Overview & Scope
This Privacy Policy applies to all individuals, corporate clients, travel coordinators, event organizers, guests, and website visitors who interact with Aura Leaf Hospitalities Pvt Ltd across all digital platforms, offline booking desks, and properties managed or contracted by us.
We adhere strictly to applicable Indian data privacy regulations, including the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the provisions of the Digital Personal Data Protection Act (DPDP Act), 2023.
Our Core Privacy Promise
We do not sell, rent, monetize, or trade your personal or corporate travel data to third-party advertisers or brokers. Your information is used strictly to deliver and enhance our hospitality and travel management services.
Information We Collect
To provide seamless corporate hospitality and travel coordination, we may collect the following categories of information:
| Category | Types of Data Collected |
|---|---|
| Personal Identification | Full name, government-issued photo identity proof (Aadhaar, Passport, Voter ID, Driver’s License required for hotel check-in under Indian hospitality regulations), nationality, gender, and date of birth. |
| Corporate & Contact Details | Company name, employee designation, official email address, telephone/mobile number, company GSTIN, corporate billing address, and employee ID. |
| Travel & Stay Information | Check-in/check-out dates, flight/train itineraries, room preferences, dietary requirements, accompanying guest details, event logistics, and MICE venue requirements. |
| Financial & Billing Data | Corporate purchase orders (PO), payment gateway transaction references, bank transfer records, credit billing authorization, and invoice histories. Note: We do not store full credit/debit card PINs or CVV numbers on our servers. |
| Technical & Usage Data | IP address, browser type, operating system, device identifiers, referring URLs, pages viewed, and session duration captured via cookies and standard server logs. |
How We Collect Your Information
We collect information through multiple touchpoints:
- Direct Submissions: When you fill out quote requests, contact forms, RFP inquiries, or subscribe to corporate travel programs on our website.
- Corporate Agreements & Offline Desks: When authorized corporate travel desks, HR managers, or procurement teams provide employee lists and travel itineraries for booking.
- Check-in Registration: When guests present identification and sign registration cards at The Leaf Studio Hospitalities or our verified partner properties.
- Communications: When you communicate with our concierge or corporate support team via telephone, WhatsApp (+91 98182 61912), or email.
- Automated Technologies: When you navigate our digital portal, automated cookies and analytics scripts collect basic telemetry data.
How We Use Your Information
We process your data for the following lawful business purposes:
- Reservation & Service Execution: To confirm hotel stays, coordinate MICE events, arrange business travel logistics, and issue stay vouchers.
- Corporate Billing & Taxation: To generate GST-compliant tax invoices, manage enterprise credit cycles, and maintain accurate financial records as required by Indian accounting laws.
- Rapid Customer Support: To respond to corporate inquiries and emergency travel requests within our committed 2-hour response window.
- Guest Safety & Legal Compliance: To comply with mandatory local police reporting (Form C for foreign nationals, local guest registries) and safety protocols.
- Service Improvement: To analyze operational performance, refine our hospitality packages, and maintain high standards across partner properties.
- Service Communications: To send booking confirmations, itinerary updates, flight status alerts, and critical travel advisories.
Sharing & Disclosure of Information
We disclose personal and corporate data only on a strict need-to-know basis under binding confidentiality and data protection obligations:
- Hotel Partners & Service Providers: Verified hotel chains, serviced apartments, airlines, conference halls, and corporate fleet operators specifically involved in executing your itinerary.
- Corporate Employers / Clients: Itemized booking summaries, attendance logs, and corporate spend reports provided directly to authorized corporate travel administrators.
- Payment Processors & Banks: Secure payment gateway partners for processing authorized corporate transactions and bank reconciliations.
- Legal & Regulatory Authorities: Law enforcement agencies, tourism departments, tax authorities, or judicial bodies when compelled by statutory notices, court orders, or applicable Indian laws.
Data Security & Storage
Aura Leaf Hospitalities maintains rigorous administrative, physical, and technical controls to safeguard your data against accidental loss, unauthorized access, destruction, or misuse:
- Encryption: Industry-standard HTTPS / TLS 1.3 encryption across our digital channels for all data in transit.
- Access Control: Role-based access restrictions ensuring only authorized personnel with verified credentials can access booking and financial records.
- Secure Cloud Infrastructure: Data is stored in secure, hardened environments with automated backup protocols and firewall defenses.
- Employee Training: Mandatory data confidentiality protocols for all hospitality staff and travel concierges.
Data Retention Policy
We retain personal data only for as long as necessary to fulfill the specific purposes outlined in this policy, satisfy contractual commitments with corporate clients, resolve disputes, and comply with mandatory statutory retention periods under Indian tax, corporate, and hospitality regulations (typically up to 7-8 years for statutory invoicing and accounting records).
Once data is no longer required, it is securely deleted, purged, or irreversibly anonymized in accordance with our data destruction protocols.
Your Legal Rights & Choices
Under applicable Indian privacy legislation (including the DPDP Act 2023), you possess specific rights regarding your personal data:
- Right to Access & Summary: Request a summary of the personal data held about you and the processing activities undertaken.
- Right to Correction & Completion: Request the correction of inaccurate, misleading, or incomplete personal data.
- Right to Erasure: Request the deletion of your personal data where retention is no longer mandated by law or contractual obligations.
- Right to Withdraw Consent: Withdraw previously given consent for non-essential communications at any time.
- Right to Grievance Redressal: Avail of an effective grievance redressal mechanism regarding any privacy concern.
To exercise any of these rights, please email our Grievance Desk at info@auraleafhospitalities.com. We will process and respond to verified requests within 30 business days.
Third-Party Websites & Services
Our website and communications may contain links to third-party services, including Google Maps, partner hotel websites, airline booking engines, or WhatsApp. We are not responsible for the privacy practices, cookie policies, or content of external websites. We encourage you to review their respective privacy policies upon navigating away from our site.
Updates to this Privacy Policy
We may modify or update this Privacy Policy from time to time to reflect changes in our operational procedures, service offerings, or legal frameworks. Any revisions will be published on this page with an updated “Last Updated” timestamp. We recommend reviewing this page periodically. Continued engagement with our services after modifications signifies acceptance of the updated policy.
Grievance Redressal & Contact Information
In compliance with the Information Technology Act, 2000 and DPDP Act 2023, if you have any questions, concerns, or grievances regarding our privacy practices or data handling, please contact our designated Grievance Officer:
Company Name
Aura Leaf Hospitalities Pvt Ltd
Registered Office
Plot No. 1044, Islampur Village, Sector 38, Gurugram, Haryana – 122002
Privacy Email
Helpline & Support
Grievance Response Commitment
All formal privacy grievances are acknowledged within 24 business hours and thoroughly investigated and resolved within 15 to 30 business days from the date of receipt.