Last updated:
This privacy policy explains how Vedic Voyages ("we", "us", "our") collects, uses, stores and protects your personal data when you use our website, contact us, or book travel with us. We are the data controller responsible for your personal data.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Questions about this policy or about how we handle your personal data, and any request to exercise your rights, can be sent to info@vedicvoyages.com.
Our aim is to collect the minimum personal data needed for the purpose in question. The information we collect depends on how you interact with us:
Technical data such as IP address, device and browser type, and pages viewed, collected through cookies, server logs and similar technologies (see section 9).
Your name, email address, telephone number and country of residence, and any message you send us. We only send marketing communications where you have given consent.
If you create an account, your name and email address (and, where you sign in with Google or Facebook, the basic profile information those services provide). Authentication is handled by Google Firebase.
To arrange and deliver your travel we may collect: title, full name as shown on your passport, date of birth, gender, postal address, telephone number, email address, the names and details of other travellers on your booking, next-of-kin details, passport and visa details, and insurance details. Payment card details are collected and processed directly by our payment providers (see section 5).
Where relevant to a booking, we may collect information about health conditions, medication, disability, accessibility needs or dietary requirements. This is special category data under Article 9 UK GDPR and is collected and processed only with your explicit consent, and only where necessary to arrange your travel safely.
We rely on the following lawful bases under Article 6 UK GDPR:
We do not sell your personal data. We share it only with the following categories of recipients, who act as our processors or as separate controllers where required to provide their service:
Where you book a trip, we share the details needed to deliver it (which may include date of birth, passport number, insurance and next-of-kin details, and any medical or dietary needs) with the ground handlers at your destination. We ask ground handlers to delete these details within 30 days of the end of your tour. Everyone named on a booking may receive information about that trip.
Payment card details are entered directly into the secure systems of our payment providers (Stripe and Razorpay) and are not stored on our own servers. These providers process your payment data as separate controllers under their own privacy policies.
Some of our providers process personal data outside the United Kingdom, including in the United States (for example Google and Stripe) and in India (for example Amazon Web Services in the Mumbai region and Razorpay). Where we transfer personal data outside the UK, we ensure an appropriate safeguard is in place, such as:
Where we embed advertising or social tools such as Google Ads that use personal data for their own purposes, we and the provider act as joint controllers under Article 26 UK GDPR for that processing. In summary, we are responsible for placing the tool and providing this notice and the choices in our cookie banner; the provider is responsible for the processing carried out on its own platform. You may exercise your rights against either party, and further detail is available in the provider's own privacy and joint-controller documentation.
We keep personal data only for as long as necessary for the purposes for which it was collected, including meeting legal, accounting or reporting requirements.
For legal and tax reasons we are required to retain basic information about reservations and clients for a period of six years. Ground handlers are asked to delete the booking details we share with them within 30 days of the end of your tour. Where appropriate we may anonymise data so that it can no longer be associated with you and retain it for statistical or research purposes.
Cookies are small files stored on your device. We use strictly necessary cookies to run the site, and — only with your consent — analytics and marketing cookies. Non-essential cookies and third-party trackers (including Google Analytics, Zoho PageSense, Interakt and any advertising tools) do not load until you accept them.
You can accept, reject or change your choices at any time using the link, available here and in the site footer.
Third-party services that may set cookies include:
We apply appropriate technical and organisational measures under Article 32 UK GDPR, including encryption of data in transit (TLS), encryption of data at rest, hashing of account passwords, access controls that limit staff access to personal data, and the use of pseudonymous identifiers in analytics.
We build data protection into our services by design and by default: we collect only the personal data we need, apply the least intrusive settings by default, and treat non-essential processing (such as marketing and analytics) as opt-in rather than opt-out.
We maintain procedures to detect and respond to personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours as required by Article 33 UK GDPR, and where the breach is likely to result in a high risk to you, we will inform you without undue delay under Article 34.
Under the UK GDPR you have the right to:
To exercise any of these rights, email info@vedicvoyages.com. You can also unsubscribe from marketing using the link in any marketing message. We will respond within one month (30 days). We may need to verify your identity before acting on a request.
If you have a concern about how we handle your personal data, please contact us first at info@vedicvoyages.com. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk/make-a-complaint or by calling 0303 123 1113.
We may update this policy from time to time. The date at the top of this page shows when it was last revised. Please check back periodically for any changes.