PRIVACY POLICY
AtithiBhaarat — Hotel Partner Platform (Website & Mobile Application)
Effective Date: 10 June 2026 Last Updated: 10 August 2026 Version: 1.0
1. INTRODUCTION
This Privacy Policy ("Policy") explains how AtithiBhaarat DigiSolutions Private Limited, a company incorporated under the Companies Act, 2013, bearing CIN U58201RJ2025PTC106325 and having its registered office at 101, Vishveshwariya Nagar, Gopalpura Bypass, Durgapura, Jaipur, Rajasthan – 302018 (hereinafter "AtithiBhaarat", "we", "us" or "our"), collects, uses, stores, discloses, transfers, retains and erases personal data in connection with the AtithiBhaarat platform made available at https://atithibhaarat.com and through the AtithiBhaarat mobile and web applications (collectively, the "Platform").
The Company is recognised as a startup by the Department for Promotion of Industry and Internal Trade ("DPIIT"), Ministry of Commerce & Industry, Government of India (Certificate No. DIPP272195, valid until 9 September 2035); is registered as a Micro enterprise under the Udyam scheme of the Ministry of Micro, Small and Medium Enterprises (Udyam Registration No. UDYAM-RJ-17-0660387); and is registered under the Government of Rajasthan's iStart initiative (iStart Registration No. 5F82239).
This Policy is published in compliance with:
| Law / Instrument | Relevance |
|---|---|
| Digital Personal Data Protection Act, 2023 ("DPDP Act") read with the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), notified by the Ministry of Electronics and Information Technology on 13 November 2025 and subject to a phased implementation culminating on 13 May 2027 | Primary data protection framework |
| Information Technology Act, 2000, Sections 43A, 72 and 72A | Data security and confidentiality |
| Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules") | Security standards, to the extent in force |
| Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 | Publication of privacy policy and Grievance Officer details |
| Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and Regulations thereunder | Restrictions on Aadhaar handling |
| Consumer Protection (E-Commerce) Rules, 2020 | Grievance redressal machinery |
| Foreigners Act, 1946 and Registration of Foreigners Rules, 1992 (Form C) | Statutory reporting of foreign nationals |
| Applicable State police / hotel guest-registration rules, including those applicable in the State of Rajasthan | Statutory guest register obligations |
This Policy is addressed principally to Hotel Partners and their authorised personnel. Personal data of travellers and guests is additionally governed by the AtithiBhaarat Traveller Privacy Notice presented to each traveller at the point of consent capture, which will separately be published at https://atithibhaarat.com/traveller-privacy-notice once the digital check-in flow launches.
2. DEFINITIONS
For the purposes of this Policy, capitalised terms bear the following meanings:
"Data Fiduciary" means any person who alone or in conjunction with others determines the purpose and means of processing of personal data, as defined under Section 2(i) of the DPDP Act.
"Data Principal" means the individual to whom the personal data relates, as defined under Section 2(j) of the DPDP Act, and includes a child's lawful guardian and a lawful guardian of a person with disability.
"Data Processor" means any person who processes personal data on behalf of a Data Fiduciary, as defined under Section 2(k) of the DPDP Act.
"Hotel Partner" means any hotel, guest house, homestay, resort, lodge, dharamshala or other accommodation establishment that has registered on the Platform, and includes its proprietors, directors, partners, managers and authorised employees.
"Personal Data" means any data about an individual who is identifiable by or in relation to such data.
"Processing" means a wholly or partly automated operation or set of operations performed on digital personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment, sharing, disclosure, restriction, erasure or destruction.
"Traveller" means any individual who obtains or holds an AtithiBhaarat Identification Number ("ABIN") or who undergoes verification or check-in through the Platform.
"Verification Data" means the identity attributes returned to the Platform through a Government-authorised source, including DigiLocker.
3. OUR ROLE AND THE HOTEL PARTNER'S ROLE
Data protection responsibility on the Platform is layered. It is important that Hotel Partners understand precisely where their own legal obligations begin.
3.1 Where AtithiBhaarat is the Data Fiduciary. We act as Data Fiduciary in respect of: (a) personal data of Hotel Partner personnel who create or operate accounts on the Platform; (b) personal data of Travellers collected for the purpose of issuing, maintaining and authenticating an ABIN; (c) Platform usage, telemetry, security and audit data.
3.2 Where AtithiBhaarat is a Data Processor. We act as a Data Processor, processing on the documented instructions of the Hotel Partner, in respect of: (a) the compilation, formatting and transmission of the statutory guest register maintained by the Hotel Partner under applicable State police rules and, in the case of foreign nationals, Form C under the Registration of Foreigners Rules, 1992; (b) any guest data uploaded by the Hotel Partner from its own property management system.
3.3 The Hotel Partner remains an independent Data Fiduciary in respect of its own guest records, its bookings, and any personal data it collects outside the Platform. The statutory obligation to maintain and furnish a guest register to the police authorities remains that of the Hotel Partner. The Platform assists compliance; it does not assume or discharge the Hotel Partner's legal duty.
4. PERSONAL DATA WE COLLECT
4.1 From Hotel Partners (Business and Onboarding Data)
| Category | Examples | Why We Need It |
|---|---|---|
| Establishment identity | Legal name, trade name, property type, number of rooms, property address, geo-coordinates | Onboarding, verification, listing |
| Statutory identifiers | GSTIN, PAN of the entity, trade/hotel licence number, fire and municipal licence references, FSSAI licence (where applicable) | Verification of a genuine, licensed establishment; tax invoicing |
| Authorised representative | Name, designation, mobile number, email address, specimen signature | Account control and legally binding instructions |
| Banking and settlement | Bank account name, account number, IFSC, cancelled cheque or bank letter, UPI VPA | Payment of incentives, refunds and settlements |
| Property media | Photographs of the property, logo, tariff information | Display on the Platform |
4.2 From Hotel Partner Personnel (Users of the Platform)
Full name; official designation and role; mobile number; email address; encrypted password credentials; multi-factor authentication data; role and permission assignments under our role-based access control ("RBAC") model; login timestamps, IP address, device identifiers, operating system and application version; and a complete audit trail of actions performed within the Platform.
4.3 From Travellers (Processed Through the Hotel Partner's Premises)
| Category | Detail |
|---|---|
| Identity attributes | Name, date of birth, gender, photograph and address, as returned by a Government-authorised verification source |
| Contact | Mobile number verified by one-time password; email address, where provided |
| Liveness verification | A mathematical facial template derived from a live capture, used solely for match-or-no-match authentication |
| ABIN record | The issued AtithiBhaarat Identification Number in the format ABIN-XX-XXXXXX and its status |
| Check-in record | Property identifier, date and time of check-in and check-out, room reference, method of check-in used, and the accompanying-persons count |
| Statutory fields | Only those fields that applicable police or immigration rules require to be recorded in the guest register |
4.4 Automatically Collected Technical Data
Server logs, IP address, browser type and version, device model, operating system, referring and exit pages, session duration, crash reports, diagnostic traces, and cookie and similar identifiers as described in our Cookie Policy.
4.5 Payment Data
Subscription and fee payments are processed through an RBI-authorised payment aggregator or payment gateway. We do not collect, store or have access to your complete card number, CVV, card PIN, net-banking credentials or UPI PIN. We receive only a transaction reference, masked instrument details, the amount and the payment status.
5. WHAT WE DELIBERATELY DO NOT COLLECT OR STORE
This section reflects a deliberate architectural decision and is a material commitment on our part.
- We do not store Aadhaar numbers. No Aadhaar number, in full or in part, is written to any database, log, backup, cache or export of the Platform. Where verification occurs through DigiLocker or another Government-authorised channel, we consume only the verified attributes necessary for the guest register and discard any identifier number.
- We do not store any other Government identity document number — including passport number, driving licence number, voter identity number or PAN of a Traveller — save only where a specific statutory instrument compels its recording, in which case it is stored in encrypted form for the minimum period prescribed and is disclosed only to the authority entitled to it.
- We do not store raw biometric images or core biometric information. Facial liveness verification produces an irreversible mathematical template. We do not retain the source video stream.
- We do not sell, rent, trade or licence personal data to any third party for advertising, marketing, profiling, data brokerage or any commercial purpose whatsoever.
- We do not use Traveller personal data to train artificial intelligence or machine-learning models for purposes unrelated to fraud prevention and platform security.
- We do not perform automated decision-making that produces legal effects on a Traveller or a Hotel Partner without a human review pathway.
6. PURPOSES OF PROCESSING AND LAWFUL BASIS
We process personal data only for lawful purposes for which the Data Principal has given consent, or for a "certain legitimate use" recognised under Section 7 of the DPDP Act.
| Purpose | Lawful Basis |
|---|---|
| Creating and administering a Hotel Partner account | Performance of the Terms & Conditions; consent |
| Verifying the genuineness and licensing status of an establishment | Consent; prevention of fraud |
| Issuing and authenticating an ABIN | Consent of the Traveller, freely given at the point of enrolment |
| Recording digital check-ins | Consent; and compliance with law under Section 7(b) of the DPDP Act |
| Compiling and transmitting the statutory guest register to police or immigration authorities | Compliance with any law in force in India, under Section 7(b) of the DPDP Act |
| Billing, invoicing, GST compliance and settlement of incentives | Performance of contract; compliance with tax law |
| Providing customer support and resolving grievances | Performance of contract; consent |
| Detecting and preventing fraud, impersonation and unauthorised access | Prevention and investigation of an offence or violation, and safeguarding the security of the Platform |
| Aggregate and anonymised analytics and reporting | Legitimate use; data is de-identified so that no individual is identifiable |
| Service communications, including outage, security and billing notices | Performance of contract |
| Promotional communications | Separate, revocable opt-in consent |
Purpose limitation. We do not process personal data for any purpose beyond those stated above without first obtaining fresh consent or establishing a fresh lawful basis.
7. NOTICE, CONSENT AND WITHDRAWAL
7.1 Notice. Before or at the time of requesting consent, we present a clear, itemised and plain-language notice describing the personal data sought, the purpose, the manner of exercising rights under Sections 12 and 13 of the DPDP Act, and the manner of making a complaint to the Data Protection Board of India.
7.2 Language. In accordance with Section 5(3) of the DPDP Act, the notice is available in English, Hindi and such other languages specified in the Eighth Schedule to the Constitution of India as we may publish from time to time.
7.3 Free, specific, informed and unambiguous consent. Consent is captured through an affirmative action. Pre-ticked boxes, silence and inactivity do not constitute consent on the Platform. Consent is limited to such personal data as is necessary for the specified purpose.
7.4 Withdrawal. A Data Principal may withdraw consent at any time, with the same ease with which it was given, through the in-Platform privacy controls or by writing to info@atithibhaarat.com. On withdrawal, we shall cease processing and cause our Data Processors to cease processing within a reasonable time, except where retention is required (a) for compliance with any law in force in India, or (b) for the establishment, exercise or defence of legal claims. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
7.5 Consequence of withdrawal. Withdrawal of consent necessary for identity verification will render the ABIN inoperative and digital check-in unavailable to that Traveller. The Hotel Partner will then be required to complete guest registration through conventional means.
7.6 Consent Managers. Where a Consent Manager registered with the Data Protection Board of India is available, Data Principals may give, manage, review and withdraw consent through such Consent Manager.
8. DISCLOSURE AND SHARING OF PERSONAL DATA
We disclose personal data only in the following circumstances:
8.1 To police, immigration and statutory authorities. Guest register data is transmitted to the jurisdictional police authority and, in the case of foreign nationals, to the Bureau of Immigration through the prescribed Form C mechanism, strictly in the form and to the extent required by law. This transmission is a statutory function and is not subject to withdrawal of consent.
8.2 To the Hotel Partner. A Hotel Partner receives only the verification status and the minimum guest particulars required for its own statutory register and its own hospitality operations in respect of guests actually staying at its property. A Hotel Partner has no access to the wider ABIN database, to a Traveller's stay history at other properties, or to any biometric template.
8.3 To Data Processors and sub-processors. We engage cloud hosting, communication, payment, analytics and support providers. Each is bound by a written contract meeting the requirements of Section 8(2) of the DPDP Act, which restricts processing to our documented instructions, imposes confidentiality and security obligations, and prohibits onward transfer without our written authorisation. A current list of material sub-processors is available on request by writing to info@atithibhaarat.com, and will be published at /subprocessors once finalised.
8.4 Pursuant to legal process. Where disclosure is required by an order of a court or tribunal, or by a lawful direction of a statutory authority, we shall disclose the minimum data necessary and, where legally permissible, notify the affected Data Principal.
8.5 On a business transfer. In the event of a merger, amalgamation, acquisition, scheme of arrangement or transfer of undertaking, personal data may be transferred to the successor entity, subject to the successor being bound by obligations no less protective than those in this Policy. Affected Data Principals shall be notified.
8.6 With express consent. For any disclosure not covered above.
We do not disclose personal data to advertisers, data brokers, or unrelated commercial third parties in any circumstance.
9. CROSS-BORDER TRANSFER
Personal data processed through the Platform is stored on servers located within the territory of India. Where any transfer outside India becomes necessary, such transfer shall be made only to a country or territory not restricted by the Central Government under Section 16 of the DPDP Act, and only under contractual safeguards ensuring a standard of protection no lower than that afforded under Indian law. Data subject to any sectoral law imposing stricter localisation shall not be transferred outside India.
10. DATA RETENTION AND ERASURE
Personal data is retained only for so long as is necessary for the purpose for which it was collected, or for such longer period as is required by law. Detailed retention periods, cache lifetimes and purge mechanics are set out in the AtithiBhaarat Cache & Data Retention Policy, which forms part of this Policy by reference.
In summary:
| Data Category | Retention |
|---|---|
| Hotel Partner account and KYC records | For the term of the relationship and 3 years thereafter |
| Statutory guest register entries | For the period prescribed by the applicable State police rules or immigration law, and no longer |
| Check-in transaction records | 3 years |
| Facial liveness templates | Deleted upon verification completion or on withdrawal of consent, whichever is earlier |
| Security and audit logs | 1 year |
| Financial, tax and invoicing records | Eight years, as required under the Companies Act, 2013, and seventy-two months, as required under the Central Goods and Services Tax Act, 2017, whichever is longer |
| Grievance records | 3 years |
Upon expiry of the applicable period, personal data is erased or irreversibly anonymised, including from backups on the next scheduled backup rotation.
Forty-eight hour pre-erasure notice. Where personal data is due to be erased on grounds of inactivity, we will give the Data Principal notice at least forty-eight (48) hours in advance, so that the Data Principal may log in or contact us to preserve the account, as contemplated by Rule 8 of the DPDP Rules, 2025.
Minimum log retention. Rule 6 of the DPDP Rules, 2025 requires personal data, traffic data and system logs to be retained for not less than one (1) year for the purposes of detection, investigation and remediation of unauthorised access — save where a longer period is required by any other law. This floor overrides any shorter period stated elsewhere in our documentation.
Third Schedule. The fixed three-year erasure timelines prescribed by the Third Schedule to the DPDP Rules apply only to notified classes of large e-commerce, social media and online gaming intermediaries above the specified user thresholds. We do not presently fall within those classes; our retention is accordingly purpose-bound under Section 8(7) of the DPDP Act. We will reassess this position if our registered user base approaches any notified threshold.
11. SECURITY SAFEGUARDS
We implement reasonable security safeguards under Section 8(5) of the DPDP Act and the SPDI Rules, including:
- Encryption of data in transit using TLS 1.2 or higher, and encryption of data at rest using AES-256 or equivalent;
- Role-based access control, least-privilege provisioning, and mandatory multi-factor authentication for all administrative accounts;
- Tamper-evident audit logging of every access to and modification of personal data;
- Network segregation, firewalling, intrusion detection and rate limiting;
- Periodic vulnerability assessment and penetration testing by an independent, CERT-In empanelled auditor;
- Secure software development practices, code review, and dependency scanning;
- Background verification and confidentiality undertakings for personnel with access to personal data;
- Encrypted, access-controlled and periodically restore-tested backups;
- A documented incident response and business continuity plan.
No method of electronic transmission or storage is absolutely secure. While we apply safeguards commensurate with the sensitivity of the data, we cannot guarantee absolute security, and we do not warrant against every conceivable form of compromise.
12. PERSONAL DATA BREACH
In the event of a personal data breach, we shall, in accordance with Section 8(6) of the DPDP Act read with Rule 7 of the DPDP Rules, 2025:
(a) notify the Data Protection Board of India without delay on becoming aware of the breach, and furnish a detailed report within seventy-two (72) hours — or such longer period as the Board may allow on written request — setting out the events leading to the breach, its nature, extent and timing, the root cause, the remedial and mitigation measures implemented, and our findings as to the person who caused it; (b) notify each affected Data Principal without delay, through the user account and by registered email or other registered mode of communication, describing the nature and extent of the breach, its likely consequences, the measures taken to mitigate risk, the safety measures the Data Principal may take, and our contact details for further queries. No harm or materiality threshold applies — every personal data breach is notifiable; (c) notify affected Hotel Partners without undue delay where the breach concerns data processed on their behalf; (d) report to CERT-In within six hours where the incident falls within the reportable categories under the CERT-In Directions of 28 April 2022.
Hotel Partners must notify us at info@atithibhaarat.com within twenty-four (24) hours of becoming aware of any actual or suspected compromise of Platform credentials, devices or data at their premises.
13. RIGHTS OF DATA PRINCIPALS
Under Chapter III of the DPDP Act, every Data Principal has the following rights, exercisable free of charge:
13.1 Right to access information — a summary of the personal data being processed, the processing activities undertaken, and the identities of all Data Fiduciaries and Data Processors with whom the data has been shared, together with a description of the data so shared.
13.2 Right to correction, completion, updating and erasure — to have inaccurate or misleading data corrected, incomplete data completed, out-of-date data updated, and data erased where it is no longer necessary for the purpose or where consent is withdrawn, subject to any overriding legal retention obligation.
13.3 Right of grievance redressal — to a readily available means of registering a grievance with us, prior to approaching the Data Protection Board of India.
13.4 Right to nominate — to nominate another individual to exercise these rights in the event of death or incapacity.
How to exercise. Requests may be made through the in-Platform privacy dashboard or by writing to info@atithibhaarat.com. We shall respond within 15 days. We may seek reasonable verification of identity before acting on a request, and may decline requests that are manifestly unfounded, excessive or repetitive, recording our reasons.
Hotel Partner obligation. Where a Traveller addresses a request to a Hotel Partner, the Hotel Partner shall forward it to info@atithibhaarat.com within forty-eight (48) hours and shall not itself respond substantively on our behalf.
13.5 Duties of Data Principals. Section 15 of the DPDP Act imposes duties on Data Principals, including the duty not to impersonate another person while providing personal data, not to suppress material information, not to register a false or frivolous grievance, and to furnish only authentic information when seeking correction or erasure. Breach of these duties may attract penalty under the DPDP Act.
14. CHILDREN AND PERSONS WITH DISABILITY
14.1 A "child" means an individual who has not completed eighteen years of age.
14.2 Where a Traveller is a child, we process personal data only after obtaining verifiable consent of the parent or lawful guardian, in the manner prescribed under Section 9 of the DPDP Act.
14.3 We do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
14.4 Hotel Partners must ensure that a child accompanying a guest is registered only against the record of a verified accompanying adult guardian, and must not attempt to enrol a child independently.
14.5 For a person with disability who has a lawful guardian, consent is obtained from such guardian on the basis of a valid guardianship instrument.
15. OBLIGATIONS OF HOTEL PARTNERS
As an independent Data Fiduciary in its own right, each Hotel Partner shall:
- Access, use and disclose Traveller data only for the specific purpose of that Traveller's stay and statutory registration;
- Restrict Platform access to trained, authorised personnel and maintain accurate role assignments, revoking access on the same day that an employee ceases to be authorised;
- Never share, sell, publish or transfer Traveller data to any third party, including travel agents, marketing agencies, group companies or affiliates, without a lawful basis;
- Never use shared, generic or dormant login credentials;
- Secure all devices used to access the Platform with device locks, updated operating systems and, where the device is shared, a supervised session;
- Display the notices, signage and consent material supplied by us at the reception desk;
- Not photograph, screenshot, transcribe or otherwise create a parallel record of Traveller identity data displayed on the Platform;
- Comply with the DPDP Act and all applicable law in its own capacity;
- Immediately report suspected misuse, unauthorised access or data loss to info@atithibhaarat.com.
Breach of these obligations constitutes a material breach of the Terms & Conditions and may result in immediate suspension, in addition to any liability arising in law.
16. COOKIES AND SIMILAR TECHNOLOGIES
Our use of cookies, software development kits, local storage, pixels and device identifiers is described in the AtithiBhaarat Cookie Policy at /cookie-policy, which forms part of this Policy.
17. THIRD-PARTY SERVICES AND LINKS
The Platform integrates with, and may link to, third-party services including DigiLocker and other Government-authorised verification sources, payment gateways, and online travel agencies to which travellers may be redirected for accommodation bookings. We do not control, and are not responsible for, the privacy practices of any third party. Once a user is redirected to a third-party website or application, the privacy policy of that third party governs. Users are advised to read those policies independently.
18. GRIEVANCE REDRESSAL AND CONTACT
Data Protection Officer / Person Responsible for Data Protection Queries Name: Jayant Chaubey Email: info@atithibhaarat.com Address: 101, Vishveshwariya Nagar, Gopalpura Bypass, Durgapura, Jaipur, Rajasthan – 302018
Grievance Officer (appointed under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the Consumer Protection (E-Commerce) Rules, 2020) Name: Jayant Chaubey Designation: Founder & Director Email: info@atithibhaarat.com Telephone: +91 77938 80880 Address: 101, Vishveshwariya Nagar, Gopalpura Bypass, Durgapura, Jaipur, Rajasthan – 302018 Working hours: Mon–Sat, 9:00 AM – 7:00 PM IST
Timelines. Every grievance is acknowledged within twenty-four (24) to seventy-two (72) hours of receipt and disposed of within twenty (20) days. Where the grievance concerns unlawful content requiring removal, action is taken within the shorter period prescribed by the applicable Rules.
Escalation. If a Data Principal is not satisfied with the response, or receives no response within the prescribed period, the Data Principal may approach the Data Protection Board of India in the manner prescribed under the DPDP Act. Consumers may additionally approach the National Consumer Helpline (1915) or the appropriate Consumer Commission.
19. AMENDMENTS
We may amend this Policy from time to time. Material amendments will be notified through the Platform, by email to the registered address of each Hotel Partner, and by an in-application notice, not less than 30 days before they take effect. The date of last revision appears at the head of this Policy. Continued use of the Platform after the effective date constitutes acceptance. Where an amendment materially expands the purposes of processing, fresh consent will be sought.
20. GOVERNING LAW AND JURISDICTION
This Policy is governed by the laws of India. Subject to the arbitration provisions of the Terms & Conditions, the courts at Jaipur, Rajasthan shall have exclusive jurisdiction.
This Policy should be read together with the AtithiBhaarat Terms & Conditions, Cookie Policy, Cache & Data Retention Policy and Refund & Cancellation Policy.