How Bhramanvisa (India) Private Limited Collects, Uses and Protects Your Personal Data
Summary: We collect only the data we need to provide travel, visa, and foreign exchange services to you. We do not sell your personal data. You have full rights over your data under the Digital Personal Data Protection Act, 2023. Our Grievance Officer is available to address any privacy concerns within 30 days.
Key Point: This policy applies to all personal data you share with FlairMyTrip through our website, mobile site, partner portal, email, phone, or physical office. By using our services, you agree to the terms of this policy.
This Privacy Policy ("Policy") is issued by Bhramanvisa (India) Private Limited ("Bhramanvisa", "FlairMyTrip", "FMT", "we", "us", or "our") and applies to the collection, processing, storage, sharing, and protection of personal data provided by or relating to any person ("Data Principal", "User", "you", "your") who has purchased, intends to purchase, or inquires about any product or service offered by FMT through any of its sales channels, including the website www.flairmytrip.com, mobile site, partner login portal, email communications, telephone, and physical office (collectively, "Sales Channels").
This Policy applies to both individual users and registered B2B Trade Partners. Where different obligations apply, this Policy specifies them separately.
This Policy does not apply to third-party websites, mobile applications, or services linked from our platform. FMT shall not be liable for the privacy practices of any third-party platform to which a hyperlink is provided. Users are strongly encouraged to review the privacy policies of such third parties independently.
By accessing or using our website or any Sales Channel, you acknowledge that you have read, understood, and agreed to the terms of this Privacy Policy. If you do not agree, please discontinue use of our services immediately.
Key Point: FMT operates under India's comprehensive data protection framework. We comply with the DPDPA 2023, IT Act 2000, and all applicable rules and regulations.
This Policy is framed in compliance with the following Indian laws, rules, and regulations:
| Law / Rule | Key Provision |
|---|---|
| Digital Personal Data Protection Act, 2023 (DPDPA) | Primary data protection framework; defines Data Fiduciary, Data Principal, and consent requirements |
| Information Technology Act, 2000 (IT Act) | Governs electronic records, digital signatures, and cyber offences |
| IT (Amendment) Act, 2008 | Expanded liability provisions for intermediaries and data handlers |
| IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules) | Defines SPDI categories and mandates security standards |
| Prevention of Money Laundering Act, 2002 (PMLA) | Governs KYC and financial data retention obligations |
| Reserve Bank of India (RBI) Guidelines | Applicable to forex transaction processing and financial data |
| Consumer Protection Act, 2019 | Applicable to consumer-facing data practices |
Where any provision of this Policy conflicts with applicable law, the law shall prevail and the Policy shall be deemed amended accordingly.
Key Point: FMT is the "Data Fiduciary" under DPDPA 2023 — we determine the purpose and means of processing your personal data. You are the "Data Principal" — the individual whose data we process.
Under the Digital Personal Data Protection Act, 2023 ("DPDPA"), Bhramanvisa (India) Private Limited (CIN: U63090MH2022PTC378XXX), trading as FlairMyTrip, is the Data Fiduciary in respect of personal data collected through our Sales Channels. As a Data Fiduciary, we determine the purpose and means of processing your personal data and are responsible for ensuring its lawful, fair, and transparent processing.
Where FMT engages third-party service providers (airlines, hotels, visa authorities, courier companies, technology vendors) to process data on our behalf, such entities act as Data Processors and are contractually bound to process data only as directed by FMT and in compliance with applicable law.
FMT may also act as a Data Processor where we process personal data on behalf of B2B Trade Partners in connection with their clients' travel arrangements.
Key Point: We collect only the data necessary to provide our services. The type of data collected depends on which services you use — basic contact details for enquiries, detailed identity documents for visa processing.
For B2B Trade Partners placing bookings on behalf of their clients: you warrant that each client has expressly consented to have their personal data shared with FMT and the relevant Suppliers. FMT shall not be liable for any failure by the Trade Partner to obtain such consent.
Key Point: FMT does not collect sensitive personal categories such as racial or ethnic origin, political opinions, religious beliefs, health data, sexual orientation, or criminal records — unless strictly required by a government authority for visa processing, in which case it is shared directly with that authority only.
FMT does not intentionally collect the following categories of personal data through its Sales Channels:
If any such data is inadvertently received, it will be deleted promptly. FMT shall not be liable for data submitted that falls outside the scope of the service requested.
Key Point: Passport details, bank statements, and financial transaction data are classified as SPDI under India's IT Rules 2011. We collect this data only with your explicit consent and only as required to deliver visa or forex services.
Under the IT (SPDI) Rules, 2011, the following categories of data collected by FMT qualify as Sensitive Personal Data or Information (SPDI) and are subject to enhanced protection:
FMT collects SPDI only with your prior, written, and explicit consent. Such consent may be given through your signed Service Agreement, electronic acceptance, or by voluntarily submitting documents through our platform. You may withdraw consent at any time; however, withdrawal may affect our ability to provide the requested services.
Passport documents, bank statements, and visa-related documents submitted to FMT are used solely for visa facilitation, forex processing, or travel booking. FMT shall not be liable for the accuracy of such documents provided by you. Any consequences arising from forged, inaccurate, or incomplete documents are the sole responsibility of the submitting party.
Key Point: We collect data only when you voluntarily provide it to us — through our website, partner portal, email, phone, or in-person. We also collect technical data automatically when you use our website.
We collect personal data directly from you when you:
We automatically collect technical and usage data when you visit our website, including IP address, browser type, device information, pages visited, and referral sources. This is done through cookies and similar technologies — see § 10 for details.
Third-Party SourcesWe may receive data from: social media platforms (where you interact with our pages); our B2B Trade Partners (who share client data for booking and visa purposes); public records; and credit/identity verification services used for KYC compliance.
Key Point: Under DPDPA 2023, FMT processes your personal data on the basis of: (a) your explicit consent; (b) performance of a contract; (c) legal obligation; or (d) legitimate interests — as specified below.
| Legal Basis | When Applied |
|---|---|
| Explicit Consent (DPDPA § 6) | Marketing communications, newsletters, promotional offers, collection of SPDI |
| Contract Performance | Processing bookings, issuing invoices, confirming reservations with Suppliers |
| Legal Obligation | KYC/AML compliance, tax reporting (GST), responses to law enforcement, PMLA obligations |
| Legitimate Interests | Fraud prevention, platform security monitoring, service improvement, analytics |
| Deemed Consent (DPDPA § 7) | Processing necessary for visa/immigration purposes where government authority requires data |
| Vital Interests | Emergency situations involving the health or safety of a traveller |
We will always tell you which legal basis applies when we collect your data. You can ask us to reconsider any processing you believe lacks a valid legal basis.
Key Point: We use your data to deliver the services you request, communicate with you about your bookings, comply with legal obligations, and improve our services. We do not use your data for any purpose you have not been informed of.
We will never use your personal data for any purpose that contradicts the purpose for which it was collected, without first obtaining your explicit consent. FMT does not sell, rent, or trade your personal data to any third party for their independent marketing purposes.
Key Point: We use cookies and similar technologies to make our website work, remember your preferences, and understand how it is used. You can control non-essential cookies through your browser settings.
FMT uses the following categories of cookies and tracking technologies on its platform:
| Cookie Type | Purpose | Consent Required? |
|---|---|---|
| Strictly Necessary | Login sessions, shopping cart, security, platform functionality | No (essential) |
| Functional / Preference | Remembering language, currency, and search preferences | Yes |
| Analytics | Understanding how users interact with our platform (aggregated data) | Yes |
| Marketing / Targeting | Serving relevant advertisements on third-party platforms | Yes |
You may disable non-essential cookies through your browser settings or our cookie preference centre. Disabling certain cookies may affect the functionality of our platform. FMT shall not be liable for any degradation in service quality resulting from the disabling of cookies by the user.
Third-party analytics and advertising tools (such as Google Analytics) used on our platform are governed by their own privacy policies. FMT does not control and shall not be liable for data collected by such third-party tools.
Key Point: We share your data only with parties necessary to deliver your service. We never sell it. All third-party sharing is governed by contractual obligations and applicable law.
Your data is shared with Suppliers (airlines, hotels, ground operators, embassies, consulates, immigration authorities, courier services, insurance providers, and other travel service providers) only to the extent necessary to fulfil your booking or visa application. By placing a booking with FMT, you explicitly consent to such sharing. FMT authorises Suppliers to use your data only for service fulfilment and not for any independent purpose. FMT shall not be liable for any misuse of data by Suppliers beyond FMT's instructions.
B2B Trade PartnersWhere a booking is placed by a Trade Partner on behalf of a client, FMT may share booking status, visa progress, and document details with that Trade Partner. FMT shall not be liable for any further sharing of such information by the Trade Partner with their own clients or third parties.
Technology and Service ProvidersFMT engages trusted third-party technology providers for functions including cloud hosting, payment processing, SMS/email communications, CRM systems, and data analytics. Such providers act as Data Processors under contractual data processing agreements and are prohibited from using your data for any purpose beyond the specified function.
Legal and Regulatory AuthoritiesWe may disclose personal data to courts, law enforcement agencies, government bodies, taxation authorities, or regulators where required by law, court order, or legal process. FMT shall cooperate with all lawful government requests and shall not be liable for any disclosure made in good faith compliance with such requirements.
Professional AdvisersLawyers, auditors, accountants, bankers, and insurers engaged by FMT may receive access to personal data to the extent necessary for the provision of their professional services and are bound by professional confidentiality obligations.
Business RestructuringIn the event of a merger, acquisition, sale of assets, or business restructuring, customer personal data may be transferred to the acquiring or successor entity. Notice will be provided to users prior to any such transfer where practicable.
FMT does not sell, rent, or trade your personal data to third parties for their own independent marketing or commercial use. All third-party sharing is limited to what is strictly necessary for service delivery or legal compliance. FMT shall not be liable for the independent privacy practices of third-party platforms, suppliers, or linked websites.
Key Point: Because FMT facilitates travel and visas globally, your data may be shared with immigration authorities, embassies, and service providers located in countries outside India. Such transfers comply with DPDPA 2023 and applicable Central Government notifications.
The international nature of travel and visa services requires FMT to transfer personal data to countries outside India, including but not limited to the UAE, Bahrain, Oman, UK, Schengen countries, Canada, Australia, and other visa destination countries. Such transfers occur to:
All such cross-border transfers are made in compliance with applicable Central Government notifications under the DPDPA 2023 and subject to the receiving country providing an adequate level of data protection equivalent to Indian standards. Where adequate protection cannot be assured, FMT will implement appropriate contractual safeguards.
FMT Limitation of Liability: Once data is transmitted to a foreign government authority (embassy, consulate, immigration department), it is subject to the laws and policies of that country. FMT shall not be liable for the data handling practices of foreign government authorities or their processing of data after receipt.
Key Point: We retain your personal data only as long as necessary for the purpose it was collected — typically 7 years for financial records (as mandated by the Companies Act and GST Act), and up to 10 years for certain visa-related records.
| Data Category | Retention Period | Reason |
|---|---|---|
| Booking and transaction records | 7 years from transaction date | Companies Act 2013, GST Act 2017 compliance |
| KYC and identity documents (B2B) | 7 years after account closure | PMLA 2002 and RBI KYC guidelines |
| Visa application documents | 5 years or as required by the relevant authority | Immigration record keeping; potential reapplication |
| Gulf country overstay records | 10 years | Indemnity obligations under T&C; legal claims |
| Forex transaction records | 5 years | FEMA 1999 and RBI guidelines |
| Marketing preferences | Until withdrawal of consent | DPDPA 2023 consent-based processing |
| Website usage / technical data | 24 months (anonymised after 12 months) | Platform analytics and security |
| Complaint and grievance records | 3 years from resolution | Legal claims and audit purposes |
After the applicable retention period, personal data will be securely deleted or anonymised so that it can no longer be associated with any identifiable individual. We may retain anonymised, aggregated data indefinitely for statistical and research purposes.
Retention periods may be extended where a legal dispute is pending, an investigation is ongoing, or we are required to retain data by a court order or regulatory authority.
Key Point: FMT does not knowingly collect personal data from individuals under 18. Under DPDPA 2023, processing data of children requires verifiable parental consent.
FMT's platform and services are not directed at individuals under the age of 18 ("Children"). In accordance with the Digital Personal Data Protection Act, 2023, FMT shall not process personal data of Children without the verifiable consent of a parent or legal guardian.
B2B Trade Partners warrant that they will not submit personal data of any minor without first obtaining verifiable parental consent. FMT shall not be liable for the submission of children's data without proper parental consent by the Trade Partner or user.
Where a booking involves minor travellers (e.g., visa applications for children), the parent or guardian placing the booking is deemed to have provided consent on behalf of the child. All data relating to minor travellers is handled with enhanced security measures and will not be used for any purpose other than service fulfilment.
If you believe we have inadvertently collected personal data from a child without appropriate consent, please contact our Grievance Officer immediately at privacy@bhramanvisa.com. We will delete such data promptly.
Key Point: We implement technical and organisational security measures in compliance with the IT (SPDI) Rules 2011. Our systems are SSL-secured and access is restricted to authorised personnel only.
In accordance with Rule 8 of the IT (Reasonable Security Practices and Procedures and SPDI) Rules, 2011, FMT implements the following security measures:
While FMT takes all reasonable precautions to secure your personal data, no internet transmission or electronic storage system is 100% secure. FMT shall not be liable for data breaches or security incidents arising from: (a) cyberattacks beyond FMT's reasonable control; (b) force majeure events; (c) actions of the user that compromise account security (e.g., sharing passwords); (d) data breaches at third-party service providers beyond FMT's direct control. In the event of a significant data breach, FMT will notify affected users and relevant authorities in accordance with applicable law.
Key Point: As a Data Principal under India's Digital Personal Data Protection Act, 2023, you have comprehensive rights over your personal data. We will respond to all valid requests within 30 days.
To exercise any of these rights, please contact our Grievance Officer (§ 18) or email privacy@bhramanvisa.com with the subject line "Data Rights Request". We will acknowledge your request within 72 hours and resolve it within 30 days. We may need to verify your identity before processing the request. FMT shall not be liable for consequences arising from requests to delete data that is still subject to a legal retention obligation.
Key Point: Under DPDPA 2023, consent must be free, specific, informed, unconditional, and unambiguous. You can withdraw consent at any time for marketing and non-essential processing.
FMT obtains consent for processing your personal data in the following ways:
You may withdraw your consent for marketing communications at any time by:
Withdrawal of consent for processing that is essential to service delivery (e.g., sharing passport data with an embassy) will mean we are unable to provide the relevant service. FMT shall not be liable for any service disruption or cancellation arising from your withdrawal of essential consent.
Key Point: As mandated by Rule 5(9) of the IT (Intermediaries Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDPA 2023, FMT has designated a Grievance Officer to address privacy concerns and data rights requests.
You may lodge a grievance regarding: any violation of your data rights; any inaccuracy in how your data is being processed; unauthorised access or sharing of your data; failure to respond to your data access or deletion request; or any other privacy concern.
Key Point: If you are not satisfied with FMT's response to your grievance, you have the right to escalate your complaint to the Data Protection Board of India, established under DPDPA 2023.
The Data Protection Board of India ("Board") is the statutory body established under the Digital Personal Data Protection Act, 2023, with the authority to adjudicate complaints relating to violations of the DPDPA by Data Fiduciaries.
If you have raised a grievance with FMT's Grievance Officer and are not satisfied with the response within 30 days, you have the right to file a complaint with the Board. The Board has the authority to investigate complaints, impose penalties on Data Fiduciaries, and award compensation to affected Data Principals.
Information on how to file a complaint with the Data Protection Board will be available on the Ministry of Electronics and Information Technology (MeitY) website once the Board is fully constituted and operational. FMT will cooperate with any investigation conducted by the Board.
Key Point: We send marketing emails, SMS, and WhatsApp messages only with your explicit consent. You can unsubscribe at any time.
FMT may use your contact information to send you the following types of communications, subject to your consent:
You may opt out of marketing communications at any time without affecting your account or the services you receive. Transactional communications (booking confirmations, payment receipts, status updates) are not subject to marketing opt-out.
FMT may share filtered contact information with carefully selected business partners for co-branded offers. Any such sharing will be subject to an opt-in by you, and the partner's own privacy policy will apply to their handling of your data. FMT shall not be liable for the marketing practices of third-party partners once you have engaged with their service.
Key Point: Our website may contain links to third-party websites. FMT is not responsible for their privacy practices. Always review the privacy policy of any third-party site you visit.
FMT's platform may contain hyperlinks to third-party websites, social media platforms, airline booking portals, hotel websites, government visa portals, and insurance provider platforms. The inclusion of any such link does not constitute an endorsement, sponsorship, or recommendation of the linked website or its content by FMT.
FMT shall not be liable for the privacy practices, security, content, or data handling of any third-party website or platform linked from our services. Once you leave our platform, this Privacy Policy ceases to apply. Users are solely responsible for reviewing and accepting the privacy policies and terms of service of any third-party site they access through links on our platform.
Key Point: We use anonymised, aggregated data (which cannot be linked to any individual) for research, analytics, and improving our services. This data is not subject to this Privacy Policy.
FMT collects, uses, and may share non-personal and aggregated data — data which cannot be used to identify any individual — for the following purposes:
If FMT combines or connects aggregated data with any personal data in a way that would make the combined data capable of identifying an individual, the combined data will be treated as personal data and processed in accordance with this Policy.
Key Point: FMT implements all reasonable security and compliance measures, but our liability for privacy incidents is limited as set out below. This section should be read carefully.
To the fullest extent permitted by applicable law, including the Digital Personal Data Protection Act, 2023, the IT Act 2000, and the IT (SPDI) Rules 2011:
FMT's maximum aggregate liability for any privacy-related claim shall not exceed the total fees paid by the user to FMT in respect of the specific transaction giving rise to the claim.
Key Point: By using FMT's services, you agree to indemnify FMT against any losses arising from your breach of this Privacy Policy, submission of inaccurate data, or failure to obtain proper consent from third parties whose data you share with us.
You agree to defend, indemnify, and hold harmless Bhramanvisa (India) Private Limited, its directors, officers, employees, agents, and affiliates from and against any claims, losses, liabilities, damages, penalties, costs, and expenses (including reasonable legal fees) arising out of or in connection with:
This indemnification obligation survives the termination of your account, the cancellation of any booking, and the expiry of this Privacy Policy.
Key Point: We may update this Policy periodically to reflect changes in law, regulation, or our services. Significant changes will be communicated via email or a prominent notice on our website.
FMT reserves the right to update, modify, or replace this Privacy Policy at any time to reflect changes in: applicable laws and regulations (including any amendments to or notifications under the DPDPA 2023); our data processing practices; new services or products we offer; or business restructuring events.
When we make material changes to this Policy, we will:
Your continued use of FMT's services after any update to this Policy constitutes your acceptance of the revised Policy. If you do not agree with any updated version, you must discontinue use of our services and may contact our Grievance Officer to exercise your data rights.
Copyrights © 2024-2025, FlareMyTrip, All rights reserved.