Data protection
DPDP data handling readiness.
Last updated: July 4, 2026
1. Role and contact
PRIYASANCHARI acts as the business deciding why and how client personal data is processed for travel planning and service records. For privacy requests, contact info@priyasanchari.in.
2. Data categories
- Identity and contact data: name, email, phone, country, billing details, and emergency contact.
- Travel context: destination, dates, comfort level, accommodation preferences, safety concerns, budget, and route needs.
- Travel-sensitive data: health/access notes, dietary restrictions, mobility needs, insurance contact, harassment concerns, and emergency context when voluntarily provided and necessary for service planning.
- Operational records: invoices, payment references, correspondence, service notes, chat records where applicable, consent logs, and dispute records.
3. Purposes
Priyasanchari processes personal data for enquiry response, service scoping, route planning, safety review, client support, invoice and GST records, fraud/spam prevention, legal compliance, dispute handling, and emergency contact where reasonably needed for safety.
4. Consent and lawful use
Where consent is used, requests should be clear, specific, informed, and limited to the data needed for the stated purpose. Clients may withdraw consent for optional processing, but withdrawal may limit or end services that require the information to proceed. Some records may still be retained where required for law, tax, accounting, safety, or dispute reasons.
5. Minimisation and sensitive travel details
Priyasanchari should collect only the information needed for the agreed service. Clients should not send passport scans, visa scans, medical reports, identity documents, payment card data, or unrelated personal documents unless specifically requested through an appropriate channel.
6. Processors and tools
Personal data may be handled through ordinary business tools such as hosting, email, AI chat providers, analytics, payment systems, document storage, accounting, and security tools. Processor access should be limited to what is needed for the service or business function.
7. Security safeguards
- Use access controls for business email, hosting, admin panels, documents, and payment records.
- Use strong authentication where supported and restrict admin access to authorised people.
- Limit copying of passport, medical, financial, and identity material.
- Keep operational logs and incident notes where needed for security review and legal compliance.
- Include reasonable data protection expectations in processor or vendor arrangements where applicable.
8. Retention and deletion
Enquiry and service records should be retained only as long as needed for service continuity, accounting, GST/tax records, legal compliance, dispute handling, safety context, and legitimate business records. Non-essential records should be deleted or anonymised when no longer needed.
9. Rights and grievances
Clients may request access, correction, completion, update, deletion, consent withdrawal, grievance review, or nomination support where applicable. Requests should be sent to info@priyasanchari.in with enough detail to identify the record. Priyasanchari may ask for verification before acting on a request.
10. Breach response
If Priyasanchari becomes aware of a personal data breach, it should investigate, contain, document, notify affected clients where required, notify authorities where required, preserve relevant logs, and take steps to reduce recurrence.