Privacy Notice

This privacy notice (“Privacy Notice”) under The Digital Personal Data Protection Act, 2023 (“Act”) describes how Sumptuous Data Sciences Private Limited (CIN-U72200PN2019PTC224948) , a company based out of Sr. No. 137, H No. 1, Marvel Fuego, A Wing, Off. No. 7070, Magarpatta Road, Hadapsar, Pune, Pune City, Maharashtra, India, 411028 (hereinafter referred to as “we”, “us” “our” “Sumptuous Data Sciences India”) collect, use, and disclose information pertaining to its customers, users, visitors (hereinafter referred to as “you”, “your”, “User”) obtained via any method including this website and any mobile application or tool (“Website”).

Please read the following to learn about our practice of category and the purposes of Personal Data, including Digital Personal Data to be processed, secure collection, use, disclosure and dissemination of information practices, the contact details of the relevant Data Protection Officer, the manner in which the Data Principal can make a complaint to the Board, the manner in which a Data Principal can exercise its rights under Act which includes the right to withdraw its consent for processing of Personal Data and right to grievance redressal.
By visiting this Website or by virtue of any commercial relation (“Services”), you agree to be bound by the terms and conditions of this Privacy Notice. If you disagree, please do not use or access our Website or Services. This Privacy Notice is incorporated into and subject to our Terms of Use (“Terms of Use”).

1) Consent

By using the Website or Services and/ or by providing your information, you consent to the collection and use of the information you disclose on the Website or during the term of the commercial contract in accordance with this Privacy Notice, including but not limited to your consent for sharing your information as per this Privacy Notice.
If you disclose any personal information relating to other people to us, you represent that you have the authority to do so and to permit us to use the information in accordance with this Privacy Notice.

2) Amendment

Our Privacy Notice is subject to change at any time without notice. Please review this Privacy Notice periodically to ensure you are aware of any changes.

3) Definition

a) “Board” means the Data Protection Board of India established by the Central Government;
b) “Child” means an individual who has not completed the age of eighteen years;
c) “Consent Manager” means a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform;
d) “Data” means a representation of information, facts, concepts, opinions or instructions in a manner suitable for communication, interpretation or processing by human beings or by automated means;
e) “Data Fiduciary” means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data;
f) “Data Principal” means the individual to whom the personal data relates and where such individual is— (i) a child, includes the parents or lawful guardian of such a child; (ii) a person with disability, includes her lawful guardian, acting on her behalf;
g) “Data Processor” means any person who processes personal data on behalf of a Data Fiduciary;
h) “Digital Personal Data” means personal data in digital form;
i) “Person” includes— (i) an individual; (ii) a Hindu undivided family; (iii) a company; (iv) a firm; (v) an association of persons or a body of individuals, whether incorporated or not; (vi) the State; and (vii) every artificial juristic person, not falling within any of the preceding sub-clauses;
j) “Personal Data” means any data about an individual who is identifiable by or in relation to such data;
k) “Personal Data Breach” means any unauthorized processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data;
l) “Processing” in relation to personal data, means a wholly or partly automated operation or set of operations performed on digital personal data, and includes operations such as collection, recording, organization, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction;

4) What is the status of Sumptuous Data India?

The below list shows the role and status of Sumptuous Data India for collecting from multiple channels and persons;

Category Status
Employee’s Personal Data Data Fiduciary
Vendor’s Personal Data Data Fiduciary
Customer’s Personal Data Data Fiduciary
Data Provided by Customer’s to provide services Data Processor
Visitor’s (Online and Offline) Data Fiduciary

5) Collection of Personal Data, including Digital Personal Data, by Sumptuous Data India

Sumptuous Data India collects Personal Data in digital form to run business activities and render services.
The following table explains the types of data we collect and the legal basis on which this data is processed:

PurposeData (key element)Basis
To analyse the data received as a result of clinical trials with good clinical practice and applicable laws.Legitimate interests – Our legitimate interest is in analysing Clinical and healthcare data to test potential treatments and deliver effective Services to our B2B Customers.
Subscribing to email updates, participating in surveys and request for services.Name, age, contact details, preferences, etc., through surveys and forms; information about whether you are eligible for any affirmative action programmes or policies; and information about the services that you use and how you use them, including log information and location information, when you use the services through the Platform.Consent – where you have given your active consent.
Job Applications and employeesName, address, date of birth, employment history, medical history, PAN, Aadhaar, CV, salary details, bank account details, etcLegitimate interests- conducting the hiring process and giving employment is necessary.
Website functionalityWebsite activity collected through cookiesLegitimate interests
– it is necessary for us to store a small amount of information, usually through cookies, to deliver the functionality you would expect, such as remembering the contents you shared earlier.
Visitors/usersIdentity, IP addresses, time spent on website, browser and device of the user.Legitimate interests- to provide better user experience.

6) How we use your data?

We will only use your data in a manner appropriate considering the basis on which it was collected, as set out in the table at the top of this Privacy Notice.

For example, we may use your personal information to:
a) To operate our business and deliver effective Services.
b) To improve our Site and enable us to provide you with the most user-friendly experience which is safe, smooth and customized;
c) Providing our services and products to you;
d) To improve and customize our services, content and other commercial/non-commercial features on the Site;
e) To send you information on our products, services, special deals, and promotions;
f) To ask you to send feedback on any or all of our services;
g) To send you alerts and marketing/promotional communications (If you do not wish to receive such marketing/promotional communications from us you may indicate your preferences at the time of registration or by following the instructions provided on the Site or by providing instructions to this effect);
h) To create various surveys and analyses in form of reports;
i) To send you service-related announcements on rare occasions when it is necessary to do so;
j) To provide customer support and the services you request; Ascertain how many people visit our Site, of what kind and what areas they visit on our Site;
k) To resolve disputes, if any and troubleshooting;
l) To avoid/check illegal and/or potentially prohibited activities and to enforce Agreements
m) To comply with any court judgment/decree/order / directive / legal & government authority /applicable law;
n) To investigate potential violations or applicable national & international laws;
o) To investigate deliberate damage to the Site/services or its legitimate operation;
p) To Detect, prevent, or otherwise address security and/or technical issues;
q) To protect the rights, property or safety of Sumptuous Data and/or its Directors, employees and the general public at large;
r) To respond to Claims of third parties;
s) To provide joint services, contents and marketing communications to the members of our corporate family and group, affiliates, service providers and third parties under a contract;
t) To send the information to other third parties to whom you explicitly require us;

7) How long we keep your Data?

We take the principles of data minimization and removal seriously and have internal policies in place to ensure that we only ever ask for the minimum amount of data for the associated purpose and delete that data promptly once it is no longer required.
Any Person who does business in India is required to comply with multiple other laws related to employment, taxation, and bookkeeping. We determine the data retention tenure by considering the requirements of these laws. We generally keep data for 10 years from the date of its collection.

8) How do we secure your Personal Data?

Your Personal Data and project data files are stored on our servers and the dedicated servers of companies we hire to provide us with processing and storage services. Sumptuous Data India continuously evaluates threat and vulnerability data to understand cyber-security risk further. Sumptuous Data India may adjust its approach to defend your data further based on available information. Sumptuous Data India takes precautions, including industry-standard administrative, technical, and physical measures that are designed to safeguard the personal information collected from visitors and customers against loss, theft, misuse, unauthorized access, disclosure, alteration, and destruction. These technologies are designed to protect the confidentiality of your Personal Data when transmitted over the internet.

9) How we share your personal information

We may share your Personal Data with national and/or international parties, authorities, and companies as may be required.
Within Group Companies Sumptuous Data may disclose your personal data amongst and between each other for the purposes set forth in this Privacy Notice.
Business Partners We may disclose your personal information to our business partners to offer their services.
Service Providers We may employ third-party companies and individuals to administer and provide the Service on our behalf (such as hosting events & webinars, email delivery and database management services). These third parties are permitted to use your personal information only to perform these tasks in a manner consistent with this Privacy Notice. They are obligated not to disclose or use it for any other purpose.
Payment gateway We may share your payment information to process your payments.
Professional advisors We may disclose your personal information to professional advisors, such as lawyers, bankers, auditors, insurers, and data analysts, where necessary in the course of the professional services they render to us.
Law Enforcement Agencies; Protection and Safety We may disclose your personal information as we believe appropriate to government or law enforcement officials or private parties (a) for the security, compliance, fraud prevention and safety purposes described above; (b) as required by law, lawful requests or legal process, such as to respond to subpoenas or requests from government authorities; (c) where permitted by law in connection with any legal investigation; and (d) to prosecute or defend legal claims.
Court/Government Agencies/Regulatory Authorities We may disclose the information if required to do so by law in order to (for example) respond to a subpoena or request from law enforcement, a court or a government agency, or in the good faith belief that such action is necessary (a) to comply with a legal obligation, (b) to protect or defend our rights, interests or property or that of third parties, (c) to prevent or investigate possible wrongdoing in connection with the services, (d) to act in urgent circumstances to protect the personal safety of customers, their users or the public; or (e) to protect against legal liability.
Website Users From time to time, we may post testimonials on Websites that may contain personal information. We obtain your consent to post Your name along with your testimonial. If you wish to update or delete your testimonial, you can contact us at

Third Parties We may also share personal information with third parties when we have your consent to do so.
Corporate Restructuring If we sell or transfer a business unit (such as a subsidiary) or an asset (such as a website) to another company (including in connection with any bankruptcy or similar proceedings), we will disclose your personal data to such company and will require such company to use and protect your personal data consistent with this Privacy Notice . We may also disclose your personal data to companies that were formerly wholly or partly included in the Sumptuous Data family of companies to whom we provide services during a transition period following separation.
In the Aggregate/De-identified
We may also disclose aggregate or de-identified data that is not personally identifiable to third parties for any purpose permitted under applicable law.

10) Cross Border Transfer

Any Personal Data we collect is stored and processed in India, and where our subsidiaries, partners, affiliates and third-party providers maintain facilities. When you give us your information, you consent to its transfer overseas. Transfers overseas may result in the data you give us being held in jurisdictions that are not subject to similar data privacy laws as ours. Therefore, if a third party engages in acts or practices that would contravene our laws, you may not be able to seek redress.

11) Rights you have over your data.

You have a range of rights over your data, which include the following:
a) right to obtain information on personal data processing by the Data Fiduciary;
b) right to correct, update or erase her personal data;
c) right to nominate someone else in the event of her death or incapacity to exercise her rights; and
d) right to withdraw consent.

12) Grievance Redressal Mechanism

At Sumptuous Data India, we are committed to upholding the rights of Data Principals (users) as outlined in the Act. To ensure transparency, accountability, and trust, we have established a Grievance Redressal Mechanism to address any concerns or grievances raised by Data Principals regarding their personal data.

13) Use of Cookies.

A “cookie” is a small piece of information stored by a Web server on a Web browser so that it can be later read from that browser. Cookies are useful for enabling the browser to remember information specific to a given user. This is done to recognise your device during future visits to our Website, primarily to provide a better user experience.

14) Consequences of Not Providing Personal Data.

If you choose not to provide your Personal Data, which is mandatory to process your request, we may not be able to provide the corresponding experience.

15) Updates to this Privacy Notice.

We may change the privacy practices and update this Privacy Notice as and when the need arises, and the same will be made available on the Website. However, our commitment to protecting users’ privacy will remain.

16) Applicable Laws.

Any dispute arising out of or concerning this Privacy Notice shall be governed by the laws of the Republic of India, and the courts of Pune, India, shall retain exclusive jurisdiction to entertain any proceedings in relation to any disputes arising out of the same.

17) Consent Manager and Grievance Officer.

Name- Mr. Swapnil Nisal