Privacy Policy

APPLICABLE LEGAL FRAMEWORK

This Privacy Policy has been drafted to comply with all laws and regulations applicable to Megamax Aviation Pvt. Ltd. as a Data Fiduciary carrying out helicopter tour and charter operations in India. The table below maps each applicable statute to the specific obligations it imposes and the sections of this Policy that address those obligations.

Applicable Law / Regulation Key Obligation on Megamax Aviation Relevant Section of this Policy
Digital Personal Data Protection Act, 2023 (DPDP Act) Lawful basis for processing; consent; Data Principal rights; Data Fiduciary obligations; breach notification; grievance redressal; children's data safeguards. Secs 3–9, 11, 12, 13
Information Technology Act, 2000 (IT Act) & IT (Amendment) Act, 2008 Reasonable security practices; liability for data breach; cyber-security obligations of body corporates. Secs 66, 70B, 72A, 79
IT (SPDI Rules), 2011 Privacy policy publication; consent for SPDI; security standards; disclosure conditions; retention & grievance. Rules 2, 4, 5(1), 5(9), 6, 8
IT (Intermediaries Guidelines & Digital Media Ethics Code) Rules, 2021 Grievance officer designation; acknowledgement and complaint resolution requirements. Rule 3(2)(a)(i); Rule 3(1)(b)
Bharatiya Vayuyan Adhiniyam, 2024 & Aircraft Rules, 1937; Civil Aviation Requirements (CARs) Passenger manifests, weight & balance records, fitness-to-fly documentation, and DGCA-mandated reporting. Secs 2, 4, 6, 10 BVA; Aircraft Rules; DGCA CARs
Foreigners Act, 1946 & Passport Entry into India Rules, 1950 Passport verification and reporting for foreign national passengers. Secs 2, 3(2)(a), 6, 7A; Passport Entry Rule 14
Consumer Protection Act, 2019 & E-Commerce Rules, 2020 Fair practice; information disclosure; grievance mechanism for consumers. Secs 2(7), 18, 35, 47, 89; E-Com Rules 4, 6, 7
Payment and Settlement Systems Act, 2007 & RBI Card Guidelines Card surcharge restrictions; secure payment data handling; PCI-DSS alignment. PSS Act Sec 10(2); RBI PA Master Direction (2020); RBI Tokenisation Guidelines (2022); PCI-DSS 4.0
DPDP Rules, 2025 Grievance redressal timelines; consent management; Data Fiduciary register requirements. Rules 3, 4, 5, 6, 7, 8, 10, 13, 14
Carriage by Air Act, 1972 (Montreal Convention, Third Schedule) Passenger data in context of air carriage; statutory record-keeping obligations; liability limits for data-related incidents during carriage

INTRODUCTION

Megamax Aviation Pvt. Ltd. (CIN: U63090UP2020PTC125788 ) ("Megamax Aviation", "Company", "we", "us", "our") is a helicopter tour and charter operator headquartered at B-40, Sector-57, Noida – 201301, Uttar Pradesh, India. We are a Data Fiduciary within the meaning of Section 2(i) of the Digital Personal Data Protection Act, 2023 ("DPDP Act").

We are committed to the lawful, fair, and transparent processing of personal data. This Privacy Policy ("Policy") sets out how we collect, use, store, share, and protect your personal data when you visit our website, make a booking with us, use our helicopter tour or charter services, including the Do-Dham / Chardham Heli-Tour, or when you deal with us through any channel.

We process personal data only for the purposes and on the legal bases stated in this Policy. We do not sell, rent, or otherwise commercially exploit your personal data.

1. SCOPE AND APPLICATION

This Policy applies to:

  • All visitors to www.megamaxaviation.com and any sub-domains operated by Megamax Aviation.
  • All passengers, prospective passengers, and their authorised agents or legal guardians who interact with us in connection with a booking, tour, charter, or related service — including the Do-Dham / Chardham Heli-Tour.
  • All individuals who contact us through any channel, including telephone, email, WhatsApp, social media, physical counter, and third-party booking platforms.
  • All corporate charter clients and their designated group representatives.

This Policy does not apply to the websites or services of third parties that may be linked from our website. Those third parties are solely responsible for their own privacy practices.

2. Personal Data We Collect

Depending on the nature of your interaction with us, we collect only the personal data necessary for the stated purpose.

2.1 Personal and Contact Information

We may collect information required to identify and contact you in connection with your booking and our services.

2.2 Government-Issued Identification

Aadhaar number or Aadhaar-linked reference number may be collected from Indian nationals solely for statutory Yatra registration requirements. Passport number, nationality, visa details, and date of birth may be collected from foreign nationals in compliance with applicable law.

2.3 Flight Safety & Biometric-Adjacent Information

Body weight is mandatory for helicopter weight-and-balance calculations under applicable aviation laws and DGCA requirements. Height and relevant physical characteristics may be collected where necessary for seat allocation and safety harness compliance.

2.4 Health-Related Information

Health conditions, fitness-to-fly certification, medical clearance documentation, and medication information relevant to flight safety may be processed where voluntarily disclosed for safety, emergency preparedness, or applicable service requirements.

2.5 Payment & Financial Information

We may collect transaction reference numbers, payment instrument type, and billing address. We do not store full card numbers, CVV codes, or PINs. Card payments are processed by authorised and PCI-DSS-compliant payment gateway partners.

2.6 Aviation & Operational Data

This may include booking reference number, flight date, departure helipad, destination, flight sequence, seat allocation, passenger manifest data, reporting time, boarding acknowledgement, and booking modification records.

2.7 Technical & Website Data

We may automatically collect IP address, browser type, device type, operating system, pages visited, cookie identifiers, and session data.

2.8 Communications Data

We may retain records of correspondence through email, telephone, WhatsApp, social media, or other channels for service quality, dispute resolution, and grievance redressal. Photographs or videos may be collected where you have separately consented to photography or videography.

3. How We Use Your Personal Data

We use personal data only for specified purposes, including:

  • Processing, confirming, amending, and administering bookings.
  • Complying with statutory and regulatory obligations.
  • Performing flight safety and weight-and-balance calculations.
  • Coordinating accommodation, ground transport, Yatra registration, Darshan facilitation, and other tour logistics.
  • Sending booking confirmations, boarding instructions, itinerary updates, operational advisories, and safety briefings.
  • Coordinating medical assistance in emergency situations.
  • Providing customer support and grievance redressal.
  • Maintaining financial and transaction records.
  • Sending marketing communications where you have provided consent.
  • Complying with court orders, lawful regulatory directions, and legal proceedings.
  • Detecting and preventing fraud, unauthorised access, and harmful activities.
  • Analysing anonymised or pseudonymised usage data to improve our services.

4. Lawful Basis for Processing

4.1 Consent

For most categories of personal data, we rely on your free, specific, informed, and unambiguous consent. You may withdraw consent at any time, although withdrawal may affect our ability to provide certain booked services.

4.2 Legal Obligation

Where processing is required to comply with a legal obligation, such as passenger manifest preparation, Yatra registration, aviation safety records, and tax or financial record-keeping, we may process such data as required by law.

4.3 Vital Interests

In emergency situations, we may process or share the minimum necessary health and identity information to protect the vital interests of a passenger or another person.

4.4 Legitimate State / Regulatory Functions

Processing carried out at the direction of a Government authority, DGCA, MoCA, tribunal, or court may be undertaken where required under applicable law.

5. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected or as required by applicable law.

Category of Personal Data Retention Period Legal Basis for Retention
Booking records 90 days post-tour conclusion unless a dispute is pending Terms & Conditions; DPDP Act
Aadhaar card / Passport copies Deleted or destroyed no later than the tour departure date, unless legally mandated otherwise Terms & Conditions; SPDI Rules, 2011
Financial transaction records 7 years from the date of transaction Income Tax Act and applicable GST legislation
DGCA passenger manifests and weight-and-balance records Minimum 2 years or as prescribed Aircraft Rules and relevant CARs
Grievance records 3 years from the date of resolution Applicable IT Rules and DPDP compliance requirements
Marketing consent records Duration of consent + 1 year DPDP Act and SPDI Rules
Health / medical clearance data Duration of the booking + 90 days, or as required by law DPDP Act, Aircraft Rules and CARs
Passenger Declaration records 1 year from tour date Terms & Conditions

At the end of the applicable retention period, personal data is securely deleted, destroyed, or anonymised.

6. Sharing & Disclosure

We do not sell, trade, or commercially transfer your personal data to third parties. We disclose personal data only where necessary and to the following categories of recipients.

6.1 Government and Regulatory Authorities

Required data may be shared with relevant Government authorities, temple authorities, Uttarakhand Tourism Department, Ministry of Civil Aviation, DGCA, and other competent authorities where required by law.

6.2 Temple Authorities & Yatra Registration Bodies

Necessary identity and registration information may be shared with relevant shrine management boards or temple trusts where required for the Do-Dham Heli-Tour and related services.

6.3 Service Providers and Data Processors

We may engage service providers for accommodation, ground transport, payment processing, website hosting, and IT support. Such providers are contractually required to protect personal data and process it only in accordance with authorised instructions.

6.4 Pilot-in-Command and Flight Operations Personnel

Relevant passenger weight, health clearance, and manifest information may be made available to authorised flight operations personnel as strictly necessary for flight safety.

6.5 Law Enforcement and Legal Process

We may disclose personal data to law-enforcement agencies, courts, tribunals, or competent authorities where required by law.

6.6 Emergency Medical Service Providers

In a medical emergency, we may share the minimum necessary health and identity data with hospitals, emergency medical providers, and evacuation services.

6.7 Business Transfers

In the event of a merger, acquisition, corporate restructuring, or transfer of assets, personal data may be transferred to a successor entity subject to appropriate data protection obligations.

We do not share health data or Aadhaar data with hotels, transport providers, or marketing partners except where legally authorised or necessary in a life-threatening emergency.

7. Cookies & Website Tracking

Our website uses cookies and similar technologies to enhance browsing experience and analyse aggregate site usage.

  • Strictly necessary cookies: Required for core website functionality, session management, forms, and online booking.
  • Analytics cookies: Used to collect anonymised or aggregated information about website usage.
  • Preference cookies: Used to remember preferences such as language settings.

We do not use cookies for targeted advertising, behavioural profiling, or the sale of data to advertisers. You may control non-essential cookies through your browser settings.

8. Data Security

We implement reasonable security practices and procedures to protect personal data. Our security framework includes:

  • Technical controls: Encryption, access controls, role-based permissions, secure server environments, and security patching.
  • Administrative controls: Internal policies, staff training, data minimisation, and need-to-know access principles.
  • Physical controls: Restricted access to physical storage and processing facilities.
  • Vendor due diligence: Data protection obligations imposed on relevant third-party processors.
  • Aviation-specific controls: Access-controlled systems for passenger manifests and weight-and-balance records.

No method of electronic transmission or storage is completely secure. In the event of a personal data breach, we will take appropriate steps to notify affected Data Principals and relevant authorities as required under applicable law.

9. Your Rights as a Data Principal

Subject to applicable law, you may have the following rights regarding your personal data:

  • Right to information about processing.
  • Right to correction and updating of data.
  • Right to erasure, subject to applicable retention obligations.
  • Right to grievance redressal.
  • Right to nominate a successor.
  • Right to withdraw consent.

To exercise these rights, please submit a written request to our Data Protection Officer. We may request identity verification before processing your request.

10. Children's Data

Megamax Aviation does not knowingly solicit or process the personal data of children under 18 years of age independently. Where a minor travels as part of a booking, the relevant personal data is collected from or with the consent of the accompanying parent or legal guardian.

We do not use the personal data of minors for purposes unrelated to fulfilling the booked service and complying with applicable legal and aviation obligations.

11. Carriage by Air Act, 1972 — Data Protection Interface

11.1 Passenger Data and the Contract of Carriage

Personal data collected for the purpose of the contract of carriage, including identity, weight, and relevant health information, may form part of carriage documentation and be subject to applicable statutory record-keeping obligations.

11.2 DGCA Passenger Manifest Data

Passenger manifests prepared in accordance with applicable Aircraft Rules and DGCA CARs constitute legally required records.

11.3 Data Incidental to Liability Events

Where a passenger incident gives rise to a claim, legal proceeding, or regulatory inquiry, relevant personal data may be retained beyond the standard retention period for the duration required by law.

11.4 Denied Boarding and Offloading Records

Records relating to denied boarding or offloading may be maintained in accordance with applicable aviation and regulatory requirements.

12. Cross-Border Data Transfers

Our helicopter tour and charter operations are primarily domestic, and we do not ordinarily transfer personal data outside India.

Where a cross-border transfer is required, such as for verification of foreign-national passenger information or emergency medical coordination, the transfer will be undertaken only in accordance with applicable Indian data protection law.

13. Changes to This Policy

We may update this Policy periodically to reflect changes in applicable law, regulatory guidance, or our operational practices.

Material changes will be published on this page with an updated version number and effective date. Where a change significantly affects the processing of personal data, we may take reasonable steps to notify affected individuals directly.

14. Third-Party Websites

Our website may contain links to third-party websites, social media platforms, partner travel portals, or temple authority portals. These websites are governed by their own privacy policies, and Megamax Aviation is not responsible for their content, privacy practices, or security.

15. Grievance Redressal & Contact

Megamax Aviation has designated a Data Protection Officer / Grievance Officer for privacy-related queries and grievances.

Designation: Data Protection Officer / Grievance Officer

Company: Megamax Aviation Pvt. Ltd.

Address: B-40, Sector-57, Noida – 201301, Uttar Pradesh, India

Email: Legal-@megamaxaviation.com

Contact: +91 95557 14275

Working Hours: Monday to Friday, 10:00 AM – 6:00 PM IST (excluding public holidays)

Upon receipt of a grievance or query, we will:

  • Acknowledge the grievance or query within the applicable timeframe.
  • Resolve grievances within the timeframe prescribed by applicable law or provide a written explanation of any delay.
  • Maintain records of grievances and their resolution in accordance with applicable legal requirements.

If you remain dissatisfied after our resolution, you may escalate your complaint to the appropriate competent authority, including the Data Protection Board of India once established and operational, or the appropriate consumer authority where applicable.