Privacy Policy for Siddhis Tours

Effective Date: Jan 13, 2018

At Siddhi’s Tours (referred to as “we,” “us,” or “our”), we are deeply committed to protecting your privacy and personal data. This Privacy Policy outlines how we collect, use, store, disclose, and protect your personal data when you use our website https://siddhistours.com/ (the “Website”), book tours with us, or otherwise interact with our services.

We operate in India and strictly adhere to the principles and requirements of the Digital Personal Data Protection Act, 2023 (DPDP Act).

1. Definitions

To help you understand this policy, here are some key terms as defined by the DPDP Act:

  • “Personal Data”: Any data about an individual who is identifiable by or in relation to such data.
  • “Data Principal”: The individual to whom the personal data relates (i.e., you, our customer or website visitor).
  • “Data Fiduciary”: The entity that determines the purpose and means of processing personal data (i.e., Siddhis Tours).
  • “Processing”: Any operation performed on personal data, such as collection, storage, use, or disclosure.
  • “Consent”: Your express, clear, affirmative, and unambiguous indication of your wishes, for the processing of your personal data for a specified purpose, given freely.

2. Personal Data We Collect

When you interact with Siddhis Tours, we may collect various types of personal data necessary to provide and improve our services. This includes:

  • Contact Information: Your name, email address, postal address, and phone number.
  • Booking Information: Travel dates, destination preferences, passport details (if required for international travel), visa information, dietary restrictions, special requests, and emergency contact details.
  • Payment Information: Billing address and payment card details (securely processed by third-party payment gateways; we do not store full card numbers).
  • Demographic Data: Your age, gender, and nationality (if relevant for visa processing or specific tour requirements).
  • Technical Data: Your IP address, browser type, operating system, device information, Browse patterns, and usage data collected through cookies and similar technologies when you visit our Website.
  • Communication Data: Records of your correspondence with us (e.g., emails, chat logs, phone calls).
  • Feedback Data: Information you provide when participating in surveys or giving us feedback.

3. How We Collect Your Personal Data

We gather your personal data through several channels:

  • Directly from You: When you complete booking forms, create an account, subscribe to our newsletter, contact us via email or phone, or participate in surveys.
  • Automatically: Through the use of cookies, web beacons, and other tracking technologies as you navigate our Website.
  • From Third Parties: In limited cases, such as from travel agents or partners through whom you book our tours, or from publicly available sources (e.g., social media if you interact with our profiles).

4. Purpose of Processing Your Personal Data

We process your personal data for specific and legitimate purposes to deliver our services and enhance your experience:

  • To Fulfill Your Bookings: To process your tour reservations, confirm arrangements with our travel partners (hotels, airlines, local guides, transport), and manage your itinerary.
  • To Provide Customer Support: To respond to your inquiries, offer assistance, and resolve any issues.
  • To Process Payments: To securely process your tour and service payments.
  • To Improve Our Services: To understand your preferences, analyze website usage, perform data analytics, and enhance our tour offerings, website functionality, and overall customer experience.
  • For Marketing and Communications: To send you updates, newsletters, promotional offers, and information about new tours or services that may interest you, based on your consent. You can easily opt-out at any time.
  • For Legal and Regulatory Compliance: To comply with applicable Indian laws, regulations (including the DPDP Act), legal processes, and government requests, such as identity verification.
  • For Security and Fraud Prevention: To protect our website, systems, and customers from fraud, unauthorized access, and other security threats.
  • To Personalise Your Experience: To tailor our website content and tour recommendations based on your past interactions and preferences.

5. Basis for Processing (Consent and Legitimate Uses)

We process your personal data only when we have a lawful basis to do so under the DPDP Act:

  • Consent: We will seek your explicit, clear, and unambiguous consent for specific purposes, such as sending marketing communications or sharing certain sensitive personal data (e.g., dietary restrictions) with partners. You have the right to withdraw your consent at any time, subject to legal requirements.
  • Legitimate Uses: Your consent is deemed to have been given where processing is necessary for:
    • Performance of a Contract: To fulfill our obligations under a contract with you (e.g., processing your tour booking).
    • Compliance with Legal Obligation: To meet our legal duties (e.g., providing data to law enforcement if legally mandated).
    • Responding to Emergencies: In situations of medical emergency or threat to the safety of any individual.

6. Disclosure and Sharing of Your Personal Data

We may share your personal data with the following types of recipients, strictly on a need-to-know basis and in compliance with the DPDP Act:

  • Travel Partners: Hotels, airlines, transport providers, local tour operators, and guides, but only the essential information needed to fulfill your booking.
  • Payment Processors: Secure third-party payment gateways for processing your transactions.
  • Service Providers: Companies providing services on our behalf, such as IT support, website hosting, marketing, analytics, and customer support. These providers are bound by confidentiality agreements and strict data protection obligations.
  • Legal & Regulatory Authorities: When required by law, court order, or to comply with a legal obligation, including government bodies and law enforcement agencies.
  • Business Transfers: In the event of a merger, acquisition, or sale of our assets, your personal data may be transferred to the acquiring entity.
  • With Your Explicit Consent: We may share your data with other third parties if we have obtained your specific consent.

7. Data Retention

We will retain your personal data only for as long as it is necessary to fulfill the purposes for which it was collected, including for satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure, the purposes for processing, and applicable legal obligations.

8. Security Measures

We implement robust technical and organisational measures to protect your personal data from unauthorized access, alteration, disclosure, loss, or destruction. Our security measures include:

  • Encryption of data in transit and at rest where appropriate.
  • Strict access controls and authentication procedures for our systems.
  • Regular security audits and vulnerability assessments.
  • Ongoing employee training on data protection and privacy best practices.
  • Secure processing of payment information through PCI DSS compliant third-party gateways.

While we strive to protect your personal data diligently, please be aware that no method of transmission over the internet or electronic storage is 100% secure. Therefore, we cannot guarantee absolute security.

9. Your Rights as a Data Principal (under DPDP Act)

As a Data Principal, you have the following rights concerning your personal data processed by Siddhis Tours:

  • Right to Access and Information: You have the right to obtain confirmation as to whether or not your personal data is being processed, and where that is the case, access to the personal data and certain information about its processing.
  • Right to Correction/Erasure: You have the right to request the correction of inaccurate or incomplete personal data. You may also have the right to request the erasure of your personal data under certain circumstances (e.g., when the data is no longer necessary for the purposes for which it was collected).
  • Right to Grievance Redressal: If you have concerns about the processing of your personal data, you have the right to register a grievance with our Data Protection Officer/Grievance Officer.
  • Right to Nominate: You have the right to nominate another individual to exercise your rights in the event of your death or incapacity.

To exercise any of these rights, please contact our Data Protection Officer/Grievance Officer using the details provided below. We will respond to your request in accordance with the DPDP Act and other applicable laws.

10. Children’s Privacy

Our services are not intended for children under the age of 18 without parental or guardian consent. We do not knowingly collect personal data from children under 18. If we become aware that we have inadvertently collected personal data from a child under 18 without appropriate consent, we will take steps to delete such information as soon as possible.

11. Links to Third-Party Websites

Our Website may contain links to third-party websites for your convenience and information. We are not responsible for the privacy practices or the content of these third-party websites. We encourage you to review the privacy policies of any third-party sites you visit.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of any material changes by posting the updated policy on our Website and updating the “Effective Date” at the top of this policy. We encourage you to review this Privacy Policy periodically.