Effective date: July 19, 2026
Company: Digibeds Technologies Private Limited (“Digibeds”, “we”, “us”), India
1. Who We Are and Scope
Digibeds Technologies Private Limited (India) is the data controller for personal data collected through this website and the data processor (and, for account administration, a controller) for personal data processed inside the Digibeds cloud software on behalf of hotel and restaurant customers. This Policy covers website visitors, prospects, customer staff users, guests whose data customers process in the platform, and Open API integration usage.
2. Personal Data We Collect
- Contact and business data: name, email, phone, company/property details, billing details, correspondence.
- Account and usage data: login identifiers, roles, device/browser type, IP address, log and security events, feature usage.
- Platform data processed for customers: reservations, guest profiles and stay details, rates, invoices, POS transactions and related operational records supplied by the customer.
- Payment data: processed by PCI-DSS-compliant payment gateways; Digibeds does not store full card numbers.
- Cookies: essential cookies for sessions and security, and limited analytics (see Section 8).
3. Purposes and Legal Bases (GDPR / UK GDPR)
- Providing and securing the Service — performance of a contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f));
- Billing, accounting and tax — legal obligation (Art. 6(1)(c));
- Responding to enquiries and demos — contract steps and legitimate interests;
- Product updates and service notices — legitimate interests; marketing where required only with consent (Art. 6(1)(a)), withdrawable at any time;
- Security monitoring, fraud and abuse prevention — legitimate interests and legal obligation.
4. India — Digital Personal Data Protection Act, 2023 and IT Act
- Digibeds processes digital personal data for the lawful purposes above with notice and, where required, consent that can be withdrawn at any time.
- Data principals may access, correct, update and request erasure of their personal data, and may nominate another individual to exercise rights in case of incapacity or death.
- Grievances are handled by our Grievance Officer, reachable at [email protected]; we respond within the timelines prescribed by law.
- Reasonable security safeguards are maintained as required by the DPDP Act and the Information Technology Act, 2000.
5. United States — State Privacy Rights (CCPA/CPRA and similar laws)
- Depending on your state (e.g., California, Virginia, Colorado, Connecticut, Utah, Texas), you may have rights to know/access, correct, delete and obtain a portable copy of your personal information, and to opt out of “sale” or “sharing” of personal information and certain profiling.
- Digibeds does not sell personal information and does not share it for cross-context behavioural advertising.
- We do not discriminate against anyone for exercising privacy rights. Requests can be made via the contact details below; authorised agents may act where the law allows, subject to verification.
6. Other Major Jurisdictions
- United Kingdom: rights equivalent to the GDPR apply under the UK GDPR and Data Protection Act 2018.
- Canada (PIPEDA): we process personal information with appropriate consent and provide access and correction rights.
- Australia (Privacy Act 1988, APPs): we handle personal information consistently with the Australian Privacy Principles, including access and correction.
- Singapore (PDPA): consent, purpose limitation, access and correction obligations are respected.
- European Economic Area: EU GDPR applies as described in Section 3, including all data-subject rights in Section 9.
7. Sharing, Subprocessors and International Transfers
- We share personal data only with: service providers/subprocessors that help operate the platform (hosting, email delivery, support tooling, payment gateways) under contractual safeguards; parties the customer instructs us to connect (e.g., OTAs, payment providers); and authorities where required by law.
- Where personal data is transferred across borders, we use lawful transfer mechanisms such as the EU Standard Contractual Clauses (with the UK addendum where relevant), adequacy decisions, or equivalent safeguards required by local law, including India’s DPDP Act transfer rules.
- A list of material subprocessors is available to customers on request; data processing agreements (DPAs) are available for signature.
8. Cookies and Analytics
Essential cookies keep sessions, security and load balancing working and cannot be switched off in our systems. Limited analytics help us understand aggregate website usage. Where local law requires consent for non-essential cookies, they are used only after consent, which can be withdrawn at any time via the cookie banner or browser settings.
9. Your Rights and How to Exercise Them
- Access, correction/rectification, deletion/erasure, restriction of processing, objection, data portability and withdrawal of consent, in each case as provided by the law that applies to you (GDPR/UK GDPR, DPDP Act 2023, US state laws, PIPEDA, APPs, PDPA and others).
- To exercise rights, email [email protected]. We may verify your identity before acting and will respond within the legally required timeframe (e.g., one month under the GDPR, 45 days under the CCPA/CPRA, or as prescribed locally).
- If you are unsatisfied, you may complain to your supervisory authority (e.g., your EU/UK data protection authority, the Data Protection Board of India, your US state Attorney General, the OPC in Canada, or the OAIC in Australia).
- Guest data inside a hotel’s account is controlled by that hotel; where you contact us about it, we will assist and refer the request to the relevant customer as the law requires.
10. Retention
We retain personal data only as long as needed for the purposes above: for the life of the customer relationship plus a limited post-expiry export window; for billing/tax records as mandated by law; and for security logs for a limited operational period — after which data is deleted or irreversibly anonymised.
11. Security
We apply the safeguards described in the Software as a Service Policy: TLS encryption in transit, salted hashing of credentials and API tokens, role-based access control, environment separation, monitoring, backups and incident response. In the event of a notifiable breach, we will notify affected customers and authorities as required by applicable law.
12. Children
The website and Service are business tools and are not directed at children. We do not knowingly collect personal data from children below the age where parental consent is required; guest records of minors inside a hotel’s account are processed solely on the customer’s instructions.
13. Automated Decision-Making
Digibeds does not make decisions producing legal or similarly significant effects about individuals based solely on automated processing.
14. Changes to this Policy
We may update this Policy from time to time. The current version, with its effective date, is always published on this page; material changes will be notified to active customers.
Contact
Questions about this document: email [email protected] or call 08040265786.