about our processing or handling of your rights.
Nomination Nomination of another individual to exercise applicable rights in the event of your death or incapacity, through the procedure communicated by the DPO.

We do not charge a fee for making a privacy request. Any limit or refusal will be explained with its applicable basis. DPDP does not create a general data portability right; any separate right available under another applicable law remains unaffected.

Making a request or complaint

Send your request to the DPO using the contact details below. Please include your name, the email or phone number used in your interaction with us, the relevant site or service, a reference number if available and the action you seek. Provide only information reasonably needed to locate the record and respond.

We use proportionate identity checks, preferably through details or authentication already associated with you. We ask for extra identification only where reasonably needed. An authorised representative or nominee may be asked to establish authority. We coordinate with relevant teams and processors, and explain any applicable retention exception or limit on the response.

We ordinarily acknowledge grievances within 3 working days, undertake initial review or assignment within 7 working days and aim to resolve routine grievances within 30 calendar days. Our maximum grievance response period is 90 days, subject to any shorter applicable requirement. These grievance targets do not postpone time-sensitive breach notifications or the requirement to act on withdrawal within a reasonable time.

If you remain dissatisfied after exhausting GDL’s grievance mechanism, you may approach the Data Protection Board of India through its officially notified procedure when the relevant provisions and complaint mechanism apply. Keep your correspondence and reference number. The DPO can help identify the official procedure but does not decide whether you may exercise a statutory right.

Read GDL’s Grievance Policy

Data protection contact

Atul Kumar Bansal Data Protection Officer
Gateway Distriparks Limited
4th Floor, Prius Platinum, Saket District Centre
New Delhi – 110017, India

Telephone: +91-11-40554400, Ext. 405

Business hours: Monday–Friday, 10:00 AM–6:00 PM IST

Email the DPO at dpo@gatewaydistriparks.com

Privacy Notice and contact information

Information you provide about others

Please provide accurate information and let us know if it needs updating. If you submit another person’s details, ensure you are authorised to do so and make this notice available to them where appropriate. This does not transfer our legal responsibilities to you or replace any notice, verification or consent that we must obtain.

Changes to this notice

We review this notice when our processing or applicable requirements change. We publish the revised version and effective date and highlight material changes appropriately. If a new purpose requires fresh consent, we obtain it before that use. An update to this notice alone does not expand an earlier consent.