zentrumhub_logo-removebg-preview Main Header

simplifying Travel Technology

Zentrumhub-blackfont-SVG 2 RateHawk Hotel API

ZentrumHub Website Privacy Notice

1. Introduction and Scope

This Privacy Policy explains how ZentrumHub Solutions Private Limited ("ZentrumHub", "we", "us", "our") collects, uses, discloses and protects personal data when you visit zentrumhub.com and submit a demo request through the Site (collectively, the "Site"). The Site collects prospect/client contact information solely to schedule and conduct product demonstration calls โ€” it does not host a careers portal, newsletter sign-up, or other marketing capture forms.

For these purposes ZentrumHub acts as the Data Controller (Art. 4(7) GDPR). This is distinct from ZentrumHub's role as a Data Processor when operating the white-label hotel booking platform on behalf of B2B clients โ€” that processing is governed by the applicable client Data Processing Agreement (DPA) and the client's own end-user privacy notice, not this document.

This Policy is issued under Articles 13โ€“14 of the EU/UK General Data Protection Regulation (GDPR) and, for data principals located in India, the Digital Personal Data Protection Act, 2023 (DPDP Act). Where the two frameworks differ, Section 9 notes the delta.

Controller details:

FieldDetail
Legal entityZentrumHub Solutions Private Limited
Registered office602, HW95+C9C Sky Vista, Mhada Colony, Viman Nagar, Pune, Maharashtra 411014
CINU72900PN2021PTC200332
Privacy contactprivacy@zentrumhub.com
Data Protection Officerdpo@zentrumhub.com

If you have an EU/UK-based representative requirement under Art. 27 GDPR, contact details will be published here once appointed.

2. Definitions

Personal Data โ€” any information relating to an identified or identifiable natural person (Art. 4(1) GDPR).

Processing โ€” any operation performed on personal data (collection, storage, use, disclosure, erasure).

Data Subject / Data Principal โ€” the individual to whom personal data relates (GDPR / DPDP terminology respectively).

Controller / Data Fiduciary โ€” the entity determining the purposes and means of processing (GDPR / DPDP terminology respectively).

Processor / Data Processor โ€” an entity processing personal data on the Controller's behalf.

Usage Data โ€” data collected automatically through Site infrastructure (IP address, browser type, device identifiers, page views, timestamps).

Cookies โ€” small files placed on your device; see Section 5.

3. Categories of Personal Data We Collect

CategoryExamplesSource
Identity & contact dataName, business email, phone number, job title, company nameYou, directly (demo request form)
Demo scheduling dataPreferred date/time, timezone, use-case/region of interest noted for the callYou, directly
Usage dataIP address, browser/device type, referring URL, pages visited, session durationAutomatically, via Site infrastructure
Cookie identifiersSession ID, analytics client ID, preference settingsAutomatically, via cookies (Section 5)

We do not knowingly collect special category data (Art. 9 GDPR) through the Site. Do not submit special category data (health, biometric, religious, political, or similar) through the demo request form.

4. Purposes and Lawful Basis (Art. 6 GDPR)

PurposeLawful BasisNotes
Scheduling and conducting the demo call you requestedContract (Art. 6(1)(b)) โ€” pre-contractual steps taken at your requestNecessary to arrange, confirm and deliver the call
Follow-up communication reasonably related to the demo (rescheduling, sending materials discussed on the call)Contract (Art. 6(1)(b)) / Legitimate interest (Art. 6(1)(f))Limited to the scope of your request โ€” not general marketing
Site analytics and performance monitoringLegitimate interest (Art. 6(1)(f))Interest: understanding Site usage to improve content and reliability
Fraud prevention and IT security monitoringLegitimate interest (Art. 6(1)(f))Interest: protecting Site integrity and preventing abuse (e.g., spam demo requests)
Legal compliance (tax, statutory filings, regulator requests)Legal obligation (Art. 6(1)(c))e.g., Companies Act 2013, Income Tax Act 1961
Establishing, exercising or defending legal claimsLegitimate interest (Art. 6(1)(f))โ€”

We do not use demo request data to develop, train, or improve generalized AI/ML models, and we do not add you to a newsletter or general marketing list from a demo request alone.

5. Cookies and Tracking Technologies

CategoryPurposeConsent required?
Strictly necessarySession management, load balancing, security (CSRF tokens)No โ€” essential to Site function
PreferenceRemembering language/region settingsNo, but rejectable via cookie banner
AnalyticsUnderstanding Site traffic and usage patternsYes (opt-in via cookie banner)
Marketing/advertisingAd targeting, retargeting (if enabled)Yes (opt-in via cookie banner)

On first visit, a cookie consent banner lets you accept or reject non-essential categories before they are set. You may withdraw consent at any time through the Site's cookie preference center or your browser settings. Rejecting non-essential cookies does not affect Site availability.

6. Recipients and Third-Party Sharing

We disclose Site visitor personal data only to:

Infrastructure and service providers processing on our documented instructions under a data processing agreement โ€” AWS (hosting, ap-south-1/us-east-1/eu-west-1), Auth0/Okta (authentication where applicable to Site accounts), analytics and email delivery providers.

Professional advisers (legal, audit, tax) where necessary and under confidentiality obligations.

Regulators or law enforcement where legally compelled.

Corporate transaction counterparties (e.g., in a merger, acquisition or asset sale), subject to equivalent confidentiality protections.

We do not sell personal data. We do not disclose personal data to third parties for their own independent marketing purposes without your explicit consent.

7. International Data Transfers

ZentrumHub is headquartered in India. Site infrastructure spans AWS ap-south-1 (India), us-east-1 (United States) and eu-west-1 (Ireland). Personal data collected via the Site is primarily processed in ap-south-1, with backup/failover capability in the other regions.

Where personal data of EEA/UK data subjects is transferred to India or the United States, we rely on the EU Standard Contractual Clauses (Module 4, Data Exporter-in-EU-to-Importer-outside-EU, or Module 2/3 as applicable per Commission Implementing Decision (EU) 2021/914) with our infrastructure providers, supplemented where required by encryption in transit (TLS 1.3) and at rest (AES-256). Transfers to AWS eu-west-1 remain within the EEA and require no additional transfer mechanism.

A copy of the applicable transfer safeguards is available on request to privacy@zentrumhub.com.

8. Retention Periods

Data CategoryRetention PeriodBasis
Demo request / scheduling data24 months from the demo call date, unless converted to a client relationship (then per client contract)Legitimate interest โ€” reasonable pipeline follow-up
Usage/analytics data14 months (cookie-based), aggregated thereafterLegitimate interest
Cookie consent logs12 monthsAccountability (Art. 5(2) GDPR)

Data is deleted or irreversibly anonymized at the end of the applicable retention period unless a longer period is required by law (e.g., active legal claim, statutory audit requirement).

9. Your Rights

Under GDPR (Art. 15โ€“22), if you are an EEA/UK data subject you have the right to:

RightArticleExercise via
AccessArt. 15privacy@zentrumhub.com
RectificationArt. 16privacy@zentrumhub.com
Erasure ("right to be forgotten")Art. 17privacy@zentrumhub.com
Restriction of processingArt. 18privacy@zentrumhub.com
Data portabilityArt. 20privacy@zentrumhub.com
Object to processing (incl. direct marketing)Art. 21privacy@zentrumhub.com or unsubscribe link
Not be subject to solely automated decision-making with legal/similar effectArt. 22privacy@zentrumhub.com โ€” note: we do not currently carry out such processing via the Site
Withdraw consent at any timeArt. 7(3)privacy@zentrumhub.com
Lodge a complaint with a supervisory authorityArt. 77Your local EU/UK data protection authority

We respond to verified requests within one month of receipt (extendable by two further months for complex or numerous requests, with notice of the extension and reason within the first month), per Art. 12(3).

DPDP Act 2023 delta (India-based data principals): ZentrumHub is a "Data Fiduciary" under the DPDP Act for Site processing. Data Principals have rights of access, correction, erasure, grievance redressal, and nomination (Sections 11โ€“14). The DPDP Act does not include an explicit portability right and routes breach notification to the Data Protection Board of India (DPBI) rather than a supervisory authority. Grievances may be raised at privacy@zentrumhub.com; unresolved grievances may be escalated to the DPBI.

10. Security of Data

We apply technical and organizational measures proportionate to risk (Art. 32 GDPR), including encryption in transit (TLS 1.3) and at rest (AES-256), role-based access control, mandatory MFA for administrative access, network segmentation via Istio service mesh policies, and centralized audit logging. No method of transmission or storage is 100% secure; we cannot guarantee absolute security but maintain a documented incident response process and notify affected individuals and authorities as required by Art. 33โ€“34 GDPR and DPDP Act breach provisions.

11. Children's Privacy

The Site is not directed at individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us via the Site, contact privacy@zentrumhub.com and we will delete it promptly.

12. Changes to This Policy

We may update this Policy to reflect changes in our practices or legal requirements. Material changes will be notified via a prominent Site notice and, where you have an active relationship with us, by email, at least 14 days before taking effect. The "Last updated" date at the top of this Policy reflects the most recent revision.

13. Contact Us

PurposeContact
General privacy questions, rights requestsprivacy@zentrumhub.com
Data Protection Officerdpo@zentrumhub.com
EEA/UK supervisory authority complaintYour local data protection authority
India โ€” DPDP grievance escalationData Protection Board of India (DPBI), after exhausting privacy@zentrumhub.com

Related documents

Free ebook download

Wait โ€” something's for you ๐Ÿ‘‹

Built for travel agencies
The 5 Hidden
Costs
of Adding a New Hotel Supplier
$
$215K+integration cost
โ—ท
6โ€“9 monthsper supplier
โŠ˜
2โ€“7% bookingsfail silently
โœ“
10โ€“15% devcapacity drain
"What CTOs and CEOs miss when they say, 'let's just integrate one more.'"
12-page report ยท 2026 edition

The real cost most OTAs never calculate.

Drop your work email and we’ll send you the 12-page report that breaks down where 6โ€“9 months and $215K+ quietly disappear โ€” free.

Your email is safe. Unsubscribe anytime.