Data Protection & Privacy Policy
- Collection and Use of Personal Data
We collect personal information (such as name, contact details, passport information, payment details, and travel preferences) solely for the purpose of processing bookings, providing travel-related services, and complying with legal/regulatory requirements. No data will be collected beyond what is necessary for service delivery.
- Data Storage and Security
All personal data shall be stored securely on company-controlled servers or trusted third-party platforms, with encryption and access controls in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and relevant provisions of the Digital Personal Data Protection Act, 2023.
- Data Sharing and Third Parties
Personal data will not be sold or shared with unauthorised parties. Data may be shared only with trusted service providers (such as airlines, hotels, or insurance companies) to fulfil travel services, and such parties shall be contractually obligated to ensure the same level of data protection.
- User Rights and Consent
Customers have the right to access, correct, and withdraw consent for processing their personal data at any time, subject to legal or contractual obligations. Explicit consent shall be obtained before collecting or processing any sensitive personal data (e.g., financial or health-related information).
- Retention and Deletion
Personal data shall be retained only for as long as necessary for the purpose for which it was collected, or as required under applicable laws. Upon completion of services or withdrawal of consent, data shall be deleted or anonymised securely.
- Indemnification Clause
The Customer agrees to indemnify, defend, and hold harmless Onze Voayagez HotelTravelia Pvt Ltd, its directors, employees, and agents from and against any claims, damages, liabilities, costs, or expenses (including legal fees) arising out of:
(a) Misuse or unauthorised disclosure of personal data provided by the Customer;
(b) Any false, inaccurate, or incomplete information submitted by the Customer;
(c) Customer’s violation of applicable data protection laws, regulations, or this Privacy Policy;
(d) Any third-party claims resulting from the Customer’s negligence, misconduct, or breach of obligations under this Policy.