Data Privacy Policy

Civaq Life Care LLP

Version: 1.0

Effective Date: June 25, 2026

Last Updated: June 25, 2026


1. Purpose

Civaq Life Care LLP ("Civaq", "we", "our", or "us") is committed to protecting the privacy, confidentiality, integrity, and security of personal information and business data.

This Data Privacy Policy establishes the principles and standards governing the collection, use, storage, processing, sharing, retention, and protection of personal information and confidential business information handled by Civaq.

The purpose of this Policy is to:

  • Protect the personal information of customers, employees, vendors, partners, and other stakeholders.

  • Ensure responsible handling of personal and business data.

  • Comply with applicable laws and regulations, including the Digital Personal Data Protection Act, 2023 (DPDP Act), where applicable.

  • Reduce the risk of unauthorized access, misuse, disclosure, loss, or alteration of data.

  • Promote a culture of privacy and information security throughout the organization.


2. Scope

This Data Privacy Policy applies to all individuals and entities that collect, access, process, store, transmit, or otherwise handle information on behalf of Civaq Life Care LLP, including:

  • Directors and Designated Partners

  • Employees

  • Consultants

  • Interns

  • Contractors

  • Vendors

  • Third-party service providers

  • Business partners

  • Temporary staff

  • Any other individual or organization authorized to access Civaq information

This Policy applies to all personal information, confidential business information, financial information, operational data, digital records, paper records, and any other information created, received, stored, or processed by or on behalf of Civaq.


3. Privacy Principles

Civaq Life Care LLP is committed to the following privacy principles:

  • Lawfulness: Personal information shall be collected and processed only for lawful purposes.

  • Purpose Limitation: Personal information shall be used only for the purposes for which it was collected or as otherwise permitted by applicable law.

  • Data Minimization: Only the personal information necessary for legitimate business purposes shall be collected and processed.

  • Accuracy: Reasonable efforts shall be made to ensure that personal information is accurate, complete, and kept up to date.

  • Security: Appropriate administrative, technical, and physical safeguards shall be implemented to protect personal information from unauthorized access, disclosure, alteration, or destruction.

  • Confidentiality: Access to personal information shall be restricted to authorized personnel with a legitimate business need.

  • Accountability: Individuals handling personal information are responsible for complying with this Policy and applicable privacy laws.

  • Retention Limitation: Personal information shall be retained only for as long as necessary to fulfil legitimate business, contractual, and legal obligations.


4. Information Covered by This Policy

This Policy applies to all information collected, created, received, stored, processed, or transmitted by or on behalf of Civaq Life Care LLP, including but not limited to:

  • Customer information

  • Employee information

  • Vendor and supplier information

  • Business partner information

  • Financial and accounting records

  • Product formulation and research data

  • Manufacturing and quality records

  • Marketing and sales information

  • Website and e-commerce data

  • Payment and transaction records

  • Intellectual property

  • Contracts and legal documents

  • Internal communications

  • Business strategies and confidential information

  • Any other information classified as confidential by Civaq

This Policy applies regardless of whether the information is stored electronically, in physical documents, cloud-based systems, email, portable devices, or any other storage medium.


5. Roles and Responsibilities

Management

Management shall:

  • Promote a culture of privacy and data protection.

  • Ensure appropriate policies, procedures, and safeguards are implemented.

  • Review this Policy periodically.

  • Ensure compliance with applicable laws.

Employees and Authorized Personnel

Employees, consultants, contractors, interns, and other authorized personnel shall:

  • Access information only where required for legitimate business purposes.

  • Protect confidential information from unauthorized access or disclosure.

  • Use company information only for authorized business activities.

  • Report any suspected data breach, privacy incident, or unauthorized disclosure immediately.

  • Follow company security procedures when handling information.

Vendors and Third-Party Service Providers

Vendors and service providers handling Civaq information shall:

  • Process information only for authorized purposes.

  • Maintain appropriate technical and organizational security measures.

  • Comply with applicable privacy and confidentiality obligations.

  • Notify Civaq promptly of any actual or suspected data breach affecting company information.


6. Information Security Measures

Civaq Life Care LLP implements appropriate administrative, technical, and physical safeguards to protect personal information and confidential business information against unauthorized access, disclosure, alteration, loss, misuse, or destruction.

These safeguards may include:

  • Role-based access controls

  • Strong password and authentication requirements

  • Encryption of sensitive information where feasible

  • Secure storage of physical and electronic records

  • Regular software updates and security patches

  • Firewalls, antivirus, and endpoint protection

  • Secure backup and disaster recovery procedures

  • Employee awareness and privacy training

  • Monitoring and logging of access to sensitive systems

  • Confidentiality agreements with employees, consultants, and third-party service providers

All individuals handling company information must follow applicable security procedures and report any suspected security incident immediately.


7. Data Retention and Secure Disposal

Civaq Life Care LLP retains personal information and confidential business information only for as long as necessary to fulfil legitimate business purposes, comply with legal and regulatory requirements, enforce contractual obligations, resolve disputes, and protect the Company's legitimate interests.

When information is no longer required, it shall be securely deleted, destroyed, anonymized, or otherwise disposed of using appropriate methods to prevent unauthorized access, recovery, or misuse.

Employees and authorized personnel shall not retain personal or confidential information longer than necessary or outside approved company systems without proper authorization.


8. Data Breach Management

Any actual or suspected data breach, unauthorized access, loss, disclosure, alteration, or misuse of personal information or confidential business information must be reported immediately to the appropriate management personnel.

Upon becoming aware of a potential data breach, Civaq Life Care LLP will:

  • Promptly assess the nature and scope of the incident.

  • Take appropriate measures to contain and mitigate the impact of the incident.

  • Investigate the cause of the breach.

  • Implement corrective actions to reduce the likelihood of recurrence.

  • Notify affected individuals and competent authorities where required by applicable law.

All employees, contractors, consultants, vendors, and other authorized personnel are required to cooperate fully in responding to privacy or security incidents.


9. Policy Compliance and Violations

Compliance with this Data Privacy Policy is mandatory for all individuals and entities covered by this Policy.

Any violation of this Policy may result in disciplinary action, termination of employment or engagement, suspension of access privileges, contractual remedies, legal action, or any other action considered appropriate under applicable law.

Civaq Life Care LLP reserves the right to investigate any suspected violation of this Policy and to take appropriate corrective action where necessary.


10. Policy Review and Updates

Civaq Life Care LLP may review and update this Data Privacy Policy from time to time to reflect changes in applicable laws, business operations, technology, security practices, or regulatory requirements.

The latest version of this Policy shall supersede all previous versions and shall become effective from the date of publication or approval.

All individuals covered by this Policy are responsible for familiarizing themselves with the latest version.


11. Contact and Grievance Officer

If you have any questions regarding this Data Privacy Policy, wish to exercise your privacy rights, or report a privacy concern or suspected data breach, please contact us:

Civaq Life Care LLP

GSTIN: 08AAWFC4394B1Z5
FSSAI Licence No.: 22226067003052

Email: support@civaq.co.in
Phone: +91 91167 95681

Website: https://www.civaq.co.in

Business Hours: Monday–Saturday, 10:00 AM – 6:00 PM IST

Registered Office

2nd Floor, Flat No. 111/56, Kumbha Marg,
Near V-Mart, Navjeevan Hospital,
Pratap Nagar, Jaipur, Rajasthan – 302033, India

We will make reasonable efforts to acknowledge and respond to privacy-related enquiries and complaints within the timelines required by applicable law.


12. Document Control

Document Name: Data Privacy Policy

Version: 1.0

Effective Date: June 25, 2026

Last Updated: June 25, 2026

Policy Owner: Civaq Life Care LLP

Approved By: Management, Civaq Life Care LLP


© 2026 Civaq Life Care LLP. All Rights Reserved.