Ananta Logo

ANANTA

By The Hill

Escape. Indulge. Unwind.

Legal

Privacy Notice

Version 2026-09-06-v1

Last updated: 6 September 2026

This is a standalone privacy noticeunder the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. It is separate from our Terms & Conditions.

Ananta By The Hill (Canary Hill Rd, Hirabaug, Hazaribagh, Jharkhand 825301) is the Data Fiduciary for personal data we decide to collect and use for our website and guest services. The registered legal entity name for Board filings will be added here once confirmed by counsel.

1. Who this covers

Data Principals in India who use our website, guest account, room booking, table reservation, food ordering, contact form, or accommodation waitlist. We do not claim consent over information you have made publicly available yourself.

2. Personal data we collect

  • Identity & contact: name, phone number, email address
  • Account: Google sign-in id (if used), profile picture, date of birth (18+ only on self-serve accounts), preferences
  • Bookings & dining: stay dates, guest count, room/table label, order items, special requests, reservation time
  • Payments: payment status and gateway reference ids (card numbers are handled by Razorpay, not stored by us)
  • Messages: enquiry subject and message text
  • Technical: session cookies to keep you signed in; cookie-preference cookie

We do not collect government ID numbers through this website.

3. Why we use your data (purpose & basis)

Under the Act we process personal data only with your consent (Section 6) or for a certain legitimate use in Section 7 (for example where a law requires hotel or tax records). We do not use GDPR-style “legitimate interest.”

  • Create and manage your guest account — consent
  • Complete room bookings, table reservations, and food orders — consent
  • Take payment and send confirmations — consent
  • Respond to enquiries — consent
  • Send accommodation waitlist updates — consent for that purpose only
  • Keep records required by Indian law (for example tax or hotel rules) — Section 7, as advised by counsel
  • Security monitoring and fraud prevention — Section 8 safeguards / applicable rules

4. Who receives your data

  • Our staff — to deliver your booking, order, or reply. Operational alerts (including name, phone, and email needed for fulfilment) may be sent to authorised staff via our internal Telegram operations channel.
  • Razorpay — payments
  • Petpooja — kitchen / POS for food orders
  • MSG91 — OTP SMS (when enabled)
  • Google — Sign-In (only if you choose it)
  • Hosting providers — Supabase (database), Vercel (website), Bunny.net (media)
  • CheckinCloud — hotel PMS when enabled

We do not sell your personal data.

5. Transfers outside India

Some providers may process data outside India. Under Section 16 and Rule 15, transfers are allowed unless the Central Government restricts a country (negative-list model). This is not based on GDPR adequacy or Standard Contractual Clauses. Future Government notifications may change localisation rules.

6. How long we keep data

We keep personal data only while needed for the purpose you shared it for, or as long as Indian law requires (for example tax or hotel records), or for security log periods under the Rules. When the purpose ends or you withdraw consent, we erase or anonymise data we control, subject to legal holds.

7. Children

Under the Act a child is under 18. Self-serve guest accounts are for adults. Do not enter a date of birth under 18 on a self-serve profile. We do not knowingly process a child’s data through this website without verifiable parental or guardian consent.

8. Your rights

  • Ask for a summary of your personal data and who we share it with
  • Ask us to correct or erase your data (subject to legal retention)
  • Withdraw consent
  • Raise a grievance
  • Nominate someone to act if you die or cannot act

The Act does not create GDPR-style data portability or a standalone right to object to automated decisions. We do not promise those rights.

Withdraw consent / request erasure · Manage your profile

9. Grievance redressal

Privacy contact: abthmanagement@gmail.com · +91 99426 31802

We aim to respond within a reasonable period not exceeding 90 days.

If you are not satisfied, you may escalate to the Data Protection Board of India through its official website or app when available for Data Principal complaints.

10. Security

We use reasonable security safeguards (access controls, hashed session tokens, payment verification, hosting backups). If a personal data breach occurs, we will intimate affected persons and the Board as required by law.

11. Language

This notice is in English. For another Eighth Schedule language, email the privacy contact and we will help.

12. Changes

Material changes will be posted here with a new notice version. New purposes may need fresh consent.

Terms & Conditions · Home