AroundU Direct · Legal

Direct Privacy Policy

How personal data is collected, used, protected and controlled when Organizers run bookings, payments, check-in, CRM and messaging through AroundU.

Effective 21 September 2026Last updated 21 September 2026

About this Policy

This Privacy Policy explains how AroundU ("AroundU", "we", "us" or "our") handles personal data through its booking storefront, payments integration, QR check-in, attendee CRM, imported contact records, WhatsApp campaign tools, connected Meta services and AI-assisted calling (together, the "Platform"). It applies to:

  1. businesses, event organisers and experience providers that use the Platform (each, an "Organizer"); and
  2. customers, attendees and other individuals whose personal data is processed through an Organizer's storefront or use of the Platform (each, an "Attendee").

This Policy should be read with any privacy notice, consent language and terms provided by the relevant Organizer.

Roles and responsibility

2.1 Attendee Data

For personal data collected by an Organizer from or about its Attendees ("Attendee Data"), the Organizer determines why and how the data is processed. The Organizer is therefore the Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act"). AroundU processes Attendee Data only on the Organizer's documented instructions and on the Organizer's behalf, as a Data Processor and technology or storage service provider.

The Organizer is responsible for providing legally required notices, obtaining valid consent or identifying another lawful basis where applicable, responding to Attendee requests and complying with its obligations under applicable law. Engaging AroundU does not reduce the Organizer's responsibility under the DPDP Act.

2.2 Organizer Account Data

Where AroundU determines the purpose and means of processing an Organizer's own account, business-contact, support or billing-administration data ("Organizer Account Data"), AroundU acts as the Data Fiduciary for that limited processing.

2.3 Data control, segregation and ownership

AroundU stores and associates Organizer Data separately for each Organizer or member account. As between AroundU and the Organizer, the Organizer retains all rights, title and control in the Attendee Data, audience lists, event data, booking records, contact lists and check-in records that the Organizer brings to or creates through the Platform. AroundU does not claim ownership of that data. This contractual allocation does not limit any rights that an Attendee has in relation to their personal data under applicable law.

An Attendee may have separate relationships with more than one Organizer. Each such relationship, and the data linked to it, is maintained independently for the relevant Organizer.

Personal data we handle

Depending on how an Organizer configures and uses the Platform, we may process:

  • Booking and Attendee information: name, phone number, email address, ticket or order details, event selections and information entered into custom booking fields created by the Organizer.
  • Payment-related information: transaction status, amount, payment reference, refund status and reconciliation information received from the Organizer's connected payment gateway. Card numbers, bank-account credentials and other full payment-instrument details are submitted directly to the payment gateway and are not stored by AroundU.
  • WhatsApp campaign information: contact lists uploaded or generated by the Organizer, campaign content, delivery status and related messaging records needed to provide the Organizer's requested campaign functionality.
  • Imported customer records: contact details and past event, booking, payment or attendance information that an Organizer chooses to import from a CSV or Excel file, including mapped custom fields.
  • Connected Meta services: account and campaign identifiers, lead-form responses, attribution and advertising results when the Organizer connects an eligible Meta account and enables those features.
  • AI-assisted calling: the selected contact and event details, consent evidence, approved call instructions, call status, outcomes and transcripts where supplied by the calling provider for a campaign the Organizer chooses to launch.
  • QR check-in information: ticket identifiers, scan timestamps and entry or check-in status.
  • Organizer Account Data: business name, contact details, login or account details, storefront settings, support communications and payout-related information supplied by the Organizer.
  • Technical and service data: device, browser, IP address, access logs, security events and diagnostic information reasonably required to operate, secure and troubleshoot the Platform.

Organizers must not collect personal data through custom fields unless it is necessary for a stated purpose and permitted by applicable law.

How we use personal data

We process data only as needed to:

  1. host and operate an Organizer's branded storefront;
  2. create and manage bookings, tickets and order confirmations;
  3. confirm, reconcile and support payments through the Organizer's connected payment gateway;
  4. provide QR-based entry and check-in;
  5. maintain the Organizer's attendee CRM and make its records available to that Organizer;
  6. import customer records supplied by the Organizer, maintain their source and history, and provide permitted exports;
  7. deliver WhatsApp campaigns that the Organizer chooses to send;
  8. sync leads, report on advertising, and prepare campaigns where the Organizer connects and enables the relevant Meta services;
  9. prepare AI-assisted work and conduct reviewed calls where the Organizer enables those tools and provides the required consent evidence;
  10. provide support, prevent fraud, maintain security, investigate errors and improve service reliability;
  11. comply with applicable law, valid legal process and lawful regulatory requirements; and
  12. enforce our agreements and protect the Platform, Organizers, Attendees and others from harm.

For Attendee Data, AroundU acts only on the relevant Organizer's instructions, except where processing is required by applicable law.

What we do not do

AroundU does not:

  • sell or rent Organizer Data or Attendee Data;
  • use an Organizer's Attendee Data to market AroundU's own products or services to those Attendees;
  • build advertising profiles from Attendee Data for AroundU's own independent advertising purposes;
  • operate a data-brokerage business or commercially resell data, whether identified or described as anonymised; or
  • disclose Attendee Data to third parties for their independent marketing purposes.

Service providers and permitted disclosures

We disclose personal data only to the extent necessary to operate the Platform or comply with law. Recipients may include:

  • the Organizer's connected payment gateway, for payment processing, reconciliation and refunds;
  • cloud hosting, database, security, monitoring and communications providers that support the Platform;
  • WhatsApp or messaging infrastructure providers used to deliver campaigns selected by the Organizer;
  • Meta and other connected advertising or lead providers when the Organizer enables those integrations, including eligible contact identifiers for advertising audience matching only where the required consent has been recorded;
  • AI and calling providers needed for features and reviewed campaigns the Organizer chooses to use;
  • professional advisers, auditors or authorities where disclosure is required by applicable law or valid legal process; and
  • a successor in connection with a merger, acquisition or sale of business assets, subject to appropriate confidentiality and continued protection of personal data.

Service providers may process data only for the services they provide to AroundU or the Organizer and are expected to protect it under appropriate contractual and legal obligations. AroundU does not permit them to use Attendee Data for their own marketing.

Data retention, export and deletion on exit

Organizer Data is stored and associated on a per-Organizer or per-member basis. AroundU retains it only for as long as reasonably necessary to provide the Platform, follow the Organizer's documented instructions, resolve disputes, maintain security and meet legal, tax, accounting or regulatory obligations.

There is no data lock-in. An Organizer may request an export, correction or deletion of its Organizer Data at any time. When an Organizer closes its account or ends its use of the Platform, the Organizer may:

  1. obtain a usable export of the audiences, events, bookings, Attendee records, contact lists, check-in records and other Organizer Data that it brought to or created through the Platform; and
  2. instruct AroundU to delete that Organizer Data and remove the departing Organizer's account, access and links to the relevant Attendees, audiences, events and records.

If an Attendee was independently onboarded by, booked with or otherwise engaged with another Organizer, the Attendee's record may continue to be retained solely in connection with that other Organizer's independent relationship and instructions. The departing Organizer's relationship, links and Organizer-specific data concerning that Attendee will be deleted. The departing Organizer may still export and delete all audience and related data that it brought to or created through the Platform.

Deletion removes the departing Organizer's data from active systems. Limited data may be retained only where required by law or reasonably necessary to establish, exercise or defend legal claims. Residual copies may remain temporarily in encrypted or access-controlled backups until they are overwritten through the ordinary backup cycle; during that period, they will not be restored or used except for disaster recovery, security or legal compliance.

Organizer controls

Subject to applicable law and the Organizer's obligations to Attendees, an Organizer may request that AroundU:

  • export the Organizer Data associated with its account in a commonly usable format, including its audiences, events, bookings, Attendee records, contact lists and check-in records;
  • correct inaccurate or incomplete Organizer-specific records;
  • delete selected Organizer-specific records; or
  • on exit, return and delete all Organizer Data that the Organizer brought to or created through the Platform, and remove its links to the relevant Attendees, subject only to Clause 7.

Requests may be sent to info@aroundu.in. AroundU may verify the requester's identity and authority before acting on a request.

Direct Pro and Premium provide permitted audience exports in CSV or Excel. Premium team roles let an Organizer grant or restrict customer viewing, editing, importing and exporting. For a broader export, correction or deletion request, the Organizer can contact AroundU using the address above.

Attendee rights and requests

An Attendee should first contact the Organizer with which they booked or interacted. Because the Organizer is the Data Fiduciary for Attendee Data, the Organizer is responsible for handling requests relating to access, correction, completion, updating, deletion, withdrawal of consent and grievance redressal, as applicable under the DPDP Act.

If an Attendee cannot reach the Organizer, the Attendee may write to info@aroundu.in. AroundU will route the request to the relevant Organizer and provide reasonable assistance. We may ask for information needed to identify the relevant booking or verify identity. We will not disclose personal data until the requester's identity and authority have been reasonably verified.

Security

AroundU uses reasonable technical and organisational safeguards designed to protect personal data against unauthorised access, disclosure, alteration, loss or misuse. These measures include encryption in transit, access controls and limiting internal access to personnel and systems that need the data to operate, support or secure the Platform.

Payment credentials are handled by the Organizer's connected payment gateway under that provider's own security and compliance obligations. Full card numbers, bank-account credentials and similar payment-instrument data do not pass through or remain on AroundU's servers.

No method of storage or transmission is completely secure. AroundU therefore cannot guarantee absolute security, but will take reasonable steps to contain, investigate and respond to a personal-data breach in accordance with applicable law and its obligations to the relevant Organizer.

International processing

Some infrastructure or messaging providers may process data from locations outside India. Where this occurs, AroundU will use service providers and contractual arrangements intended to protect personal data and will comply with restrictions on cross-border transfers that apply under Indian law.

Children's data

The Platform is not intended to enable an Organizer to collect children's personal data without the notice, verifiable parental consent and other safeguards required by applicable law. Each Organizer is responsible for determining whether an Attendee is a child and for configuring its collection practices accordingly. Organizers must notify AroundU before using the Platform for an offering directed primarily to children.

Changes to this Policy

We may update this Policy to reflect changes in the Platform, our practices or applicable law. The revised version will be posted with a new "Last updated" date. Where a change materially affects how Organizer Data or Attendee Data is processed, we will provide reasonable notice to affected Organizers.

Grievance and contact details

Questions, data requests or grievances concerning this Policy may be sent to:

AroundU - Privacy Contact Email: info@aroundu.in Website: https://aroundu.in

For Attendee Data, AroundU will coordinate with the relevant Organizer, which remains responsible for responding as the Data Fiduciary. If applicable law requires AroundU to designate or publish further grievance-officer details, those details will be added to this section.

Governing law and jurisdiction

This Policy is governed by the laws of India, including the DPDP Act and rules in force under it. Subject to any mandatory rights or remedies available under applicable law, disputes relating to this Policy are subject to the jurisdiction of the competent courts in India identified in the applicable agreement between AroundU and the Organizer.