Privacy policy
EasyDharma asks seekers personal questions. TruPath asks about your temperament and what you are looking for. Booking a stay may require you to tell us about your health. Some of what you tell us we pass to a spiritual space so that it can receive you properly. This policy explains what we collect, why, who sees it, and what you can ask us to do about it. It is written to be read, not to be scrolled past.
1. Who we are
Atha Yoga Anushasanam Private Limited ("EasyDharma", "we", "us") is the data fiduciary for the personal data described in this policy, within the meaning of the Digital Personal Data Protection Act, 2023.
Contact for anything relating to your data: hello@easydharma.com
2. What this policy covers
This policy covers personal data we collect through easydharma.com, through TruPath, through our correspondence with you, and through arranging your booking at a spiritual space.
It does not cover how a spiritual space handles your data once you deal with the space directly, or once you arrive there. Spaces are independent organisations and are responsible for their own handling of your data. Ask them for their policy.
3. What we collect
Identity and contact data. Your name, email address, telephone or WhatsApp number, country and city of residence, nationality, age or date of birth, and where a space requires it, government identification details.
TruPath data. Your answers to the TruPath questionnaire and your archetype result.
Booking data. What you tell us about your practice, tradition, experience level, and what you are looking for; the experience and dates you request; the space concerned; our correspondence with the space about your booking; and any logistics material we send you.
Health and wellbeing data. Physical and mental health conditions, psychiatric history, current medication, allergies, dietary requirements, mobility or accessibility needs, pregnancy, and anything else you disclose as relevant to your suitability and safety at a spiritual space. We ask for this only where a space requires it or where it is necessary for your safety, and we treat it with heightened care. You choose what you tell us. Withholding relevant health information may mean we cannot arrange a booking.
Transaction data. The fact, amount, date, and status of any payment you make to us, and the invoice we raise. We do not collect or store your card number, CVV, UPI credentials, or bank account details. These go directly to our payment gateway.
Technical data. IP address, browser and device type, operating system, referring page, pages visited, time on page, and similar analytics data collected through cookies and server logs.
Communications. Emails, messages, form submissions, and call notes.
4. How we collect it
Directly from you, when you complete TruPath, fill in a form, write to us, speak with us, or pay us. Automatically, through cookies and server logs. Occasionally from a spiritual space, where it tells us something about your booking that we need to know.
5. Why we use it, and on what basis
We process your personal data on the basis of your consent, and where the Digital Personal Data Protection Act, 2023 permits certain legitimate uses, on that basis.
| Purpose | Data used | Basis |
|---|---|---|
| Give you your TruPath result | TruPath answers | Consent |
| Surface experiences that may be of interest to you | TruPath and booking data | Consent |
| Pass your booking request to a spiritual space | Identity, booking, relevant health data | Consent, see section 6 |
| Confirm your booking and send logistics information | Identity, booking data | Performance of the service you asked for |
| Take payment and issue an invoice | Identity, transaction data | Performance of contract, legal obligation |
| Meet tax, accounting, and statutory obligations | Identity, transaction data | Legal obligation |
| Respond to your enquiries and complaints | All relevant data | Performance of the service, legal obligation |
| Send you transactional email about your booking | Identity, booking data | Performance of the service |
| Send you our publications and updates | Name, email | Consent, withdrawable at any time |
| Improve our service and understand how our site is used | Technical data, aggregated and de-identified TruPath data | Consent |
| Handle a report of harm or protect someone's safety | All relevant data | Legitimate use, legal obligation |
| Establish, exercise, or defend a legal claim | All relevant data | Legal obligation, legitimate use |
We do not sell your personal data. We do not rent it. We do not share it with advertisers or data brokers. We do not use your TruPath answers, your health disclosures, or your correspondence for advertising.
6. What we share with a spiritual space, and your control over it
This is the most significant sharing we do, so it gets its own section.
a. To arrange a booking, we pass a spiritual space what it needs in order to decide whether it can host you and to receive you properly. Depending on the space, that may include your name, age, nationality, contact details, practice background, the dates you want, and any health, dietary, or accessibility information the space requires.
b. We will not share health information with any spiritual space without telling you first and obtaining your consent to send it. You may decline, though a space may then decline to host you.
c. Where a space requires identification documents, we will tell you what it needs and why, and you may send it directly to the space instead of through us.
d. Once a spiritual space receives your information, it becomes an independent handler of that data. We do not control what it does with it. We ask spaces to use it only to host you, and to hold it no longer than they need to, but we cannot enforce this and we are not responsible for it. This is one reason we send only what a space actually needs.
e. You may withdraw consent to future sharing at any time by writing to hello@easydharma.com. Withdrawal does not undo sharing that has already happened.
7. Who else we share it with
Service providers. We use the following processors, who handle personal data on our instructions and only for the purposes we specify:
| Provider | Purpose |
|---|---|
| Supabase | Database and authentication |
| Lovable | Website hosting and build platform |
| Razorpay | Payment processing |
| Resend | Transactional and newsletter email |
| Google Workspace | Email, documents, and file storage |
Some of these providers store or process data on servers outside India. See section 8. We will keep this list current, and where we add or change a processor we will update this page.
Professional advisers. Our accountants, compliance advisers, auditors, and lawyers, under confidentiality, where necessary.
Authorities. Where we are required by law, court order, or a lawful request from a competent authority, or where disclosure is necessary to protect someone's life or safety, or to prevent or address serious harm.
A successor. If we are acquired, merged, or reorganised, your data may transfer, subject to this policy.
8. Transfers outside India
Some of our processors store or process personal data outside India. Where they do, we transfer only what is necessary, and only to countries not restricted by the Central Government under section 16 of the Digital Personal Data Protection Act, 2023. We require contractual protections from our processors. Standards of protection differ between countries. If you want to know where a particular category of your data is held, write to hello@easydharma.com and we will tell you.
9. How long we keep it
| Data | Retention |
|---|---|
| TruPath answers and archetype, where no booking follows | 24 months from completion, then deleted or de-identified |
| Booking records and correspondence | 3 years from the end of your stay |
| Health disclosures | Deleted or redacted within 12 months of the end of your stay, unless a live safety matter or claim requires otherwise |
| Financial and tax records | 8 years, as required under Indian tax and company law |
| Reports of harm | As long as necessary, and no longer, having regard to the seriousness of the matter |
| Marketing consent and contact details | Until you withdraw consent, then removed from active lists |
| Technical and analytics data | 14 months |
Where the law requires us to keep something longer, we keep it, and only for that purpose.
10. How we protect it
Data in transit is encrypted over HTTPS. Access to our database is restricted, authenticated, and limited to those who need it. Payment credentials never touch our systems. Health information is held separately from general records where practicable, and access is restricted to those arranging your booking.
No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and affected individuals as required under the Digital Personal Data Protection Act, 2023 and the rules under it.
11. Your rights
Under the Digital Personal Data Protection Act, 2023 you have the right to:
a. be informed about the personal data we hold about you and who we have shared it with;
b. correct, complete, update, or erase your personal data;
c. withdraw consent at any time, as easily as you gave it, after which we will stop the processing that relied on it;
d. nominate another person to exercise your rights in the event of your death or incapacity;
e. raise a complaint with us, and if you remain dissatisfied, with the Data Protection Board of India.
To exercise any of these, write to hello@easydharma.com. We will respond within 30 days and may ask you to verify your identity first. Some data we may have to keep, for example financial records required by law, and we will tell you if that applies.
You also have a duty under the Act not to furnish false particulars or file frivolous complaints.
12. Cookies
We use cookies that are strictly necessary for the site to function, and, with your consent, cookies that help us understand how the site is used. We do not use advertising or cross-site tracking cookies. You can decline non-essential cookies through our cookie banner, and you can clear or block cookies through your browser, though some features may then not work.
13. Children
Our services are for adults. We do not knowingly collect personal data from anyone under 18. We do not use personal data for tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a minor has given us data, write to us and we will delete it.
14. Changes to this policy
We will update this page when our practices change and will change the date at the top. Where a change is material, particularly to what we share or with whom, we will tell you by email and, where the law requires it, ask for your consent again.
Questions about this policy: hello@easydharma.com