1. Who we are
Serturner Labs Private Limited ("Serturner", "we", "us") is a company incorporated in India, with its registered office at 1st Floor, Parinee Crescenzo, G Block, BKC, Bandra East, Mumbai, Maharashtra 400051. We distribute pharmaceuticals, medical devices, consumables and laboratory products, deliver facility set-up and service programmes, and operate related software. For personal data processed through our own websites and software we act as the data fiduciary (controller). Where we process data on the written instructions of a hospital, laboratory, clinic or other institutional customer, that customer is the fiduciary and we act as a data processor on its behalf.
2. Data we collect
We collect only what we need to respond to you and to run the services you or your organisation have asked for:
Contact and enquiry data — name, work email, phone number, employer or facility name, role, city, and the content of your enquiry, quote request, demo request or support ticket.
Account and transaction data — login credentials, user permissions, purchase orders, delivery addresses, invoices, payment references, licence and registration numbers required by law for the supply of regulated products (for example drug licence, GST and, where applicable, narcotic or blood-bank licences).
Operational data you upload — consumption files, stock and par-level data, equipment and service records submitted to the Serturner Portal, Insights or practice-management software.
Technical data — IP address, device and browser type, pages viewed, referring page, timestamps, and diagnostic logs generated when you use our sites or software.
Recruitment data — where you apply for a role, the information in your application and any references you provide.
We do not seek patient-identifiable health information through our website forms, and we ask that you do not submit it there. Where a service does involve patient records, it is governed by a separate written agreement described in section 6.
3. How we use it
We use personal data to respond to enquiries and quote requests; to verify eligibility to purchase regulated products; to process, deliver, invoice and support orders; to provide, secure and improve the Serturner Portal, Insights and related software; to run facility set-up, installation, commissioning and service programmes; to send service, delivery, recall and product-safety communications; to meet statutory, regulatory, tax, pharmacovigilance and traceability obligations; to detect and prevent fraud, misuse and security incidents; to defend legal claims; and, where you have opted in, to send relevant updates and knowledge-bank material. You can withdraw marketing consent at any time using the unsubscribe link or by writing to us. We do not sell personal data, and we do not use it for automated decisions that produce legal effects about you.
4. Consent and legal basis
We process personal data on the basis of your consent, given when you submit a form or create an account; the performance of a contract with you or your organisation; compliance with legal obligations under the Drugs and Cosmetics Act 1940 and its Rules, the Companies Act 2013, tax legislation and other applicable law; and our legitimate uses as permitted under the Digital Personal Data Protection Act 2023, including responding to a request you have made to us. Where consent is the basis, you may withdraw it at any time, which will not affect processing already carried out or processing we are legally required to continue.
5. Disclosure and sharing
We disclose personal data only to: manufacturers, principals and technology partners where this is necessary to fulfil an order, honour a warranty, arrange installation or service, or handle a product complaint or recall; logistics, cold-chain and courier providers, to the extent needed for delivery; payment processors, banks and auditors; IT, hosting, email, analytics and support vendors engaged under written contracts that restrict their use of the data to our instructions; professional advisers; and regulators, courts or law-enforcement authorities where disclosure is required by law or necessary to protect rights, safety or property. If our business or a part of it is reorganised, merged or transferred, data may pass to the successor entity subject to this policy. All processors are bound by confidentiality and security obligations and may not use the data for their own purposes.
6. Facility, consumption and clinical data
Data your organisation uploads to Insights or a practice-management deployment belongs to your organisation. We process it to deliver the service you have subscribed to, and we may use aggregated, de-identified information — from which no facility, individual or patient can reasonably be identified — to produce benchmarks, demand trends and research material. Where a deployment involves patient or clinical records, processing is governed by a separate written data-processing agreement with your organisation, which sets out purpose limitation, confidentiality, sub-processing, breach notification, audit and deletion terms. We do not use identifiable clinical data for marketing, and we do not disclose it to manufacturers or other customers.
7. Cookies and analytics
Our sites use strictly necessary cookies and local browser storage to keep sessions active, remember preferences and secure forms, and may use analytics cookies to understand which pages are useful. You can block or delete cookies in your browser settings; strictly necessary cookies cannot be disabled without affecting site function. Where required, we ask for your consent before setting non-essential cookies.
8. Security
We maintain reasonable technical and organisational safeguards appropriate to the sensitivity of the data, including encryption of data in transit, access control on a need-to-know basis, role-based permissions in our software, logging, environment separation, vendor due diligence and staff confidentiality obligations. No system can be guaranteed absolutely secure; you are responsible for keeping account credentials confidential and for notifying us promptly of any suspected unauthorised access. In the event of a personal data breach we will notify the Data Protection Board of India and affected individuals as required by law.
9. Retention
We keep personal data only as long as needed for the purpose it was collected, and then for any period required by law — including record-keeping, batch traceability, warranty, tax and audit requirements applicable to the supply of medicines and medical devices in India. Enquiry data not converted to an account is deleted or anonymised within a reasonable period. On termination of a subscription, customer data is returned or deleted in line with the applicable agreement, save for records we must retain by law.
10. Your rights
Subject to applicable law, you may request access to a summary of the personal data we hold about you and how it is processed; correction or completion of inaccurate or incomplete data; erasure of data we no longer need; withdrawal of consent; nomination of another person to exercise your rights in the event of death or incapacity; and grievance redressal. To exercise a right, write to the grievance officer below from the email address on record, with enough detail for us to identify you. We may ask for verification and will respond within the timelines prescribed by law. Where we act as a processor for your hospital or laboratory, please direct your request to that organisation and we will support it.
11. Cross-border transfers
Our primary hosting and processing is in India. Some vendors — for example email, hosting or support tools — may process data outside India. Where that happens we transfer only what is necessary, use contractual safeguards including confidentiality, security and purpose-limitation terms, and do not transfer data to any territory restricted by the Central Government.
12. Children's data
Our sites and software are intended for businesses and healthcare professionals and are not directed at children. We do not knowingly collect personal data of anyone under 18 through our forms. Where a clinical deployment necessarily involves data about minors, it is processed only on the instructions of the treating institution under a written agreement, with verifiable parental or guardian consent obtained by that institution. If you believe a child's data has reached us in error, write to us and we will delete it.
13. Changes to this policy
We may update this policy to reflect changes in law, technology or our services. The revised version takes effect when published on this page, and the "last updated" date above will change. Where a change materially affects how we use data you have already given us, we will notify account holders by email or through the Serturner Portal. Continued use of our sites or services after publication constitutes acceptance of the updated policy.
14. Grievance officer and contact
For any question, request or complaint about this policy or the handling of your personal data, contact our grievance officer. We acknowledge complaints promptly and aim to resolve them within the timelines prescribed under Indian law. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
Grievance Officer — Serturner Labs Private Limited
1st Floor, Parinee Crescenzo, G Block, BKC, Bandra East, Mumbai, Maharashtra 400051, India
privacy@serturner.com · +91 97693 67602
This policy is governed by the laws of India. Courts at Mumbai, Maharashtra have exclusive jurisdiction over any dispute arising from it. Please also read our
Disclaimer.