Add your friends to your group and get more discounts 

Privacy Policy

Last updated: 31 August 2026

At INDEOR, we respect your privacy and are committed to protecting your personal data.

This Privacy Policy explains how Indeor World Experiences (“INDEOR”, “we”, “us” or “our”) collects, uses, stores, shares and protects personal data when you visit www.indeor.com (the “Website”), contact us, request a quotation, make a booking, subscribe to our newsletter or otherwise communicate with us.

This Privacy Policy is intended to address the requirements applicable to INDEOR under Indian data-protection law and, where applicable, the European Union General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable European electronic-privacy/cookie requirements.


 

1. DATA CONTROLLER

The entity responsible for the processing of your personal data is:

Indeor World Experiences

Head Office
43, Kongorpilly – Alangad – Kadungalloor Road
Kongorpilly P.O.
Ernakulam, Kerala – 683518
India

Website: www.indeor.com

For questions concerning this Privacy Policy or your personal data, please contact us through the contact details published on our Website.


 

2. PERSONAL DATA WE COLLECT

Depending on how you interact with INDEOR, we may collect the following information.

2.1 Information you provide to us

This may include:

  • name and surname;

  • email address;

  • telephone/mobile number;

  • country of residence;

  • preferred language;

  • travel dates;

  • number of travellers;

  • destination preferences;

  • accommodation preferences;

  • transportation preferences;

  • meal preferences;

  • activities and experiences requested;

  • information contained in your enquiry;

  • information contained in correspondence with us; and

  • any other information that you voluntarily provide.

2.2 Information required to organise a trip

If you proceed with a booking, we may need information necessary to arrange the requested services, including:

  • passport or travel-document information;

  • nationality;

  • date of birth;

  • flight details;

  • arrival and departure information;

  • accommodation information;

  • transport requirements;

  • emergency-contact information;

  • dietary requirements;

  • accessibility requirements; and

  • other special travel requirements.

We only request information reasonably necessary for the relevant travel service.

If you provide information concerning another traveller, you should ensure that you are authorised to provide that information and that the traveller has been appropriately informed where required by applicable law.

2.3 Information collected when you use our Website

When you visit our Website, technical information may be collected automatically, including:

  • IP address;

  • browser type;

  • device type;

  • operating system;

  • language settings;

  • approximate geographic information;

  • pages visited;

  • date and time of visits;

  • referring website;

  • technical information concerning your browser or device; and

  • information concerning Website interactions.

Some information may be collected using cookies or similar technologies. Please see our Cookie Policy.


 

3. HOW WE USE PERSONAL DATA

We use personal data for the following purposes.

3.1 Responding to enquiries

We use information submitted through our Website, email or other communication channels to:

  • respond to enquiries;

  • understand your travel requirements;

  • prepare quotations;

  • design personalised itineraries;

  • recommend travel services; and

  • communicate with you concerning your request.

3.2 Providing travel services

Where you make a booking, we use relevant information to:

  • administer your booking;

  • arrange accommodation;

  • arrange transportation;

  • arrange guides and activities;

  • coordinate arrival and departure arrangements;

  • communicate with travel suppliers;

  • provide customer assistance;

  • manage payments and accounting; and

  • provide the services included in your travel arrangements.

3.3 Customer service

We may use your information to:

  • communicate with you before, during and after your trip;

  • respond to requests;

  • resolve complaints;

  • handle service issues; and

  • maintain appropriate records of our relationship with you.

3.4 Marketing

Where permitted by applicable law, we may use your contact information to send information concerning:

  • new travel experiences;

  • group departures;

  • destinations;

  • travel inspiration;

  • special offers; and

  • INDEOR services.

Where marketing requires consent, we will obtain that consent separately.

You may withdraw your marketing consent or unsubscribe at any time.

3.5 Website operation and security

We may process technical information to:

  • operate the Website;

  • maintain security;

  • prevent abuse and fraudulent activity;

  • diagnose technical problems;

  • improve Website performance; and

  • maintain the reliability of our online services.

3.6 Analytics and advertising measurement

Our Website uses Google Tag Manager, identified on the live Website by the container GTM-KH98CR29. Google Tag Manager is a technology used to manage Website tags and scripts. citeturn1view1

The tags deployed through this container may change over time. Where analytics, advertising or other non-essential technologies are used, the relevant technologies will be described in our Cookie Policy and, where required, activated only after the appropriate consent has been obtained.


 

4. LEGAL BASIS FOR PROCESSING

Where the GDPR applies, we process personal data on the following legal bases.

Contract

Where processing is necessary to take steps at your request before entering into a contract or to perform a contract with you.

This includes preparing and administering travel arrangements.

Legal obligation

Where processing is necessary to comply with applicable legal, tax, accounting, regulatory or other obligations.

Legitimate interests

Where processing is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms.

This may include:

  • operating and securing our Website;

  • preventing fraud;

  • managing our business;

  • maintaining customer records;

  • improving our services;

  • responding to customer communications; and

  • establishing, exercising or defending legal claims.

Consent

Where consent is required, we will request it separately and provide an appropriate mechanism for withdrawing it.

Consent must be freely given, specific, informed and unambiguous. GDPR guidance expressly rejects silence, inactivity and pre-ticked boxes as valid consent. citeturn5search0


 

5. NEWSLETTER AND MARKETING

If you subscribe to the INDEOR newsletter, we may process your email address to send you travel information, inspiration, offers and other marketing communications.

Marketing consent is separate from consent required to process an enquiry or provide a travel service.

You can unsubscribe at any time using the unsubscribe mechanism included in our marketing communications or by contacting us.

Withdrawal of marketing consent will not affect processing that is necessary for an existing enquiry, booking or contractual relationship.


 

6. TRAVEL SUPPLIERS AND SERVICE PROVIDERS

To provide your requested travel services, we may share relevant personal data with third parties, including:

  • hotels and resorts;

  • airlines and transport providers;

  • drivers;

  • local guides;

  • activity and excursion providers;

  • restaurants and other suppliers;

  • payment providers;

  • technology and hosting providers;

  • communication and email providers;

  • professional advisers;

  • insurers where relevant and authorised; and

  • government or public authorities where required by law.

We disclose only information reasonably necessary for the relevant purpose.


 

7. INTERNATIONAL DATA TRANSFERS

INDEOR is established in India and arranges travel services in India and other countries.

Your personal data may therefore be processed or accessed in countries outside your country of residence, including countries outside the European Economic Area.

Where the GDPR applies, we will use legally recognised safeguards for international transfers where required.

Because international travel arrangements may require us to communicate personal information to hotels, airlines, guides, transport providers and other suppliers located in countries outside the EEA, certain transfers may be necessary to provide the travel service requested by you.


 

8. DATA RETENTION

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected.

Retention periods may depend on:

  • the nature of the information;

  • whether you have an active enquiry or booking;

  • accounting and tax requirements;

  • legal obligations;

  • dispute-resolution requirements; and

  • the establishment, exercise or defence of legal claims.

When personal data is no longer required, we will delete, anonymise or securely dispose of it where reasonably practicable.


 

9. DATA SECURITY

We use reasonable technical and organisational measures intended to protect personal data against:

  • unauthorised access;

  • unlawful processing;

  • accidental loss;

  • destruction;

  • alteration; and

  • unauthorised disclosure.

However, no internet transmission or electronic storage system can be guaranteed to be completely secure.


 

10. YOUR RIGHTS UNDER THE GDPR

Where the GDPR applies, you may have the right to:

  • request access to your personal data;

  • request correction of inaccurate information;

  • request deletion of personal data;

  • request restriction of processing;

  • object to certain processing;

  • request data portability;

  • withdraw consent where processing is based on consent;

  • object to direct marketing; and

  • lodge a complaint with a competent data-protection supervisory authority.

These rights are subject to the limitations and conditions established by applicable law.

The GDPR provides, among other rights, access, rectification, erasure, restriction, portability and objection rights. citeturn5search0


 

11. RIGHTS UNDER INDIAN DATA-PROTECTION LAW

INDEOR also recognises rights applicable under India’s Digital Personal Data Protection Act, 2023 and associated rules, as and when the relevant provisions apply to the processing concerned.

The DPDP Act requires consent, where consent is the basis of processing, to be free, specific, informed, unconditional and unambiguous and based on clear affirmative action. It also provides for withdrawal of consent and requires processing to cease, subject to applicable legal exceptions, after withdrawal. citeturn4search45

The DPDP Rules, 2025 require notices to be clear, standalone and understandable and to explain the personal data collected and the purposes for which it is processed. citeturn4search47


 

12. WITHDRAWAL OF CONSENT

Where processing is based on consent, you may withdraw your consent.

Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal.

Where required by applicable law, we will cease processing based on the withdrawn consent within the applicable period, unless continued processing is permitted or required by law or is necessary for another lawful purpose.


 

13. COOKIES AND SIMILAR TECHNOLOGIES

INDEOR uses cookies and similar technologies.

These may include:

  • strictly necessary technologies;

  • Website functionality technologies;

  • analytics technologies;

  • advertising or marketing technologies; and

  • technologies used to measure Website or campaign performance.

The Website currently uses Google Tag Manager (GTM-KH98CR29). citeturn1view1

Because Google Tag Manager can deploy different tags, the exact non-essential technologies in use may change. Our Cookie Policy should therefore be maintained together with the Website’s actual tag configuration.

Where consent is required for cookies or similar technologies, non-essential technologies should not be activated before the visitor has provided the required consent.


 

14. THIRD-PARTY WEBSITES

Our Website may contain links to third-party websites, including travel providers, social-media platforms and other external websites.

We are not responsible for the privacy practices of those websites.

You should review the privacy policy of any third-party service before submitting personal information.


 

15. SOCIAL MEDIA

INDEOR may operate social-media pages and may use social-media services for communication and marketing.

If you interact with us through a social-media platform, that platform may independently process your personal information under its own privacy policy.


 

16. CHILDREN

Our Website and travel services are primarily intended for adults.

We do not knowingly seek personal information directly from children except where such information is necessary for a travel service and is lawfully provided by a parent, guardian or authorised person.


 

17. SPECIAL TRAVEL REQUIREMENTS

Travel arrangements may require information concerning dietary requirements, accessibility, mobility assistance or other special requirements.

Some such information may constitute sensitive or special-category information under applicable law.

We will only process such information where necessary for providing the requested service and where an appropriate legal basis exists.


 

18. AUTOMATED DECISION-MAKING

INDEOR does not intend to make decisions producing legal or similarly significant effects on individuals solely through automated processing of personal data.


 

19. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy when our services, technology, data-processing practices or applicable laws change.

The latest version will be published on this page with its effective date.


 

20. CONTACT

For questions about this Privacy Policy or to exercise applicable privacy rights, please contact:

Indeor World Experiences
43, Kongorpilly – Alangad – Kadungalloor Road
Kongorpilly P.O.
Ernakulam, Kerala – 683518
India

Please use the current contact information published on www.indeor.com for privacy enquiries.


 

21. RIGHT TO COMPLAIN

If you are protected by the GDPR and believe that your personal data has been processed unlawfully, you may lodge a complaint with the competent data-protection supervisory authority in your country of residence, place of work, or place of the alleged infringement.


Effective date: 31 August 2026

Scroll to Top