PHARMICOMContact us
Legal & compliance

Privacy policy

Last updated: 11 October 2026 · Applies to pharmicom.com

In short: we only collect what you send us through the enquiry form or by email, we use it to reply to you, we never sell it, we set no cookies and run no tracking, and you can ask us to see, correct or delete your data at any time.

  1. Who we are
  2. What this policy covers
  3. What we collect
  4. Why we use it, and our legal basis
  5. Consent and withdrawing it
  6. Who we share it with
  7. International transfers
  8. How long we keep it
  9. How we protect it
  10. Your rights
  11. Grievance Officer
  12. Children
  13. Cookies and tracking
  14. Other websites
  15. Changes to this policy
  16. Contact

Who we are

This website is operated by Pharmicom (“we”, “us”), based in Pune, Maharashtra, India.

For personal data collected through this website, we are the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the controller under the EU and UK General Data Protection Regulation (GDPR).

Contact for privacy questions: hello@pharmicom.com. Grievance Officer: see section 11.

What this policy covers

This policy covers personal data collected through pharmicom.com and enquiries sent to us. It does not cover data we process for clients while delivering projects; that is governed by our client contracts and, where required, a data processing agreement.

What we collect

Information you give us

Information collected automatically

What we do not collect

Why we use it, and our legal basis

PurposeDataBasis in India (DPDP Act)Basis in the EU / UK (GDPR)
Reply to your enquiry and send a proposalForm and email detailsYour consent (section 6), or a specified purpose you gave the data for (section 7(a))Steps before a contract at your request (Art. 6(1)(b)) and consent (Art. 6(1)(a))
Deliver services if you engage usContact and business detailsConsent and contractContract (Art. 6(1)(b))
Keep the website secure and prevent abuseServer logsReasonable security safeguards we must keep (section 8(5))Legitimate interests (Art. 6(1)(f))
Meet legal, tax and accounting dutiesContract and invoice recordsCompliance with law (section 7)Legal obligation (Art. 6(1)(c))

We do not use your data for automated decision-making or profiling, and we do not send marketing emails unless you separately ask us to.

The enquiry form asks for your consent with an unticked checkbox. You can withdraw consent at any time, as easily as you gave it, by emailing hello@pharmicom.com. Withdrawal does not affect anything we did lawfully before it. After withdrawal we stop processing your data and delete it unless the law requires us to keep it.

Who we share it with

We never sell or rent personal data. We share it only with service providers who help us run the website and reply to you, under contracts that require confidentiality and security:

International transfers

We are based in India. Some of our service providers store data outside India, for example in the USA or the EU. The DPDP Act allows such transfers except to countries the Government of India restricts by notification; we will not transfer data to any restricted country.

For people in the EU, EEA or UK, transfers out of those regions rely on an adequacy decision or on the European Commission’s Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement) offered by our providers.

How long we keep it

How we protect it

We use reasonable security practices in line with section 43A of the Information Technology Act, 2000 and the IT (SPDI) Rules, 2011, and the safeguards required by section 8(5) of the DPDP Act. These include HTTPS everywhere, strict browser security headers (Content Security Policy, HSTS, frame and content-type protections), access limited to staff who need it, and two-step login on our email and hosting accounts.

If a personal data breach happens, we will inform the Data Protection Board of India and affected people as the DPDP Act and its rules require, and, where the GDPR applies, the relevant supervisory authority within 72 hours.

Your rights

Everyone

Whatever your location, you can ask us what data we hold about you, ask us to correct or delete it, or withdraw your consent. Email hello@pharmicom.com. We reply within 30 days and may ask you to confirm your identity first.

India (DPDP Act, sections 11 to 14)

EU, EEA and UK (GDPR)

United States (for example California, CCPA/CPRA)

Grievance Officer

In line with the DPDP Act and rule 5(9) of the IT (SPDI) Rules, 2011, you can contact our Grievance Officer:

Grievance Officer
Pharmicom
Pune, Maharashtra, India
Email: hello@pharmicom.com (subject line: “Grievance”)

We acknowledge grievances within 72 hours and aim to resolve them within 30 days. If you are not satisfied, you may complain to the Data Protection Board of India.

Children

This website is for business and healthcare professionals. It is not directed at anyone under 18 (a “child” under the DPDP Act), and we do not knowingly collect children’s data. If you believe a child has sent us data, email us and we will delete it.

Cookies and tracking

This website sets no cookies, uses no browser storage, and runs no analytics, advertising or tracking pixels. Our fonts are loaded from Google Fonts, which receives your IP address to deliver them (see Google’s privacy policy at policies.google.com/privacy). Read the full Cookie notice.

If we ever add analytics, we will ask for your consent first and update this policy before doing so.

Links to other websites are provided for convenience. Their owners are responsible for their own privacy practices.

Changes to this policy

We may update this policy. The date at the top shows the latest version. If a change materially affects how we use your data, we will say so on the homepage, and ask for fresh consent where the law requires.

Contact

Pharmicom, Pune, Maharashtra, India. Email hello@pharmicom.com.