Legal

Privacy policy.

Effective 6 June 2026

This Privacy Policy explains how Praveen Kumar Adha, an Indian sole proprietor trading as "HereVR" ("we", "us", "our"), collects and processes personal information about you when you visit herevr.in, request access to the service, or engage us as a client. It is written to comply with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and to align with the principles of the EU General Data Protection Regulation ("GDPR") and UK GDPR for clients and visitors in those regions.

1.Who we are

HereVR is operated by Praveen Kumar Adha as a sole proprietorship. For all privacy enquiries, exercise of rights, or complaints, contact hello@herevr.in. For DPDP Act purposes, Praveen Kumar Adha is the Data Fiduciary; for GDPR purposes, the Data Controller.

2.Scope

This policy covers personal data processed through our website, the request-access form, our client onboarding process, and the day-to-day operation of the lifestyle office.

3.What we collect

  • Identifiers & contact data: name, email address, phone number with country code, country / state / city.
  • Request-access data: the message you send us and any context you provide about your situation. This is currently captured into a private Google Sheet accessible only to us.
  • Client engagement data (if you become a client): household composition where relevant, travel and lifestyle preferences, addresses, supplier details, calendar information, instructions you send us.
  • Communications: emails, calls, messages, and notes from conversations.
  • Billing data: invoice details, amounts, and payment confirmations. Card data, when collected, is handled by our payment processor; we do not store it ourselves.
  • Technical & analytics data: IP address, device and browser information, pages viewed, session recordings and heatmaps collected via Microsoft Clarity, and standard server logs.

4.Why we collect it (lawful basis)

  • To respond to enquiries and assess fit, necessary for steps prior to entering a contract (GDPR Art. 6(1)(b)) / specified purpose with notice (DPDP §4–5).
  • To deliver the service, performance of contract.
  • To run the business (invoicing, accounting, tax compliance, fraud prevention), legal obligation and legitimate interest.
  • To improve the website via analytics, legitimate interest (and consent where required).
  • To send service-related communications, performance of contract. We do not send marketing emails.

5.How long we retain it

  • Request-access submissions that do not lead to engagement: up to 12 months, then deleted or anonymised.
  • Client engagement records: for the duration of the engagement and up to 7 years afterwards to meet Indian accounting and tax obligations.
  • Billing records: 8 years, as required by Indian tax law.
  • Analytics data: per provider defaults (Microsoft Clarity retains data for up to 13 months).

6.Who we share it with

We do not sell personal data. We share it only with:

  • Google LLC, Google Sheets (USA) stores lead-form submissions; Google Workspace for email.
  • Microsoft Corporation, Microsoft Clarity (USA) for website analytics and session replay.
  • Lovable / hosting providers, for serving the website and edge functions.
  • Vetted suppliers engaged to deliver a specific request you have asked us to coordinate (e.g. a travel partner, vendor, clinician), on a strict need-to-know basis.
  • Professional advisers, accountants and lawyers, under confidentiality.
  • Authorities, where compelled by valid legal process.

7.International transfers

We are based in India. Some of our processors are located in the United States and the European Union. Where personal data is transferred outside your country of residence, we rely on appropriate safeguards including Standard Contractual Clauses with our processors and, where applicable, country-adequacy arrangements. Transfers from India follow §16 of the DPDP Act.

8.Cookies & tracking

Detail of cookies, local storage, and trackers we use, and how to opt out, is in our Cookie Notice.

9.Your rights

You have the right to:

  • Access the personal data we hold about you, and receive a copy.
  • Correct or update inaccurate information.
  • Request erasure of your data, subject to legal retention obligations.
  • Withdraw consent for processing that relies on consent (e.g. analytics).
  • Object to or restrict processing in certain circumstances (GDPR).
  • Receive your data in a portable format (GDPR / DPDP).
  • Nominate another person to exercise these rights on your behalf in the event of death or incapacity (DPDP §14).

To exercise any of these rights, email hello@herevr.in. We respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with the Data Protection Board of India (under the DPDP Act) or with your local supervisory authority (under GDPR / UK GDPR).

10.Children's data

The service is intended only for adults aged 18 or over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

11.Security

We apply reasonable security safeguards: access controls, least-privilege sharing, encrypted transport (HTTPS), provider-side encryption at rest, separation of operational and analytics data, and regular review of who has access. No online service is perfectly secure; we will notify affected individuals and the Data Protection Board promptly if a reportable breach occurs.

12.Changes to this policy

We may update this policy. Material changes will be notified to active clients by email and reflected in the "Effective" date above.

13.Contact

For any privacy matter, write to hello@herevr.in. Praveen Kumar Adha is the sole point of contact and serves as our privacy officer until a registered entity is in place.

This policy reflects our current operating model as an Indian sole proprietorship and is not legal advice. It will be updated when HereVR is incorporated.