SwaanStay Legal

Data Protection Policy

How SwaanStay protects your personal and financial information under the DPDP Act 2023.

1. Data Fiduciary

Swaan Hotels & Resorts Private Limited is the Data Fiduciary for personal data processed on this platform. Our Data Protection Officer can be reached at Support@swaanstay.com.

2. Lawful basis

We process personal data based on your consent, contractual necessity (bookings), and legitimate interests (fraud prevention, service improvement).

3. Security safeguards

  • TLS 1.3 for all data in transit.
  • AES-256 encryption at rest for MongoDB collections.
  • bcrypt password hashing with per-user salt.
  • Role-based access control; least-privilege principle for staff.
  • Quarterly penetration tests & monthly dependency-vulnerability scans.

4. Breach notification

In the event of a personal data breach, we will notify the Data Protection Board of India and affected users within 72 hours of confirmed detection, along with details of the breach and remedial steps.

5. Cross-border transfers

All primary data is stored on servers in India (Mumbai region). Limited AI-processing may involve transient transfers to servers in the EU/US under Standard Contractual Clauses. No sensitive data (Aadhaar, biometric) is ever transferred abroad.

6. Children

We do not knowingly collect data from anyone under 18. Parents/guardians who believe we might have collected their child's data can request deletion via dpo@swaanstay.com.

7. Complaints

If you're unhappy with how we handle your data, contact grievance@swaanstay.com. If unresolved within 30 days, you may escalate to the Data Protection Board of India.

Last updated: February 2026