Back to top

Privacy Policy

Privacy Policy
Effective Date: 09 June 2025

1. Purpose & Scope

OmniBRx Biotechnologies Private Limited (“OmniBRx”, “we”, “our” or “us”) is committed to protecting the privacy of every individual who interacts with the website www.omnibrx.com (the “Site”). This Privacy Policy explains how we collect, use, disclose, transfer and safeguard Personal Information when you:

  • browse or use the Site;
  • enquire about, purchase or use our single-use bioreactor products or our services; and
  • otherwise communicate or transact with us offline or online.

This Policy is drafted to comply with:

  • the Information Technology Act 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011;
  • the Digital Personal Data Protection Act 2023 (“DPDP Act”) as and when it comes into force;
  • sector-agnostic global standards such as the EU General Data Protection Regulation (“GDPR”), the UK GDPR, and, where applicable, the California Consumer Privacy Act (“CCPA”).

Where these laws confer more protective rights on you, we will apply the higher standard.

2. Definitions

  • “Personal Information” (“PI”) means any information that relates to an identified or identifiable natural person.
  • “Sensitive Personal Data or Information” (“SPDI”) has the meaning set out in the IT (SPDI) Rules 2011 and includes passwords, financial information, health data, biometric data, etc.
  • “Processing” covers any operation performed on PI such as collection, storage, use, disclosure, transfer or deletion.

3. Information We Collect

Category Typical data elements Source Primary purpose
Identity & Contact name, job title, organisation, postal address, email, phone you / employer account set-up, contracts
Transactional purchase history, invoices, shipping details you / logistics partners order fulfilment, warranties
Device & Usage IP address, browser type, referring URLs, pages viewed, clicks, cookies, heat-maps automated means Site performance, analytics
Marketing & Preferences newsletter opt-ins, event registrations, survey responses you tailored communications
SPDI (limited) bank details (for refunds), government ID (if required by law) you payments, statutory compliance

We do not intentionally collect information about children under 18 years.

4. Legal Grounds for Processing

Legal ground Examples
Consent optional newsletters, cookies that are not strictly necessary.
Contractual necessity supplying a product, providing services.
Legitimate interests improving our Site and products, preventing fraud, B2B marketing to existing customers.
Legal obligation tax records, product-safety recalls, mandatory disclosures.

Where we rely on consent you may withdraw it at any time without affecting prior lawful Processing.

5. How We Use Your Information

  • Provide, operate and maintain the Site and our products/services;
  • Respond to enquiries or support requests;
  • Create and manage customer or supplier accounts;
  • Process payments, ship products and provide after-sales service;
  • Conduct quality control, R&D, statistical and market analysis;
  • Send administrative or marketing communications (you can opt-out at any time);
  • Detect, prevent and investigate security incidents or legal violations;
  • Comply with applicable laws, regulations, court orders and enforcement requests.

6. Cookies & Similar Technologies

We use first- and third-party cookies, pixels and device-fingerprinting to:

  • enable core Site functionality;
  • remember your preferences;
  • perform analytics (e.g. Google Analytics);
  • deliver retargeted adverts on LinkedIn or Google Ads.

Non-essential cookies are deployed only after you click “Accept” on our banner. You may change or revoke consent via Cookie Settings in the footer at any time.

7. Sharing & Disclosure

We do not sell your PI. We may share it only:

  • Within OmniBRx – to authorised employees on a need-to-know basis.
  • Service providers – cloud hosting, logistics, payment gateways, CRM, email platforms – bound by written contracts and confidentiality.
  • Business transfers – if we reorganise, merge or sell any part of our business, your data may transfer to new owners subject to this Policy.
  • Legal or regulatory authorities – when required to comply with law, protect rights, safety or enforce contracts.
  • Third-party analytics/advertising partners – only pseudonymised or aggregated data where possible

8. International & Cross-Border Transfers

Our primary servers are located in India; however, some trusted vendors may process data in the EU, United States, or other jurisdictions. Whenever we transfer PI outside India or the originating region we rely on:

  • adequacy decisions (e.g. EU-US Data Privacy Framework);
  • Standard Contractual Clauses plus supplementary safeguards; or
  • your explicit consent where none of the above is available.

9. Data Security

We implement administrative, technical and physical safeguards aligned to ISO/IEC 27001 and the IS 17428 standard, including:

  • encryption in transit (TLS 1.2+) and at rest;
  • role-based access controls and multi-factor authentication;
  • firewalls, intrusion-detection and anti-malware tools;
  • regular vulnerability assessments and employee training;
  • supplier due-diligence and NDAs.

10. Retention

We retain PI only for as long as necessary to fulfil the purposes described above, unless a longer period is required by tax, regulatory or litigation hold obligations. When no longer needed, data is securely deleted or irreversibly anonymised.

11. Your Rights

Depending on your jurisdiction, you may have the right to:

  • access and obtain a copy of your PI;
  • correct inaccurate or incomplete PI;
  • withdraw consent and/or object to certain Processing;
  • request erasure or restriction of Processing;
  • receive PI in a portable format;
  • lodge a complaint with the relevant supervisory authority (e.g. Indian Data Protection Board, EU Data Protection Authority).

To exercise these rights please contact our Grievance Officer (details below). We will verify your identity and respond within the statutory timeframe (currently 30 days under Indian rules).

12. Links to Third-Party Sites

Our Site may contain links or plug-ins to third-party websites (e.g. YouTube, LinkedIn). We do not control and are not responsible for the privacy practices of such sites. Please read their privacy notices before providing any PI.

13. Children’s Privacy

Our products and services are business-to-business and not directed to children. We do not knowingly collect PI from anyone under 18 years. If you believe a minor has provided us PI, please notify us so we can delete it promptly.

14. Changes to This Policy

We may update this Policy periodically. Material changes will be highlighted on the Site or notified via email where appropriate. The “Effective Date” at the top indicates when the latest version became effective.

15. Contact Information & Grievance Redressal

Data Controller / Grievance Officer
Mr. Ravindra Patel
Grievance Officer
OmniBRx Biotechnologies Pvt Ltd.
5, Times Corporate Park, Thaltej-Shilaj Road, Opp. Copper Stone, Thaltej, Ahmedabad, Gujarat 380058, India

Phone: +91 77188 43943
Email: privacy@omnibrx.com (or info@omnibrx.com)

If you are unsatisfied with our response, you may escalate to the Data Protection Board of India or the competent supervisory authority in your jurisdiction.

16. Governing Law & Jurisdiction

This Policy shall be governed by and construed in accordance with the laws of India. Any disputes shall be subject to the exclusive jurisdiction of the competent courts at Ahmedabad, Gujarat, without prejudice to mandatory local consumer or data protection rights.

Your continued use of www.omnibrx.com signifies that you have read, understood and agree to the practices described in this Privacy Policy.