Last Updated: May 2026
Garuda Technologies ('we', 'us', or 'our') is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, share, and protect information about you when you visit garudatechnologies.co.in, use our IT and digital services, or make travel bookings through our travel brands. This policy is compliant with India's Digital Personal Data Protection Act (DPDPA) 2023.
Data Type | What We Collect and When |
Contact information | Name, phone number, email address, and company name provided when you contact us, submit a form, or request a quote. |
Booking information | For travel bookings: passenger names, travel dates, passport details (where required by airline/visa), and payment information. |
IT project information | Website URL, business details, and project requirements shared during IT service consultations. |
Usage data | IP address, browser type, pages visited, time on site, and referring URL collected automatically via cookies and analytics tools. |
Communication data | Emails, chat messages, and call notes from interactions with the Garuda Technologies team. |
Payment data | We do not store full payment card details. Payment processing is handled by certified payment gateways. We retain transaction reference numbers and amounts for billing records. |
Purpose | How Your Data Is Used |
Service delivery | Processing IT project requirements, delivering completed services, and managing travel bookings on your behalf. |
Communication | Responding to inquiries, sending project updates, booking confirmations, and service-related notifications. |
Billing and accounts | Generating invoices, processing payments, and maintaining financial records as required by Indian accounting law. |
Website improvement | Analyzing usage data to improve website content, performance, and user experience. |
Marketing (with consent) | Sending information about new services, offers, and industry insights where you have provided explicit consent. You may withdraw consent at any time. |
Legal compliance | Retaining records as required by Indian law, including GST records for 7 years and travel booking records for the duration required by applicable regulations. |
We process your personal data on the following legal bases under the DPDPA 2023: your consent (for marketing communications and non-essential cookies), the performance of a contract (for service delivery and travel bookings), compliance with legal obligations (for tax and regulatory record-keeping), and legitimate interests (for website analytics and security monitoring).
Garuda Technologies does not sell your personal data to third parties. We share your data only in the following circumstances:
• Travel service providers: Airlines, hotels, cruise lines, and car rental operators require booking information (passenger names, travel dates, contact details) to confirm reservations.
• Payment processors: Transaction data is shared with certified payment gateway providers to process payments securely.
• Technology partners: IT service delivery may involve subcontractors or cloud service providers (AWS, Google Cloud, Microsoft Azure) who process data on our behalf under data processing agreements.
• Legal authorities: We disclose data to law enforcement or regulatory authorities when required by applicable Indian law or court order.
Data Category | Retention Period |
IT project data | Retained for the duration of the engagement plus 3 years for reference and support purposes. |
Travel booking data | Retained for 7 years from the booking date for GST and financial compliance purposes. |
Marketing preferences | Retained until you withdraw consent. Withdrawal requests processed within 30 days. |
Website analytics | Anonymized aggregate data retained indefinitely. Individual session data retained for 26 months (Google Analytics standard). |
Communication records | Email and call records retained for 2 years from last interaction. |
• Right to access: Request a copy of the personal data we hold about you.
• Right to correction: Request correction of inaccurate or incomplete personal data.
• Right to erasure: Request deletion of your personal data where it is no longer necessary for the purposes collected.
• Right to withdraw consent: Withdraw consent for marketing communications at any time without affecting processing based on other legal grounds.
• Right to grievance redressal: Raise concerns with our Data Protection Officer at info@garudatechnologies.co.in.
Requests under these rights will be processed within 30 days of receipt. Identity verification may be required before processing access or erasure requests.
Garuda Technologies implements appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include SSL/TLS encryption for data in transit, access controls limiting data access to authorized personnel, regular security audits of systems handling personal data, and secure deletion procedures for data no longer required.
Travel booking data may be transferred to airlines, hotels, and travel service providers operating outside India when you book international travel. Such transfers occur because they are necessary to perform the travel booking contract. We ensure that international service providers maintain appropriate data protection standards.
Garuda Technologies does not knowingly collect personal data from children under the age of 18 without verified parental consent. If you believe we have inadvertently collected data from a minor, contact us immediately at info@garudatechnologies.co.in and we will delete the data promptly.
For privacy-related questions, data subject requests, or concerns: Data Protection Contact: Garuda Technologies | Email: info@garudatechnologies.co.in | Phone: +91-9910844235 | Address: Plot No. 750, Udyog Vihar Phase V Rd, Phase V, Udyog Vihar, Sector 19, Gurugram, Haryana 122016.