Book a Day Pass!

Price: ₹0 / Seat
Su
Mo
Tu
We
Th
Fr
Sa

Privacy Policy

Last updated 27 July 2026
Website https://www.thinkhaus.in
Privacy contact admin@thinkhaus.in

ThinkHaus Spaces Private Limited (“ThinkHaus”, “we”, “us” or “our”) respects your privacy and is committed to handling Personal Data responsibly. This Privacy Policy explains how we collect, use, disclose, store, retain and otherwise process Personal Data when you interact with our website, enquire about or book a workspace, schedule a tour, visit or use a ThinkHaus location, communicate with us, apply for a role, or otherwise use our services.

We process Personal Data in accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023 (“DPDPA”) and rules made under it, to the extent such provisions are in force and applicable, together with other applicable legal requirements.

Please read this Policy before providing Personal Data.

By using our website or services, you acknowledge that you have read this Policy. Where consent is the appropriate legal ground, we will request it through a clear affirmative action. You may withdraw consent as described in Section 7.

Scope

This Policy applies to prospective and current members, day-pass users, tour attendees, visitors, guests, authorised representatives and employees of member organisations, job applicants, vendors, service providers, business partners and other individuals who interact with ThinkHaus.

For this Policy, our “Services” include our website and online forms; enquiries, tours and bookings; coworking desks, private suites, meeting and board rooms, podcast studios, managed workspace solutions, events and related facilities; customer support; visitor and access management; and communications by email, phone, SMS or messaging services such as WhatsApp.

This Policy does not govern a third party’s independent processing of Personal Data. Third-party websites, payment services, maps, social media pages and booking platforms may have their own privacy notices. Please review those notices before providing information to them.

1. Definitions

“Personal Data” means any data about an individual who is identifiable by or in relation to that data.

“Data Principal” means the individual to whom Personal Data relates. In this Policy, this generally means you.

“Data Fiduciary” means the person that determines the purpose and means of processing Personal Data. ThinkHaus ordinarily acts as the Data Fiduciary for the processing described here.

“Data Processor” means a person that processes Personal Data on behalf of a Data Fiduciary.

“Processing” means any operation performed on Personal Data, including collection, recording, organisation, storage, use, sharing, retrieval, alteration or erasure.

“Consent” means consent that is free, specific, informed, unconditional and unambiguous, expressed through a clear affirmative action.

Terms not defined in this Policy have the meanings assigned to them under applicable data protection law.

2. Lawful Grounds for Processing

We process Personal Data only for a lawful purpose and on a ground permitted under applicable law.

2.1 Consent

We may rely on your consent when you submit an enquiry or booking form, request a tour, opt in to marketing, register for an event, provide optional information, accept non-essential cookies, or otherwise agree to a specified use. Where we rely on consent:

Withdrawal does not affect processing lawfully carried out before withdrawal. It may, however, limit our ability to provide a service that depends on the relevant Personal Data.

2.2 Certain Legitimate Uses and Other Lawful Processing

Where applicable law permits, we may process Personal Data without consent for certain legitimate uses, including when:

3. Personal Data We Collect and How We Use It

The Personal Data we collect depends on your relationship with ThinkHaus, the service you request and the channel through which you interact with us. We seek to collect only data reasonably necessary for the purposes below. Some information is required to provide a requested service; if you do not provide it, the relevant feature or service may not be available.

Category What this includes and why we use it
Identity information Examples: name, photograph, date of birth where required, member or booking reference, government-issued identification details where access, contract or legal requirements make them necessary

Collected through: enquiry, booking and onboarding forms; membership documentation; visitor or access processes; information provided by your employer or host Uses: identify you; administer bookings or memberships; verify identity; manage workspace and visitor access; prevent misuse; meet legal or contractual requirements Ground: consent; certain legitimate uses; compliance with law
Contact information Examples: email address, mobile number, company name, city, postal or correspondence address and emergency contact details where relevant Collected through: website forms; calls, email, SMS or WhatsApp; booking channels; contracts; customer support

Uses: respond to enquiries; schedule tours; confirm bookings; provide service, operational or emergency notices; deliver support; send marketing where permitted

Ground: consent; certain legitimate uses
Professional and business information Examples: organisation, designation, team size, workspace requirements, business sector, authorised users and billing contact details

Collected through: sales enquiries; proposals; membership or managed-office discussions; information supplied by your organisation

Uses: recommend suitable workspace solutions; prepare proposals and contracts; administer corporate memberships and authorised users; manage client relationships

Ground: consent; certain legitimate uses; steps requested by you before entering into an arrangement
Booking, membership and transaction information Examples: day passes, tours, desks or rooms booked, membership terms, service usage, invoices, payment status, billing details, refunds and support history

Collected through: website or partner booking channels; contracts; payment providers; member services; support interactions

Uses: process and manage bookings, memberships, payments and refunds; provide facilities; maintain financial records; detect fraud; resolve disputes

Ground: consent; certain legitimate uses; compliance with law
Payment information Examples: payment method, transaction reference, amount, billing address and limited payment status information

Collected through: payment gateways, banks and other payment providers

Uses: complete transactions; reconcile accounts; process refunds; prevent fraud; maintain legally required records

Ground: certain legitimate uses; compliance with law. Full card or banking credentials are generally processed directly by the payment provider rather than stored by ThinkHaus
Visitor, access and security information Examples: visitor name, host, visit time, access logs, entry or exit records, vehicle details where applicable, and CCTV footage at ThinkHaus premises

Collected through: reception or visitor systems; access-control systems; security personnel; CCTV cameras in designated common and access areas

Uses: manage access; maintain safety and security; investigate incidents; protect people, property and confidential information; comply with lawful requests

Ground: certain legitimate uses; consent where required; compliance with law
Technical, device and usage information Examples: IP address, browser, device type, operating system, referring pages, pages viewed, timestamps, cookie identifiers, logs and approximate location inferred from IP

Collected through: website, cookies, analytics and security technologies

Uses: operate and secure the website; remember preferences; understand usage; troubleshoot; prevent fraud or abuse; improve performance and experience

Ground: consent where required; certain legitimate uses
Marketing and preference information Examples: communication preferences, campaign engagement, event registration, feedback, survey responses and areas of interest

Collected through: website forms; email, SMS or WhatsApp interactions; events; surveys; marketing platforms

Uses: send relevant offers, updates and event invitations where permitted; measure campaign performance; improve our services

Ground: consent; certain legitimate uses for service-related communications
Recruitment information Examples: résumé or CV, qualifications, work history, portfolio, compensation expectations, references and interview notes

Collected through: careers enquiries; email; recruitment platforms; recruiters; references authorised by you

Uses: assess applications; communicate with candidates; conduct recruitment and pre-employment checks where lawful; maintain hiring records

Ground: consent; employment-related legitimate uses; compliance with law
Vendor and business-partner information Examples: contact details, role, organisation, proposals, contracts, tax or payment details, due-diligence records and communications

Collected through: vendor onboarding; contracts; email; procurement and finance processes

Uses: evaluate and engage vendors; administer contracts and payments; manage relationships; conduct due diligence; comply with legal obligations

Ground: certain legitimate uses; compliance with law
Information you choose to provide Examples: feedback, messages, documents, support content, special requests or other information included in your communications

Collected through: forms; support channels; calls, email, SMS or WhatsApp; in-person interactions

Uses: respond to your request; provide or improve services; resolve issues; maintain appropriate business records Ground: consent; certain legitimate uses

3.1 Personal Data Received from Other Sources

We may receive Personal Data from your employer, organisation, host, authorised representative, booking or channel partner, payment provider, recruiter, referral source, publicly available business source, or a vendor supporting our Services. We may combine such information with data received directly from you where reasonably necessary for the stated purposes.

If you provide Personal Data about another individual—for example, a colleague, employee, guest, visitor, authorised user, reference or emergency contact—you confirm that you are authorised to provide it and have delivered any required notice or obtained any required consent.

3.2 Automated Decisions

ThinkHaus does not currently use solely automated processing to make decisions that produce legal or similarly significant effects for individuals. If this changes, we will provide any notice and safeguards required by applicable law.

4. Data Sharing and Disclosure

We do not sell your Personal Data. We may share it only where reasonably necessary for the purposes described in this Policy, subject to contractual, organisational and technical safeguards appropriate to the circumstances.

4.1 Service Providers

We may share Personal Data with vendors that help us operate our business, such as:

Service providers are expected to process Personal Data only for agreed purposes, maintain appropriate confidentiality and security, and comply with applicable law.

4.2 Member Organisations, Hosts and Authorised Users

If your access or booking is arranged by an organisation, employer, host or account administrator, we may share relevant booking, access, usage, billing or support information with that party to administer the arrangement. ThinkHaus and the relevant organisation may each act as an independent Data Fiduciary for different processing activities.

4.3 Legal, Safety and Regulatory Disclosures

We may disclose Personal Data where reasonably necessary to:

4.4 Corporate Transactions

If ThinkHaus is involved in a merger, acquisition, restructuring, financing, sale of assets or similar transaction, Personal Data may be disclosed to advisers and counterparties subject to appropriate confidentiality arrangements and applicable law.

4.5 Services You Request

Where you ask us to arrange or connect you with a third-party service, we may share the minimum Personal Data reasonably necessary to fulfil that request. The third party’s independent processing will be governed by its own privacy notice.

4.6 Cross-Border Processing

Some service providers may store or access Personal Data from locations outside India. Where cross-border processing occurs, we will take reasonable steps to ensure that it is carried out in accordance with applicable Indian law, including any restrictions notified by the Government of India, and that appropriate contractual and security safeguards apply.

5. Protection of Personal Data

We use reasonable technical, organisational and physical safeguards designed to protect Personal Data from unauthorised access, use, disclosure, alteration, loss or destruction. Depending on the nature of the processing, these measures may include:

No system or transmission method is completely secure. You should protect account credentials, avoid sending sensitive information through unsecured channels, and notify us promptly if you suspect misuse or unauthorised access.

6. Your Rights as a Data Principal

Subject to applicable law and verification, you may have the following rights in relation to Personal Data processed by ThinkHaus:

These rights are not absolute. We may decline or limit a request where permitted or required by law, and will explain the basis where appropriate.

7. Exercising Your Rights and Raising a Grievance

To exercise a right, withdraw consent, register a nominee or raise a privacy grievance, email admin@thinkhaus.in with the subject line “Privacy Request” and briefly describe your request.

We may take the following steps:

  1. Acknowledge the request and provide a reference or confirmation where appropriate.
  2. Verify your identity and, for a nominee or authorised representative, verify that person’s identity and authority.
  3. Ask for information reasonably necessary to identify the relevant records and understand the request.
  4. Review and respond within the period required by applicable law.

Please do not send passwords, full payment-card details or unnecessary identity documents by email. If verification documents are needed, we will tell you how to provide them securely.

If you are not satisfied with our response, you may use our internal grievance process by replying to the same email and requesting escalation. Where applicable, and after exhausting the grievance process required by law, you may approach the Data Protection Board of India.

8. Children and Persons Requiring Lawful Guardian Consent

Our website and Services are intended for adults and business users. We do not knowingly offer online services directly to children or knowingly process a child’s Personal Data for behavioural monitoring or targeted advertising.

A child may enter a ThinkHaus location only in accordance with applicable workspace rules and while accompanied or authorised by a parent, lawful guardian, host or responsible adult, as appropriate. If processing a child’s Personal Data becomes necessary, we will seek verifiable consent from the parent or lawful guardian where required by law.

Where applicable law requires consent from a lawful guardian for a person with a disability, we will take reasonable steps to verify the guardian’s identity and authority before relying on that consent.

If you believe a child or another person requiring lawful guardian consent has provided Personal Data improperly, contact us at admin@thinkhaus.in so that we can review and take appropriate action.

9. Cookies and Similar Technologies

Our website may use cookies, pixels, tags, local storage and similar technologies to operate securely, remember preferences, understand how visitors use the site, measure performance and support communications or marketing.

Where required, we will request consent before placing non-essential cookies. You can use available cookie controls or browser settings to reject or delete cookies. Blocking some technologies may affect site functionality. If we publish a separate Cookie Notice, it will provide additional details and form part of this Policy.

10. Data Retention and Deletion

We retain Personal Data only for as long as reasonably necessary for the purpose for which it was collected, or for a longer period where required or permitted by law. Retention periods vary according to the nature of the data, the service and our legal or operational needs.

When setting retention periods, we consider:

When Personal Data is no longer required, we will take reasonable steps to delete, anonymise or de-identify it. Backup copies may remain for a limited period until securely overwritten through routine processes. A deletion request may be declined to the extent retention is necessary or permitted by law.

11. Personal Data Breach

We maintain processes to identify, assess, contain and respond to suspected Personal Data breaches. Where a breach occurs, we will take reasonable steps to limit harm, investigate the cause, restore security and prevent recurrence.

We will notify affected Data Principals and the Data Protection Board of India, or another competent authority, when and in the manner required by applicable law. Notifications may describe the nature and extent of the breach, likely consequences, mitigation measures, safety steps you may take and contact information for questions.

If you suspect that Personal Data provided to ThinkHaus has been compromised, email admin@thinkhaus.in with the subject line “Suspected Data Breach”. Do not include passwords or sensitive credentials in the message.

12. Review and Changes to This Policy

We may update this Policy to reflect changes in our Services, technology, data practices or legal requirements. The updated version will be posted at https://www.thinkhaus.in with a revised “Last updated” date.

Where a change materially affects how we process Personal Data, we may provide an additional notice or request fresh consent where required. We encourage you to review this Policy periodically.

13. Contact Us

For questions, rights requests or grievances relating to this Policy or our processing of Personal Data, contact:

Organisation ThinkHaus Spaces Private Limited
Attention Privacy Contact / Grievance Redressal
Email admin@thinkhaus.in
Website https://www.thinkhaus.in

Lets schedule a tour for you!

Book a Space!

Price: ₹0 /day + 18% GST
Su
Mo
Tu
We
Th
Fr
Sa

Book a Day Pass!

Price: ₹0 / Seat
Su
Mo
Tu
We
Th
Fr
Sa