Legal

GDPR & Data Protection Policy

Last updated: 27 July 2026. This page is maintained by Stay Circle Travel Solution Private Limited.

Stay Circle Travel Solution Private Limited (CIN U79110HR2025PTC130447) is committed to handling personal data lawfully, fairly and transparently. This policy explains our approach under the EU/UK General Data Protection Regulation, where it applies to travellers and clients in those regions, and under India's Digital Personal Data Protection Act, 2023. It supplements our Privacy Policy.

Controller and roles

When we decide why and how personal data is processed — for example our own client relationships and marketing — we act as a controller. When we process traveller data strictly on the documented instructions of a corporate or defence client, we act as a processor for that client and will enter into a data processing agreement on request.

Lawful bases for processing

Lawful basisTypical use
ContractIssuing tickets, confirming hotels, servicing an itinerary
Legal obligationTax invoicing, statutory record keeping, government/regulatory reporting
Legitimate interestsAccount management, fraud prevention, service quality and security
ConsentMarketing communications, non-essential cookies, special-category data where required

Categories of data

Identity and contact details, passport and government ID details where travel requires them, employer and cost centre information, itinerary and booking history, payment details processed through our payment partners, and technical data such as IP address and device identifiers.

Data subject rights

Subject to applicable law, you may exercise the following rights:

  • Access a copy of the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase data where it is no longer needed and no legal duty requires us to keep it
  • Restrict or object to certain processing, including direct marketing
  • Receive your data in a portable, machine-readable format
  • Withdraw consent at any time, without affecting prior lawful processing
  • Lodge a complaint with your supervisory authority or the Data Protection Board of India

We respond to verified requests within 30 days. Where a request relates to data we process on behalf of a corporate client, we will forward it to that client and support their response.

International transfers

Travel inherently involves sharing data across borders with airlines, hotels, ground operators and immigration authorities in the destination country. Where personal data moves outside the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, or on the derogation permitting transfers necessary to perform a contract with the traveller.

Retention

We retain booking and financial records for the period required by Indian tax, accounting and audit law, and delete or anonymise personal data once it is no longer needed for the purpose it was collected for. Marketing data is retained until you opt out.

Security

We apply role-based access control, encryption of data in transit, supplier due diligence, activity logging and periodic access reviews. Our quality management system is certified to ISO 9001:2015.

Personal data breaches

We maintain an incident response process. Where a breach is likely to result in a risk to individuals, we notify the competent supervisory authority within 72 hours of becoming aware of it, and notify affected individuals and controller-clients without undue delay.

Sub-processors

We use travel technology providers, global distribution systems, payment processors and cloud hosting providers to deliver our services. A current list of sub-processors is available to clients on request.

Contact our data protection contact

Write to privacy@staycircle.in or Stay Circle Travel Solution Private Limited, Gurugram, Haryana, India.