StayRata — a product of Cyborian Tech Labs Pvt. Ltd.
Last updated: August 9, 2026
This Privacy Policy is prepared in alignment with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), notified 14 November 2025, and reflects current implementation practice among comparable B2B/B2C SaaS and travel-marketplace platforms as of the date of drafting. It is not itself legal advice.
Compliance under the DPDP Rules is being phased in three stages — Board establishment (13 November 2025), enforcement powers, penalties, and Consent Manager registration (13 November 2026), and full substantive compliance covering consent, notice, security safeguards, and data-principal rights (13 May 2027). Counsel should confirm which specific obligations are already binding as of the date this Policy is published, and revisit this Policy as each phase takes effect.
Cyborian Tech Labs Pvt. Ltd. ("Company", "we", "us", "our") is the Data Fiduciary in respect of personal data processed through the StayRata mobile application(s) and web dashboard (the "Platform"). This Privacy Policy describes what personal data we collect from Travel Agents, Resort Partners, and their representatives ("you", "User"), why we collect it, how it is used and shared, and the rights available to you as a Data Principal under the DPDP Act.
This Policy applies to all Users of the Platform. It does not apply to end guests of a Resort Partner unless they interact directly with the Platform (for example, via a booking confirmation notification).
2.1 Identity and Contact Data
2.2 Verification and KYC Data
2.3 Financial and Transaction Data
2.4 Trust and Reputation Data
2.5 Usage and Device Data
2.6 Communications Data
Consistent with the DPDP Rules' requirement that notice itemize the specific personal data collected against each specific purpose, we process personal data for the following purposes only:
We do not process personal data for any purpose beyond what is disclosed in this Policy or subsequently notified to you, consistent with the purpose-limitation principle under the DPDP Act.
We process personal data on the basis of your consent — free, specific, informed, unconditional, and unambiguous, given through clear affirmative action at the point of collection, as required under Section 6 of the DPDP Act. Consent requests are presented in clear, itemized language, in English and, where offered, regional languages, independent of any bundled or pre-ticked mechanism.
You may withdraw consent at any time, with the same ease with which it was given, through the Platform or by writing to connect@cyborian.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and may result in your inability to continue using features of the Platform that depend on that data.
Where processing is necessary for the performance of a contract with you (for example, processing a confirmed booking or settling a Wallet transaction) or to comply with a legal obligation, we may rely on the applicable legitimate-use grounds recognized under the DPDP Act in addition to, or instead of, consent, as permitted by law.
Consent Manager interoperability: the DPDP Rules establish a Consent Manager framework, with registration opening in the second implementation phase. As of the effective date of this Policy, the Platform's consent mechanism is a checkbox-based affirmative consent captured at registration; interoperability with a registered Consent Manager has not yet been built and should be assessed by engineering and counsel ahead of that framework becoming operative, so this Policy and the underlying consent flow do not require rebuilding at that stage.
We share personal data only with the following categories of recipients, strictly for the purposes described in Section 3, and under contractual obligations requiring them to protect such data:
We do not sell personal data to any third party, and we do not share personal data for third-party marketing without your separate, specific consent.
As of the effective date of this Policy, Platform infrastructure is provided by Cloudflare, Inc. (application hosting, edge network, and object storage for uploaded photographs) and Neon, Inc. (Postgres database hosting, currently located in the AWS ap-southeast-1 region, Singapore), accessed via Cloudflare Hyperdrive. Cloudflare's edge network is global by design and may process data outside India as part of ordinary request routing and content delivery.
Under Section 16 of the DPDP Act, cross-border transfer is permitted by default except to countries specifically restricted by the Central Government. [Counsel to confirm current restricted-country notifications, if any, as of the date of publication, and confirm whether the hosting arrangement described above requires any additional disclosure or safeguard.]
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy or as required by applicable law, including limitation periods under the Indian Contract Act, 1872 and applicable tax and financial record-keeping requirements.
Identity documents (PAN/national ID) of a blacklisted User are retained beyond standard retention periods solely to prevent re-registration in enforcement of the End User License Agreement's fraud provisions. [Retention schedule, by data category, to be finalized with counsel.]
Where your purpose for using the Platform ends or you withdraw consent, we will erase your personal data, or anonymize it in the case of Trust Score/ratings history retained for platform-integrity purposes, and will notify you at least 48 hours in advance of erasure unless retention is otherwise required by law, in accordance with the DPDP Rules.
Under the DPDP Act, you have the right to:
Requests may be submitted to connect@cyborian.com. We will respond within the timeframe prescribed under the DPDP Rules.
Grievance Officer: [Name — to be confirmed by the Company]
Contact: connect@cyborian.com
We will acknowledge and address grievances within the timeframe prescribed under the DPDP Rules. If you are not satisfied with our response, you may escalate your grievance to the Data Protection Board of India.
We implement technical and organizational safeguards proportionate to the sensitivity of the data we process. As of the effective date of this Policy, this includes:
[Counsel/security team to confirm organizational safeguards not reflected above — access-control policy, employee data-handling training, incident-response procedures, and audit logging practices — for accurate and complete disclosure. Do not overstate measures not yet implemented.]
In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals in accordance with the timelines and content requirements prescribed under the DPDP Rules, including a description of the breach, the categories of data affected, and the protective measures available to you.
As of the date of this Policy, the Company has not been designated a Significant Data Fiduciary under the DPDP Act. Counsel should monitor MeitY notifications and revisit this section, together with any additional obligations — including Data Protection Officer appointment, Data Protection Impact Assessments, and independent audits — should the Company's data volume or risk profile change or should such designation occur.
The Platform is intended for business use by Travel Agents and Resort Partners aged 18 and above and is not directed at children. We do not knowingly collect personal data from individuals under 18. If we become aware that we have inadvertently collected such data, we will take steps to delete it, subject to verifiable parental/guardian consent requirements under the DPDP Act should any such processing become necessary.
As of the effective date of this Policy, the Platform does not use cookies for advertising or third-party tracking. It uses browser local storage for limited functional purposes (for example, preventing accidental duplicate form submissions) and a service worker for offline availability and performance caching of the website.
This section will be updated if analytics, advertising, or other cookie-based technologies are introduced, including confirmation of whether a separate cookie-consent mechanism becomes required for the web dashboard at that time.
We may update this Privacy Policy from time to time, including to reflect further phases of DPDP Rules implementation. Material changes will be notified through the Platform prior to taking effect.
For questions regarding this Privacy Policy, contact connect@cyborian.com.