Book a demoExplore the eBMR
Home / Legal / Privacy Policy
PP

Privacy Policy

What we collect, why, and what you can do about it

Written to be read rather than survived. If you are a customer, section 7 is the one that matters — the data inside your installation is yours, and we act only on your instructions.

Last updated 5 September 2026

Who we are

DeepScience Tech Pvt Ltd (“DeepScience Tech”, “we”, “us”) is a private limited company incorporated in India, with its place of business at Hyderabad, Telangana, India. We build and support DeepPharmaERP and DeepEBMR.

This policy explains what personal data we collect through this website and through our commercial relationship with you, why we collect it, and what you can do about it. It is written to be read, not to be survived.

This policy covers this website and our sales process. It does not cover data inside a DeepPharmaERP system deployed at your site — where we host or support an installation, we act as a data processor under a separate written agreement, and your own policies govern the data in it. That distinction is set out in section 7.

What we collect

We keep this deliberately small.

Information you give us

  • Your name, work email address, phone number, company and role, when you contact us, request a demo or exchange correspondence.
  • Anything you choose to tell us about your operation during a sales conversation — plant details, current systems, requirements.
  • Records of the meetings, calls and documents exchanged during an evaluation.

Information collected automatically

  • Standard server logs: IP address, browser type, pages requested, referring page, date and time. Retained for security and diagnostics.
  • Analytics data, if analytics is enabled on this site, in aggregated and pseudonymised form.

What we do not collect

  • We do not knowingly collect data from anyone under 18.
  • We do not collect sensitive personal data through this website — no health data, no financial account details, no government identifiers.
  • We do not buy contact lists or scrape personal data to build a prospect database.

Why we use it

We use personal data only for these purposes:

PurposeBasis
Responding to your enquiry or demo requestSteps taken at your request before entering a contract
Delivering an implementation or support contractPerformance of a contract
Keeping the website secure and diagnosing faultsOur legitimate interest in a working, secure service
Statutory records — invoices, tax, company filingsLegal obligation under Indian law
Occasional product updates to existing contactsConsent, withdrawable at any time

We do not use your data for automated decision-making that produces legal effects, and we do not profile you for advertising.

Cookies

This website uses cookies sparingly.

  • Strictly necessary cookies keep the site working. These cannot be switched off.
  • Analytics cookies, where enabled, help us understand which pages are useful. These are set only with your consent where consent is required.

We do not use advertising or cross-site tracking cookies. You can block or delete cookies through your browser; the site will continue to work.

Fonts on this site are served by Google Fonts, which means your browser makes a request to Google's servers and Google may log your IP address. If you would prefer this not to happen, we can self-host the fonts on request — and we do so by default for on-premise deployments.

Who we share it with

We do not sell personal data. We do not rent it, and we do not share it for anyone else's marketing.

We share data only with:

  • Service providers who host our website, email and business systems, bound by contract to process data only on our instructions.
  • Professional advisers — auditors, lawyers, accountants — where they need it to advise us.
  • Authorities, where we are legally required to disclose. If we receive such a demand and are permitted to tell you, we will.

International transfers

We are based in India and our systems are principally located in India. Some service providers may process data outside India.

Where personal data protected by the EU or UK GDPR is transferred outside those jurisdictions, we rely on appropriate safeguards, including Standard Contractual Clauses. If you would like details of the safeguards applied to a particular transfer, ask us and we will tell you.

Data inside a DeepPharmaERP installation

This section matters if you are a customer rather than a website visitor.

When we implement, host or support DeepPharmaERP for you, the data inside that system — your employees, your batches, your suppliers — is yours. You are the data controller (in Indian terms, the data fiduciary). We act as a processor, and only on your documented instructions.

  • We access your production system only when you ask us to, or under an agreed support procedure, and that access is logged.
  • We do not use your operational data to train models, benchmark other customers or for any purpose of our own.
  • Where AI features are enabled, models can be trained and run entirely within your own infrastructure. For air-gapped installations nothing leaves your plant at all.
  • On termination we return or delete your data as instructed, subject to any retention your own regulator requires.

The specific terms are set out in the services agreement and data processing agreement signed with you, which prevail over this policy.

How long we keep it

  • Enquiries that do not proceed — up to 24 months, then deleted.
  • Customer and contract records — for the life of the contract and then as long as Indian tax and company law requires, which is generally eight years.
  • Server logs — typically 90 days.
  • Marketing consent records — until you withdraw consent, plus a record of the withdrawal itself.

Your rights

Depending on where you are, you may have the right to:

  • Ask what personal data we hold about you and get a copy.
  • Have inaccurate data corrected.
  • Have your data erased, where we have no continuing lawful reason to keep it.
  • Object to or restrict processing based on legitimate interests.
  • Receive your data in a portable format.
  • Withdraw consent at any time, without affecting processing already carried out.
  • Complain to a supervisory authority.

To exercise any of these, write to info@deepsciencetech.com. We will respond within 30 days. We do not charge for this and we will not make it difficult.

Security

We apply access control on a need-to-know basis, encryption in transit, encrypted backups, and logging of administrative access. Staff are bound by confidentiality obligations.

No system is perfectly secure, and we would rather say so than claim otherwise. If a breach affects your personal data and is likely to cause you harm, we will notify you and the relevant authority as required by law.

Grievance officer

Under the Information Technology Act 2000 and rules made under it, and in anticipation of the Digital Personal Data Protection Act 2023, you may contact our grievance officer:

Grievance Officer
DeepScience Tech Pvt Ltd
Hyderabad, Telangana, India
Email: info@deepsciencetech.com
Phone: +91 90009 99505

We acknowledge grievances within 24 hours and aim to resolve them within 15 days.

Changes to this policy

If we change this policy we will update the date at the top. Where a change materially affects your rights, we will tell existing customers and contacts directly rather than relying on you to notice.

Questions about any of this: info@deepsciencetech.com.

See it on your own floor.

Two hours with your production and QA leads. We walk one product end to end and show you where it lands in the system — then you decide whether a gap study is worth it.