Legal

Privacy Policy

How Vini Holidayscollects, uses, shares and protects your personal data — and the rights you hold over it under India's Digital Personal Data Protection Act, 2023.

Effective date: 17 August 2026

1. Introduction & scope

Vini Holidays ("we", "us", "our") is a Destination Management Company offering tailor-made holiday planning, hotel and transport bookings, guided experiences and visa assistance across Asia, Europe and beyond. This Privacy Policy explains how we handle your personal data when you visit our website, submit an enquiry form, or contact us by phone, email or WhatsApp.

This policy is issued in compliance with the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the rules framed under it, and also reflects our obligations under the Information Technology Act, 2000 and applicable travel-industry regulations. If you are located outside India, additional local data protection laws may apply to you and we will honour those rights to the extent they are applicable.

Under the DPDP Act we act as the Data Fiduciary — the entity that determines the purpose and means of processing your personal data. You are the Data Principal — the individual to whom the personal data relates.

2. Who we are (Data Fiduciary details)

Data Fiduciary
Vini Holidays (DMC Worldwide)
India office
Office No 1483, 14th Floor, Space, Mall Office, Greater Noida W Rd, Gaur City 1, Sector 4, Greater Noida, Ghaziabad, Uttar Pradesh 201318
Azerbaijan office
Main Nizami Street, Xaqani Ticarat Marcazi, 2nd Floor, Shop No. 4, Baku, Azerbaijan
Email
info@viniholidays.com
Phone
+91 8796550862 · +91 8796550867 · +91 9667501437

Our designated Grievance Officer / data protection contact can be reached at info@viniholidays.com — see section 12 for the full grievance redressal process.

3. Personal data we collect

We practise data minimisation: we collect only the personal data necessary for the specific purpose for which it is being collected. Depending on how you interact with us, this may include:

  • Identity and contact data — your name, email address, phone number and country of residence, provided when you submit an enquiry form or contact us directly.
  • Travel enquiry data — your destination of interest, preferred travel dates, number and type of travellers, budget range, interests and the free-text message you send us.
  • Booking and traveller data (only once you proceed with a booking) — passport details, date of birth, nationality, gender as printed on travel documents, emergency contact, and the names of accompanying travellers.
  • Payment data — billing name and address, and transaction references. Card and banking credentials are captured and processed by our payment gateway or bank; we do not store full card numbers, CVV or net-banking passwords on our systems.
  • Special requirements you choose to disclose — dietary preferences, accessibility needs, or health information relevant to your itinerary or insurance. Where such data is sensitive we process it only with your explicit consent and only to fulfil the travel service.
  • Technical and usage data — IP address, browser and device type, referring page and pages viewed, recorded in aggregate by our hosting provider for security and site-performance purposes.
  • Correspondence — emails, WhatsApp messages and call records exchanged with our travel designers, retained as a record of your booking instructions.

4. Purposes for which we process your data

In line with the notice and purpose-limitation requirements of the DPDP Act, we process your personal data only for the purposes listed below. We will not use your data for a new, unrelated purpose without giving you a fresh notice and obtaining your consent.

  • To respond to your enquiry, prepare a quotation and design a proposed itinerary.
  • To make and manage bookings on your behalf with hotels, airlines, transport operators, guides, activity providers and insurers.
  • To process visa and travel-documentation applications with the relevant embassies, consulates and visa service centres.
  • To take payment, issue invoices and receipts, and process refunds or cancellations.
  • To provide customer support before, during and after your trip, including assistance in an emergency.
  • To send you service communications about a confirmed booking — vouchers, itineraries, schedule changes and travel advisories.
  • To send you marketing communications about offers and new destinations, only where you have separately consented, and always with an unsubscribe option.
  • To maintain our accounting, tax and statutory records, and to establish, exercise or defend legal claims.
  • To secure our website and systems, prevent fraud and misuse, and improve our services through aggregate, non-identifying analysis.

6. Children and persons with disability

Our website and services are directed at adults. We do not knowingly collect the personal data of a child (a person under 18 years of age) except as part of a family or group travel booking made by a parent or lawful guardian.

Where we process a child's personal data we do so only after obtaining verifiable consent from the parent or lawful guardian. As required by the DPDP Act we do not undertake tracking, behavioural monitoring or targeted advertising directed at children, and we do not process a child's data in any manner likely to cause a detrimental effect on their well-being. The same protection applies to a person with disability who has a lawful guardian.

If you believe a child's data has been provided to us without the required consent, contact info@viniholidays.com and we will verify and erase it.

7. Who we share your data with

We do not sell your personal data. We share it only as necessary to deliver the travel services you have asked for, or where the law requires it. Every Data Processor we engage is bound by a written contract limiting them to processing your data on our instructions, for our stated purposes only, with appropriate security safeguards.

  • Travel suppliers — hotels, resorts, airlines, rail and ground-transport operators, cruise lines, local DMC partners, guides and activity providers who need traveller details to honour the booking.
  • Embassies, consulates and visa facilitation centres, where you have asked us to assist with a visa application.
  • Insurance providers, where travel insurance is arranged as part of your package.
  • Payment gateways, banks and card networks, to collect payment and process refunds.
  • Technology service providers — our website host, our enquiry-delivery service (EmailJS), and our communication and storage tools — acting strictly as processors.
  • Professional advisers — auditors, accountants and lawyers — under a duty of confidentiality.
  • Government authorities, regulators, courts or law-enforcement agencies, where disclosure is required by an enforceable legal obligation.
  • An acquirer or successor entity, if our business is merged, acquired or reorganised, subject to this policy continuing to apply to your data.

8. Cross-border transfer of personal data

Because we arrange international travel, fulfilling your booking necessarily involves transferring your personal data outside India — for example to a hotel in Baku, an airline in Vietnam or a visa centre in Europe. Section 16 of the DPDP Act permits such transfers except to countries specifically restricted by notification of the Central Government, and we will not transfer data to any territory so restricted.

Where data is transferred abroad we send only the minimum fields the supplier needs, require contractual confidentiality and security commitments, and remain accountable to you as the Data Fiduciary for that data. Certain suppliers and authorities may also be subject to their own local disclosure laws.

9. Data retention and erasure

We keep your personal data only for as long as it is necessary for the purpose it was collected for, or for as long as the law requires us to keep it — whichever is longer. Indicative periods:

  • Enquiries that do not lead to a booking — retained for up to 24 months so we can resume the conversation if you return, then erased.
  • Booking, traveller and itinerary records — retained for the duration of the trip and for 8 years thereafter, in line with statutory accounting, tax and limitation-period requirements.
  • Invoices, payment records and tax documents — retained for the period prescribed by Indian tax and companies legislation.
  • Marketing contact details — retained until you unsubscribe or withdraw consent, after which your address is suppressed or deleted.
  • Website technical logs — retained in aggregate for a short period for security and diagnostics.

10. Security safeguards & breach notification

We implement reasonable technical and organisational safeguards to prevent a personal data breach, including encryption of data in transit (HTTPS/TLS), access controls on a need-to-know basis, staff confidentiality obligations, protected credentials for our booking and email systems, and periodic review of the processors we use.

No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security. In the event of a personal data breach we will notify the Data Protection Board of India and each affected Data Principal in the form and within the timelines prescribed under the DPDP Act, describing the nature of the breach, its likely consequences and the mitigation steps taken.

11. Your rights as a Data Principal

Chapter III of the DPDP Act gives you the following rights over your personal data. To exercise any of them, write to info@viniholidays.com. We will verify your identity before acting on a request and respond within the period prescribed under the Act.

Right to access information
Obtain a summary of the personal data we hold about you, the processing we undertake with it, and the identities of the other Data Fiduciaries and processors with whom it has been shared, along with a description of the data shared.
Right to correction and completion
Have inaccurate or misleading personal data corrected, and incomplete data completed or updated — important for passport and ticketing details, where a mismatch can prevent travel.
Right to erasure
Have your personal data erased where it is no longer needed for the purpose it was collected for, unless retention is required by law.
Right to withdraw consent
Withdraw your consent at any time, as easily as you gave it (see section 5).
Right of grievance redressal
Have a readily available means of registering a grievance with us about our handling of your data or our response to a rights request (see section 12).
Right to nominate
Nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.

12. Grievance redressal

If you have a question, concern or complaint about how your personal data is handled, contact our Grievance Officer:

Grievance Officer
Data Protection Contact, Vini Holidays
Email
info@viniholidays.com
Phone
+91 8796550862
Post
Office No 1483, 14th Floor, Space, Mall Office, Greater Noida W Rd, Gaur City 1, Sector 4, Greater Noida, Ghaziabad, Uttar Pradesh 201318

Please include your name, contact details, the nature of your grievance and any reference number for your enquiry or booking. We will acknowledge your grievance and respond within the timeline prescribed under the DPDP Act and its rules.

If you are not satisfied with our response, or we do not respond within the prescribed period, you may escalate the matter to the Data Protection Board of India as provided under the DPDP Act. Exhausting our internal grievance process first is a precondition to approaching the Board.

13. Your duties as a Data Principal

Section 15 of the DPDP Act places certain duties on you. When dealing with us, please:

  • Comply with applicable law when exercising your rights under the Act.
  • Do not impersonate another person when providing personal data — for group bookings, provide co-travellers' details only where you are authorised to do so, and make them aware of this policy.
  • Do not suppress material information when providing data that is legally required, such as passport or visa particulars.
  • Do not file a false or frivolous grievance or complaint.
  • Provide only verifiably authentic information when exercising your right to correction or erasure.

14. Cookies and website analytics

Our website is a statically generated marketing site and does not use advertising or cross-site tracking cookies. Essential browser storage may be used to remember interface preferences, and our host may record standard server logs for security and availability. If we introduce analytics or marketing cookies in future, we will present a cookie notice offering you a genuine choice before any non-essential cookie is set.

Our pages link to third-party services such as WhatsApp and our social media profiles. Once you follow such a link, that provider's own privacy policy governs your data.

15. Changes to this policy

We may update this policy to reflect changes in our services, technology or the law — including rules notified under the DPDP Act. The effective date shown at the top of this page indicates when it was last revised. Where a change materially affects how we use your personal data, we will give you a fresh notice and, where required, seek your consent again.

Questions about your data?

Write to info@viniholidays.com or call +91 8796550862. Our team will help you access, correct or erase your data, or withdraw your consent.