Privacy Policy
We Protect What
Matters Most
At CoTrav, your data privacy is not an afterthought — it is a core commitment. This policy explains exactly what we collect, why we collect it, and how we keep it safe.
How We Put Your Privacy First
Six principles that govern every decision we make about your data.
Who We Are
This Privacy Policy is published by BAI Infosolutions Private Limited, trading as CoTrav ("CoTrav", "we", "our", or "us"). We are a corporate travel management company incorporated under the Companies Act 2013 and registered at Unit No. 4 & 5, Ground Floor, DLF Building 9B, DLF Cyber City, Phase 2, Sector 24, Gurugram 122002, Haryana, India.
CoTrav operates a corporate travel management platform accessible via our website, mobile application, and direct relationship manager channels. This policy applies to all personal data processed in connection with our platform and services.
Data We Collect
We collect personal data through three primary channels: information you provide directly, information generated through your use of our platform, and information obtained from your employer (our corporate client) to facilitate your travel arrangements.
For VISA and FRRO services, we may additionally collect passport copies, visa application forms, invitation letters, and immigration documentation strictly as required by the relevant embassy or Indian immigration authority.
How We Use Your Information
We use your data only for the purposes for which it was collected or for directly related purposes that you would reasonably expect.
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Processing flight, hotel, cab, train & bus bookings | Identity, travel details, payment data | Contract performance |
| VISA application facilitation | Passport, identity, travel history | Contract performance |
| FRRO / FRO registration & compliance | Identity, immigration documents | Legal obligation |
| Travel policy enforcement & approvals | Booking data, employee grade, cost centre | Legitimate interest (employer) |
| Expense reporting & GST invoicing | Payment, booking, and company data | Legal obligation / contract |
| 24/7 support & relationship management | Contact details, booking history | Contract performance |
| Platform security & fraud prevention | Technical and usage data | Legitimate interest |
| Service improvement & analytics | Anonymised usage data | Legitimate interest |
| Marketing communications (opt-in only) | Contact details, preferences | Consent |
Sharing & Disclosure
CoTrav does not sell your data. We share it only with the parties listed below, and only to the extent necessary to provide our services.
- Airlines, hotels, and transport providers — your booking details are transmitted to the relevant provider to complete your reservation. These parties operate under their own privacy policies.
- Your employer (our corporate client) — travel data, itinerary details, and expense information are shared with your company's designated travel administrators and finance teams as part of our managed travel service.
- VISA and immigration authorities — passport, identity, and application documents are submitted to embassies, consulates, and FRRO / FRO offices solely to complete your application.
- Payment processors — billing data is processed by PCI-DSS compliant payment gateways. CoTrav does not store full card numbers on its systems.
- Technology sub-processors — cloud infrastructure, communication, and analytics tools we use to operate our platform. All sub-processors are bound by data processing agreements.
- Legal and regulatory authorities — when required by applicable law, court order, or government regulation, we may disclose data as legally mandated.
Cookies & Tracking Technologies
Our website and platform use cookies and similar tracking technologies to deliver a functional, secure, and personalised experience.
You can manage your cookie preferences through your browser settings or via the cookie preference centre accessible from the footer of our website. Disabling essential cookies may prevent certain platform features from functioning correctly.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purpose it was collected for, or as required by applicable law.
- Travel booking records — retained for 7 years from the date of travel to satisfy GST and financial audit requirements under Indian law.
- VISA and FRRO documents — retained for 5 years post-completion or as required by the relevant immigration authority.
- Active account data — retained for the duration of your employer's contract with CoTrav, plus a 90-day grace period for data export.
- Marketing preferences & consent records — retained until consent is withdrawn, plus 1 year for audit trail purposes.
- Technical and usage logs — retained for 12 months in identifiable form; anonymised and aggregated thereafter for up to 3 years for service analytics.
Security Measures
We take the security of your data seriously and implement technical and organisational measures proportionate to the risks involved in corporate travel management.
- Encryption: All data in transit is protected with TLS 1.3. Data at rest is encrypted using AES-256. Sensitive documents (passports, VISA files) are stored in encrypted, access-controlled vaults.
- Access controls: Role-based access control (RBAC) ensures that only authorised personnel can access personal data relevant to their function. All access is logged and audited.
- Infrastructure security: Our platform is hosted on ISO 27001-certified cloud infrastructure with regular penetration testing, vulnerability scanning, and security patching.
- Incident response: We maintain a documented incident response plan. In the event of a personal data breach affecting your rights and freedoms, we will notify affected individuals and, where required, the relevant authority within 72 hours of discovery.
- Employee training: All CoTrav team members handling personal data complete mandatory data protection training and are bound by confidentiality obligations.
Your Rights
Under India's Digital Personal Data Protection Act (DPDPA) 2023 and applicable data protection principles, you have the following rights with respect to your personal data.
- Right to Access — request a copy of the personal data we hold about you and information about how we use it.
- Right to Correction — request correction of inaccurate or incomplete personal data. You may also update many details directly through the CoTrav platform.
- Right to Erasure — request deletion of your personal data where it is no longer necessary for the purpose it was collected, subject to our legal retention obligations.
- Right to Data Portability — request your data in a structured, machine-readable format (CSV / JSON) to transfer to another service provider.
- Right to Withdraw Consent — where processing is based on consent (e.g., marketing emails), you may withdraw it at any time without affecting prior processing.
- Right to Grievance Redressal — raise a complaint with our Data Protection Officer. If unresolved, you may escalate to the Data Protection Board of India once it is operationally established.
Please note: some rights apply to data processed on behalf of your employer. For such data, your employer is the data controller and may need to be involved in fulfilling your request.
Children's Privacy
CoTrav is a B2B corporate travel management platform intended solely for business use by adults. Our services are not directed at individuals under the age of 18.
We do not knowingly collect personal data from minors. If we become aware that a minor's data has been submitted to our platform without appropriate authorisation, we will take immediate steps to delete it. If you believe we have inadvertently collected such data, please contact us at privacy@cotrav.co.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or data processing practices. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page.
- Send an email notification to registered users and corporate account administrators.
- Display a prominent notice within the CoTrav platform for 30 days following significant changes.
Your continued use of our platform after the effective date of changes constitutes acceptance of the updated policy. If you do not agree with the changes, you may request account closure by contacting us.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the way CoTrav handles your personal data, please contact our Data Protection team:
Response within 2 business days.
Monday–Friday, 9 AM – 6 PM IST
Unit No. 4 & 5, Ground Floor, DLF Building 9B,
DLF Cyber City, Phase 2, Sector 24, Gurugram 122002, Haryana, India
This Privacy Policy was last reviewed and approved by the CoTrav Legal and Compliance team on June 22, 2026. It is governed by the laws of India and subject to the exclusive jurisdiction of courts in Gurugram, Haryana.
Trusted Corporate Travel
Your Data. Your Trust. Our Responsibility.
Questions about how CoTrav handles your data? Our team is available 24/7 to address any privacy concern.