Legal
Privacy Policy
How we collect, use, retain, and protect personal data — for healthcare professionals, partners, and visitors to this website.
Last updated: 31 July 2026
1. Who we are
Oculentis Medical Pvt. Ltd. (“Oculentis”, “we”, “us”, “our”) is a private limited company headquartered at:
501-A, Pinnacle Corporate Park, 5th Floor. Nr. Trade Center, BKC, Bandra (E), Mumbai - 400051 India
We manufacture, supply, and distribute ophthalmic pharmaceutical products — sterile eye drops across anti-infective, lubricant, anti-glaucoma, anti-allergic and NSAID therapy areas, plus an eye-nutrition nutraceutical — to healthcare professionals, hospitals, clinics, and authorised distributors across India. Oculentis serves the Indian market only.
For the purposes of applicable data protection law, Oculentis is:
- a “Data Fiduciary” under India's Digital Personal Data Protection Act, 2023 (“DPDP Act”);
- a “person or entity” bound by the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“IT Act / SPDI Rules”);
- a “data controller” under the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) where we process personal data of individuals in the European Economic Area (EEA), the UK, or Switzerland in connection with offering goods or services to them.
2. What personal data we collect
This website is intended for healthcare professionals (“HCPs”), procurement personnel, and business partners. We do not knowingly collect personal data from patients or from anyone under 18 years of age.
We collect the following categories of personal data:
2.1 Data you give us directly
| Source | Data collected | Purpose |
|---|---|---|
| Contact form | Name, professional email, phone number, hospital/clinic/organisation name, role/designation, country, message content | Responding to your enquiry; routing to the correct regional team |
| Product sample / catalogue request | Name, work email, phone, organisation, speciality, country, professional registration number (where requested to verify HCP status) | Verifying professional status; fulfilling the request; legitimate follow-up |
| Distributor / partner application | Contact person details, company details, business registration and licence numbers, markets served, references | Evaluating and onboarding distribution partners; regulatory due diligence |
| Adverse event / product complaint report | Reporter name, profession, contact details, and any information you include about the event (see Section 9) | Legal and regulatory obligations for pharmacovigilance and product quality complaint handling |
| Email correspondence | Your email address and the contents of emails you send us | Handling your enquiry |
| Webinar / event registration (if offered) | Name, email, organisation, role | Administering the event; attendance records |
Please do not send us patient-identifiable information (patient names, IDs, images, case numbers) through website forms. Our adverse-event form is designed to capture de-identified information only.
2.2 Data collected automatically
| Category | Examples | Tooling |
|---|---|---|
| Technical data | IP address (truncated where configured), browser type, device type, operating system, referring URL, pages visited, timestamps | Web server logs; content delivery network |
| Analytics data | Pseudonymised usage statistics, page interactions, session duration, approximate geography (country level) | Google Analytics 4 (“GA4”) via Google Tag Manager (“GTM”) — loaded only with consent where required |
| Behaviour/UX data | Heatmaps, scroll depth, anonymised session recordings | Hotjar — loaded only with consent where required |
| Marketing data | LinkedIn member interactions with our content/ads | LinkedIn Insight Tag — loaded only with consent where required |
See our Cookie Policy for the full cookie table and how to control these.
2.3 Data we receive from third parties
- Analytics and advertising platforms (aggregated/pseudonymised reports, per your consent settings).
- Distributors or event organisers who introduce you to us (with your knowledge).
- Public professional registries, where used solely to verify that an applicant is a licensed medical practitioner or licensed business.
3. Lawful bases for processing
We process personal data only where a lawful basis applies:
| Law | Bases we rely on |
|---|---|
| DPDP Act 2023 (India) | Consent — for form submissions, sample requests, marketing communications, and non-essential cookies (you may withdraw consent at any time, as easily as you gave it). Legitimate uses under s 7 — e.g., where you voluntarily provide data for a specified purpose and have not objected, and for compliance with law. Note: DPDP Rules 2025 are being phased in; we will update this policy as commencement notifications take effect. |
| IT Act 2000 / SPDI Rules (India) | Consent for collection of “sensitive personal data or information”; reasonable security practices (see Section 8); this published policy satisfies the Rule 4 requirement to make a privacy policy available. |
| GDPR (EEA/UK/CH visitors) | Art. 6(1)(a) consent (analytics/marketing cookies; marketing emails); Art. 6(1)(b) contract or pre-contractual steps (responding to enquiries, sample/catalogue requests); Art. 6(1)(c) legal obligation (adverse-event and complaint records under applicable pharmacovigilance obligations); Art. 6(1)(f) legitimate interests (B2B relationship management, site security, fraud prevention — balancing tests documented internally). |
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
4. How we use your data
- To respond to enquiries and provide requested product information, IFUs, catalogues, and samples.
- To verify HCP or business status where content or products are restricted to professionals.
- To evaluate and manage distributor and commercial relationships.
- To meet pharmacovigilance, complaint-handling, and record-keeping obligations in India, where our products are supplied.
- To operate, secure, and improve the website (with consent where required).
- To send you professional communications (product updates, event invitations) only where you have opted in or where law permits B2B communication — every message includes an unsubscribe option.
5. Retention
| Record type | Retention period |
|---|---|
| General enquiries | Up to 24 months after last contact, then deleted or anonymised |
| Sample/catalogue requests and HCP verification records | Duration of the business relationship + 3 years |
| Distributor applications | If unsuccessful: 12 months. If onboarded: duration of agreement + period required by contract and law |
| Adverse-event, complaint, and vigilance records | As required by applicable pharmacovigilance and drugs regulations in India — typically no less than 10 years; statutory periods may vary |
| Analytics data (GA4) | 14 months (configured), then automatically deleted |
| Server/security logs | 12 months |
| Marketing consents | Until withdrawn, plus an auditable record of consent/withdrawal for 3 years |
When data is no longer needed we delete or irreversibly anonymise it, consistent with the storage-limitation principles of the DPDP Act, GDPR, and the APPs.
6. Cross-border transfers
We are headquartered in India and use service providers whose infrastructure may be located in India, Singapore, the EEA, or the United States.
- India (DPDP Act): We transfer personal data outside India only as permitted by the DPDP Act and any government notifications restricting transfers to specified countries.
- EEA/UK/CH (GDPR): Where we transfer EEA personal data to a country without an adequacy decision, we use appropriate safeguards, typically the European Commission's Standard Contractual Clauses (Module 2), plus supplementary measures where required. Copies of relevant safeguards are available on request.
- Our distributors and regional partners receive only the data necessary to fulfil your request and are bound by confidentiality and data-protection obligations.
7. Your rights
Depending on your location, you have some or all of the following rights:
All users: withdraw consent at any time (without affecting prior lawful processing); opt out of marketing at any time via the unsubscribe link or by emailing us.
India (DPDP Act / IT Act): access a summary of your personal data and processing activities; correct, complete, update, or erase your personal data; grievance redressal through our designated officer; nominate a person to exercise your rights in the event of death or incapacity.
EEA/UK/CH (GDPR): access; rectification; erasure; restriction of processing; data portability; objection to processing based on legitimate interests or for direct marketing; lodge a complaint with your local supervisory authority.
To exercise any right, email privacy@oculentismedical.com or write to the address in Section 1, marked “Privacy”. We will respond within the statutory timeframe applicable to you — in practice within 30 days (one month under GDPR; grievance-acknowledgement timelines under DPDP Rules once notified). We may need to verify your identity before acting.
8. Security
We apply reasonable security practices and procedures consistent with the SPDI Rules and industry standards, including: TLS encryption in transit, access controls and least-privilege permissions, vendor due diligence, audit logging, and breach-response procedures. If a personal data breach occurs, we will notify affected individuals and the relevant authority where required (e.g., the Data Protection Board of India and affected Data Principals under the DPDP Act; the lead supervisory authority within 72 hours under GDPR where applicable).
No method of transmission over the internet is 100% secure; we encourage you to report suspected security issues to privacy@oculentismedical.com.
9. Special note: adverse-event and complaint data
Reports submitted through our adverse-event channel are processed under legal-obligation and public-interest bases (GDPR Art. 6(1)(c)/9(2)(i) where applicable), and shared with regulatory authorities in India (e.g., CDSCO and the Pharmacovigilance Programme of India) as required by law. Reporter identities are kept confidential to the extent the law allows. Please do not include patient-identifying details; if we receive them inadvertently, we will redact them before further processing.
10. Cookies
We use strictly necessary cookies and, with your consent, analytics and marketing cookies. Full details, the cookie table, and instructions for changing your consent at any time are in our Cookie Policy.
11. Third-party links and social media
Our site may link to third-party sites (e.g., LinkedIn, Instagram, regulator databases). Their privacy practices are governed by their own policies; we are not responsible for them.
12. Children
This website is a professional B2B resource. It is not directed at children, and we do not knowingly collect data from anyone under 18. If you believe a child has provided us data, contact us and we will delete it.
13. Grievance Officer (India) and contact
Grievance / Privacy Contact
Oculentis Medical Pvt. Ltd.
501-A, Pinnacle Corporate Park, 5th Floor. Nr. Trade Center, BKC, Bandra (E), Mumbai - 400051 India
Email: privacy@oculentismedical.com
The name and designation of our Grievance Officer, as required by the SPDI Rules, are available on request via the contact details above.
14. Changes to this policy
We may update this policy from time to time. The version and effective date will change, and material changes will be flagged on this page. Prior versions are available on request.