This Privacy Policy explains how Brandesia LLP (“Brandesia”, “we”, “us”) collects, uses, discloses and protects information in connection with the Travel CRM platform at travelcrm.brandesia.com (the “Platform”). It should be read together with our Terms & Conditions. We are committed to handling personal data in accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.
1. Roles
For information about our own subscribers and website visitors, Brandesia acts as a data fiduciary/controller. For personal data that a subscriber (a travel business) enters about its own customers into the Platform, Brandesia acts as a data processor on that subscriber’s behalf, and the subscriber remains responsible for obtaining the necessary consents from those individuals.
2. Information We Collect
- Account & business information: name, company name, GSTIN, email, phone, address, and login credentials.
- Subscriber content: data you enter to run your business, which may include your customers’ names, contact details, travel details, and identity/financial documents (e.g. passport, PAN, Aadhaar) that you choose to store.
- Payment information: transactions are processed by our payment processor (Razorpay). We do not store full card numbers; we retain limited transaction references for accounting and support.
- Usage & technical data: log data, device/browser information, IP address and actions taken on the Platform, used for security, diagnostics and improvement.
3. How We Use Information
- to provide, operate, secure and support the Services;
- to process payments, subscriptions and Module purchases;
- to send service, transactional and account communications;
- to prevent fraud and abuse and to comply with legal obligations;
- to analyse and improve the Platform (in aggregated or de-identified form where feasible).
4. Sub-Processors & Third Parties
We use trusted third-party service providers to deliver the Services, including:
- Payments: Razorpay (payment processing);
- Hosting/Infrastructure: cloud hosting providers on which the Platform runs;
- Email/Messaging: providers used to send transactional emails and notifications;
- AI providers: where a subscriber connects an AI key, the relevant prompt data is sent to that provider to generate itineraries. Subscribers choose their own AI provider and are responsible for that provider’s terms.
We share personal data with these providers only as necessary to provide the Services, and under appropriate safeguards.
5. Security
We apply reasonable technical and organisational measures to protect data, including encryption of traffic in transit (HTTPS/TLS), encryption of sensitive identity fields at rest (AES-256), database-level tenant isolation, access controls, and rate limiting. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. Data Retention
We retain personal data for as long as your account is active or as needed to provide the Services, and thereafter as required to comply with legal, tax and accounting obligations or to resolve disputes. Subscriber content may be deleted after a reasonable period following account termination.
7. Your Rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal data, and may withdraw consent where processing is based on consent. For personal data that belongs to a subscriber’s customers, such requests should be directed to the relevant subscriber (the data fiduciary), and we will assist that subscriber as a processor.
8. Cookies
We use strictly necessary cookies and similar technologies to keep you signed in and to operate the Platform securely. We do not use them to build advertising profiles.
9. Children
The Platform is intended for businesses and is not directed at children. We do not knowingly collect personal data from children.
10. Grievance / Contact
For any privacy questions, data-rights requests or grievances, contact the Grievance Officer of Brandesia LLP at support@brandesia.com. We will address valid requests within the timelines prescribed by applicable law.
11. Changes
We may update this Privacy Policy from time to time. Material changes will be notified via the Platform or by email, and the “Last updated” date above will be revised.