Privacy policy
Purpose of the Policy
At Strides Pharma Science Limited (hereafter referred to as “Strides,” “we” or “company”) we are committed to protecting the personal data of all individuals whose information we collect such as patients, employees, job applicants, customers, suppliers, vendor, contractors, partners, clinical trial participants, website users and other personal information collected in due course.
This Privacy Policy establishes the principles and requirements governing the collection, use, processing, storage, disclosure, transfer, retention, and protection of personal data in compliance with applicable data protection laws, including the Digital Personal Data Protection Act, 2023 (India) and applicable rules thereunder, the General Data Protection Regulation (GDPR), and other applicable privacy regulations.
The company’s commitment to data privacy also includes a zero-tolerance approach towards any form of data mismanagement.
Privacy Governance and Accountability
Strides is responsible for determining the purposes and means of processing personal data. Certain processing activities may be performed by other authorized service providers acting on behalf of Strides under appropriate contractual, confidentiality, security, and privacy obligations.
Privacy and data protection risks form an integral part of Strides' enterprise-wide risk management and compliance framework. Privacy risks are periodically identified, assessed, monitored, reported, and mitigated through established governance mechanisms.
A Data Protection Officer (DPO), supported by a cross-functional privacy governance team, is responsible for overseeing compliance with this Policy, responding to privacy-related concerns, coordinating investigations, and monitoring implementation of privacy controls across the organization.
Principles of Data Processing
Our data processing activities are based on the following principles together with any other prevailing global practices:
- Lawfulness, Fairness, and Transparency;
- Purpose limitation;
- Data Minimization;
- Accuracy of Data;
- Storage Limitation;
- Data Integrity and Confidentiality;
- Accountability
Legal Basis for Processing
Where required by applicable law, Strides processes personal data based on one or more of the following legal grounds:
- Consent of the individual;
- Performance of a contract;
- Compliance with legal or regulatory obligations;
- Protection of vital interests;
- Legitimate business interests that do not override individual rights;
- Scientific, medical, clinical, or research purposes permitted under applicable laws.
- Other lawful basis permitted by applicable law
Where consent is required, personal data shall not be collected, used, retained, processed, or disclosed unless valid consent has been obtained.
Privacy Notice and Transparency
Strides shall provide individuals with appropriate information regarding the personal data collected, purpose of processing, applicable rights, consent requirements, and available channels for exercising privacy rights, in accordance with applicable law.
Scope and applicability
This Policy applies to all personal data collected, processed, and stored by Strides and its subsidiaries, across their global operations, platforms, and services.
This policy shall govern all Employees (including part time, temporary, contractual), workers, trainees, consultants, customers, volunteers of the Company, and its Subsidiaries, suppliers, contractors, and service providers integrated within the Strides ecosystem. This policy shall extend across our value chain, defining our forward-thinking approach to collaborating with partners and setting clear standards for their operational conduct bound by strict contractual safeguards.
Categories of Personal Data Collected
Depending on the association with the company, company may collect the following categories of personal data;
- Patients and trial participants;
Health-related data, diagnoses, and biometric details for the purpose of scientific research and clinical trials; - Employees, contactors, and potential job applicants
Documents containing information on their identity, contact information, professional experience, payroll and benefits information, emergency contact details and other information required for employment purposes (including details of family members to comply with employee benefit requirements such as medical insurance, other regulatory compliance requirements such as SEBI Insider Trading compliance or any other legitimate purpose) - Website visitors IP addresses, device identifiers, browser information, website usage information, cookie-related information;
- Customers, Vendors, and Business Partners;
Contact information, business information, contractual and financial information, communication records
Strides’ website may also passively gather certain information about your visits without requiring you to actively submit it. This data may be collected through various technologies such as cookies, internet tags, and web beacons.
To protect their privacy, data principal/subject may choose to accept or defer from providing information that is not specifically requested by the company. When you register using third-party accounts such as Facebook, Twitter or Gmail, Strides may access the necessary information from those accounts to facilitate your registration, maintain ongoing communication, and deliver applicable services.
Sensitive and Special Category Personal Data
Strides shall apply appropriate safeguards to sensitive or special category personal data, including health, biometric, and clinical trial data, and shall restrict access and processing to authorized personnel in accordance with applicable law.
Children's Personal Data
Strides shall process children's personal data only in accordance with applicable laws and shall obtain parental or lawful guardian consent where required.
Purposes of Processing
Personal data may be processed for:
- Recruitment and employment administration;
- Compensation and benefits management;
- Customer relationship management;
- Contract administration;
- Regulatory and legal compliance;
- Clinical research and pharmacovigilance activities;
- Product quality and patient safety activities;
- Vendor and supplier management;
- Information security monitoring;
- Business operations and continuity;
- Website administration and improvement;
- Protection of company assets and interests;
- Any other legitimate purpose permitted by applicable law.
Protection Against Secondary Use
Personal data collected by Strides shall be used only for the specific, explicit, and lawful purposes for which it was collected or for other compatible purposes permitted under applicable law. Personal data shall not be processed, disclosed, or used for unrelated or secondary purposes without an appropriate legal basis, including obtaining additional consent where required by applicable law.
Customer Privacy Rights and Choice
Strides is committed to ensuring individuals maintain control over their personal data.
Where applicable, individuals may:
- Provide or withhold consent for processing activities;
- Withdraw consent at any time;
- Opt out of processing based on consent or legitimate interests, subject to legal or contractual limitations;
- Control preferences regarding communications and use of personal information
Withdrawal of consent shall not affect the lawfulness of processing conducted before such withdrawal.
Cookies and Similar Technologies
Strides may use cookies, web beacons, internet tags, and similar technologies on websites and digital platforms to enhance user experience, improve website functionality, maintain security, and analyze website usage. These technologies may collect information such as IP addresses, browser type, device information, website activity, and user preferences. Where required by applicable law, users will be provided with the option to provide or withdraw consent for non-essential cookies. Users may also manage cookie preferences through their browser settings; however, disabling certain cookies may affect website functionality and user experience.
Disclosure of Personal Data
Personal data may be disclosed only where necessary and lawful, including to:
- Strides affiliates and group entities;
- Authorized service providers;
- Regulatory authorities and government agencies;
- Auditors, legal advisors, and professional consultants;
- Clinical research organizations and research partners;
- Information technology service providers;
- Potential acquirers or successors during mergers, acquisitions, or corporate restructuring activities.
All disclosures shall be subject to appropriate confidentiality, privacy, and security obligations.
Personal data shall not be sold to third parties.
Third-Party and Processor Management
Third parties processing personal data on behalf of Strides shall be subject to appropriate privacy, confidentiality, security, contractual, and compliance requirements, including appropriate oversight of sub-processors where applicable.
Cross-Border Transfers
Where personal data is transferred across national borders, Strides shall implement appropriate safeguards and comply with applicable legal, regulatory, and contractual requirements governing international data transfers.
Security and Confidentiality
Strides is committed to ensuring that personal information collected/processed is secured. In order to prevent unauthorized access or disclosure, the company has put in place suitable physical, electronic and managerial procedures to safeguard and secure the information company collects. Our systems are safeguarded through role-based access controls, advanced encryption, intrusion detection mechanisms, and secure data backups.
Data Retention
Personal data shall be retained only for as long as necessary to fulfill the purpose for which it was collected and to satisfy legal, regulatory, contractual, scientific, business, or operational requirements.
Upon expiry of applicable retention periods, personal data shall be securely deleted, anonymized, archived, or otherwise disposed of in accordance with approved procedures and applicable laws.
Data Breach Management
In the unlikely event of a data breach, a clearly defined incident response plan is promptly activated -
- The incident shall be promptly investigated;
- Appropriate containment and remediation measures shall be implemented;
- Impact assessments shall be conducted;
- Affected individuals and competent authorities shall be notified where required by law within prescribed timelines;
- Corrective and preventive actions shall be implemented.
Where required by applicable law or contractual obligations, relevant information regarding processors and sub-processors engaged for processing personal data shall be made available to the concerned individuals or customers
Data Principals/subject right
The company believes that privacy rights should be accessible and actionable.
Data principals/subjects have the right to know what data the company holds about them, request correction or deletions, and to request data transfer either with their consent or for the purpose of fulfilling a contract or statutory obligation-to another organization. Additionally, data principals/subjects ,in line with procedure established by law, may withdraw their consent at any time; however, this will not impact the legality of any data processing carried out prior to the withdrawal. Depending on the applicable law, individuals may have rights relating to their personal data, including access to information, correction of inaccurate data, deletion or erasure where applicable, withdrawal of consent, objection or restriction of processing where applicable, data portability where applicable, grievance redressal, and nomination of another individual where permitted by law. The availability and scope of these rights shall be subject to applicable laws, exemptions, and limitations.
As a Data Principal/subject right, you may (where applicable):
- Request access to personal data held by Strides;
- Obtain information regarding processing activities;
- Request correction of inaccurate or incomplete information;
- Request deletion of personal data;
- Request restriction of processing;
- Object to processing where permitted by law;
- Withdraw consent;
- Request transfer of personal data to themselves or another service provider in a structured, commonly used, and machine-readable format where applicable and feasible;
- Nominate another individual to exercise rights on their behalf where permitted by law;
- Lodge complaints regarding privacy practices.
Requests shall generally be processed without charge unless permitted otherwise under applicable law.
Privacy Training and Awareness
Strides conducts periodic privacy, data protection, cybersecurity, and confidentiality training and awareness programmes for employees and relevant third parties to support effective implementation of this Policy.
Strides monitors compliance with this Policy through periodic reviews and assessments.
To uphold our commitment towards data protection, company commits to conduct internal and independent audits periodically.
Findings arising from such reviews shall be addressed through corrective and preventive actions.
Violations and Disciplinary Actions
Violation of this Policy may result in corrective actions, disciplinary measures up to and including termination of employment or contractual engagement, recovery of damages where appropriate, and legal or regulatory action.
Strides maintains a zero-tolerance approach towards intentional misuse, unauthorized disclosure, or unlawful processing of personal data.
Contact and Grievance Redressal
Questions, concerns, complaints, or requests relating to privacy and personal data may be directed to:
Data Protection Officer (DPO)
Ms. Tintu Varghese
Email: dataprotection@strides.com
All privacy-related complaints and requests shall be investigated and addressed within timelines prescribed by applicable laws.
Periodic Review
This Policy shall be reviewed at least annually and whenever required due to changes in applicable laws, regulations, organizational structure, technologies, business operations, or industry best practices. Revisions shall be documented, approved, communicated, and incorporated into relevant training and awareness programmes.
Glossary of Key Terms
Term | Definition |
|---|---|
Consent | Freely given, informed, and unambiguous agreement by the data subject / data principal for the processing of their personal data |
Cookies | Small data files stored on a user’s device by websites to remember preference or track activity for analytics and performance |
Cross-Border Data Transfer | The transfer of personal data outside the country where it was originally collected, subject to applicable privacy safeguards |
Data Breach | Any unauthorized access, disclosure, or loss of personal data. It requires notification and remediation under applicable laws |
Data Controller | The entity (in this case Strides) that determines how and why personal data is processed |
Data Processor | A third party/entity /person (such as vendors, service providers) that processes personal data on behalf of the data controller |
Data Protection Officer (DPO) | The designated individual responsible for ensuring compliance with data protection obligations and addressing privacy-related queries or concerns |
Data Subject | Any individual whose personal data is collected or processed (such as patients, employees, healthcare professionals) |
Personal Data | Information that identifies or can be used to identify an individual, such as name, email address, contact information, health records and IP address |
Right to access/erasure | The data subject’s right to request access to their data or request its deletion under applicable laws |
Web beacon | Tiny graphics embedded in emails or web pages used to monitor user interactions at the website for the purpose of web analytics |