Privacy Policy

Effective Date: 01/01/2022  —  Last Updated: 10/07/2025

1 Data Controller Identification

Data Controller: Dawell Lifescience Pvt. Ltd. is the organization determining the purposes and means of processing your personal data. We are a company registered in India.

Registered Address: 1194/27D, Kamala Classic Apartment, Off Ghole Road, Shivaji Nagar, Pune, Maharashtra – 411005, India

We also maintain an office at 5th Floor, Office No. 563, 564, 566, YMCA Tourist Hostel Complex, Gate No. 1, Connaught Place, New Delhi – 110001, India.

Contact Information: If you have any questions, requests, or complaints regarding your personal data or this Privacy Policy, please contact our privacy team at info@dawelllifescience.com . You may also write to us at the postal address above (Attention: Privacy Officer). For EU residents, we will provide an EU representative or Data Protection Officer contact if required by law (please reach out to the email above for details).

2 Types of Data Collected

We collect various categories of personal and technical data through our website, contact forms, demo request forms, and other digital platforms. The types of data we collect include:

Technical Data: When you use our website and Services, we automatically collect certain technical information by electronic means:

We do not intentionally collect any sensitive personal data (also known as special category data) via our website, such as financial information, health data, or passwords, unless necessary for our Services or required by law. Please refrain from submitting any sensitive personal data in free-text fields. If you do provide sensitive data (for example, images or information that might be considered sensitive under applicable law), we will handle it with special care and only use it for the limited purpose for which you provided it.

3 Purpose of Data Collection

We collect and use personal data for the following purposes, which align with Dawell’s mission of empowering public governance, safety, and justice dawelllifescience.com . Each purpose is pursued only to the extent relevant and necessary for that context:

We ensure that all personal data we collect is used only for the purposes stated at the time of collection or compatible purposes. We do not use your personal data for wholly unrelated purposes without your consent. We also limit the data we collect to what is relevant and necessary for each purpose (data minimization). For example, if you only request a product demo, we will not collect or use your data for marketing unless you separately opt in.

4 Legal Basis for Processing

We process personal data under the following legal bases, as permitted by GDPR and the DPDP Act:

Where we rely on consent , you have the right to withdraw that consent at any time, and we will stop the processing that was based on consent. Where we rely on legitimate interests , you have the right to object if you feel your rights outweigh our interests. If you object, we will consider your request and generally cease the contested processing unless we have compelling legitimate grounds or it is needed for legal claims. For legal obligations , public interest , or contractual necessity , your rights to erasure or objection may be limited if the processing is strictly required, but we will inform you of such situations and process your data only to the minimum extent necessary.

5 Cookies and Tracking Technologies

Our website and online Services use cookies and similar tracking technologies to provide functionality, analyze usage, and enhance user experience. When you visit our site, small data files called cookies may be placed on your device. We classify and handle cookies as follows:

Cookie Consent and Opt-Out: When you first visit our website, you will see a cookie notice (banner) if required by law. You can choose to accept or decline non-essential cookies. Once you have given consent, you can withdraw it at any time by clearing cookies or using the opt-out mechanisms described here:

We do not use cookies to collect personally identifiable information without your knowledge, and we do not allow third parties to place cookies for their own advertising purposes via our site. For more details, you can refer to our separate Cookies Policy (if available on our website) which provides a detailed list of cookies and their lifespans. If you have questions about specific cookies or tracking technologies, feel free to contact us.

6 Third-Party Integrations and Data Sharing with Third Parties

Dawell’s digital platforms are integrated with several third-party services to enable certain features and functionality. When you interact with us through these integrations, your data may be shared with or collected by those third parties under their own privacy policies. We carefully vet our partners and ensure that we have appropriate agreements in place (including Data Processing Addendums where required) to protect your data. Below are key third-party integrations we use and how personal data is involved in each:

We will update this section if we add new integrations that affect personal data (for example, a new chat bot, support ticketing system, or any plugin that collects user info).

Important: Except as described in this Policy, we do not share your personal data with any third parties for their own marketing or advertising purposes . We do not sell or rent personal information to data brokers or advertisers. Any data sharing is limited to the third parties above (who act on our behalf or in partnership with us), or as described in Section 10 (legal or strategic disclosures).

7 Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, as outlined in this Policy, or as required by applicable laws and legitimate business requirements. Because our activities involve government projects and public safety initiatives, some data may need to be kept for extended periods to comply with government audit requirements or to support long-running projects, while other data can be disposed of sooner. Our retention practices are as follows:

After the applicable retention period ends, we will securely delete, destroy, or irreversibly anonymize the personal data. We have defined processes for records deletion, and we take care to prevent any unauthorized access during storage or disposal. If deletion is not immediately feasible (e.g., the data is stored in backups), we will isolate the data from active use until deletion is possible.

8 User Rights (Data Subject/Data Principal Rights)

We respect the rights of individuals over their personal data. Depending on whether you are subject to GDPR (e.g., an EU resident) or the DPDP Act (an Indian resident), you are entitled to various privacy rights. We extend these rights to all users where feasible, so that you have control over your personal information. These rights include:

To exercise any of your rights, please contact us at [email protected] with your specific request. We may need to verify your identity to ensure we do not disclose or alter data to the wrong person. This verification might involve confirming information we already have on file or asking for identification (only to the extent permitted by law). We will respond to your request within a reasonable timeframe: under GDPR, typically within 30 days; under DPDP, the timelines will be followed as prescribed (we aim for 15 days for simple requests and up to 30 days for complex cases, subject to change if rules stipulate differently).

Please note that these rights are subject to certain limitations. For example, if fulfilling your request would reveal personal data about another person, we might need to redact or seek consent. Some rights may not apply in full under the DPDP Act until relevant rules are notified (but we will strive to honor them in spirit). Regardless, we will provide clear explanations if we cannot fulfill a request in part or in full, and we'll always try to accommodate your inquiry to the maximum extent possible.

9 Data Security Measures

We take the security of your personal data very seriously. Dawell Lifescience has implemented a range of technical and organizational measures to protect personal data from unauthorized access, alteration, disclosure, or destruction. While no system can be 100% secure, we strive to follow best practices and maintain a high level of security appropriate to the risks. Key security measures in place include:

We want to emphasize that while we use “state-of-the-art” security measures, no method of transmission or storage is completely foolproof . However, we continuously improve our security posture to meet evolving threats. By using security measures like secure and tamper-proof data storage and transmission , we aim to ensure that your data remains confidential and intact. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel your account has been compromised), please immediately notify us at [email protected] so that we can take appropriate action.

10 Data Sharing and Disclosure

We treat your personal data with care and confidentiality. We do not share, sell, or rent personal data to unrelated third parties for their own use. However, there are certain circumstances where we may disclose or share your data with others, as outlined below, always in accordance with applicable law:

No Unauthorized Disclosure: We do not disclose personal data to third parties except as described above. In particular:

If in the future we need to share data in a way not covered by this Policy, we will update the Policy and, if required, obtain your consent or give you a clear opportunity to opt out.

11 International Data Transfers

Dawell Lifescience operates primarily in India, but we also engage with international services and clients (especially in the EU). Personal data we collect may be stored and processed in servers located in India or in other countries where our service providers are based or where we or our partners have a presence. For example, our website hosting or cloud storage might be in the United States or European Economic Area (EEA) , and our CRM provider might process data in the US or other jurisdictions. Additionally, if you are located outside India (such as in the EU), your data will naturally be transferred to our servers in India for us to respond to you.

Cross-Border Transfer under DPDP Act (India): The DPDP Act allows personal data to be transferred outside India to most countries, except any that may be specifically restricted by the Indian government. We will ensure compliance with any future rules on international transfers under the DPDP Act. As of now, we may transfer data to countries such as the United States or member states of the EU, which are not prohibited destinations. We commit that any cross-border transfer of personal data from India will be done in accordance with DPDP Act requirements – for instance, only under a valid contract (such as having our processors bound by strict data protection terms) and not to any country that the Government of India declares as disallowed for data transfers. We also take into account whether the receiving country has adequate data protection standards; even though the DPDP Act uses a blacklist approach, we voluntarily align with global best practices to safeguard data abroad.

Cross-Border Transfer under GDPR (EU): For personal data of individuals in the European Union that we transfer out of the EEA (for example, to India or the US), we will ensure that one of the adequacy or safeguard mechanisms under GDPR is in place. Typically, this means:

Other Jurisdictions: For users in other countries (like UK, which has similar GDPR rules, or countries in Asia-Pacific, etc.), we will similarly ensure compliance with local data transfer laws. For UK, we use the UK International Data Transfer Addendum with SCCs as needed.

We understand that data protection regulations are evolving. If any specific requirement arises (for example, if India implements a whitelisted countries system or the EU updates its transfer frameworks), we will adapt accordingly and update this Policy.

Despite different laws, our approach is to provide a high level of protection no matter where your data is . We hold our partners and ourselves to consistent standards. If data is transferred to our servers in India, we protect it under the robust security measures described in Section 9 and honor the commitments of this Policy. If data is stored in the cloud in the US, we ensure the provider has equivalent protections and contractual commitments.

By using our Services or submitting your information to us, you acknowledge that your personal data may be transferred to and processed in countries other than your own. These countries may have different data protection laws, which might not be as comprehensive as those in your jurisdiction – but we will take steps to ensure that a similar level of data protection is afforded to your information as is provided in your home country.

If you have questions about international data transfers or need more specific details about where your data is stored, please contact us using the details in Section 1.

12 Policy Updates and Communication

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When we update the Policy, we will revise the “Last Updated” date at the top. For significant changes, we will provide a more prominent notice of the update, such as:

Versioning: Each update will be assigned a new version or date. We encourage you to review our Privacy Policy periodically to stay informed about how we are protecting your information. If required by applicable law, we will seek your consent for material changes that broaden how we use personal data (for instance, if we later decide to process your data for a new purpose not covered by this Policy, we would get your consent or give you a chance to opt-out).

Previous Versions: For transparency, upon request we can provide prior versions of this Policy. If you are reading this Policy in a situation where multiple versions exist (e.g., you received a copy via email at the time of your interaction), the version currently on our website is the most current and applicable.

Continued Use: By continuing to use our Services after any changes to this Privacy Policy take effect, you are deemed to have accepted the updated terms (to the extent permitted by law). If you do not agree with any update, you should stop using the Services and may request us to delete your data as per Section 8.

We will not reduce your rights under this Privacy Policy without your explicit consent. If any change would involve using your personal data in a way that is materially different from what was disclosed at the time of collection, we will notify you and obtain consent as needed.

Communication of Changes: In addition to website notifications, if you have an ongoing relationship with us (e.g., you’re a registered user of a pilot platform or you have signed up for updates), we may send you direct communication about the Privacy Policy updates. This could be via email or messaging service, briefly explaining what’s changed and linking to the new Policy.

If you have any questions or concerns about this Privacy Policy or any privacy-related matters, please do not hesitate to contact us at info@dawelllifescience.com . We value your privacy and will respond to your inquiries as soon as reasonably possible.