Introduction
SevenQ Nutrition LLP. (“SevenQ Nutrition,” “we,” “our,” or “us”) is committed to respecting and safeguarding your privacy. This Privacy Policy (“Policy”) outlines the principles and practices governing the collection, processing, use, disclosure, storage, transfer, and protection of personal data in the course of our operations.
We recognize the sensitivity of the data entrusted to us, especially in a sector dealing with health, wellness, and human safety, and are fully committed to transparency, accountability, and data protection by design.
SevenQ Nutrition complies with applicable data protection legislation. This Policy governs all data collected through offline and online modes and is applicable to all data subjects, regardless of geographic location, unless superseded by local law.
1. Scope and Applicability
Data Subjects
- Employees, job applicants, contractors
- Patients (clinical trials or pharmacovigilance)
- Vendors, healthcare professionals, partners, shareholders, clients, users
Touchpoints
- Corporate websites and mobile applications
- HRMS tools and employment records
- Email communications, CCTV, third-party integrations
Jurisdiction
- India
2. Categories of Personal Data We Collect
A. Identification & Contact Information
- Full name, date of birth, gender, nationality
- Phone numbers and email addresses
- Residential and mailing addresses
- Government-issued IDs (PAN, Aadhaar, Passport, Voter ID)
- Emergency contact details
B. Employment & HR Data
- Education and professional qualifications
- Employment history and references
- Salary, benefits, and compensation data
- Biometric data
- Occupational health and wellness records
C. Sensitive Personal Data
- Medical and vaccination records
- Genetic or biometric identifiers
- Disability and accommodation needs
- Union membership (if applicable)
D. Technical and Device Data
- IP address, MAC address, browser and OS details
- Cookies and session logs
- Login credentials and access logs
E. Financial & Transactional Data
- Bank account details
- UAN, EPFO, insurance information
- Invoices, payments, vendor contracts
F. Marketing & Communication Data
- Subscription preferences
- Email open and click data
- Event registrations and feedback
G. Vendor & Business Partner Data
- Company details and GSTIN
- Supplier contacts and due diligence records
- NDAs and audit documentation
H. Consent Records
- Timestamped consent for employment, health, marketing, and disclosures
3. How We Collect Personal Data
A. Direct Collection
- Onboarding and contracts
- Medical or clinical documentation
- Website forms, surveys, feedback portals
B. Automated Means
- CCTV and access control systems
- Attendance and security logs
- Cookies, analytics, and CRM tools
C. Third Parties
- Insurance providers and TPAs
- Recruitment and verification agencies
- Academic institutions and regulators
4. Purposes for Processing
A. Employment Lifecycle Management
- Recruitment and payroll
- Benefits and leave management
- Disciplinary and exit processes
B. Compliance and Legal Obligations
- Taxation and statutory filings
- Health, safety, and legal compliance
C. Information Security
- Access control and surveillance
- Data loss prevention
D. Marketing and Communication
- Regulatory disclosures
- Event and stakeholder communication
5. Legal Bases for Processing
- Consent
- Contractual necessity
- Legal obligation
- Legitimate interest
- Vital interest
6. Data Sharing and Disclosures
- Group companies
- Service providers and vendors
- Regulators, auditors, and legal advisors
7. Cross-Border Data Transfers
Transfers are conducted only when necessary and safeguarded by applicable laws.
8. Data Security Measures
- Physical and digital access controls
- Security monitoring at facilities
9. Data Retention and Deletion
- Employment data: 7 years
- Financial data: 8 years
- Clinical trial data: 15–25 years
- CCTV footage: 90 days
10. Rights of Data Subjects
- Access and correction
- Deletion or restriction
- Data portability
- Consent withdrawal
- Complaint to authority
11. Children’s Data
We do not knowingly collect personal data from children under 13.
12. Policy Updates
Updates will be published on our website as required.
13. Data Minimization and Purpose Limitation
We collect only necessary data for defined purposes.
14. Anonymization and Pseudonymization
Data may be anonymized or pseudonymized where feasible.
15. Employee Confidentiality and Training
- Confidentiality agreements
- Annual data protection training
- Incident response drills
16. Vendor Due Diligence and Onboarding
Vendors are assessed and bound by Data Processing Agreements.
17. Sub-Processor Disclosures
Sub-processors are managed with transparency and safeguards.
18. Incident and Breach Response Framework
Breaches are addressed and reported as required by law.
19. Privacy by Design and Default
Privacy controls are embedded into systems by default.
20. Internal Audit and Compliance Monitoring
Regular audits ensure ongoing compliance.
21. Data Localization Requirements
Sensitive data is stored within India or approved jurisdictions.
22. Enforcement and Disciplinary Action
Violations may result in disciplinary or legal action.
23. Interpretation and Governing Law
Governed by the laws of India with jurisdiction in Delhi.
24. Contact Us
Email: sales@sevenqnutrition.com