Skip to content

Legal

Privacy notice

Working draft, 12 August 2026, written against India’s Digital Personal Data Protection Act, 2023.

Draft — pending legal review. Not yet binding.

This text is a working draft written for the Dreamvaca showcase build. It has not been reviewed by a lawyer, it is not a contract, and no part of it takes effect until Thirty3 Fundos Technology publishes a reviewed version alongside live bookings.

1. Who holds your data

THIRTY3 FUNDOS TECHNOLOGY PRIVATE LIMITED (CIN U82990DL2024PTC426235), C-203 Badhwar Apartment, Dwarka Sector 6, New Delhi 110075, is the Data Fiduciary for personal data collected through Dreamvaca, within the meaning of the Digital Personal Data Protection Act, 2023 ("DPDP Act").

A Grievance Officer has not yet been appointed for this product, because the product is not yet processing live customer data. One will be named on this page before any live booking is accepted, as the DPDP Act requires.

2. What is collected, and only what is needed

The DPDP Act permits collection only of data necessary for a stated purpose. Dreamvaca collects:

  • Enquiry data — name, mobile number, optional email, destination, dates and party size, so a holiday can be shaped and priced.
  • Booking data — traveller names as they appear on the passport, dates of birth, passport number and expiry, and dietary or accessibility requirements, because airlines, hotels and consulates require them.
  • Visa data — the supporting documents listed on the relevant visa page, held only for the duration of the application.
  • Payment data — handled entirely by the payment gateway. Dreamvaca does not receive or store card numbers, CVVs or UPI credentials.
  • Site data — language preference and basic, aggregated page analytics. No advertising profile is built and no data is sold.

In the current showcase build, the enquiry form transmits nothing: it composes your text locally in your browser so you can copy it. No enquiry database exists yet.

4. Who it is shared with

Only with the suppliers required to deliver your trip — the airline, the hotel or its destination management company, the transfer operator, the insurer, the visa service provider and the payment gateway — and only the fields each of them actually needs. A hotel does not receive your passport scan; a consulate does not receive your hotel preferences beyond the confirmed booking it requires.

International travel necessarily involves transferring data outside India — to the airline and the hotel in the destination country. By booking an international trip you are asking us to do exactly that. We do not transfer data to any jurisdiction restricted by the Central Government under the DPDP Act.

5. Your rights under the DPDP Act

  • The right to know what personal data we hold about you and who it has been shared with.
  • The right to have inaccurate or incomplete data corrected or completed.
  • The right to have data erased once the purpose it was collected for has been served, unless a law requires us to retain it.
  • The right to nominate another person to exercise these rights if you die or become incapacitated.
  • The right to a readily available means of grievance redressal, before approaching the Data Protection Board of India.

6. How long it is kept

Visa supporting documents are deleted once the application is decided. Booking records are retained while the trip is live and thereafter only for the period Indian tax and company law requires. Enquiry data that never becomes a booking is deleted within twelve months.

7. Children

Children travel on family bookings, and their data is provided by a parent or guardian who books on their behalf. Dreamvaca does not knowingly collect a child’s personal data directly, does not track children, and does not direct advertising at them — which the DPDP Act prohibits outright.

8. Security, and what to do if it fails

We apply reasonable technical and organisational safeguards: encrypted transport, access limited to the people who need it, and payment data kept out of our systems entirely. No safeguard is absolute. If a breach occurs, the DPDP Act requires us to notify both the Data Protection Board of India and every affected person, and we will.