Privacy Policy
Last updated: 16 September 2026
This policy explains what Hariom Yoga Vidya School does with information about you: what we collect when you use this website or train with us, why we hold it, how long we keep it, who else can see it, and what you can ask us to do about it.
It describes how this website and this school actually work. Where it names a period — ninety days, one year, three years — that is the period a scheduled job on our systems genuinely enforces, not an estimate.
If anything here is unclear, or you want something done about your own information, write to us at contact@hariomyogavidyaschool.com and a person will answer.
Who is responsible for your information
Hariom Yoga Vidya School, Tapovan, Rishikesh, Uttarakhand 249192, India, decides what happens to the information described in this policy.
For any question about your information, including the requests described under "What you can ask us to do" below, the contact point is contact@hariomyogavidyaschool.com.
What we collect, and why
When you send us an enquiry. Your name, email address, phone number, gender, which course or retreat you are asking about, and whatever you write in the message. We need these to answer you — that is the entire purpose, and an enquiry you send us is the only way any of it reaches us.
Alongside an enquiry we also record how you arrived: the page you were reading, the page you first landed on, the site that referred you, and any campaign information in the link you followed. This tells the school which of its adverts and listings actually bring students, and it is only ever sent when you choose to submit the form.
If you enroll. The information a residential school needs in order to have you stay and study: your date of birth and nationality, your address, an emergency contact, your course and dates, your room, what you have paid, and any allergy, dietary or health note you give us so that the kitchen and the teaching team can look after you properly.
Identity documents. If you give us a passport or Aadhaar number, we do not store it as readable text. The number is encrypted; we keep the last four digits in plain form so a staff member can confirm which document is on file without decrypting anything, and a one-way fingerprint so we can tell whether the same document is already registered under another name. Nobody at the school reads the full number out of the database in the ordinary course of things.
Your certificate. If you graduate, we keep the record that lets your certificate be verified by anyone you show it to — your name, the training, the hours and the dates. This is permanent by design and is explained under retention below.
When you visit the website. We add one to a tally of how many times each page was read that day, and — for the page you arrived on — whether you came from a search, an advertisement, a social network or a link. That tally holds no identifier of any kind: it is a set of daily totals, and nothing in it distinguishes you from anyone else who read the same page on the same day. It runs whatever you tell the cookie notice, because there is nothing in it that is about you.
Visit measurement. With measurement on, we count you as one visitor rather than several using a random number, and we record which pages were read and what was pressed. The random number is not your name and we cannot work out who you are from it. With measurement off, none of this happens.
Whether measurement starts on or off depends on where you are reading from. If you are in the European Union, the European Economic Area, the United Kingdom or Switzerland, it is off until you say otherwise: a cookie notice asks you first, and nothing optional runs until you answer it. Everywhere else, measurement is on from the start of your visit, no notice is shown, and you can turn it off at any time — see "What goes in your browser" below.
The notice is shown to visitors in Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, Iceland, Liechtenstein, Norway, the United Kingdom and Switzerland.
To decide which applies, we use the country your connection comes from, as reported by the company that hosts this website. We keep only the two-letter country code, only for the length of your visit, and use it for nothing else. If we cannot tell where you are — or it takes more than a few seconds to find out — we treat you as being somewhere the notice is shown, and ask. If you use a VPN, the country is the VPN's.
Your IP address is never stored as an IP address. Where we keep it at all, we keep a one-way fingerprint of it, which is enough to tell two visits apart and not enough to identify a person or a household.
When you use the chat assistant. Your question is sent to Google's Gemini service so that it can be answered from the school's own published material. We do not keep a copy of the conversation on our systems; it lives in your browser for the length of your visit and is gone when you close the tab.
The cookie notice itself. When you answer it, we add one to a counter for that day — how many people were shown it, and how many chose each option. It is a counter and not a log: there is no row about you, no identifier, and no record of which way any individual answered. Counting that somebody declined is not tracking them; recording who declined would be.
What we never do
We do not sell your information, and we do not rent, trade or share it with anyone for their own marketing.
If you are in the European Union, the European Economic Area, the United Kingdom or Switzerland, we do not track you before you have answered the cookie notice. Until you press one of its buttons this site sets no identifier and Google's tags are told to store nothing. The anonymous page tally described above is the one exception, and it is an exception only in the sense that it runs — it records no identifier, so there is nothing in it to connect to you.
We do not ignore a refusal, wherever you are. Once you have turned measurement off — on the notice or on this page — that choice holds in every country, including the ones where the notice is not shown.
We do not require you to accept anything in order to read the site or to write to us. Turning measurement off is one press and the site works the same.
We do not ask for payment card details on this website. Where you pay by bank transfer or through PayPal, that happens with your bank or with PayPal, and the card or account details never pass through us.
What goes in your browser
Where the cookie notice is shown, the full list is printed on it under "Read more". This section describes the same list in the same words.
Always, because the site needs them to work: the record of your measurement setting, once you have chosen one; a note that the enquiry form has already opened or that you have already written to us, so nothing interrupts you twice; the currency you asked prices to be shown in; the two-letter country your connection came from, kept only for this visit and used only to decide whether to show the notice; and the advert or link that brought you here, which is kept only for this visit and is only ever transmitted if you fill in the enquiry form yourself.
Only while measurement is on: a random visitor number kept for two years, our own record of which pages were read, and Google Analytics and Google Ads cookies, which are set by Google and read by Google and may last up to two years. In the European Union, the European Economic Area, the United Kingdom or Switzerland that means only after you press Accept on the notice; everywhere else it means unless you turn measurement off.
You can change your setting at any time with the control below, wherever you are. Turning measurement off takes effect immediately: we stop recording, tell Google's tags to stop storing and reading their cookies, and delete our visitor number from your browser. Anything recorded before you turned it off is kept only for the periods under "How long we keep it" — ask us and we will delete it sooner.
Who else can see it
The school's own staff, to the extent their work requires it. Health and dietary notes reach the kitchen and the teaching team; fees reach whoever keeps the register.
Neon, which hosts the database, and Vercel, which serves this website. Both hold information on the school's behalf and are not permitted to use it for anything of their own. Vercel is also what tells the site which country a connection comes from; we read only the country.
Resend, which delivers the school's email — an enquiry notification, a confirmation, a document you asked for.
Google, while measurement is on for you (see above): Analytics and Ads, for measuring which adverts bring people to the school. Google's Gemini service also receives chat questions, as described above. Google acts under its own privacy policy for these.
Cloudflare, which runs the check that tells a person from an automated script on our forms.
Calendly, if you book a video call, which receives the details you give it in order to make the booking.
We may also disclose information where the law requires it of us.
Some of these services process information outside India, including in the European Union and the United States. Where that happens it is under the terms those providers publish for exactly this purpose.
How long we keep it
Enquiries: kept, because they are the school's record of who asked and what was answered.
Student records, certificates and enrollments: kept, because a graduate must still be able to have their credential verified years from now.
Identity documents — passport and Aadhaar numbers: destroyed three years after your last training with us ends. This is enforced by a scheduled job, not by somebody remembering.
Health and dietary answers: destroyed on the same three-year rule. They are held so that the kitchen and teaching team can act on them during your stay, not as a permanent record of your health.
Detailed website activity: ninety days. The short per-visit record: one year. After that only day-by-day totals remain, which are counts and contain nothing about any individual.
Sent email: thirty days. Mail that failed to send is kept until somebody has dealt with it, because deleting the evidence of a notification nobody received would be deleting exactly the wrong thing.
The cookie-notice counters and the anonymous page tally: kept, because they are daily totals and hold nothing about any person.
What you can ask us to do
Write to contact@hariomyogavidyaschool.com and you can ask us to do any of the following with information about you.
Tell you what we hold, and give you a copy of it.
Correct anything that is wrong. A misspelled name on a certificate is the common one, and we would rather fix it than not.
Delete it. We will, except where we are obliged to keep something — a certificate record is the main example, because destroying it would make a real qualification unverifiable, and that would harm you rather than protect you. We will tell you plainly if that applies and why.
Stop using it for something, including stopping email from us.
Withdraw a permission you gave, at any time. Withdrawing does not undo what was done while the permission stood, and it does not affect anything we hold for a reason other than your permission.
We will answer within thirty days. There is no charge for asking.
If you are in India, the Digital Personal Data Protection Act 2023 gives you these rights and lets you take an unresolved complaint to the Data Protection Board of India. If you are in the European Union or the United Kingdom, the GDPR gives you these rights, including the right to receive your information in a portable form and the right to complain to your national data protection authority. You are welcome to complain to either without asking us first, though we would rather you gave us the chance to put it right.
Keeping it safe
The site is served only over an encrypted connection. Passport and Aadhaar numbers are encrypted where they are stored, so that a stolen copy of the database is a copy of ciphertext. Access to the school's administrative system is by individual account with defined permissions, and what each account does to a student record is logged.
No system is beyond compromise and we will not claim otherwise. If information about you is exposed in a way that puts you at risk, we will tell you and the relevant authority rather than wait to be asked.
Children
Our trainings are open to students aged sixteen and above, and this website is not directed at children. If you believe a child has given us information, write to contact@hariomyogavidyaschool.com and we will remove it.
Changes to this policy
If this policy changes, the date at the top of this page changes with it. Where a change materially affects what we do with information we already hold, we will say so on the cookie notice where it is shown, and on this page, rather than rely on you re-reading it.
Governing law
This policy is governed by the law of India, and the courts of Uttarakhand have jurisdiction over any dispute arising from it. This does not remove any right you have under the law of the country you live in.
