Privacy Policy
What we collect, why, who else sees it, how long we keep it and what you can ask for.
Last updated
Who is responsible for your information
M. Gautam Gopiya, sole proprietor trading as Humming Nest is responsible for deciding why and how personal information is used through https://www.abhiraamgautham.com and the programmes. Abhiraam Gautham is the public-facing brand of this website.
- Address
- No. 66, Fourth Cross, NKV Parkview, 17th Cross, MCECHS Layout, Bengaluru, Karnataka 560077, India
- Privacy contact
- Privacy Contact, Humming Nest
- Privacy email
- hello@hummingnest.com
- Privacy phone
- +91 96116 94999
In Indian data-protection terminology, we may act as a Data Fiduciary. In EU or UK terminology, we may act as a controller. The correct role can vary for a specific processing activity.
Scope
This Policy applies to website visits, enquiries, enrolment, payment administration, assessments, programme delivery, live-session administration, support, marketing choices and privacy requests. It does not govern an independent third-party website that publishes its own policy.
Information we may collect
We collect only information reasonably needed for the stated purpose. Depending on how you interact with us, this may include:
- identity and contact information, such as name, email, telephone number, country and time zone
- transaction information, such as programme, price, currency, payment status, payment reference, invoice details and refund status
- onboarding and programme information, such as goals, preferences, availability, participation records and support messages
- limited wellness and safety information that you choose to provide through an assessment or safety form
- communications, such as email, approved messaging, feedback and grievance records
- content you submit, such as journal responses, voice notes or questions, only where the programme uses that feature
- technical information, such as device type, browser, IP address, security logs, page errors and consent records
- marketing choices, such as subscription and unsubscribe status
Payment details are entered on Razorpay’s own secure payment pages and are processed by Razorpay through its own systems. This website does not host a checkout form and does not receive them. We do not store full card numbers, card security codes or online-banking credentials.
Sensitive wellness information
Information about physical or mental health may be sensitive or special-category personal data in some countries. We collect it only when the assessment or safety process genuinely needs it, provide a specific notice, and obtain the form of consent or other legal basis required for the participant’s location.
How we obtain information
We receive information directly from you when you browse, enquire, enrol, pay, complete a form, attend a session, contact support, submit content or exercise a right. We may receive limited transaction information from Razorpay, fraud-prevention information from a payment provider, or technical information from the services that operate the site.
We do not buy sensitive wellness information from data brokers.
Why we use information
We may use personal information to:
- answer an enquiry
- create and administer an enrolment
- process and reconcile payment, invoicing, cancellation and refund activity
- deliver 7 Nights or BreathOS
- conduct proportionate onboarding and safety screening
- schedule and administer live sessions
- provide support and resolve complaints
- protect accounts, participants, the website and the business from abuse, fraud or security threats
- keep tax, accounting, consent and legal records
- improve site reliability and programme administration using appropriately limited information
- send marketing only where permitted and in line with the person’s choices
- establish, exercise or defend legal claims
We will not use personal information for a materially incompatible new purpose without providing a new notice and obtaining any required consent.
Legal bases
The legal basis depends on the activity and jurisdiction. It may include performing a contract, taking requested steps before a contract, complying with law, a legitimate interest that is not overridden by the person’s rights, consent, explicit consent for limited sensitive information, or protection of vital interests in a genuine emergency.
When we share information
We may share the minimum necessary information with contracted providers that support:
| Purpose | Provider |
|---|---|
| Website hosting and security | Netlify |
| Payment processing | Razorpay, which hosts the payment pages the priced buttons open |
| Email and cloud storage | Google Workspace |
| Messaging | WhatsApp Business |
| Assessments and forms | Google Forms and restricted Google Workspace Sheets |
| Programme delivery | WhatsApp Business, Google Workspace email and restricted Google Drive links |
| Video sessions | Google Meet |
| Customer administration | Restricted Google Workspace Sheets |
| Accounting and professional advice | The appointed chartered accountant, tax adviser and legal adviser where necessary |
| Analytics | Google Analytics, loaded only after you allow it and switched off for advertising and cross-site signals. Google Search Console may be used for search-performance data |
We may also disclose information where required by law, to respond to a valid legal process, to protect a person’s safety, to investigate fraud or security incidents, or as part of a legitimate business transaction with appropriate safeguards.
We do not sell personal information. We do not share health or assessment information for cross-context behavioural advertising.
International transfers
Some service providers may process information in more than one country. We periodically review the current Netlify, Google, Meta and Razorpay service terms and relevant account settings, and document the processing locations and safeguards that apply to the services we use. We will not state a single storage country unless the actual account configuration supports that statement.
Direct enrolment from the EU, EEA and UK is disabled at initial launch. Before enabling it, we will document any required transfer mechanism, privacy representative, special-category basis and regional consumer wording.
Retention
We keep information only as long as needed for its stated purpose, legal obligations, safety, dispute handling and security. The approved schedule is:
| Record | Retention period |
|---|---|
| Enquiries that do not become clients | 12 months after the last meaningful contact |
| Programme and account administration | Three years after programme completion |
| Routine assessment and safety responses | 12 months after programme completion |
| Safety incident records | Three years after the incident is closed, or longer if a claim or law requires it |
| Session scheduling and attendance | 12 months after programme completion |
| Support and grievance messages | Two years after resolution |
| Session recordings | 90 days after the recorded session, unless earlier deletion is requested or a legal hold applies |
| Recording consent | Three years after the relevant programme ends |
| Payment, invoice and GST records | At least 72 months from the due date of the relevant GST annual return, and longer where a proceeding requires it |
| Contract, safety and policy acceptance records | Three years after programme completion or dispute resolution, whichever is later |
| Marketing suppression record | While marketing continues, plus three years after the final campaign |
| Security logs | 12 months, unless an incident requires a documented legal hold |
| Routine backups | Rolling 90 days |
When retention ends, we delete or de-identify the information unless law requires continued storage.
Security
We use reasonable technical and organisational safeguards appropriate to the information and risk. These may include encryption in transit, access controls, multi-factor authentication, restricted facilitator access, secure provider configuration, backups, logging, patching, processor contracts and incident procedures.
No online system is completely risk-free. If a personal-data incident occurs, we will investigate, limit harm and notify affected people or authorities where required.
Your choices and rights
Depending on your location and the reason for processing, you may have rights to:
- receive clear information about processing
- request access to personal information
- correct or complete inaccurate information
- request deletion where applicable
- withdraw consent
- object to or restrict certain processing
- request portability where applicable
- complain through our grievance process or to a competent authority
- nominate another person where Indian law provides that right
Marketing messages include an unsubscribe method. Withdrawing marketing consent does not cancel an active programme or prevent essential service messages.
Send requests to hello@hummingnest.com. We may verify identity and may decline or limit a request where the law permits, explaining the reason when required.
Cookies and analytics
We use essential storage needed to operate and secure the website. We use non-essential analytics, advertising or embedded-media technologies only as described in the Cookie Policy and after the required choice.
This site uses optional analytics. Nothing is loaded until you allow it, your choice is remembered, and you can change it at any time through the Cookie Settings link in the footer. No advertising or cross-site tracking technology is used.
Children
Paid programmes are intended for adults aged 18 or older. We do not knowingly enrol a child. If you believe a child has submitted personal information, contact hello@hummingnest.com so we can investigate and take appropriate action.
Automated decisions
We do not use solely automated decisions that produce legal or similarly significant effects unless this statement is updated with the required explanation and safeguards. An assessment may help a human organiser understand programme needs, but it must not silently make a significant eligibility decision.
Third-party links
The site may link to independent services. Review their privacy information before providing data. A link does not make us responsible for an independent party’s practices.
Changes
We may update this Policy to reflect changes in law, technology or services. We will show the new date and provide a reasonable notice of material changes where required.
Contact and complaints
- Privacy email
- hello@hummingnest.com
- Privacy contact
- Privacy Contact, Humming Nest
- Privacy phone
- +91 96116 94999
- Grievance email
- hello@hummingnest.com
- Postal address
- No. 66, Fourth Cross, NKV Parkview, 17th Cross, MCECHS Layout, Bengaluru, Karnataka 560077, India
If we do not resolve a concern, you may have the right to contact the Data Protection Board of India, an EU or UK supervisory authority, or another authority in your location, subject to the law and commencement status applicable at that time.
Questions about this page
Write to us and we will help. For a formal complaint, use the grievance route on the Contact page.
Contact and Grievance Redressal