1. Purpose & Scope of This Privacy Charter
Welcome to Red River Hospitality and Ventures LLP (operating as "Beau Monde Serviced Suites", "we", "our", or "us"). As curators of premier serviced boutique apartments and residential suites across Guwahati, Assam (including our flagship hubs at Rukmini Nagar adjacent to GS Road and Sewali Path, Hatigaon), we hold the privacy, discretion, and data integrity of our esteemed guests and digital visitors with the utmost gravity.
This Privacy Policy comprehensively delineates the mechanisms through which we collect, store, process, utilize, transmit, and safeguard personal identifiable information (PII) when you visit our official portal (www.beaumondesuites.com), book a serviced apartment, contact our concierge desk, or reside within our accommodations.
2. Categories of Personal Data We Collect
To render seamless hospitality, verify physical check-ins under local police norms, and process financial reservations, we collect distinct classes of information depending on your level of engagement:
A. Direct Reservation & Contact Coordinates
- Full Legal Name: As presented on government-recognized identification.
- Contact Coordinates: Valid electronic mail address, primary mobile telephone number, and active WhatsApp contact credentials.
- Residential Coordinates: Permanent residential address, city, state, postal PIN code, and nationality.
- Travel Parameters: Scheduled check-in date, check-out date, number of accompanying adult guests, children counts, suite category preferences, and specialized hospitality requests.
B. Identity Verification & Statutory KYC Documents
- Copies or verified digital records of government identification (e.g., Aadhaar Card, Passport, Indian Voter Identity Card, or Driving License) for domestic travelers.
- Valid Passport details, Visa credentials, immigration entry stamps, and Form C Foreigner Registration documentation for international travelers.
C. Digital Device & Technical Metadata
- Internet Protocol (IP) address, browser client identity, operating system configuration, referring URLs, access timestamps, and session activity logs.
3. Lawful Basis & Methods of Collection
We acquire your personal information exclusively through equitable and lawful conduits:
- Direct Submission: When you enter reservation parameters on our website booking engine, complete guest check-in folios, submit corporate partner inquiries, or converse with our 24/7 concierge via WhatsApp or telephone.
- Automated Digital Technologies: Via technical cookies, server transaction telemetry, and performance logs during portal navigation.
- Authorized Aggregator Portals: When reservations are initiated through licensed travel distribution partners (e.g., MakeMyTrip, Airbnb, Booking.com), who transmit guest voucher credentials to our system for arrival fulfillment.
4. Purpose of Personal Data Processing
Beau Monde Serviced Suites LLP processes personal data exclusively for defined, legitimate hospitality purposes:
- Reservation Fulfillment & Stay Management: Issuing instant booking confirmations, room access allocations, arrival reminders, and itemized tax invoices.
- Statutory & Police Verification: Complying with Section 144 orders, the Foreigners Act 1946, and District Magistrate circulars for mandatory police guest registration.
- Direct Concierge Communication: Transmitting keyless access coordinates, Wi-Fi passwords, emergency assistance updates, and airport transfer scheduling.
- Financial Reconciliation & Auditing: Recording GST tax assessments, SAC code accounting (SAC 996311), and banking reconciliation.
- Safety & Loss Prevention: Protecting property assets, preventing fraudulent bookings, and maintaining a secure environment across our residential hubs.
5. Payment Security & Zero Card Storage Policy
We recognize that financial peace of mind is fundamental to luxury travel. We enforce an unyielding Zero Financial Credential Storage architecture:
- We do not collect, process, record, or retain complete credit card numbers, debit card numbers, CVV/CVC codes, net banking passwords, or UPI PINs on any server operated by Beau Monde Suites.
- All payment transactions are routed directly via end-to-end encrypted Application Programming Interfaces (APIs) to Razorpay Software Private Limited, an RBI-licensed payment aggregator certified under PCI-DSS Level 1 (Payment Card Industry Data Security Standard).
- Our databases retain only non-sensitive transaction tokens (such as `pay_xxxxxxxxxxxxx`), transaction timestamps, settled rupee amounts, and payment status indicators necessary for generating official tax invoices.
6. Technical Security & Encryption Architecture
We adopt rigorous physical, electronic, and procedural safeguards designed to protect guest records against unauthorized access, loss, alteration, or disclosure:
- Transport Layer Security (TLS 1.3): All digital transmissions between your browser and our servers are encrypted with 256-bit cryptographic keys.
- Encryption at Rest: Sensitive guest contact tables within our operational databases are safeguarded utilizing AES-256-GCM authenticated encryption.
- Role-Based Access Control (RBAC): Administrative access to the Super Admin portal is restricted exclusively to authorized senior personnel protected by session verification, multi-factor authentication, and audited activity logs.
- Periodic Vulnerability Auditing: Regular penetration assessments, code audits, and secure coding practices ensure our digital infrastructure resists SQL injection, CSRF, and XSS vectors.
7. Third-Party Disclosures & Non-Sale of Data
Data is shared solely with vetted partners under strict non-disclosure obligations:
- Payment Aggregators (Razorpay): Solely for settling authorized room payments and executing refund disbursements.
- Cloud Infrastructure Providers: ISO/IEC 27001 certified cloud server facilities maintaining encrypted database clusters.
- Statutory Authorities & Law Enforcement: Strictly when mandated under valid judicial subpoenas, court warrants, or local police verification directives.
8. Local Police Registration & Foreigners Form C
In accordance with the statutory hotel and hospitality regulations established by the Government of Assam and the Bureau of Immigration (Ministry of Home Affairs, Government of India):
- All domestic guests aged 18 and above are required to provide government-authorized identity documents during check-in. Information is recorded in the physical or digital register maintained for inspection by administrative authorities.
- For non-Indian passport holders, statutory regulations compel the submission of Form C to the Foreigners Regional Registration Office (FRRO) within 24 hours of arrival. Refusal to provide immigration documentation legally mandates the refusal of accommodation.
9. Cookies, Analytics & Session Tracking
Our digital platform utilizes small text files termed "cookies" to deliver core application functionality:
- Essential Functional Cookies: Session identifiers (`PHPSESSID`) required to maintain authentication states, preserve stay dates in the booking drawer, and manage CSRF security tokens.
- Performance Telemetry: Aggregated, anonymized metrics that record page response latencies, browser types, and navigation paths to optimize page load speeds across mobile networks.
- You maintain the liberty to disable or purge cookies through your browser settings; however, disabling essential session cookies may impede the booking engine from retaining reservation parameters.
10. Data Retention & Permanent Erasure
We retain personal data only for as long as is necessary to fulfill the purposes delineated in this policy, unless an extended retention period is mandated by Indian statutory tax laws:
- Tax & Accounting Records: Booking vouchers and tax invoices with GSTIN data are retained for 7 years in compliance with Section 36 of the Central Goods and Services Tax (CGST) Act, 2017.
- Guest Profiles & Inquiry Logs: Marketing contact logs and general contact queries are purged or anonymized after 24 months of dormancy unless an active guest account is retained.
- Upon formal written request from an individual whose legal retention duration has elapsed, we execute cryptographic deletion of personal records across active databases and backups.
11. Your Rights as a Data Principal (DPDP Act, 2023)
Under the Digital Personal Data Protection Act, 2023, you are endowed with defined rights regarding your digital information:
- Right to Access: The right to request an itemized summary of personal data held by us, alongside identities of third parties with whom it has been shared.
- Right to Correction & Updating: The right to rectify incomplete, inaccurate, or outdated contact and personal details.
- Right to Erasure: The right to request the deletion of your personal data, subject to statutory retention obligations under tax and police laws.
- Right to Grievance Redressal: The right to readily accessible grievance resolution channels for any privacy-related concerns.
- Right to Nominate: The right to designate another individual who may exercise your privacy rights in the event of death or incapacity.
12. Designated Grievance Officer & Contact Coordinates
To exercise any statutory privacy rights, submit inquiries, or lodge a grievance regarding our data governance practices, you may formally contact our designated Compliance & Grievance Officer: