Vendor Login Hotel, Restaurant & Bar PMS
LEGAL & COMPLIANCE DIRECTIVE

Privacy Policy & Data Protection

Comprehensive data privacy compliance framework adhering strictly to India's Digital Personal Data Protection (DPDP) Act 2023.

Effective Date: January 1, 2026 DPDP Act 2023 Compliant

1. Data Fiduciary Classification & Compliance Framework

PixelGo HMS acts as a Data Fiduciary under India's Digital Personal Data Protection (DPDP) Act 2023. We collect and process personal data belonging to hotel guests, restaurant patrons, and vendor staff members strictly for specified, lawful business purposes connected to hospitality management operations.

2. Specified Lawful Processing Purposes

Personal data (Name, Mobile Number, Email, Government Photo ID, Passport Details, Booking Dates, Room Charges, Food & Beverage Orders) is collected exclusively for:
- Legal hotel check-in compliance and mandatory C-Form reporting for foreign nationals.
- Generating itemized room folios, restaurant KOT receipts, and SAC GST tax invoices.
- Automated SMS and WhatsApp booking confirmations and digital invoice delivery.
- Enforcing shift balancing audits and preventing financial fraud.

3. Encrypted Data Storage & Sovereign Indian Data Residency

All personal data, guest identity documents, and financial ledgers are stored exclusively on secure cloud servers located within the physical boundaries of the Republic of India. All data in transit is encrypted using TLS 1.3 protocols, and all data at rest is secured via AES-256 cryptographic standards.

4. Data Principal Rights (Access, Correction, Erasure)

Under the DPDP Act 2023, individuals ("Data Principals") hold enforceable rights regarding their personal data:
- Right to Access: View complete stored personal data logs via our DPDP Transparency Portal.
- Right to Correction: Request immediate update of inaccurate or incomplete personal records.
- Right to Erasure (Right to be Forgotten): Request permanent deletion of personal data logs subject to statutory hotel record retention laws.

5. Zero Third-Party Data Monetization Guarantee

PixelGo HMS maintains a strict zero-monetization data policy. We never sell, lease, trade, rent, or commercialize guest personal information or property transaction analytics to advertising networks, data brokers, or third-party marketing agencies under any circumstances.

6. Authorized Infrastructure Sub-Processors

PixelGo HMS engages vetted technical sub-processors solely for infrastructure delivery:
- Cloud Data Centers: Tier-4 Indian server infrastructure for encrypted hosting.
- SMS & WhatsApp Gateways: TRAI-approved messaging gateways for automated receipts.
- Payment Settlement Gateways: RBI-licensed payment aggregators (Razorpay, Stripe) for secure processing.

7. Security Audits, Incident Response & Breach Notifications

We conduct regular Vulnerability Assessment and Penetration Testing (VAPT) audits. In the unlikely event of a security incident impacting personal data, PixelGo HMS will notify the Data Protection Board of India and affected Data Principals within statutory deadlines.

8. Data Retention Schedules & Automated Purging

Guest identity records and room folios are retained for three (3) years to comply with Indian Police regulations and local Hotel Licensing Acts, after which data is automatically purged using cryptographic sanitization routines.

9. Protection of Children's Data

PixelGo HMS does not knowingly process personal data belonging to minors under eighteen (18) years of age without explicit consent from a parent or legal guardian during hotel check-in.

10. Data Protection Officer (DPO) Contact Details

For privacy grievances, data rights execution, or DPDP Act 2023 compliance inquiries, contact our Data Protection Officer directly at dpo@pixelgo.live.

What players say

Loved by Hospitality
Leaders Across India

ENTERPRISE GOVERNANCE

Questions About Our Legal Framework?

Our legal compliance team is available to assist property owners and corporate groups.

Speak to Legal Desk →