Introduction
When you register and use drivecarclub.com (“this website”), you gain access to the enhanced
websites, services and other content from Berggruen Car Rentals Private Limited, India and its
affiliates (collectively known as “Berggruen”). When you register and use this website, you
provide personally identifiable information. This Privacy Policy (“Policy”) explains the
information practices that apply to your personally identifiable information. Berggruen has
implemented this privacy policy to explain to you how it uses and protects personally
identifiable information that may be collected from you through this website.
Applicability
By accessing and using this website, your use indicates your agreement to the terms of this
Policy. If you do not agree to the terms of this Policy, please do not use this website.
This Policy applies only to information that Berggruen collects about you as a user of this
website. This Policy does not apply to information about you, collected by Berggruen's
affiliated providers, or third party websites and offering linked to or otherwise accessible
from this website. The information collected or received by Berggruen's affiliated providers and
these third parties is subject to their own privacy policies.
Physical Security
2. Are visitors and housekeeping escorted by authorized personnel?.
Yes
3. What type of physical access control is used for entering the company campus?.
Biometric Access system with pin and finger scan
4. Are the physical security systems monitored 24/7?
The Security control room is manned 24X7 for monitoring the Physical security systems
5. Are photo IDs issued for employees?
Yes. Photo ID based access cards are issued to employees
6. Provide detail on third-party security audits (e.g. SSAE16 SOC2, ISO, etc.) you have had
performed. Include copies of these audits if possible.
- I. At what level are you certified?
- II. Date of first certification?
- III. Date of last certification?
- ISO 27001:2013 - Date of first certification: 30-May-2008, Date of last certification:
30-May-2017
- ISO 9001:2015 - Date of first certification: 26-Feb-2005, Date of last certification:
15-Mar-2017
- ISO 20000-1:2011 - Date of first certification: 11-Dec-2008, Date of last certification:
11-Dec-2017
Disaster Recovery
1. Emergency power capabilitiesinstalled?
Yes. UPS systems and Diesel Generators are installed for emergency power requirements
2. Do you have documented Emergency escalation plans?
Yes
Disaster Recovery
1. Emergency power capabilitiesinstalled?
Yes. UPS systems and Diesel Generators are installed for emergency power requirements
2. Do you have documented Emergency escalation plans?
Yes
Intrusion Protection
1. Are externally facing servers OS hardened?
Yes. OS hardening reviews are carried, and accordingly hardening process is initiated
2. Are externally facing web servers using Web Application Firewalls?
No (Not part of subscribe service)
3. Are your web applications subject to Web vulnerability assessments?
No (Not part of subscribe service)
4. Are firewalls used between external and internalservices?
Yes
5. Are you using OS vulnerability assessment tools such as Nessus?
No
6. Are you using Intrusion Detection appliances in your external environment?
Yes
7. Is Anti-virus installed on all servers/clients?
Anti-virus services not being provided for clients
8. Has the system undergone security analysis or penetration testing, either by TI personnel or third-party firm? If so, please provide review date and summary of findings.
No
Data Deletion Declaration
Cookies help us improve website functionality, remember
preferences and analyze traffic.
You may request the deletion of your personal data by contacting us at Corporate@drivecarclub.com. Please note that certain data may be retained for a limited period after your request to fulfill legal obligations or for legitimate business purposes.
We take the protection of your data seriously and will make all reasonable efforts to ensure its timely deletion in accordance with applicable laws and regulations.
Personnel and Training
1. Do you perform criminal background checks on employees?
Yes. Reference checks are carried out
2. Is contract labor used for administrative duties or application development?
No. Administrative duties are handled only by employees. No application development services are rendered to customers
3. Are your developers and Admins trained in security best practices? Code reviews held?
Yes. They are trained on the Security aspects
Policies
1. Do you have a documented patch policy forservers?
Yes
2. Do you have a documented customer data handling policy?
Yes. Information has varying degrees of sensitivity to the Reliance IDC. The level of security and the types of protective controls and measures used to secure information are depends on the sensitivity of information. Certain information needs an additional level of protection due to its criticality. In Reliance IDC one of the fundamental principles of information security is the "need to know” and “least privilege”. This principle holds that information should be disclosed only to those people who have a legitimate business need for the information. The data classification scheme has been designed to support the “need to know” policy so that information will be protected from unauthorized disclosure, use, modification, and deletion. Data classification is followed for handling customer data
3. Do you have a documented customer data classification policy?
Yes. Classification Levels are as below:
-
i. CONFIDENTIAL
CONFIDENTIAL information is that which is to be shared only with a very limited group and the unauthorized disclosure of which could be reasonably expected to cause damage to the business or its security.
-
ii. PRIVATE
While its unauthorized disclosure is against policy, it is not expected to seriously or adversely impact IDC its employees / customers, business partners can be classified as PRIVATE.
-
iii. INTERNAL
The information which is generated for/ by Reliance IDC employees and can be shared with Reliance IDC or Reliance ADAG group companies and can be shared or transferred to only identified external customers or any out of Reliance entity is classified as INTERNAL.
-
iv. PUBLIC
By definition, there is no such thing as unauthorized disclosure of this information and it may be freely disseminated without potential harm.
4. Do you have a documented customer data destruction policy?
-
For media like floppy and CDs are broken.
-
For Hard Disk and Tape storage media, the media is formatted before leaving the Reliance IDC.
-
For equipment like switches, routers, firewall etc. all the configuration files are deleted, and the device is set to factory default condition.
-
For decommissioned servers hard disk drives are formatted prior to sending the server to the stores.
-
Any PC leaving the IDC premises, the user of the PC formats the hard disk drive before handing over the PC to the Central IT.
5. What is the process for notification of customers in case of a security breach? How/When?
It is done via email by IDC Tech desk. An incident case is generated by IDC Tech desk and notification is sent to the Customer.
Application Access and Authorization
1. How do users access the application? Examples: Web access, console, command line interface
Not Applicable - Services not Managed by IDC
2. What authentication is used for client access to application? Are you compatible with Federated IDSAML 2.0 standards?
Complexity enabled Password
4. Does the application have an administrator or other privileged account that may have permissions greater than those of the typical user?
Yes. There is an Administrative/Super user Right
5. Do administrators use named credentials when accessing systems or use root/administrator?
Named credentials are used for accessing the systems
6. Are administrative activities logged and archived?
Yes
7. Is system access logged? If so, please note the current retention period of system access logs. As part of an investigation would TI be allowed to access these logs?
Administrative activities are logged but not archived. Logs will be overwritten once it reaches 20 MB size limit, Any Change on system will be carried out with service request raised by customer or by IDC.
8. Are any additional application and server logs archived? How long are they retained? As part of an investigation would TI be allowed to access these logs?
Incident logs are retained for 3 months for investigation purpose. In case of incidents, the logs may be shared with TI
9. Does the application lock an account after repeated failed login attempts?
System User Accounts will be locked after 3 invalid attempts & will be unlocked after 30 Minutes of time
Separation of Duties
1. Do any business processes supported by this application require “Separation of Duties (SoD)” or other safeguards to prevent a single user from abusing the system?
There is a "Segregation of duties" logic followed. Accesses to systems and applications are given only as per the role requirement
2. Have the roles and assignments been reviewed to ensure SoD conflicts do not exist?
Yes
Account Provisioning
1. Who provides new users with access to the system?
As customer & IDC both have Administrative privileges we both can create/provide.
2. Who provides existing users escalated privileges if needed?
As customer & IDC both have Administrative privileges we both can create/provide.
3. How are users removed from the system after termination or job change?
As customer & IDC both have Administrative privileges we both can create/provide.
4. Are there established approval and review processes for the above? If so, please describe
IDC create users only if we receive request from customer to do so.
Data Approval
1. Is someone responsible for reviewing and/or approving the output of this application? If so, please identify the responsible individual(s) and describe the review process
-
User access right review responsibility is assigned to the asset owners and they are instructed to review the current access rights verses valid access request forms every month.
-
Asset owners disable the unwanted or expired user accounts if account holders do not reply after expiry date intimation mail.
-
Whenever any employee resigns the job or gets transferred to other departments, the respective department head sends e-mail to all asset owners to disable his/her user accounts.
Customer App
Location Data
We collect and use Customer location data to provide location-based services such as creating trips based on your current location. Your location data is only used when the app is active and is not shared with third parties without your consent. You may choose to disable location services at any time through your device settings.
Profile Information
You can upload a profile picture as part of your user account. This image is stored securely within the app and is only used for personalizing your profile. We do not share your profile picture with third parties.
Usage of Cookies
A cookie is a small file which asks permission to be placed on your computer's hard drive. Once you agree, the file is added and the cookie helps analyze web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences.
We use traffic log cookies to identify which pages are being used. This helps us analyze data about webpage traffic and improve our website in order to tailor it to customer needs. We only use this information for statistical analysis purposes and then the data is removed from the system.
Overall, cookies help us provide you with a better website, by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.
Any information about you, other than the data you choose to share with us. You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of the website.
With Whom Information May Be Shared
Berggruen cannot ensure that all of your private communications and other personally identifiable information will never be disclosed in ways not otherwise described in this Privacy Policy.
By way of example (without limiting the foregoing), Berggruen may be required to disclose information to the government or third parties under certain circumstances, or third parties may unlawfully intercept or access transmissions or private communications.
Berggruen can (and you authorize us to) disclose any information about you to governmental and legal authorities as it, in its sole discretion, believes necessary or appropriate, in connection with an investigation of fraud, intellectual property infringements, or other activity that is illegal or may expose us to legal liability.
Therefore, although Berggruen uses industry standard practices to protect your privacy, Berggruen does not promise, and you should not expect, that your personally identifiable information or private communications would remain private. As a general proposition, Berggruen does not sell or rent any personally identifiable information about you to any third party.
In the event that ownership of Berggruen was to change as a result of a merger, acquisition or transfer to another company, your personally identifiable information may be transferred.
Berggruen will share much of our data, including personally identifiable information about you, with its subsidiaries and other websites so that you gain greater value addition from the services and information provided by them. To the extent that these entities are getting access to your information, they will treat it at least as protectively as they treat information they obtain from their other users.
USAGE OF SUBCONTRACTORS
Berggruen may use subcontractors to provide some products or services to you. Berggruen also may need to share your personal data with these subcontractors so that they can provide services to it. Berggruen's subcontractors are not allowed to use such personal data for any other purposes and Berggruen imposes confidentiality requirements on their services.
EXTERNAL LINKS
This site may contain links to other sites. Please note that Berggruen is not responsible for the privacy practices or contents of any other sites. Berggruen recommends that you read the privacy policies of such sites.
CHOICES YOU CAN MAKE ABOUT YOUR INFORMATION
Berggruen gives you a number of choices about the collection, use and distribution of your information. For example, you must affirmatively request to receive e-mail from Berggruen and/or business partners concerning information about special offers, promotions and new features, products and services. Every Berggruen e-mail will provide you with the opportunity to remove yourself from the e-mail list.
ACCURACY OF COLLECTED DATA
Berggruen will on its own initiative or at your request, free of charge, replenish, rectify or erase any incomplete, inaccurate or outdated personal data retained by it in connection with the operation of this site. Please consult the contact information posted below on this page, if any, or elsewhere on this site to determine how best to contact Berggruen to update and/or review your personal data and/or opt-out of receiving marketing communications from Berggruen.
SECURITY PROVIDED BY BERGGRUEN
Berggruen has established safeguards to help prevent unauthorized access to or misuse of your personally identifiable information, but cannot guarantee that your personally identifiable information will never be disclosed in a manner inconsistent with this Policy (for example, as a result of unauthorized acts by third parties that violate applicable law or the policies of the service and its affiliated providers). To protect your privacy and security, Berggruen uses passwords to help verify your identity before granting access or making corrections to any of your personally identifiable information.
CHANGE IN TERMS
Berggruen may update this Privacy Policy from time to time, and so you should review this Policy periodically. If there are significant changes to Berggruen's information practices, you will be provided with appropriate online notice. You may be provided other privacy-related information in connection with your use of offerings from Berggruen, as well as for special features and services not described in this Policy that may be introduced in the future.
Except as otherwise expressly discussed in this Privacy Policy, this document only addresses the use and disclosure of information that Berggruen collects from you.