Mynnt Hospitality Book now

LegalMynnt HospitalityNew Delhi

Privacy policy

How Mynnt Hospitality collects, uses, shares and protects your personal data across our hotels, apartments and restaurants — and the rights you hold under India’s Digital Personal Data Protection Act, 2023.

Effective [date to be confirmed] Version 1.0 DPDP Act 2023

At a glance

18

Sections

Read in full, or jump to one

05

Properties covered

Hotels, apartments and restaurants

03

Years

Upto, for guest and booking records

90

Days

Within which we resolve a grievance

01

Section one

Who we are

Mynnt Hospitality (“Mynnt”, “we”, “us”, “our”) is a hospitality group in New Delhi. Under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) we act as the Data Fiduciary for the personal data described here, and you are the Data Principal.

This policy applies to all our properties: The Chapter Hotel, Hotel HomeAste, HomeAste Apartment, Mark’s Eatery and Vertigo.

The fiduciary

Mynnt Hospitality Plot 74, Pocket 10, Sector 23B, Dwarka
New Delhi – 110078, India
GSTIN 07ACIFM1473F1Z9 info@mynnthospitality.com · +91 89296 66600

02

Section two

What this policy covers

It covers personal data we handle when you visit this website, make an enquiry or booking, stay with us, eat with us, hold an event with us, or apply for a job.

It does not cover third-party sites you reach from ours. When you book through Booking.com, Airbnb or Zomato, that platform handles your data under its own policy as well as ours — read theirs too.

03

Section three

The data we collect

Identity & contact
Name, phone number, email address, postal address, nationality, and the names of others in your party.
Statutory identification
Indian law requires hotels to record guest identity at check-in. We collect government photo ID, and for foreign nationals the passport and visa details needed for Form C reporting to the Bureau of Immigration. We record only what the law requires.
Booking & stay
Dates, room or table, number of guests, occasion, arrival time, dietary or accessibility requirements, requests you make during the stay, and your booking history with us.
Payment
Amount, date, method and transaction reference, plus the billing name and GST number where you need an invoice. We do not store full card numbers. Card payments are handled by our payment gateway on its own systems.
Website & device
IP address, browser and device type, pages viewed, the site that referred you, and approximate location derived from IP. Collected through cookies — see section 15.
CCTV
Camera footage of public and common areas of our properties. See section 13.
Feedback & correspondence
Reviews, complaints, survey answers, and messages you send us by email, phone or WhatsApp.
Recruitment
If you apply to work with us: your CV, work history, qualifications and references.
What we do not ask for We do not seek sensitive data such as religion, caste, health or biometrics. If you volunteer a dietary, medical or accessibility need so we can look after you, we use it only for that purpose.

04

Section four

How we collect it

Directly from you
Enquiry forms on this site, phone, WhatsApp, email, or in person at the front desk.
From booking platforms
Booking.com, Airbnb, Zomato and similar partners pass us the details needed to honour your reservation.
Automatically
Cookies and server logs while you use this website.
From a person booking for you
A colleague, travel desk or event organiser. If you book for someone else, please make sure they have seen this policy.

05

Section five

Why we use it, and on what basis

Under the DPDP Act we process personal data either with your consent, or for a legitimate use the Act permits — including where you have voluntarily given us data for a purpose and have not objected to its use for that purpose.

To answer your enquiry and manage your booking
Confirming a reservation, holding a table, preparing your room, billing you. Basis · performing the service you asked for.
To meet legal obligations
Guest registers, Form C filings, GST invoicing, tax and accounting records, FSSAI requirements. Basis · compliance with Indian law.
To keep guests, staff and property safe
CCTV in common areas, incident records, access control. Basis · safety and security of persons and property.
To improve what we do
Reading feedback, reviewing service standards, understanding which pages of this site are useful. Basis · your consent for analytics cookies; legitimate use for feedback you send us.
To send you offers and news
Only where you have opted in. Basis · your consent, which you can withdraw at any time.
We do not sell your personal data, and we do not use it for automated decision-making or profiling that produces legal effects for you.

06

Section six

Disclosures the law requires of us

As a hotel operating in India, we are obliged to share certain guest information whether or not you consent:

  • Guest particulars to police or local authorities where required, including on lawful request.
  • Form C details of foreign national guests to the Bureau of Immigration, as required under the Foreigners Act framework.
  • Invoice and transaction records to tax authorities.
  • Information required by a court order, or to establish, exercise or defend a legal claim.

07

Section seven

Who we share it with

We share personal data only with parties who need it to deliver our service, and only under contract requiring them to protect it and use it for no other purpose:

  • Booking and listing platforms — Booking.com, Airbnb, Zomato.
  • Payment gateway and banking partners.
  • Property management, reservation and point-of-sale software providers.
  • Website hosting, email, form handling and analytics providers.
  • Professional advisers — accountants, auditors and lawyers — under confidentiality.
  • Other Mynnt properties, where your booking involves more than one of them.
To be completed [Named processors to be listed here before publication.]

08

Section eight

Transfers outside India

Some of our providers — hosting, email and analytics among them — operate servers outside India. Where personal data is transferred abroad we do so in line with the DPDP Act and any restrictions the Central Government notifies, and we require the recipient to protect it to the standard set out in this policy.

09

Section nine

How long we keep it

We keep personal data only as long as the purpose requires, then erase it — unless a law requires us to hold it longer.

Enquiries that do not become bookings
Upto 365 days
Guest and booking records
Upto 3 years
Invoices and accounting records
As required by tax law
CCTV footage
[period, typically 30 days]
Unsuccessful job applications
Upto 30 days
Marketing consent records
Until you withdraw, plus proof of consent
To be completed [Retention periods to be confirmed with counsel and entered above.]

10

Section ten

How we protect it

We take reasonable security safeguards as the DPDP Rules require, including:

  • Encryption of data in transit, and access control on the systems that hold guest records.
  • Access limited to staff who need it, with logs and periodic review.
  • Backups, so a booking is not lost if a system fails.
  • Confidentiality obligations in staff and vendor contracts, and training for the people who handle guest data.
  • Physical security for paper registers and ID copies.

11

Section eleven

Your rights as a Data Principal

The DPDP Act gives you the following rights over your personal data:

Access
A summary of the personal data we hold about you and what we are doing with it, and who we have shared it with.
Correction and erasure
Correct anything inaccurate, complete anything missing, update anything out of date, or have data erased where we are not required to keep it.
Withdraw consent
As easily as you gave it. Withdrawal does not affect processing already carried out lawfully.
Nominate
Name someone to exercise these rights on your behalf if you die or become incapacitated.
Grievance redressal
Complain to us first, and escalate to the Data Protection Board of India if we do not resolve it.

To exercise a right, write to our Grievance Officer in section 18 with enough detail to identify you and your booking. We may ask for proof of identity so we do not disclose your data to someone else. We respond within the period the DPDP Rules prescribe, and in any event resolve grievances within 90 days.

There is no charge. You also have duties under the Act — most importantly, not to raise false or frivolous complaints, and to give authentic information when the law requires identification.

12

Section twelve

Children’s data

This website is not directed at children. Where a booking includes a child under 18, we process that child’s data only as needed for the stay and only on the consent of a parent or lawful guardian. We do not track children, target advertising at them, or use their data for marketing. If you believe we hold a child’s data without proper consent, tell our Grievance Officer and we will delete it.

13

Section thirteen

CCTV on our premises

We operate cameras in entrances, corridors, lobbies and other common areas for the safety of guests, staff and property, and signage marks where they are. There are no cameras in guest rooms, bathrooms or changing areas. Footage is held for a limited period, access is restricted to authorised staff, and it is released only to law enforcement on lawful request or where needed for a legal claim.

14

Section fourteen

Marketing, and how to stop it

We send offers and news only to people who have opted in. Every message carries a way to unsubscribe, and you can also reply asking to be removed, or write to the Grievance Officer. We act on it promptly and confirm. Withdrawing marketing consent does not affect a booking you already hold — we will still send you the messages needed to run your stay.

15

Section fifteen

Cookies

We use necessary cookies to run this site, and optional cookies only after you consent. The full list, their lifetimes, and the controls to change your choice are in the cookie policy.

Read the cookie policy

16

Section sixteen

If something goes wrong

If a personal data breach occurs, we will notify the Data Protection Board of India and every affected Data Principal in the manner and within the timelines the DPDP Rules require, describing what happened, the likely consequences, what we are doing about it, and what you can do to protect yourself.

17

Section seventeen

Changes to this policy

We update this policy when our practices or the law change. The effective date and version at the top always show the current one. Where a change materially affects how we use your data, we will tell you directly.

18

Section eighteen

Grievance Officer

For any question about this policy, to exercise a right, or to make a complaint about how we have handled your data:

Grievance Officer · Mynnt Hospitality

Ravi Sharma info@homeaste.com +91 85888 87999 Mynnt Hospitality, Plot 74, Pocket 10, Sector 23B, Dwarka, New Delhi – 110078, India

We acknowledge grievances on receipt and resolve them within 90 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.

For anything that is not a privacy matter — stays, tables, events or corporate travel — write to info@mynnthospitality.com or call +91 89296 66600.