Legal Document

Privacy Policy

This policy explains what personal and health information Vedanjana Yoga & Ayurveda collects, how we use it, who we share it with, and what your rights are as a data subject.

Last Updated: 1 January 2025
Effective: 1 January 2025
Version: 3.2
Controller: Vedanjana Yoga & Ayurveda Pvt. Ltd.

01 Who We Are

Vedanjana Yoga & Ayurveda Private Limited ("Vedanjana", "we", "us", "our") operates a residential Ayurvedic healing retreat and online yoga platform at Tapovan, Laxman Jhula, Rishikesh, Uttarakhand 249201, India.

For the purposes of applicable data protection law — including the Information Technology (Amendment) Act 2008 (India), the Digital Personal Data Protection Act 2023 (India), and the EU General Data Protection Regulation (GDPR) where applicable to European residents — Vedanjana Yoga & Ayurveda Pvt. Ltd. is the data controller responsible for your personal information.

Our commitment: We handle all personal and health information with the utmost confidentiality and discretion. Health records collected during your programme are treated as medically confidential and are never shared without your explicit written consent.

02 Data We Collect

We collect personal information in the following categories:

Identity & Contact Information

  • Full name, date of birth, nationality and gender
  • Email address, phone number and postal address
  • Passport or government-issued ID number (for check-in compliance only)
  • Emergency contact name and relationship

Booking & Payment Information

  • Programme selected, arrival date, duration and preferences
  • Payment method and transaction identifiers (card details are processed by Razorpay and are never stored on our servers)
  • Correspondence with our team before and during your stay

Website & Technical Information

  • IP address, browser type and device information
  • Pages visited, time spent and navigation patterns
  • Cookie identifiers (see Section 9)
  • Referral source (how you found our website)

Communication Records

  • Emails, WhatsApp messages and phone calls to and from our team
  • Reviews or testimonials you voluntarily submit
  • Survey responses and feedback forms

03 Health & Medical Information

Special category data: Health information is classified as "special category" data under GDPR and equivalent regulations. We treat this information with heightened protection and collect it only with your explicit consent, which you provide when completing our health intake form and agreeing to our terms.

We collect health information necessary to provide safe, personalised Ayurvedic care, including:

  • Current medical conditions, diagnoses and symptoms
  • Current and past medications and supplements
  • Surgical history and significant medical history
  • Allergies, dietary restrictions and sensitivities
  • Mental health history relevant to treatment planning
  • Reproductive health information (for relevant programmes)
  • Lifestyle information including diet, sleep and exercise patterns
  • Physician's clinical notes from consultations during your stay
  • Pulse diagnosis (Nadi Pariksha) and Prakriti assessment records
  • Treatment session notes and progress observations

Your health records are accessible only to the Vedanjana clinical team directly involved in your care. They are never shared with third parties without your written consent, except where required by Indian law (e.g., public health emergencies) or to prevent immediate risk to life.

04 How We Use Your Information

PurposeData UsedLegal Basis
Providing your Ayurvedic programme and clinical careIdentity, health, booking dataContract + Explicit Consent
Processing your booking and paymentIdentity, contact, payment dataContract performance
Sending confirmation emails and Zoom linksName, email addressContract performance
Pre-arrival physician consultationHealth history, contact dataExplicit consent
Post-programme follow-up and home protocolHealth, contact dataExplicit consent
Sending wellness newsletters (if opted in)Name, email addressLegitimate interest / Consent
Improving our programmes and websiteAnonymised usage dataLegitimate interest
Legal and regulatory complianceAs requiredLegal obligation

We do not use your personal or health data for advertising, profiling or automated decision-making that produces legal or similarly significant effects.

05 Legal Basis for Processing

Under GDPR and equivalent regulations, we process your data on the following legal bases:

  • Contract performance: Processing necessary to fulfil your booking and provide your programme.
  • Explicit consent: For health data and for optional communications such as newsletters. You may withdraw consent at any time without affecting prior processing.
  • Legitimate interests: For improving our services, ensuring website security and conducting anonymised analytics — where these interests are not overridden by your rights.
  • Legal obligation: Where processing is required by applicable Indian law.

06 Sharing Your Data

We share personal data only as follows, and never sell data to third parties:

Service Providers

  • Razorpay: Payment processing (card and UPI data). Subject to their own privacy policy and PCI-DSS compliance.
  • Google (Workspace): Email communications and calendar management.
  • Zoom Video Communications: Online yoga class delivery. Zoom's privacy policy applies to session data.
  • SMS and WhatsApp: Programme communications via Meta Business Platform.

Legal Disclosure

We may disclose information to government authorities or law enforcement where required by Indian law, court order, or where necessary to prevent serious harm to a person's life or safety.

Business Transfers

In the event of a merger, acquisition or sale of Vedanjana, personal data may transfer to the acquiring entity, subject to the same privacy protections described here.

Health data: Your medical and health records are never shared with any third party — including family members not designated by you as your emergency contact — without your explicit written consent.

07 Data Retention

We retain your data for the following periods:

  • Health and clinical records: 7 years from your last treatment (Indian medical records requirement). After this period, records are securely destroyed.
  • Booking and financial records: 7 years for tax and accounting compliance.
  • Marketing communications: Until you unsubscribe or withdraw consent.
  • Website analytics: 26 months in anonymised form.
  • Correspondence: 3 years from the date of last contact.

You may request early deletion of personal data (subject to our legal retention obligations) by contacting us at privacy@vedanjanayoga.com.

08 Your Rights

Depending on your location, you have the following rights regarding your personal data:

  • Right of access: Request a copy of all personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your data (subject to legal retention requirements).
  • Right to restrict processing: Request that we limit how we use your data.
  • Right to portability: Receive your data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent: Withdraw consent for health data or marketing at any time.

To exercise any of these rights, email privacy@vedanjanayoga.com with "Data Rights Request" in the subject line. We will respond within 30 days. Identity verification may be required before processing requests relating to health data.

09 Cookies & Tracking

Our website uses the following types of cookies:

  • Strictly necessary cookies: Required for the website to function (booking form sessions, payment processing). Cannot be disabled.
  • Analytics cookies: Google Analytics (anonymised) to understand how visitors use our site. You may opt out via browser settings or the Google Analytics opt-out browser add-on.
  • Preference cookies: Remember your language and display preferences.

We do not use advertising cookies, retargeting cookies, or social media tracking pixels on our main site. You can manage cookie preferences through your browser settings. Disabling non-essential cookies will not affect your ability to book a programme.

10 Data Security

We implement technical and organisational measures to protect your personal data, including:

  • SSL/TLS encryption for all data transmitted to and from our website
  • Access controls limiting health data to treating clinical staff only
  • Encrypted storage of clinical records on password-protected systems
  • Regular security training for all staff who handle personal data
  • Paper health forms stored in locked filing in our clinic and destroyed after digitisation

Despite our measures, no system is completely immune from breach. In the event of a data breach affecting your rights, we will notify you within 72 hours as required by applicable law.

11 Children's Privacy

Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from anyone under 16 without verifiable parental or guardian consent. Guests under 18 must be accompanied by a parent or guardian who consents to data collection on their behalf. If you believe we hold data for a child without proper consent, please contact us immediately at privacy@vedanjanayoga.com.

12 Contact & Complaints

For any privacy-related enquiry, request or complaint:

If you are located in the European Economic Area and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. A list of EU data protection authorities is available at edpb.europa.eu.

We may update this Privacy Policy from time to time. Material changes will be communicated by email to registered guests and by a prominent notice on our website for at least 30 days before they take effect.