This document is a digital document in phrases of Information Technology Act, 2000 and rules there beneath as applicable and the amended provisions relating electronic statistics in diverse statutes as amended by the Information Technology Act, 2000. This electronic record is generated by way of a laptop device and does not require any bodily or virtual signatures.
This file is published according with the provisions of Rule three (1) of the Information Technology Rules, 2011 that require publishing the policies and regulations, privateness coverage and Terms of Use for getting right of entry to or utilization of www.affordd.Com
The domain name www.affordd.com is owned and operated by Innovbit Technologies OPC Pvt. Ltd. a Private Company limited by shares, incorporated under the provisions of the Companies Act, 2013, and having its registered office at 1/34, Virat Khand, Gomti Nagar, Lucknow UP, 226010, India, where such expression shall, unless repugnant to the context thereof, be deemed to include its respective representatives, administrators, employees, directors, officers, agents and their successors and assigns.
At Affordd Hotels, protecting our guests' personal data is a foundational element of our commitment to hospitality. Whether you're browsing our digital platforms, checking availability, enrolling in loyalty programs, or staying at our property, this policy outlines how your personal information is treated with confidentiality, transparency, and purpose across all touchpoints.
We believe that every individual deserves clear and accountable data protection. From consent to collection, and from usage to retention, this policy explains your rights, our obligations, and how we ensure your trust is never compromised. We also recognize that trust is built not only through service excellence but through ethical digital practices. We’ve established this policy to empower our users with complete knowledge of their rights and our duties in the evolving landscape of information privacy and hospitality technology.
We define key terms that appear throughout this policy to eliminate ambiguity. By clarifying these definitions, we ensure consistent understanding and alignment between our guests, and our data protection protocols, fostering transparent digital engagement and meaningful control for users:
These definitions are consistent with standard interpretations under Indian IT law and international privacy norms like GDPR and CCPA.
We treat data with the same care and respect we offer our guests. Our collection processes are minimal, our retention is purpose-bound, and our sharing is always regulated. Ethical processing is not an option, it is our standard.
Data ethics is not just about compliance, it's about commitment. We implement a culture of 'privacy by design' across departments, training staff to recognize the sensitivity and context of personal information. This philosophy informs every digital and physical process at our hotel. Every member of our team is sensitized to ensure that guest privacy is not only maintained but prioritized in all operations be it through secure guest records, discreet communication, or responsibly managed vendor access.
We gather data in three primary ways:
Each source of data is documented and stored under policy-compliant conditions. Our data capture procedures are aligned with lawful purposes and include digital safeguards like encrypted form submissions, secured booking channels, and verification-based access control to ensure authenticity.
Data is used solely for guest service delivery, customer support, marketing, compliance, and business insights. Your data supports booking confirmations, payment processing, room personalization, loyalty point tracking, and reward program operations.
Additionally, we may use data for internal audits, market segmentation analysis, and service improvements. We believe in using data to enhance and not exploit guest experiences. Data helps us identify service bottlenecks, assess demand patterns, and introduce innovations like smart-room access, predictive housekeeping, or location-based concierge recommendations. All processing is done with transparency, accountability, and meaningful guest control.
We may share your data with:
Every external engagement is governed by signed data processing agreements and non-disclosure terms. We continuously vet our partners to maintain the integrity of our data ecosystem. We restrict access only to those entities with a direct service delivery mandate, ensuring that shared data is limited in scope, securely transmitted, and promptly deleted upon fulfilment of purpose.
We implement a multi-layered security framework:
Data security is a living process, not a one-time implementation. We regularly review our defences and train our team on emerging cyber threats and mitigation strategies. From guest reservation systems to archived visitor logs, our information architecture is reinforced with both digital and physical security layers. Devices are patched routinely, access credentials are monitored, and suspicious activity triggers immediate review.
Under applicable laws, you can:
These rights empower you to remain in control of your personal data. Our privacy team ensures requests are handled promptly, with a turnaround time of no more than 15 business days unless legally extended. You may exercise your rights through email, in writing, or via secure account login portals. We believe privacy should be accessible, not just enforceable.
Data is stored only for durations legally required or operationally necessary:
All expired data is either anonymized for research purposes or completely purged through secure deletion protocols. For digital systems, we implement scheduled deletion automation backed by audit logs to verify that no obsolete data remains in operational use.
Cookies help us:
You have the option to accept or reject cookies. Non-important cookies require explicit consent through our cookie banner. You can revoke or modify cookie preferences anytime from your browser or account settings. Our site is also compatible with cookie preference managers to enhance consent-based controls.
Our website or app may link to third-party tools like:
These parties work independently and hold separate privacy policies. We recommend reviewing their terms before engagement. These integrations exist to enhance functionality, not to compromise your autonomy. Where third-party tools collect personal data, our system will flag the interaction for your confirmation where applicable.
We do not track data from any under 18 where such data is inadvertently obtained, we will erase it upon verification. Parental or guardian consent is mandatory for any services involving minors.
We take additional precautions when handling sensitive information relating to families, and we never target children in marketing communications. Any child-related data that must be stored (e.g., dietary needs for family rooms) is stored in isolation from marketing systems and deleted upon checkout.
If you have privacy concerns or wish to report data misuse or request rectification, please reach out to our designated data protection authority:
Our grievance officer is trained in data privacy law and empowered to investigate and resolve issues within defined legal timelines. All grievances are acknowledged within 72 hours and resolved based on priority and complexity.
This policy is subject to revision and refinement in accordance with evolving legal, technological, and business requirements. Major updates will be communicated via our website and through email notifications where appropriate. We may modify content, restructure sections, or add new provisions to reflect better clarity, alignment with updated data protection regulations, or improvements to guest data interaction protocols.
We encourage all users, both new and returning, to review this document periodically to stay informed about how we safeguard your personal data and update our practices. Continued use of our services after updates constitutes acceptance of the revised policy terms.
This policy shall be governed by, and interpreted in accordance with, the applicable laws of the Republic of India. Disputes arising from or related to the interpretation, execution, or validity of this policy shall be subject to the exclusive jurisdiction of the competent courts located in the respective City.
We aim to resolve all concerns through mutual discussion and conciliation wherever possible. If resolution cannot be achieved amicably, the matter shall proceed to arbitration under the Arbitration and Conciliation Act, 1996. The arbitration proceedings shall be conducted in English, with a sole arbitrator appointed mutually by both parties. The location of arbitration shall be respected by the City, unless otherwise agreed upon.
By using our services, you agree to abide by these terms, including the mechanisms of dispute resolution laid out herein.
We Follow Indian Government Guideline: - https://tourism.gov.in/sites/default/files/2020-02/Hotel_Guidelines_From%2019-01-2018.pdf