GDPR & Data Protection Policy
Last updated: 27 July 2026. This page is maintained by Stay Circle Travel Solution Private Limited.
Stay Circle Travel Solution Private Limited (CIN U79110HR2025PTC130447) is committed to handling personal data lawfully, fairly and transparently. This policy explains our approach under the EU/UK General Data Protection Regulation, where it applies to travellers and clients in those regions, and under India's Digital Personal Data Protection Act, 2023. It supplements our Privacy Policy.
Controller and roles
When we decide why and how personal data is processed — for example our own client relationships and marketing — we act as a controller. When we process traveller data strictly on the documented instructions of a corporate or defence client, we act as a processor for that client and will enter into a data processing agreement on request.
Lawful bases for processing
| Lawful basis | Typical use |
|---|---|
| Contract | Issuing tickets, confirming hotels, servicing an itinerary |
| Legal obligation | Tax invoicing, statutory record keeping, government/regulatory reporting |
| Legitimate interests | Account management, fraud prevention, service quality and security |
| Consent | Marketing communications, non-essential cookies, special-category data where required |
Categories of data
Identity and contact details, passport and government ID details where travel requires them, employer and cost centre information, itinerary and booking history, payment details processed through our payment partners, and technical data such as IP address and device identifiers.
Data subject rights
Subject to applicable law, you may exercise the following rights:
- Access a copy of the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase data where it is no longer needed and no legal duty requires us to keep it
- Restrict or object to certain processing, including direct marketing
- Receive your data in a portable, machine-readable format
- Withdraw consent at any time, without affecting prior lawful processing
- Lodge a complaint with your supervisory authority or the Data Protection Board of India
We respond to verified requests within 30 days. Where a request relates to data we process on behalf of a corporate client, we will forward it to that client and support their response.
International transfers
Travel inherently involves sharing data across borders with airlines, hotels, ground operators and immigration authorities in the destination country. Where personal data moves outside the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, or on the derogation permitting transfers necessary to perform a contract with the traveller.
Retention
We retain booking and financial records for the period required by Indian tax, accounting and audit law, and delete or anonymise personal data once it is no longer needed for the purpose it was collected for. Marketing data is retained until you opt out.
Security
We apply role-based access control, encryption of data in transit, supplier due diligence, activity logging and periodic access reviews. Our quality management system is certified to ISO 9001:2015.
Personal data breaches
We maintain an incident response process. Where a breach is likely to result in a risk to individuals, we notify the competent supervisory authority within 72 hours of becoming aware of it, and notify affected individuals and controller-clients without undue delay.
Sub-processors
We use travel technology providers, global distribution systems, payment processors and cloud hosting providers to deliver our services. A current list of sub-processors is available to clients on request.
Contact our data protection contact
Write to privacy@staycircle.in or Stay Circle Travel Solution Private Limited, Gurugram, Haryana, India.

