Data Protection

Privacy Policy

Your privacy matters to us. This policy explains what data we collect, how we use it, and the controls you have over your information — written in plain language.

No data selling
AES-256 Encryption
India-hosted Data
GDPR-aligned Practices
Effective: 1 January 2026
Last Updated: 1 June 2026
Jurisdiction: India
Section 01
Overview & Scope

This Privacy Policy ("Policy") describes how Exergy Infotech, operating as SaralDesk ("we", "us", "our"), collects, uses, stores, and protects personal information when you visit our website, create an account, or use our hospitality management platform and services.

This Policy applies to all users of SaralDesk, including hotel owners, restaurant operators, their staff members, and end guests whose information is processed through the Platform. By using SaralDesk, you consent to the practices described in this Policy.

Our Core Privacy Commitment

We collect only what we need, use it only for stated purposes, store it securely in India, and never sell it. We believe your data belongs to you — we are simply its custodian while you use our platform.

This Policy should be read alongside our Terms & Conditions. In the event of any conflict between the two documents, the Terms & Conditions shall prevail.

Section 02
Data We Collect

We collect different categories of data depending on your relationship with SaralDesk:

A. Account & Business Data (Subscribers)
  • Full name, business name, and designation of the account holder.
  • Email address, mobile number, and WhatsApp number.
  • Business address, GST number, and PAN number (for billing and compliance).
  • Payment details processed securely through our payment gateway partner (Razorpay). We do not store raw card numbers.
  • Subscription history, plan details, and billing records.
B. Guest Data (Processed on Your Behalf)
  • Guest name, contact number, email, and address entered during check-in.
  • Government-issued identity document scans or uploads (Aadhaar, Passport, Driving Licence) required for Police Form C compliance.
  • Nationality, date of birth, and purpose of visit (for foreign nationals under the Foreigners Act, 1946).
  • Booking dates, room preferences, and stay history.
Data Processor Role

For guest data, SaralDesk acts as a Data Processor on your behalf. You (the hotel/restaurant owner) are the Data Controller and remain responsible for obtaining appropriate consent from your guests for data collection and retention as required under applicable law.

C. Usage & Technical Data
  • IP address, browser type, operating system, and device identifiers.
  • Pages visited, features used, session duration, and clickstream data.
  • Error logs, crash reports, and performance diagnostics.
  • Geolocation data (city/region level only, derived from IP address).
Section 03
How We Use Your Data
PurposeData UsedBasis
Providing the Platform Account data, subscription data Contract
Processing Payments Billing data, GST number Contract
Police Form C Compliance Guest identity data, nationality Legal Obligation
Customer Support Account data, usage data Legitimate Interest
Platform Improvement Anonymised usage data, crash logs Legitimate Interest
Marketing Communications Email address, name Consent
Security & Fraud Prevention Technical data, IP address Legitimate Interest
Legal Compliance & Audits Billing records, contracts Legal Obligation

We will never use your data for purposes not listed above without obtaining your explicit consent in advance.

Section 04
Legal Basis for Processing

SaralDesk processes personal data under the following legal bases in accordance with India's Digital Personal Data Protection Act, 2023 (DPDPA) and internationally recognised data protection principles:

  • Consent: For marketing emails, newsletters, and non-essential cookies. You may withdraw consent at any time without affecting prior processing.
  • Contractual Necessity: Processing required to deliver the Services you have subscribed to, including account management and billing.
  • Legal Obligation: Processing required to comply with Indian law, including Police Form C filing under the Foreigners Act, 1946, and GST record-keeping under the CGST Act, 2017.
  • Legitimate Interest: Processing for security monitoring, fraud prevention, product analytics, and platform improvement, where such interests are not overridden by your rights.
Section 05
Data Sharing & Disclosure

SaralDesk does not sell, rent, or trade your personal data. We share data only in the following limited circumstances:

Service Providers (Sub-Processors)
  • Razorpay — Payment processing. Governed by Razorpay's own PCI-DSS certified privacy practices.
  • Cloud Infrastructure Provider — Secure data hosting within India (AWS Mumbai / equivalent).
  • Communication Services — Transactional email and SMS delivery (OTP, invoices, alerts).
  • Analytics Tools — Anonymised, aggregated usage analytics to improve Platform performance.

All sub-processors are bound by contractual data processing agreements that require them to maintain confidentiality and security standards equivalent to ours.

Legal & Regulatory Disclosure

We may disclose your data if required to do so by a valid court order, government authority, or applicable law — including to law enforcement for guest records under the Foreigners Act or in the investigation of a crime. We will notify you of such requests where legally permitted to do so.

We Will Never

Sell your personal data or your guests' data to advertisers, data brokers, or any third party for commercial purposes. This is a firm commitment, not just a policy — it is contrary to our business model and values.

Section 06
Cookies & Tracking Technologies

SaralDesk uses cookies and similar tracking technologies on our website and platform. Cookies are small text files stored on your device that help us deliver and improve our Services.

Cookie TypePurposeDurationCan Opt Out
Essential Login sessions, security tokens, CSRF protection Session No
Functional Language preference, UI settings, last-viewed module 1 year Optional
Analytics Page views, feature usage, performance monitoring 90 days Yes
Marketing Retargeting, campaign tracking (only on public website) 30 days Yes

You can manage or withdraw cookie consent at any time via the Cookie Preferences banner on our website or through your browser settings. Note that disabling essential cookies will prevent you from logging into the Platform.

Section 07
Data Storage & Security

We take extensive technical and organisational measures to protect your data from unauthorised access, disclosure, alteration, or destruction.

AES-256 EncryptionData at rest & in transit
India-hostedGeo-redundant cloud vaults
Daily Backups30-day backup retention
2FA AvailableFor all staff accounts
  • All data is transmitted over HTTPS / TLS 1.2+ encrypted connections.
  • Access to production data is restricted to authorised engineers under a strict role-based access control (RBAC) policy.
  • Identity documents uploaded for Police Form C are stored in isolated, encrypted vaults with limited access controls.
  • Regular security audits and vulnerability assessments are conducted on our infrastructure.
  • In the event of a data breach affecting your personal data, we will notify you and relevant authorities within 72 hours of becoming aware of the breach.

While we implement industry-leading security practices, no method of transmission or storage is 100% secure. We encourage you to use strong passwords and enable two-factor authentication on your account.

Section 08
Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, comply with legal obligations, and resolve disputes.

Data CategoryRetention PeriodReason
Account & Subscriber Data Active subscription + 90 days post-cancellation Service delivery & data export window
Billing & GST Records 7 years from transaction date Indian Income Tax & GST Act requirements
Guest Identity Documents As required by the Foreigners Act (typically 1 year); configurable by property Regulatory compliance
Guest Booking Records Subscriber's account duration + 90 days Operational records
Usage & Analytics Data 90 days (anonymised thereafter) Platform improvement
Support & Communication Logs 3 years from last interaction Service quality & dispute resolution

Upon expiry of the applicable retention period, data is securely and permanently deleted from all active systems and backup storage within 30 days of the deletion trigger.

Section 09
Your Rights

Under the Digital Personal Data Protection Act, 2023 and internationally recognised data protection frameworks, you have the following rights regarding your personal data:

Right to Access
Request a copy of the personal data we hold about you and how it is being used.
Right to Correction
Request correction of inaccurate or incomplete personal data held by us.
Right to Erasure
Request deletion of your personal data where it is no longer necessary or lawful to retain it.
Right to Portability
Receive your data in a machine-readable format (CSV/JSON) for transfer to another service.
Right to Object
Object to processing of your data for direct marketing or where based on legitimate interests.
Right to Withdraw Consent
Withdraw consent at any time for processing based on consent, without affecting prior processing.
How to Exercise Your Rights

Submit your request to privacy@saraldesk.com with the subject line "Data Rights Request". We will respond within 30 days. In complex cases, this may be extended by an additional 30 days with prior notice. Requests are free of charge.

Section 10
Children's Privacy

SaralDesk's Platform and Services are intended for use by business owners, operators, and their staff who are 18 years of age or older. We do not knowingly collect, store, or process personal data from individuals under the age of 18.

In the context of hotel guest management, guest records may include details of minor guests as part of a family booking. Such data is collected by the hotel (the Data Controller) for regulatory compliance purposes and is processed by SaralDesk solely as a Data Processor on the hotel's instructions.

If you believe that we have inadvertently collected personal data from a child under 18 in our subscriber base, please contact us immediately at privacy@saraldesk.com and we will take prompt action to delete such data.

Section 11
Third-Party Links & Integrations

The SaralDesk website and Platform may contain links to third-party websites, tools, or services — such as payment gateways, social media platforms, or documentation portals. This Privacy Policy applies solely to data processed by SaralDesk and does not cover the privacy practices of any third-party websites or services.

We encourage you to review the privacy policies of any third-party services you interact with. SaralDesk is not responsible for the privacy practices or content of external websites accessed via links from our Platform.

Payment Gateway

All payment processing is handled by Razorpay. SaralDesk does not receive or store raw card data. Razorpay is PCI-DSS Level 1 certified. For details on how Razorpay handles your payment data, please refer to Razorpay's Privacy Policy at razorpay.com/privacy.

Section 12
Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Services we offer. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page.
  • Send an email notification to your registered email address at least 14 days before the changes take effect.
  • Display a prominent notice on the Platform dashboard informing you of the update.

For minor, non-material changes (such as typographical corrections or clarifications that do not affect how we use your data), we may update this page without prior notice.

Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you disagree with a material change, you have the right to close your account and request deletion of your data before the change takes effect.

Section 13
Contact & Grievance Redressal

If you have any questions, concerns, or complaints regarding this Privacy Policy or our data handling practices, please contact our Data Protection Officer (DPO):

Contact TypeDetails
Data Protection Officer privacy@saraldesk.com
General Privacy Queries support@saraldesk.com
WhatsApp Support +91 98935 60964
Response Time Within 30 days of receiving your request
Registered Address Exergy Infotech, Indore, Madhya Pradesh, India
Grievance Redressal

In accordance with the Digital Personal Data Protection Act, 2023, if you believe your data rights have been violated, you may first raise a grievance with us. If unsatisfied with our response, you may escalate to the Data Protection Board of India once operational, or approach the appropriate courts of jurisdiction in Indore, Madhya Pradesh.