We at Namami Health Retreat and A Wellness Sanctuary along with all of our, affiliates, subsidiaries, and all of the separate and distinct legal entities, (hereinafter referred to as ‘we’ or ‘us’ or ‘our’) sets out sight on providing a healing experience to our guests harmonising the best of alternate medical practises to complement the modern medical practises. We endeavour to provide our guests a sanctum where you will be able to relax, unwind and ‘breath health’.
Through this policy we would like to bring clarity on the type of data that we may seek from you, as authorised under the relevant data protection laws. The data may be collected from you during your various interaction with us in person, through our website or mobile application. We have also explained the legal basis for processing of such data and have adhered to all statutory limitations placed.
Further, we recognise the rights and choices that you as the owner of the data possess as laid out in the privacy and data protection laws of your respective jurisdiction. You may feel free to approach us regarding any issues regarding our privacy practises at firstname.lastname@example.org.
You are advised to carefully read this Privacy Notice before using or availing any of our products and/or services.
- APPLICATION OF THE POLICY:
This policy explains our practises regarding the data collected by us when you interact with Namami Health Retreat and A Wellness Sanctuary through:
- Our websites – including www.namamihealth.com and our various booking sites – (collectively, “Website”).
- Our mobile applications – including World of Namami Health Retreat and A Wellness Sanctuary – (collectively the, “Application”).
- In person, such as when you visit us at Namami Health Retreat and A Wellness Sanctuary Location.
- When you communicate with us by phone, text, direct message, social media, or other similar functionality.
- WHAT INFORMATION WE MAY COLLECT ABOUT YOU
Namami Health Retreat and A Wellness Sanctuary collects various data for the purposes mentioned in this policy. The data may include and not limited the following:
- Contact and Identification Information: We may collect information such as your name, contact details (e.g., phone number(s), address, or email) professional title, employer or professional affiliations, and passport and visa information;
- Account Information and Marketing Preferences: We may collect your account details and credentials our various programs. We may also collect information on your marketing preferences;
- Stay and Purchase Information: We may collect information such as the retreats where you have stayed or booked a stay, dates of arrival and departure, goods and services purchased or utilized at Namami Health Retreat and A Wellness Sanctuary Locations or on the Website or Application, physical and digital room key usage, special requests made, service and stay preferences, telephone numbers dialled and faxes sent, calls or messages received, and any feedback or content you provide to us regarding your stay. We may also collect information through the use of closed-circuit television systems, Internet systems (including wired or wireless networks, smart or mobile device, or your location), and other security and technology systems;
- Payment and Credit Information: We may collect credit card and other payment method details. In limited cases, we may also collect information relating to the credit of customers;
- Location Information: We may automatically collect information about your precise geolocation when you access the Website or Application to the extent permitted by applicable law. We may also collect information about your general location using your IP address and your postal code;
- Demographic Information: We may collect demographic information, such as your gender, nationality, age, and date and place of birth;
- Biometric, Health-related or other Sensitive Personal Information: We may collect Sensitive Personal Information such as health-related so as to tailor our wellness programs so as to appropriately fit your personal need. We may also collect religion related data so as to cater to any special needs as per your request;
- Audio and Visual Information: We may record our customer service calls and security footage of our properties, which may include your voice and/or image;
- Preferences and Inferences: We may collect your preferences or make inferences about you, reflecting what we believe to be your preferences, characteristics, and predispositions, based on other personal information we have; and
- Device Content: With your permission, we may collect information relating to the content on your device.
- Other information which may include sensitive personal data: “Sensitive Personal Information” can mean personal information from which we can determine or infer an individual’s racial or ethnic origin, political opinions, religious beliefs or other beliefs of a similar nature, membership in a trade union or professional, religious, philosophical, or political association, physical or mental health or condition, medical treatment, genetic data, biometric information, and information about an individual’s sexual life or sexual orientation. In some very rare instances, financial records, credit card information and location data may constitute Sensitive Personal Information where you are located.
- HOW WE COLLECT DATA
We collect the above-referenced categories of personal information from the following categories of sources:
- Directly from you: Much of the personal information we process is information that you or someone acting on your behalf directly provides to us. For example, you may provide us with Contact and Identification Information, Stay and Purchase Information, Payment Information, Demographic Information, and Health-related Information, when you book a reservation; take part in our wellness and education programs; complete surveys; purchase our products; sweepstakes, contests or promotional offers; contact customer service; use WiFi or contact us via email, use our app, text, or chat, over the phone, in person, or through third parties.
- From other businesses or individuals: We work with business and marketing partners and social media platforms that give us personal information about you that they have collected either directly or indirectly from you. We also use features that let your friends and family give us your personal information, for example when a family member or friend checks in on your behalf. We also may receive your personal information from (i) someone acting on your behalf, such as your travel agent or your employer (where your employer books for you), (ii) your travel provider, such as an airline, or (iii) your third-party card or loyalty scheme provider.
- From social media: If you post to one of our pages on a social media site, we may receive Contact and Identification Information, Stay and Purchase Information, Internet and Network Activity, and any other personal information contained in your social media posts or profile.
However, you can make decisions regarding collection and use of your data. You may opt to access edit or remove your data from our website or mobile application. For more information refer to section titled “your rights and choices” given below.
- DATA COLLECTED AUTOMATICALLY:
- We automatically collect certain data while you visit our website or our application which aids in providing the right content and helps in navigation. Such data collected includes your IP address.
- Our web servers or affiliates who provide analytics and performance enhancement services collect IP addresses, operating system details, browsing details, device details and language settings. This information is aggregated to measure the number of visits, average time spent on the site, pages viewed and similar information. We use this information to measure the site usage, improve content and to ensure safety and security, as well enhance performance of our website or mobile application.
- We may also collect your data automatically through cookies or other similar technologies. Cookies are unique identifiers that we transfer to your device to enable our systems to recognize your device. We also use pixels and similar technologies to analyse traffic on our website and mobile application to improve your experience of using them. You may adjust your web browser software if you do not wish to receive Cookies or web beacons, but this may prevent you from taking advantage of some of the features of our website and mobile application.
- HOW WE USE YOUR PERSONAL INFORMATION:
Subject to applicable laws, we may collect, use, and disclose your personal information in order to:
- Provide, charge for, and manage retreat accommodation and other goods and services;
- Provide you with customer support and a better or more personalized level of service at Namami Health Retreat and a Wellness Sanctuary location as well as through the website, application, third-party applications, products or services, or through products or services Namami Health Retreat and a Wellness Sanctuary develops in the future;
- Allow us to evaluate, analyse, and improve the functionality of our websites, applications, or goods and services;
- Tailor health and wellness programs to cater to your requirements and health conditions.
- Plan your meals as per any prevalent dietary restrictions
- Facilitate concierge services on your behalf, e.g., restaurant, attraction and transportation transactions;
- Administer loyalty, travel, or discount programs and the Namami Health Retreat and a Wellness Sanctuary frequent guest program
- Administer contests, sweepstakes, or other promotions;
- Fulfil contractual obligations to you, anyone involved in the process of making your travel arrangements (e.g., travel agents, group travel organizers, or your employer) and vendors (e.g., credit card companies, airline operators, and third-party loyalty, travel, or discount programs);
- Conduct market research, customer satisfaction and quality assurance surveys;
- Conduct marketing and sales promotions and serve targeted advertising for products, services, events, or promotions you might be interested in. Where permitted by law, we may work with other companies to serve advertisements or marketing that we think you may find relevant and useful. This may include advertisements displayed on our own websites or applications, contained in emails or other communications sent by us, or advertisements from us displayed on other companies’ websites. The advertisements you see may be based on information collected by us or third parties and/or may be based on your activities on our websites, applications or third-party websites;
- Provide for the safety and security of staff, guests and other visitors;
- Prevent, detect, and investigate fraud, cyber incidents, or other illegal activity;
- Communicate with you about our relationship, such as updates to this policy or other important legal or business changes;
- Administer general record keeping;
- Meet legal and regulatory requirements;
- Test and evaluate new products and services;
- Process credit applications;
- Fulfill other purposes as disclosed to you in accordance with applicable law or with your consent; and
- Use certain pieces of personal information to verify your identity if you make requests regarding your personal information pursuant to this policy. The verification steps and the pieces of personal information that we request may vary depending on the sensitivity and nature of your request.
Under the relevant Data protection laws, we need to ensure that the processing of the data is justified on legal grounds. The following grounds enable us to lawfully process data:
We may process certain data to carry out the obligations arising out of contract entered into with you, for instance to process transactions or to communicate on our products or services.
- Where processing of personal data is within our legitimate interest or that of a connected third party, except where such interests are overridden by the fundamental freedom or rights of yours which require protection of the personal data.
- where opt in consent has been given to process personal data, as required by certain Data Protection laws. However, this consent can be withdrawn anytime, details for which is provided below.
- where processing data is required to comply with a legal obligation. This will not be in anyway prejudicial to your right as you may object to us processing your personal information in certain circumstances.
- We will only process certain process certain category of personal data as permitted according to the relevant Data protection laws, provided there is a valid legal basis. We will use and retain your personal information for as long as is necessary to fulfil the purpose for which it is being processed, and in line with our legal and regulatory obligations and risk management guidelines
- Where we use your personal data on behalf of another entity as part of services provided to another entity then that entity will be responsible for ensuring that the legal grounds for the collection of data are met. When we do outsource the processing of your personal information to third parties or provide your personal information to third-party service providers, we oblige those third parties to protect your personal information in accordance with the terms and conditions of this Policy, with appropriate security measures
- DISCLOSURE OF YOUR PERSONAL INFORMATION
From time to time, we may disclose your personal information. We would always make that disclosure in accordance with applicable law. In some jurisdictions, data privacy laws may require us to obtain your consent before we disclose your information to third parties. When you consent to this Policy, you are, to the extent required and permitted under your local law, granting your consent to the transfer of your personal information to such third parties for the purpose and to the extent stated in this section and as described in the Section above.
We may also share your data with service providers who may process it in the course of providing the relevant services like storing and analysing data, providing customer service, securing our systems, payment processing, processing data for profiling etc. We may also share your data with the medical professionals and medical service providers in the course of your wellness program to avail you the best possible medical services.
We disclose your information to other organisations within the Namami Health Retreat and A Wellness Sanctuary Group for the purposes described in this Policy, such as providing you with our services, administering the membership programs and for our internal business purposes.
When we do outsource the processing of your personal information to third parties or provide your personal information to third-party service providers, we oblige those third parties to protect your personal information in accordance with the terms and conditions of this Policy, with appropriate security measures. We may also share data with other third parties that you request or authorize to do so, compliance to any applicable law, to operate and maintain the security of our website or mobile application and to prevent attack on computer systems or network. The sharing of the data will be in accordance with the applicable laws and the process set out in the policy.
We also reserve the right to retain personal information collected and to process such personal information to comply with accounting and tax rules and regulations and any specific record retention laws.
Our websites do not sell products or services for purchase by children and we do not knowingly solicit or collect personal information from children. If you are under the age of 18 (or a minor in the jurisdiction in which you are accessing our websites), you may only use our websites with the involvement of a parent or guardian.
- DATA SECURITY
We employ technical and organisational measures to ensure the security of the data and store it in secure servers. We have put in place all security measure as required to according to the relevant laws applicable. If you suspect misuse of data or unauthorised access, let us know immediately by mail.
- PROCESSING YOUR DATA
We take steps to ensure that your Data is processed according to the provisions of this Privacy Notice and the requirements of applicable law. To ensure that your Data receives an adequate level of protection, we have put in place appropriate arrangements with our other Entities, Partners and Service Providers that we share your Data with
- RETENTION OF DATA
We retain data for as long as necessary for the access of our products or services or to provide access to our website or mobile application, for complying with any legal obligation, resolving disputes, enforcing agreements as long as it is necessary for our legitimate interests.
When you download or register to use one of our apps, you may submit personal information to us such as your name, address, email address, phone number, date of birth, username, password and other registration information, financial and credit card information, personal description and/or image.
Further, when you use our apps, we may collect certain information automatically, including technical information related to your mobile device, your device’s unique identifier, your mobile network information, the type of mobile browser you use and information about the way you use the app.
- RIGHTS AND CHOICES
You have certain rights with regard the data that we hold about you, it may however vary according to the jurisdiction you belong to. You may have following rights with respect to your data:
- Right to Confirmation and Access – you may ask us to confirm what Data we hold about you at any time, and request us to modify, update or delete such Data. You may also request a copy of the Data we hold about you.
- Right to Rectification – you have the right to request that we rectify any inaccurate or incomplete Data that we hold about you, including by means of providing a supplementary statement.
- Right to be Erasure – you have the right to request that we “erase” your Data in certain circumstances.
- Right to Restrict Our Use of your Data – you have the right to request that we restrict our processing of your Data in certain circumstances, for example if you dispute the accuracy of the Data that we hold about you or you object to our processing of your Data (including where we process your Data for our legitimate interests, where permitted under applicable law).
- Right to Object – this right enables you to object to us processing your Data where we do so for certain reasons.
- Right to Data Portability – you have the right to request that we transfer your Data to another third party. This right of data portability only applies to certain types of Data.
- Right to Withdraw Consent – where we have obtained your consent to process your Data for certain activities, you may withdraw this consent at any time and we will cease to carry out that particular activity that you previously consented to unless we consider that there is an alternative legal basis to justify our continued processing of your Data for this purpose.
- California privacy rights:
If you reside in California, you may also make the following more specific requests with respect to your personal information in accordance with applicable law:
- Access – You can request that we disclose to you the categories of personal information collected about you, the categories of sources from which the personal information is collected, the categories of personal information sold or disclosed, the business or commercial purpose for collecting and selling the personal information, the categories of third parties with whom we share the personal information, and the specific pieces of personal information collected about you over the past 12 months.
- Deletion – You can request that we delete your personal information that we maintain about you, subject to certain exceptions.
- GDPR privacy rights:
Guests belonging to the jurisdictions where the General Data Protection Regulation is applicable (EU nations), have right to erasure of the personal information on request, right to restrict the use of certain information and the right to data portability to enable transfer of data provided to us without any hinderance to another controller of data, in addition to the other rights mentioned above. GDPR lays its legal basis on consent for the collection and processing of personal information and such consent may be withdrawn anytime.
- China Privacy Rights:
This Policy, as updated from time to time, is inclusive of the laws of the People’s Republic of China.
We value and respect your privacy rights and attempt to function recognising the rights accorded to you by the virtue of your citizenship. You may contact us on email@example.com regarding any further request regarding exercise of such rights.
- CONTACTING US
If you have any questions about this Policy, about the processing of your data described, or any concerns or complaints with regard to the administration of the Policy, or if you would like to submit a request (in the manner described above) to exercise your rights in relation to the personal information that we maintain about you, you may contact us through our phone number or mail id as provided in the website.
You may also directly contact with our grievance officer by mailing at firstname.lastname@example.org.