Heal at India
+91

INR

Privacy Policy

Your privacy is our priority

1. Who we are

This policy explains how Heal at India LLP ("Heal at India", "we", "us", "our") collects and handles your personal data when you use healatindia.com and our related pages, tools and services (the "Platform").

We are the Data Fiduciary for your personal data under the Digital Personal Data Protection Act, 2023 ("DPDP Act").

Legal nameHEAL AT INDIA LLP
ConstitutionLimited Liability Partnership, incorporated under the Limited Liability Partnership Act, 2008
LLP Identification NumberACT-2027
PANAASFH9571M
GSTIN36AASFH9571M1ZD
Registered officePlot No. 6, 7 and 8, Kondapur, Serilingampally, Hyderabad, Rangareddy District, Telangana 500084, India

Please read this policy alongside our Terms and Conditions and our Cancellation Policy.

2. What this policy covers

This policy covers the personal data we handle as a booking platform: data about Guests, Hosts and visitors to the Platform.

It does not cover what a Host does with your data after we pass it to them. When you book, the retreat centre becomes a separate Data Fiduciary for the data it holds about you, and it handles that data under its own policy. If you want to know what a Host does with your data, ask the Host.

It also does not cover other websites we link to.

3. What we collect

Information you give us

Account. Your name, email address, phone number, password, country and currency preference. Your password is stored in encrypted form and we cannot read it. If you sign in using Google or Facebook, we receive your name, email address and profile picture from them. We do not receive your Google or Facebook password.

Bookings. Your name, email address, phone number, billing address, travel dates, number of guests, room preference and anything you write in a special request or enquiry.

Payments. Our payment partners process your payment. From them we receive the amount, the status, the transaction reference, the payment method and the last four digits of your card. We never see or store your full card number, your CVV or your UPI PIN.

Content you post. Reviews, ratings, photographs, wishlists, and messages you send to us or to a Host through the Platform.

Enquiries. Anything you send us by email, contact form or support request.

If you are a Host. Your business name, registered address, contact details, PAN, GSTIN, bank account details, and any licence, registration or certificate you upload.

Information we collect automatically

Your IP address, device type, browser, operating system, language, time zone, the pages you view, the searches you run, the links you click, the site that referred you, and the dates and times of access.

We also use a session analytics tool that records how a page is used — mouse movement, clicks and scrolling — so that we can see where the Platform is confusing or broken. Section 9 explains this and how to control it.

Information we receive from others

Our payment partners tell us whether your payment succeeded. Hosts confirm your arrival and tell us when a Retreat is completed. Google and Facebook pass us the details above if you choose to sign in through them.

4. Why we use it, and on what basis

The DPDP Act lets us process your personal data with your consent, or for the legitimate uses set out in Section 7 of the Act. Indian law does not provide a general "legitimate interests" basis, and we do not rely on one.

What we doBasis
Create and manage your accountData you voluntarily gave us for this purpose — Section 7(a)
Take your booking, confirm it, and pass your details to the HostData you voluntarily gave us for this purpose — Section 7(a)
Process your payment, any balance and any refundData you voluntarily gave us for this purpose — Section 7(a)
Answer your questions and handle complaintsData you voluntarily gave us for this purpose — Section 7(a)
Keep the Platform secure and detect fraudData you voluntarily gave us for this purpose — Section 7(a); and the security safeguards we are required to keep under Section 8(5) of the DPDP Act
Meet legal, tax and accounting obligations, and respond to a valid legal orderSections 7(d) and 7(e); retention for this purpose is permitted by Section 8(7)
Send you marketing emails or messagesYour consent — Section 6
Run analytics, personalisation and advertising cookiesYour consent — Section 6
Publish your review with the name and location you submitYour consent — Section 6
Pass health information you choose to share to your HostYour consent — Section 6

You can use the Platform without agreeing to marketing or to non-essential cookies.

5. Health information

Some Retreats involve fasting, dietary restriction, physical exertion, Panchakarma, massage, herbal preparations, heat, cold or altitude. Section 13 of our Terms and Conditions explains why a Host may need to know about your health before accepting your booking.

We do not ask health questions. Creating an account and making a booking on the Platform do not require you to give us any health information. Where a Host needs a health disclosure, that disclosure is made to the Host.

If you choose to share it with us anyway — in a special request, an enquiry or a message to a Host — this is what we do with it:

  • we pass it only to the Host you are booking with, and only for that booking
  • we do not use it for marketing, profiling, advertising or ranking
  • we do not share it with anyone else, and we never sell it
  • we remove it from our records within 90 days of your Retreat ending, unless we are required to keep it to defend or bring a legal claim

Health information you give a Host directly is held by that Host under its own policy, not ours.

6. Who we share it with

Hosts. When you book, we give the Host your name, contact details, booking details and anything you asked us to pass on. The Host is a separate Data Fiduciary for that data.

Service providers, who act on our instructions and only for the purposes in Section 4:

ProviderWhat they do
RazorpayPayments and refunds for Indian and card payments
PayPalPayments and refunds for international payments
Amazon Web Services (Mumbai region)Hosting, databases and file storage for the Platform
SendGrid (Twilio)Booking confirmations, account emails and newsletters
MSG91SMS and WhatsApp booking notifications and one-time passwords
Google FirebasePush and in-app notifications
Google Analytics, Google Tag ManagerUnderstanding how the Platform is used
Microsoft ClaritySession analytics — heatmaps and session recording
Google Ads, Meta (Facebook and Instagram) PixelMeasuring and targeting our advertising
Google MapsShowing retreat locations

Authorities. We share data where the law requires it, where we receive a valid legal order, or where we need to establish, exercise or defend a legal claim.

Professional advisers. Our accountants, auditors and lawyers, where they need it to advise us.

Business transfer. If our business is sold, merged or reorganised, your data may transfer to the buyer. We will tell you if that happens.

We do not sell your personal data, and we do not share it with data brokers.

7. Where your data is stored and sent

We store your data on servers in India, in the Amazon Web Services Mumbai region.

Some of the service providers listed in Section 6 operate outside India. Where that happens, we transfer your data in line with Section 16 of the DPDP Act, which permits transfer to any country except one the Central Government restricts by notification.

If you are outside India, booking a Retreat in India means your data will be processed in India, and shared with a Host in India.

8. How long we keep it

We keep your data only for as long as we need it for the purpose you gave it for.

DataHow long
Account dataWhile your account is open, then one year
Booking, payment, invoice and tax recordsEight years, as tax, GST and LLP law require
Health information you volunteered90 days after your Retreat ends
Reviews and content you postUntil you ask us to remove it, under Section 17 of our Terms
Support and complaint correspondenceThree years
Marketing consent recordsWhile you are subscribed, then three years, as proof that you consented
Access, security and server logsOne year

Once we no longer need your data, we delete it or anonymise it so that it can no longer identify you.

9. Cookies and similar technologies

Necessary cookies keep you logged in, remember your currency, hold your booking in progress and protect against fraud. The Platform cannot work without them and they do not need your consent.

Analytics, personalisation and advertising cookies and tags — Google Analytics, Google Tag Manager, Microsoft Clarity, Google Ads and the Meta Pixel — tell us how the Platform is used and let us measure our advertising. These are not necessary to run the Platform and we use them only where you consent.

How to control them. You can block or delete cookies through your browser settings, and you can turn off Google Analytics using Google's browser opt-out add-on. We are adding a cookie preference centre to the Platform; once it is live you will see a banner on your first visit and a Cookie Settings link in the footer, and you will be able to change your choice at any time.

Some parts of the Platform will not work properly if you block necessary cookies.

10. Marketing messages

We send you service messages about your booking - confirmations, reminders, changes and support replies. You cannot opt out of these while you have an active booking.

We send marketing messages by email, SMS or WhatsApp only where you have opted in. You can withdraw that consent at any time using the unsubscribe link in any marketing email, by replying STOP to a message, or by writing to info@healatindia.com. Withdrawing consent does not affect your bookings or your service messages.

Our SMS and WhatsApp messages are sent through templates registered under the Telecom Regulatory Authority of India's DLT framework.

11. How we protect your data

We encrypt data in transit using TLS, restrict internal access to personal data to the people who need it, keep access logs, and review our controls regularly. Our payment partners are PCI-DSS compliant and handle card data directly, so your full card details never reach our systems.

No system is completely secure. If a personal data breach affects your data:

  • we will tell you without delay, in plain language — what happened, what it means for you, what we are doing about it, what you can do, and who to contact
  • we will inform the Data Protection Board of India without delay, and give the Board a detailed report within 72 hours of becoming aware of the breach, as Rule 7 of the Digital Personal Data Protection Rules, 2025 requires
  • we will report the incident to CERT-In where the Information Technology (CERT-In) Directions, 2022 require it

12. Your rights under the DPDP Act

You can:

  • Access a summary of the personal data we hold about you, how we are processing it, and the identity of everyone we have shared it with
  • Correct data that is wrong, complete data that is incomplete, and update data that has changed
  • Erase data that we no longer need for the purpose you gave it for
  • Withdraw consent at any time, as easily as you gave it
  • Nominate another person to exercise your rights on your behalf if you die or become unable to act for yourself
  • Complain to us, and then to the Data Protection Board of India

Withdrawing consent does not undo processing we carried out before you withdrew it, and does not affect data we are required by law to keep.

You can delete your account yourself from your profile page. For anything else, write to the contact in Section 16. We will respond within 30 days.

Please give us enough information to find your records and to be satisfied that the request is really from you. We may ask you to verify your identity. We may decline a request that is unfounded or repetitive, and if we do we will tell you why.

13. If you are in the United Kingdom or the European Economic Area

We market Retreats to travellers in the UK and Europe, so the UK GDPR and the EU GDPR may also apply to you. Where they do, you have the rights set out in Section 12 and, in addition, the right to object to processing, the right to restrict processing, and the right to receive the data you gave us in a portable format.

Your data is processed in India. India has not received an adequacy decision from the European Commission or the UK Government, so where we transfer your data from the UK or the EEA to India we rely on the appropriate safeguards permitted by those laws, or on your explicit consent to the transfer for the purpose of arranging your booking.

You may complain to your local supervisory authority. We would prefer you to raise it with us first.

14. Children

The Platform is for people aged 18 and over. Under the DPDP Act, anyone under the age of 18 is a child.

We do not knowingly collect a child's personal data through the Platform. We do not track children, monitor their behaviour, or show them targeted advertising.

Some Retreats allow a child to attend with a parent or guardian. Where that happens, the booking adult gives us the child's name and age, confirms that they are the child's parent or lawful guardian, and takes responsibility for the child. We treat that confirmation as the verifiable consent required by Section 9 of the DPDP Act, and we record it against the booking. We use a child's data only to pass it to the Host for that booking.

If you believe a child has given us personal data, write to info@healatindia.com and we will delete it.

15. Changes to this policy

We may update this policy. The current version is always on this page with the date it was last updated.

Where a change is material, we will tell you by email or by a notice on the Platform before it takes effect.

16. Contact us and how to complain

For anything about your personal data, or to exercise your rights:

NameRaj Kishore
DesignationFounder — Data Protection Contact and Grievance Officer
Emailinfo@healatindia.com
AddressHeal at India LLP, Plot No. 6, 7 and 8, Kondapur, Serilingampally, Hyderabad, Rangareddy District, Telangana 500084, India
HoursMonday to Friday, 10:00 to 18:00 IST

Raj Kishore is also our Grievance Officer under the Information Technology Act, 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

Heal at India
WHAT'S OUR STORY?

Heal at India grew from a simple belief : India's ancient healing traditions can genuinely transform lives, yet the world has barely discovered them.

WHY CHOOSE US?

We're not just running a business - we're spreading wellness, we love what we do. Book with us and you're cared for at every step: from finding the retreat that's right for you to standing by you when something goes wrong. You'll feel looked after, understood, and safe throughout..

Secure Payments
VisaMastercardApple PayPayPalGPay
Currency