
This notice explains what personal data NTHRYS Biotech Labs collects, why, how we use and protect it, how long we keep it, and the rights available to you under the Digital Personal Data Protection Act 2023 and the Information Technology Act 2000.
Last updated 3 August 2026 ยท Issued by NTHRYS Biotech Labs ยท GSTIN 37AGDPC3092P1Z4
NTHRYS Biotech Labs is the data fiduciary in respect of the personal data described in this notice. We determine the purposes and means of processing and are accountable for compliance.
| Registered name | NTHRYS Biotech Labs |
|---|---|
| GSTIN | 37AGDPC3092P1Z4 |
| Constitution | Proprietorship |
| Jurisdiction | India |
| Registered office | Flat 201, Plot No 140, Street No 22, Telecom Nagar Extension, Gachibowli, Hyderabad, 500032, India |
| Trading name | NTHRYS |
| Contact | smo@nthrys.com |
Data protection enquiries should be addressed to smo@nthrys.com.
We do not receive, process or store full payment card details. Card data is captured and processed by Razorpay. We receive only a transaction reference, the result, and the last four digits of the card for reconciliation.
We do not deliberately collect sensitive personal data. Where you disclose such data in correspondence โ for example a health condition relevant to attendance arrangements โ we process it only so far as necessary and on the basis of your explicit consent.
| Creating and administering your account | Necessary for the service you have requested |
|---|---|
| Accepting and fulfilling orders | Necessary for performance of the contract |
| Delivering services and issuing certification | Necessary for performance of the contract |
| Responding to enquiries and support requests | Legitimate use in responding to you |
| Handling complaints | Legitimate use; legal obligation where applicable |
| Maintaining accounting and tax records | Legal obligation |
| Preventing fraud and securing the platform | Legitimate use |
| Analytics and service improvement | Consent, given through the cookie banner |
| Marketing communications | Consent |
Where processing is based on consent, that consent may be withdrawn at any time as set out below.
We share personal data only where necessary and under appropriate safeguards. Recipients fall into the following categories:
Where a recipient processes data on our behalf, a written contract requires the processing to be carried out only on our documented instructions and subject to appropriate technical and organisational measures.
We do not sell personal data, and we do not share it with third parties for their own marketing purposes.
Certain infrastructure and communication providers used in delivering the platform operate outside India. Personal data may therefore be processed outside India in the course of providing a service you have purchased.
Such transfers are made only to jurisdictions not restricted by the Central Government, and under contractual arrangements requiring standards of protection equivalent to those applied here.
| Account and profile data | For the life of the account, then 12 months after closure. |
|---|---|
| Order and transaction records | 6 years from the end of the accounting period, as required by law. |
| Certification records | Retained indefinitely, so that certification can be verified on request. |
| Correspondence and support | Three years from the date of the last exchange. |
| Complaint records | 6 years from resolution. |
| Marketing consents | Until withdrawn, and a record of the withdrawal thereafter. |
| Analytics data | 26 months from collection. |
At the end of a retention period data is deleted or anonymised so that it can no longer be associated with you.
Subject to the conditions set out in applicable law, you have the right to:
To exercise a right, write to smo@nthrys.com. We will respond within one month. That period may be extended where a request is complex, and we will tell you within one month if that is the case.
Grievance redressal. Grievances concerning the handling of your personal data should be addressed to smo@nthrys.com and will be acknowledged within 5 working days. Where a grievance remains unresolved you may escalate it to the Data Protection Board of India.
We apply technical and organisational measures appropriate to the risk, including encryption of data in transit, hashed storage of credentials, access control on a least-privilege basis, logging of administrative access, and segregation of production data from development environments.
No transmission over the internet can be guaranteed entirely secure. Where a personal data breach occurs we will notify the Data Protection Board of India and affected individuals without undue delay, as required by law.
Cookies and similar technologies are addressed separately in the cookie policy, which sets out the categories used, their purpose and duration, and how consent may be given or withdrawn.
We may amend this notice to reflect changes in our processing, in the services we provide or in applicable law. The date at the head of this page indicates when it was last revised. Where a change is material we will notify registered account holders directly.