Taj Pharma operates a data-protection framework aligned with GDPR principles and applicable local law (including the DPDP Act 2023 in India).
1. Principles #
- Lawfulness, fairness, transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
2. Data Scope #
| Category | Examples | Retention |
|---|---|---|
| B2B contacts | Distributor, tender, regulator contacts | Relationship + 3-10 years |
| Pharmacovigilance | ICSR content | 10+ years |
| Website analytics | IP (anonymised where applicable), visits | Up to 24 months |
| Customer audits | Audit reports, CAPA | 10 years |
3. Security Measures #
- HTTPS/TLS in transit
- Role-based access controls
- Audit logging
- Regular backup / DR testing
- Vendor due diligence and DPAs
- Staff training
4. Rights #
Access, rectification, erasure (where not required for regulatory retention), restriction, portability, objection. Email privacy@tajpharma.com.
5. International Transfers #
SCCs or equivalent safeguards.
6. Breach Notification #
Notification to supervisory authority and (where required) data subjects per applicable law timeframes.
7. Sub-Processors #
Vetted sub-processors under written agreements. Current list available to B2B customers on request.