Namaste...

Legal

Privacy Policy

Last updated: 28 June 2026  ·  Effective from: 28 June 2026

Asha Yoga Life ("we", "us", "our") operates the website ashayogalife.com (the "Site"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our Site, register for events, or book a training batch. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) (EU) 2016/679 and applicable Indian data protection laws.

1. Data Controller

The data controller responsible for your personal data is:

Asha Yoga Life
WhatsApp: +91 81496 90746
Instagram: @ashayogalife
Email: info@ashayogalife.com

For any privacy-related queries, contact us at the details above.

2. Personal Data We Collect

We collect the following categories of personal data:

Category Data Collected When Collected
Identity & Contact Full name, email address, phone number Batch booking, Yoga Day registration
Health Information Injuries or health conditions (optional, provided voluntarily) Batch booking form
Payment Information Payment amount, Razorpay transaction/order ID On successful payment
Usage Data Server logs: IP address, browser type, pages visited, timestamps (IST) Automatically on every page visit
Event Registration Email address, phone number International Yoga Day 2026 free session sign-up
Special category data: Health information you provide (injuries, conditions) is considered sensitive under GDPR Article 9. It is used solely to ensure safe and appropriate yoga instruction and is never shared with third parties.

3. Legal Basis for Processing (GDPR Article 6)

  • Contract performance (Art. 6(1)(b)): Processing your name, email, phone, and batch details is necessary to confirm your booking and deliver the yoga service.
  • Legitimate interests (Art. 6(1)(f)): Server logs are maintained for security, debugging, and fraud prevention. Our interest is to operate a secure and reliable service.
  • Consent (Art. 6(1)(a)): Registering for our International Yoga Day free session and receiving event communications is based on your explicit consent. You may withdraw it at any time.
  • Legal obligation (Art. 6(1)(c)): Payment records may be retained to comply with applicable tax and financial laws.

For health data, our legal basis is explicit consent (Art. 9(2)(a)) — you choose whether to provide it.

4. How We Use Your Data

  • To process and confirm your yoga batch booking
  • To send booking confirmation emails to your provided email address
  • To notify you about your registered event (International Yoga Day 2026)
  • To process payments securely via Razorpay
  • To log booking details for our internal records and dispute resolution
  • To ensure your physical safety by recording health conditions relevant to yoga practice
  • To maintain server security and prevent fraudulent activity
  • We do not use your data for automated decision-making or profiling
  • We do not sell or rent your personal data to any third party

5. Third-Party Services & Data Sharing

We share minimal data with the following trusted third parties to operate our service:

Service Provider Purpose Data Shared Privacy Policy
Razorpay Payment processing Name, email, phone, amount razorpay.com/privacy
Email / SMTP Provider Sending booking confirmation emails Name, email address Governed by our email host's policy
Instagram (Meta) Social media links (no data sent by us) None — external links only Instagram Privacy

We do not transfer your data outside India or the European Economic Area (EEA) except via Razorpay, which maintains appropriate safeguards under applicable data protection law.

6. Data Retention

  • Booking data (name, email, phone, batch, payment amount) — retained for 3 years from the date of booking, for service delivery and dispute resolution purposes.
  • Health information — retained only for the duration of your active enrollment. Deleted upon request or after 12 months of inactivity.
  • Event registration data (Yoga Day) — retained for 6 months after the event date, then deleted.
  • Server / application logs — retained for 90 days on a rolling basis.
  • Payment transaction IDs — retained for 7 years to comply with financial record-keeping requirements.

After the applicable retention period, your data is securely deleted or anonymised.

7. Your Rights Under GDPR

If you are in the EU/EEA, you have the following rights regarding your personal data:

Right of Access (Art. 15)

Request a copy of the personal data we hold about you.

Right to Rectification (Art. 16)

Ask us to correct inaccurate or incomplete data.

Right to Erasure (Art. 17)

Request deletion of your data ("right to be forgotten"), where no legal obligation requires us to retain it.

Right to Restrict Processing (Art. 18)

Ask us to limit how we use your data in certain circumstances.

Right to Data Portability (Art. 20)

Receive your data in a structured, machine-readable format.

Right to Object (Art. 21)

Object to processing based on legitimate interests at any time.

To exercise any of these rights, contact us at info@ashayogalife.com or via WhatsApp. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection supervisory authority.

8. Cookies & Session Data

Our Site uses the following minimal cookies:

  • .AspNetCore.Antiforgery.* — A security cookie (session-only) that prevents cross-site request forgery (CSRF) attacks on form submissions. It is strictly necessary and does not track you.
  • Browser localStorage — We store a single flag (yogaDay2026Registered) in your browser's localStorage to avoid showing the Yoga Day popup repeatedly. This stores no personal data.

We do not use advertising cookies, third-party tracking cookies, or analytics cookies. No consent banner is required for strictly necessary cookies under GDPR Recital 47.

9. Data Security

  • All data in transit is encrypted via HTTPS / TLS
  • Payment card data is never handled by us — it is processed entirely by Razorpay, which is PCI-DSS compliant
  • Payment signatures are verified server-side using HMAC-SHA256 before confirming any booking
  • Application access logs are maintained to detect unauthorised access
  • Anti-CSRF tokens are enforced on all form submissions

Despite our best efforts, no transmission over the internet is 100% secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by GDPR Article 33–34.

10. Children's Privacy

Our services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The "Last updated" date at the top of this page will always reflect the most recent version. For significant changes, we will notify you via email (if we hold your address) or by placing a prominent notice on our Site.

Continued use of our Site after changes are posted constitutes acceptance of the updated policy.

12. Contact & Complaints

Asha Yoga Life — Privacy Contact
Email: info@ashayogalife.com
WhatsApp: +91 81496 90746
Instagram: @ashayogalife

If you are not satisfied with our response, you have the right to complain to a supervisory authority. EU residents may contact their national Data Protection Authority (DPA). Indian residents may refer to the Ministry of Electronics and Information Technology (MeitY).

Chat with us!