Privacy Policy

Notice under the Digital Personal Data Protection Act, 2023 · version 2026-07-21

Tulsi Rams Travel (“we”, “us”) is the Data Fiduciary for the personal data you share with us. This notice explains what we collect, why, the lawful basis for it, and the rights you (the Data Principal) have under India’s DPDP Act, 2023.

1. Personal data we collect

Contact details are stored encrypted at rest. We collect only what is needed to plan and fulfil your trip (data minimisation).

2. Why we process it, and our lawful basis

We process your data on the basis of your consent, given by a clear affirmative action at the point of collection, for these purposes only:

We do not use your data for any new purpose without asking you again. You can withdraw consent at any time (see section 5); withdrawal is as easy as giving it, and does not affect processing already carried out.

3. Who we share it with

We share the minimum necessary data with the service providers (Data Processors) who fulfil your trip, under contracts that bind them to protect it and use it only on our instructions:

Cross-border transfer: some of these providers process data outside India to complete an international booking. We only transfer what the booking requires, and never to a country the Government of India has restricted under Section 16 of the Act. We do not sell your personal data.

4. How long we keep it

We keep your personal data only as long as needed for the purpose above or as required by law. Enquiry contact details are erased after a period of inactivity, and booking records are kept as long as tax/accounting law requires. When you withdraw consent or ask for erasure, we delete your data unless we are legally required to retain it.

5. Your rights

Under the DPDP Act you have the right to:

Submit a data-rights request

6. Children’s data

Our services are intended for adults (18+). We do not knowingly collect a child’s personal data without verifiable parental or guardian consent, and we do not carry out behavioural tracking or targeted advertising directed at children.

7. How we protect your data

We apply reasonable technical and organisational safeguards — encryption of contact data at rest, encrypted transport (HTTPS), access controls, rate limiting and audit logging. If a personal data breach occurs, we will notify the Data Protection Board of India and every affected person as required by the Act.

8. Grievance Officer

For any question or complaint about your personal data, contact our Grievance Officer:

If your grievance is not resolved to your satisfaction, you may approach the Data Protection Board of India.

9. Changes to this notice

We may update this notice; the version and date appear at the top. Material changes affecting how we use your data will be brought to your attention.

This notice is provided in English. On request we can provide it in a language listed in the Eighth Schedule to the Constitution of India.