1. Who we are
This policy applies to Wanderfly Travel Private Limited ("Wanderfly", "we", "us"), registered at Vaddipalem, Narayana Medical College, 6/4/355, Nellore, Andhra Pradesh 524004, CIN U63030AP2022PTC122473. It covers our website at wanderfly.in, our web and mobile applications, and the wellbeing services we provide to organisations and their people (together, the "Services").
2. Our role depends on how you reached us
Wanderfly is sold to employers, but used by individuals. Under the Digital Personal Data Protection Act, 2023 ("DPDP Act") that means we wear two different hats, and your rights differ slightly depending on which one applies:
- Where your employer enrolled you, your employer is the Data Fiduciary and decides why your data is processed. Wanderfly acts as a Data Processor on their documented instructions. Requests to delete or export your account data may need to go through them, and we will tell you when that is the case.
- Where you came to us directly — a website enquiry, a newsletter signup, our blog, the wellbeing quiz, or a personal account — Wanderfly is the Data Fiduciary and is directly answerable to you for that data.
3. What we collect
- Account and identity data: name, work email, employer or team, role, and language or accessibility preferences.
- Wellbeing data: responses to assessments, surveys, check-ins, quizzes and any content you choose to write. This can reveal information about your physical and mental health, so we treat it as our most sensitive category and apply the restrictions in section 5.
- Usage data: pages and features used, session timestamps, device and browser type, approximate location derived from IP address, and diagnostic logs.
- Communications: messages you send us through contact or support forms, and your responses to our emails.
- Billing data for organisational customers. Card details are handled by our payment processors and are not stored on Wanderfly systems.
4. Why we process it
We process personal data to deliver and secure the Services, personalise wellbeing content and recommendations, produce the aggregated insights described below, respond to enquiries and support requests, meet legal and tax obligations, and — where you have separately consented — send marketing communications. We ask for consent at or before the point of collection, in clear language, and you can withdraw it at any time without affecting processing already carried out.
We do not sell personal data. We do not use your individual wellbeing responses to target advertising, and we do not share them with data brokers.
5. What your employer can and cannot see
Your individual wellbeing responses are not shown to your employer.
Employers receive insights only in aggregated, de-identified form, and only where a reporting group contains at least 5 people. Where a group is smaller than that, we suppress the result rather than risk an individual being identified from it.
An employer administrator can typically see:
- whether an account is active, and aggregate participation or engagement rates;
- org-level or team-level trends and themes across a cohort of at least 5 people;
- billing, licensing and administrative records.
An employer administrator cannot see:
- your individual answers to any assessment, survey, check-in or quiz;
- your individual scores, notes, or free-text entries;
- any record of individual sessions you may book with a counsellor, coach or practitioner through the Services.
The one exception is where disclosure is required by law, or where we form a good-faith belief that disclosure is necessary to prevent an imminent risk of serious harm to you or another person. We will limit any such disclosure to what is strictly necessary.
6. Sharing and sub-processors
We share personal data with vetted service providers who help us run the Services — cloud hosting, content management, email delivery, analytics, payment processing, and customer support tooling. They act on our instructions under written contracts and may not use the data for their own purposes. We also disclose data where required by law, court order, or a lawful request from a government authority, and in connection with a merger, acquisition or restructuring, in which case we will notify affected users.
7. Cross-border transfers
Some of our providers process data outside India. Where that happens we transfer data only to jurisdictions permitted under applicable Indian law and put appropriate contractual safeguards in place. You can request the current list of sub-processors and their locations at privacy@wanderfly.in.
8. Retention
We keep personal data only as long as needed for the purpose it was collected. For employer-provided accounts, we retain data for the term of our agreement with your employer and delete or de-identify it within a defined window after that agreement ends, unless a longer period is required by law. Aggregated, de-identified insights that can no longer be linked to an individual may be retained indefinitely.
9. Security
We apply reasonable technical and organisational safeguards including encryption in transit, access controls on a need-to-know basis, logging, and periodic review of our providers. No system is completely secure, so we cannot guarantee absolute security. If a personal data breach affects you, we will notify you and the Data Protection Board of India as required under the DPDP Act and the rules made under it.
10. Your rights
Subject to applicable law, you may:
- Access a summary of the personal data we process about you and who we have shared it with;
- Correct or complete inaccurate or outdated data;
- Erase data where it is no longer needed for the purpose it was collected;
- Withdraw consent at any time, as easily as you gave it;
- Nominate another individual to exercise your rights if you die or become incapacitated;
- Raise a grievance with us and, if unsatisfied, with the Data Protection Board of India.
Write to privacy@wanderfly.in to exercise any of these. We may need to verify your identity first. Where your employer is the Data Fiduciary, we will forward your request to them and support them in answering it.
11. Cookies and analytics
We use cookies and similar technologies to keep you signed in, remember preferences, and understand how the Services are used. We use Google Analytics for aggregate usage measurement. You can control cookies through your browser settings; blocking some of them may affect how the Services work.
12. Children
The Services are intended for people aged 18 and over and we do not knowingly collect data from children. If we learn that we have collected data from a child without verifiable parental consent, we will delete it.
13. Changes to this policy
We may update this policy as the Services and the law evolve. We will revise the "last updated" date above and, for material changes, give notice through the Services or by email before the change takes effect.
14. Contact and grievance redressal
For any question about this policy, or to complain about how we have handled your data, contact our Grievance Officer. We acknowledge grievances promptly and aim to resolve them within the timelines set by applicable law.
Grievance Officer: Kishore
Email: info@wanderfly.in
Address: Vaddipalem, Narayana Medical College, 6/4/355, Nellore, Andhra Pradesh 524004
If you are not satisfied with our response, you may escalate to the Data Protection Board of India.