Document control
- Document
- BSHQ-LGL-001
- Version
- 1.0
- Status
- Published
- Effective
- 24 July 2026
- Last reviewed
- 24 July 2026
- Owner
- Office of Legal & Governance
- Approval
- Board of Directors
- Jurisdiction
- Republic of India
- Classification
- Public
I
Purpose
BioStackHQ is committed to protecting personal information and maintaining appropriate standards for privacy, transparency and responsible information management.
This Policy applies to personal information processed by BioStack HQ through its public websites, communications, events, applications and services, and to information received from authorised representatives, service providers and public sources where applicable.
The responsible owner shall maintain proportionate procedures, records and review arrangements to give effect to this provision. Any exception requires appropriate authority, documentation and, where the risk warrants it, consultation with the Office of Legal & Governance or another competent control function.
Processing is subject to documented purpose limitation, access controls, retention practices, incident-management procedures and review by the Office of Legal & Governance. Where a legal obligation, contractual commitment or individual right requires a different outcome, BioStack HQ will apply that requirement to the extent applicable.
II
Information Collection
Information may be collected when individuals interact with BioStackHQ websites, platforms, publications, forms or services. The nature of information collected depends on the purpose of interaction.
This Policy applies to personal information processed by BioStack HQ through its public websites, communications, events, applications and services, and to information received from authorised representatives, service providers and public sources where applicable.
The responsible owner shall maintain proportionate procedures, records and review arrangements to give effect to this provision. Any exception requires appropriate authority, documentation and, where the risk warrants it, consultation with the Office of Legal & Governance or another competent control function.
Processing is subject to documented purpose limitation, access controls, retention practices, incident-management procedures and review by the Office of Legal & Governance. Where a legal obligation, contractual commitment or individual right requires a different outcome, BioStack HQ will apply that requirement to the extent applicable.
III
Use of Information
Collected information may be used to provide services, respond to enquiries, improve user experience, maintain security and fulfil legitimate organisational requirements.
This Policy applies to personal information processed by BioStack HQ through its public websites, communications, events, applications and services, and to information received from authorised representatives, service providers and public sources where applicable.
The responsible owner shall maintain proportionate procedures, records and review arrangements to give effect to this provision. Any exception requires appropriate authority, documentation and, where the risk warrants it, consultation with the Office of Legal & Governance or another competent control function.
Processing is subject to documented purpose limitation, access controls, retention practices, incident-management procedures and review by the Office of Legal & Governance. Where a legal obligation, contractual commitment or individual right requires a different outcome, BioStack HQ will apply that requirement to the extent applicable.
IV
Information Protection
BioStackHQ implements reasonable administrative, technical and organisational safeguards designed to protect information against unauthorised access, disclosure, alteration or misuse.
This Policy applies to personal information processed by BioStack HQ through its public websites, communications, events, applications and services, and to information received from authorised representatives, service providers and public sources where applicable.
Implementation is risk-based and may differ according to the sensitivity of the activity, the systems involved, the scale of potential harm and the operational context. Control effectiveness is reviewed periodically and following material change, identified weakness or incident.
Processing is subject to documented purpose limitation, access controls, retention practices, incident-management procedures and review by the Office of Legal & Governance. Where a legal obligation, contractual commitment or individual right requires a different outcome, BioStack HQ will apply that requirement to the extent applicable.
V
Individual Rights
Individuals may contact BioStackHQ regarding questions, requests or concerns relating to the handling of their personal information.
This Policy applies to personal information processed by BioStack HQ through its public websites, communications, events, applications and services, and to information received from authorised representatives, service providers and public sources where applicable.
Requests and concerns should include enough information to identify the relevant relationship, record or issue. BioStack HQ may request verification, additional detail or a reasonable extension where permitted, and will respond through the appropriate channel while protecting confidentiality, legal privilege and the rights of others.
Processing is subject to documented purpose limitation, access controls, retention practices, incident-management procedures and review by the Office of Legal & Governance. Where a legal obligation, contractual commitment or individual right requires a different outcome, BioStack HQ will apply that requirement to the extent applicable.
Revision history
- v1.024 July 2026
Initial issue of the Privacy Policy.