Privacy Policy
We take the privacy of everyone who visits this website and engages with us seriously. This policy explains, in plain language, what personal data we collect, how we use it, and what rights you have — governed by Indian law.
Last updated: October 7, 2026 | Version 1.0
This Privacy Policy ("Policy") is published by Laherika Pvt. Ltd. ("Laherika", "Company", "we", "us", or "our"), a company incorporated under the Companies Act, 2013, with its registered office at Kolkata, India, India. This Policy governs the collection, receipt, storage, use, processing, retention, transfer, and protection of personal data provided to us through this website (the "Site").
By accessing or using this Site, or by submitting any information to us, you acknowledge that you have read, understood, and agree to this Policy. If you do not agree, please do not use the Site or submit any information to us.
1. Legal framework and our role
This Policy is framed in accordance with:
- The Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), notified by the Ministry of Electronics and Information Technology ("MeitY") on 13 November 2025 and being implemented in phases, with full compliance required by 13 May 2027;
- The Information Technology Act, 2000 ("IT Act") and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), which continue to apply until superseded;
- The Health Data Management Policy of the Ayushman Bharat Digital Mission ("ABDM HDMP"), issued by the National Health Authority ("NHA"), which sets the minimum standards for data privacy in the ABDM ecosystem; and
- Other applicable Indian laws.
Under the DPDP Act, we act as a Data Fiduciary in respect of personal data you provide through this Site — meaning we determine the purpose and means of processing that data and are accountable for it. Where we engage service providers to assist with website operations, they act as Data Processors under our instructions.
2. Personal data we collect
We collect only the minimum personal data necessary for the stated purposes. On this website, we collect:
2.1 Data you voluntarily provide
When you submit the "Request a Demo," "Contact," or "Investor Enquiry" form, we collect:
- Full name;
- Professional email address;
- Organisation or institution name;
- Role or designation;
- Phone number; and
- The content of your message.
This is business contact information. We do not treat it as "sensitive personal data" as defined under the SPDI Rules, 2011. Do not submit any health records, patient data, Aadhaar numbers, financial information, or other sensitive personal data through these forms.
2.2 Data collected automatically
Our hosting infrastructure (Hostinger) may automatically log limited technical data including IP address, browser type and version, operating system, pages visited, and date and time of access. This is used solely to maintain the security and functioning of the Site. We do not use this data for profiling or targeted advertising.
2.3 What we do not collect
We do not collect financial data, biometric data, Aadhaar numbers, health records, caste or religious information, or any other sensitive personal data as defined under the SPDI Rules through this website.
3. Purpose and lawful basis for processing
Under the DPDP Act, consent is the primary lawful basis for processing personal data. When you submit a form on this Site, your act of submission constitutes free, specific, informed, and unambiguous consent to the uses described below. You may withdraw this consent at any time by contacting us (see Section 10).
We process your personal data for the following specific purposes only:
- To respond to your enquiry and arrange a demonstration, conversation, or briefing;
- To communicate with you about our platform, services, and developments relevant to your expressed interest;
- To maintain a record of business contacts and engagements for operational purposes;
- To protect, operate, and improve the security and functionality of this Site; and
- To comply with our legal and regulatory obligations under Indian law, including any lawful order of a court or government authority.
We will not process your personal data for any purpose beyond those stated above without obtaining fresh, specific consent from you. Purpose limitation is a core obligation under the DPDP Act, and we treat it as such.
4. How we share personal data
We do not sell, rent, or trade your personal data. We do not share it for advertising. We may share limited personal data only in the following circumstances:
- Data Processors (service providers): We may share data with our hosting provider (Hostinger) and email infrastructure provider, solely to enable the operation of this Site. These parties process data only on our instructions and may not use it for any other purpose. We ensure, through contractual obligations, that they maintain appropriate security safeguards consistent with the DPDP Act and SPDI Rules.
- Professional advisers: We may share information with our legal, financial, or regulatory advisers where strictly necessary and subject to professional confidentiality obligations.
- Legal requirement: We will disclose personal data if required to do so by any applicable law, court order, or lawful direction from a government authority in India, including the Data Protection Board of India once operational.
- Breach of our rights: Where necessary to protect the rights, property, or safety of the Company, our staff, or others.
In all cases, we share only the minimum data necessary for the specific purpose.
5. Data retention and erasure
Under the DPDP Act and SPDI Rules, we must not retain personal data beyond the period necessary for the purpose for which it was collected.
We retain business enquiry data for a period not exceeding three (3) years from the date of last contact or last meaningful interaction, whichever is later, after which it is permanently deleted or irrevocably anonymised. Where a business relationship proceeds to a contractual engagement, data may be retained for the duration of that engagement plus such further period as is required by applicable Indian law (for example, for financial records under the Companies Act, 2013 and Income Tax Act, 1961).
You may request erasure of your enquiry data at any time by writing to us (see Section 10). We will action such requests within the timeframe required by applicable law and will confirm deletion in writing.
6. Security safeguards
Under Section 43A of the IT Act and Rule 8 of the SPDI Rules, and consistent with the DPDP Act and DPDP Rules 2025, we implement reasonable security practices and procedures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration, and destruction. Our measures include:
- Transmission of form data over TLS-encrypted connections;
- Access controls restricting enquiry data to authorised personnel only;
- Secure email infrastructure with authenticated sending protocols; and
- Periodic review of security practices as our operations evolve.
No electronic transmission or storage is perfectly secure. If you become aware of any security concern, please notify us immediately at info@laherika.com.
7. Personal data breach notification
In the event of a personal data breach affecting data you have provided through this Site, we will:
- Notify affected Data Principals (you) without undue delay of the nature and potential consequences of the breach;
- Report the breach to the Data Protection Board of India within 72 hours of becoming aware of it, as required under the DPDP Rules 2025; and
- Take prompt steps to contain, investigate, and remediate the breach.
8. Cross-border data transfers
Our company has operational connections with its technology partners and may engage with service providers whose infrastructure is located outside India. The DPDP Act permits the transfer of personal data outside India subject to the conditions notified by the Central Government from time to time. Where personal data is transferred outside India, we take steps to ensure that the recipient provides a standard of protection at least equivalent to that required under Indian law, through contractual safeguards or otherwise.
As of the date of this Policy, our primary hosting infrastructure is operated by Hostinger. Any cross-border data flows arising from that hosting arrangement are governed by our agreement with that provider. We do not transfer personal data to countries that have been restricted by the Central Government under the DPDP Act.
9. Cookies and tracking
This Site aims to use the minimum cookies necessary for it to function. We do not currently deploy analytics platforms, retargeting pixels, or advertising cookies. If we introduce non-essential cookies in future, we will update this Policy and, where required under applicable law, obtain your specific consent before deploying them. You may control cookies through your browser settings at any time without affecting your ability to access the Site.
10. Your rights as a Data Principal
Under the DPDP Act, 2023, as a Data Principal you have the following rights in respect of personal data we hold about you:
- Right to access: You may request a summary of the personal data we hold about you and information about how it has been processed.
- Right to correction and erasure: You may request correction of inaccurate or incomplete data, or erasure of data we no longer have a lawful basis to retain.
- Right to withdraw consent: You may withdraw consent to processing at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal. To withdraw consent, contact us using the details in Section 11.
- Right to grievance redressal: You may raise a grievance with our Grievance Officer (details in Section 11), and if not resolved to your satisfaction, with the Data Protection Board of India once it is operational and accepting complaints.
- Right to nominate: You may nominate another individual to exercise your rights in the event of your death or incapacity.
Indian residents also retain rights under the SPDI Rules, 2011 (including the right to review and correct sensitive personal data held by us) until those Rules are superseded.
Residents of other jurisdictions (for example, in the European Union or United States) may have additional rights under applicable local law; we will honour such requests to the extent required by applicable law and operationally practicable from India.
11. Grievance Officer and contact
In accordance with the IT Act, 2000 and SPDI Rules, 2011, we have designated the following point of contact for privacy grievances:
We will acknowledge your grievance within 5 business days of receipt and aim to resolve it within 30 days, or as required by applicable law.
12. Children's data
This Site is directed at healthcare institutions, enterprises, investors, and healthcare professionals. It is not directed at children. Under the DPDP Act, a "child" is defined as any person below the age of 18 years. We do not knowingly collect personal data from anyone under 18 through this Site. If you believe a child has submitted data through this Site, please notify us immediately at info@laherika.com and we will delete it promptly.
13. Changes to this Policy
We may update this Policy from time to time to reflect changes in law, our practices, or our services. When we do, we will revise the "Last updated" date above. Where changes are material, we will make them prominent on this page. Your continued use of the Site after any change takes effect constitutes your acknowledgement of the updated Policy. We recommend checking this page periodically.
14. Governing law
This Policy is governed by and construed in accordance with the laws of India. Any disputes arising in connection with this Policy shall be subject to the exclusive jurisdiction of the courts of competent jurisdiction located in Kolkata, West Bengal, India.