Privacy Policy - BioSignatures Tech Private Limited
Who We Are
BIOOMICSIGNATURES Tech Private Limited (“BioSignatures,” “we,” “us,” “our”) owns, operates and manages as BioSignatures Tech with the domain name https://biosignaturestech.com (the “Site”). We are a early stage company focused on designing and developing screening and diagnostic panels for neurological disorders. This site is informational at this point and not to be used for any clinical purpose.
Scope
This policy explains how we handle personal data connected to use of the site and direct communications with us (e.g., emails you send). It does not cover clinical or research datasets we work with outside the site; those are handled under Data Use Agreements (DUAs), IRB/ethics approvals, and project-specific SOPs.
Please do not send identifiable patient data via the public website or generic email addresses.
What We Collect
We do not offer account sign-ups, web forms, newsletters, analytics, or advertising cookies at this time.
Our host may generate transient technical logs (e.g., IP address, timestamp, requested URL, user-agent/referrer) strictly for security and reliability. We do not use these logs to profile individuals and we keep them briefly for troubleshooting and abuse prevention.
If you email us, we receive whatever you include (name, email, affiliation, message) and use it solely to respond.
If we later enable forms or analytics, we will update this Policy and, where required, seek consent before any non-essential processing.
Clinical & research collaborations (outside this Policy)
For our work, we handle pseudonymized clinical, imaging, and -omics datasets under DUAs and approved protocols. Standard safeguards include: pseudonymization at the source with key separation; data minimization; isolated compute/pipeline environments; encryption in transit and at rest; least-privilege access; audit logs; vendor due diligence and aggregate reporting with no re-identification attempts.
The binding terms for research data (including participant notices, legal bases, retention, and data access) are always the DUA/SOW/protocol, not this Site Policy.
Why We May Process Data
Operate, secure, and debug the Site (fraud/abuse prevention, reliability).
Respond to your messages and manage ordinary business communications.
Recruitment administration if you apply by email.
Legal compliance (e.g., lawful requests, record-keeping).
Sharing your information
We do not sell personal data. Limited sharing occurs only with:
Hosting & IT/email providers necessary to run the Site and email;
Professional advisors (legal/financial) under confidentiality;
Authorities where required by law.
These providers are contractually bound to confidentiality, appropriate security, and purpose limits.
International handling
Limited Site-related data (e.g., server logs, email routing) may be processed in India, the EEA/UK, or the United States. When international transfers are legally in scope, we use recognized safeguards such as the EU Standard Contractual Clauses and, for UK transfers, the UK Addendum/IDTA, following official guidance
Security
We apply layered controls, including, least-privilege access, multi-factor authentication, encryption in transit and at rest, monitoring and audit logging, backups, and incident response. If a breach affecting you occurs, we will notify you and/or regulators where legally required.
Retention
We keep Site-related data only as long as needed for the purposes above or to meet legal requirements:
Server logs: short rolling cycle (typically ≤30–90 days) unless needed for investigations.
General correspondence: up to 24 months.
Recruitment files (email-based applications): up to 3 months unless hired (then per HR policy).
Minimal records may be kept to demonstrate compliance or resolve disputes.
Research-dataset retention is set by the DUA and may differ.
Your rights
We support the rights afforded by applicable data-protection laws (including GDPR/UK GDPR), such as access, correction, erasure, restriction, objection (to certain processing), portability, and withdrawal of consent where consent is used. Because genomic and health data are special-category information, our research programs operate with appropriate safeguards and due transparency.
How to exercise: email founders@biosignaturestech.com. We may need to verify your identity and will respond within legally required timelines.
Complaints: You may contact your local supervisory authority (e.g., in the UK, the ICO). We appreciate the chance to address concerns first.
Children
The Site is not directed to children under 18. We do not knowingly collect personal data from children via the Site. (Any research involving minors proceeds only under explicit approvals, not via the Site.)
Links to other resources
Our Site may link to third-party websites. Those sites are governed by their own policies. The presence of a link does not imply endorsement.
Changes to this Policy
We will update this Policy if our practices change. The Effective date above shows the latest version.
Contact us
Email: founders@biosignaturestech.com
Postal address: We are currently located at FSID, IISc, Bengaluru, Karnataka ⟮Pincode⟯, India