Privacy Policy
Effective Date
Effective as of September 24, 2026.
Overview & Scope
This Privacy Policy describes how SICORG LLP (LLPIN: ADA-6373, "we," "us," or "our") processes personal information that we collect through our digital or online properties, website, social media pages, marketing activities, and live events (collectively, the "Service").
Registered Office: B/201 Deep Jyoti Apartment, Nalasopara East, Mumbai – 401209, Maharashtra, India.
SICORG LLP provides an AI-native ERP and operational intelligence platform for pharmaceutical operations and regulated high-growth enterprise manufacturing. This Privacy Policy does not apply to information that we process on behalf of our business customers while providing our platform to them, which is governed by our enterprise master services agreements with those entities.
Global Privacy & Cookie Consent Framework (GDPR, DPDP, CCPA, Australia)
SICORG LLP provides transparent, multi-jurisdiction privacy consent management across all digital touchpoints:
- Privacy Consent & Notice: We process enterprise credentials, plant operation logs, and organizational records to maintain secure audit trails and support AI-native ERP services.
- Granular Cookie Control: Users can manage preferences via our interactive consent center for Necessary Cookies (Required for 21 CFR Part 11 audit logs & auth), Performance & Analytics (Google Analytics & Tag Manager), and Matchmaking & Advisory Alerts.
- Multi-Region Compliance: Designed in accordance with European Union GDPR (EU 2016/679), UK GDPR, India Digital Personal Data Protection (DPDP) Act 2023, United States CCPA/CPRA (California), and Australia Privacy Act 1988 (Cth).
Personal Information We Collect
Information you provide to us through the Service includes:
- Contact Data: First and last name, salutation, email address, billing and mailing addresses, professional title, company name, plant location, and phone number.
- Demographic Data: City, state, country of residence, postal code, and pharmaceutical industry segment (API, Formulation, Contract Manufacturing).
- Communications Data: Messages, enquiry details, and exchanges when you contact us through the Service or communicate with us via support channels or social media.
- Transactional Data: Information needed to complete enterprise subscription orders, invoice metrics, and transaction history.
- Marketing Data: Your preferences for receiving marketing communications and details about your engagement with them.
- Compliance & Verification Data: Enterprise authorization documents and security contact details.
Third-Party Sources & Automatic Data Collection
We may combine personal information we receive from you with data obtained from public sources (government agencies, public records, regulatory filings) and partners (industry associations, co-sponsors).
Automatic Data Collection: We, our service providers, and our analytics partners automatically log device and activity information over time:
- Device Data: Operating system type and version, browser type, screen resolution, IP address, unique identifiers, and location metrics.
- Online Activity Data: Pages viewed, time spent on pages, navigation paths, access times, and interaction logs.
Tracking Technologies (Google Analytics & Google Tag Manager)
Cookies and Tracking Technologies: Some of our automatic collection is facilitated by essential cookies, web beacons, and analytical scripts.
We utilize Google Cookies, Google Analytics, and Google Tag Manager (including measurement container IDs GTM-WWNM6MQP and G-3DV3L35YS1) to measure website traffic, analyze user interaction patterns, monitor site performance, and improve platform security.
Google Analytics processes device identifiers and browser interaction metrics. You can learn more about Google Analytics and opt out or modify cookie preferences at any time via our Cookie Preferences link in the website footer or by visiting: https://tools.google.com/dlpage/gaoptout
India Digital Personal Data Protection (DPDP) Act 2023 Compliance
As an Indian LLP, SICORG LLP strictly complies with the Digital Personal Data Protection Act, 2023 (DPDP Act):
- Data Principal Rights: You have the right to access summary information, seek correction or erasure of personal data, and nominate representatives.
- Lawful Basis: Personal data is processed under legitimate business use or explicit consent obtained via transparent notice.
- Data Fiduciary Accountability: We implement technical & organizational data security safeguards and store personal data within compliant data centers.
- Penalties Notice: Non-compliance under DPDP Act 2023 attracts statutory penalties of up to INR 250 crore per breach instance.
How We Use Your Personal Information
We process personal information for the following business purposes:
- Service Delivery & Operations: Providing the Service, enabling plant security features, sending administrative updates, audit notifications, and customer support messages.
- Service Personalization: Tailoring module workflows to user roles (QA/QC, Auditor, Plant Manager).
- Service Improvement & Analytics: Analyzing aggregated usage trends, evaluating system resilience, and optimizing platform performance.
- Marketing & Advisory: Sending relevant regulatory updates, compliance whitepapers, and software feature notifications.
- Compliance & Legal Protection: Fulfilling statutory requirements under Indian IT Act 2000, IT Rules 2021, and CDSCO Schedule M guidelines.
Retention of Personal Data
We retain personal information for the period necessary to fulfill the purposes outlined in this policy, including statutory record-keeping under CDSCO, tax, and corporate laws in India.
When personal data is no longer required for business or legal compliance, it is securely deleted, anonymized, or isolated from processing.
How We Share Personal Information
We may share personal information with:
- Corporate Partners & Affiliates: Controlled entities or partners supporting deployment.
- Infrastructure & Hosting Service Providers: Cloud infrastructure providers (AWS / Azure India region datacenters), customer support platforms, and security monitoring tools.
- Professional Advisors: Legal counsel, statutory auditors, and regulatory consultants.
- Regulatory & Statutory Authorities: Law enforcement or statutory bodies when mandated by applicable law.
Google API Services User Data Policy: SICORG LLP's use and transfer of information received from Google APIs adheres strictly to Google API Services User Data Policy, including Limited Use requirements. We do not use user data for advertising, nor sell it or use it to train generalized AI models.
Notice to European & Global Users (GDPR, CCPA & Australia)
For individuals located in the European Economic Area (EEA), United Kingdom (UK), United States (California), or Australia:
Data Controller: SICORG LLP (legal@sicorg.com)
Legal Bases for Processing: Contractual necessity, statutory compliance, legitimate interests in secure platform operation, and explicit consent where required. You maintain rights to access, rectification, erasure, restriction, and portability under GDPR, CCPA/CPRA, and Australia Privacy Act 1988.
Contact Us
If you have questions or concerns regarding this Privacy Policy, please contact our Data Protection Officer:
Entity: SICORG LLP (LLPIN: ADA-6373) Address: B/201 Deep Jyoti Apartment, Nalasopara East, Mumbai – 401209, Maharashtra, India Website: https://www.sicorg.com Email: support@sicorg.com
