NORION

How we handle your personal data

This notice explains what personal data NTHRYS Biotech Labs collects, why, how we use and protect it, how long we keep it, and the rights available to you under the Digital Personal Data Protection Act 2023 and the Information Technology Act 2000.

Last updated 3 August 2026 ยท Issued by NTHRYS Biotech Labs ยท GSTIN 37AGDPC3092P1Z4

01

Who is responsible

The data fiduciary in respect of your data.

NTHRYS Biotech Labs is the data fiduciary in respect of the personal data described in this notice. We determine the purposes and means of processing and are accountable for compliance.

Registered nameNTHRYS Biotech Labs
GSTIN37AGDPC3092P1Z4
ConstitutionProprietorship
JurisdictionIndia
Registered officeFlat 201, Plot No 140, Street No 22, Telecom Nagar Extension, Gachibowli, Hyderabad, 500032, India
Trading nameNTHRYS
Contactsmo@nthrys.com

Data protection enquiries should be addressed to smo@nthrys.com.

02

Data we collect

What we hold, and where it comes from.

Data you provide

  • Identity data โ€” name, title, and where relevant your institution, department or employer.
  • Contact data โ€” electronic mail address, telephone number, postal address.
  • Account data โ€” username, password in hashed form, account preferences.
  • Order data โ€” services purchased, mode and duration selected, scheduling preferences, order references.
  • Academic data โ€” where relevant to the service, your programme of study, level, institution and prior experience.
  • Correspondence โ€” enquiries, support requests, complaints and our replies.

Data generated automatically

  • Technical data โ€” internet protocol address, browser type and version, device and operating system, time zone.
  • Usage data โ€” pages viewed, navigation paths, features used, duration of visits.

Data we do not hold

We do not receive, process or store full payment card details. Card data is captured and processed by Razorpay. We receive only a transaction reference, the result, and the last four digits of the card for reconciliation.

We do not deliberately collect sensitive personal data. Where you disclose such data in correspondence โ€” for example a health condition relevant to attendance arrangements โ€” we process it only so far as necessary and on the basis of your explicit consent.

03

Purposes and basis of processing

Why we process, and the ground for each purpose.
Creating and administering your accountNecessary for the service you have requested
Accepting and fulfilling ordersNecessary for performance of the contract
Delivering services and issuing certificationNecessary for performance of the contract
Responding to enquiries and support requestsLegitimate use in responding to you
Handling complaintsLegitimate use; legal obligation where applicable
Maintaining accounting and tax recordsLegal obligation
Preventing fraud and securing the platformLegitimate use
Analytics and service improvementConsent, given through the cookie banner
Marketing communicationsConsent

Where processing is based on consent, that consent may be withdrawn at any time as set out below.

04

Sharing and recipients

Who else may receive your data.

We share personal data only where necessary and under appropriate safeguards. Recipients fall into the following categories:

  • Payment service providers โ€” to process payments and manage refunds and chargebacks.
  • Hosting and infrastructure providers โ€” who store data on our behalf.
  • Electronic mail and communication providers โ€” to deliver transactional and support correspondence.
  • Analytics providers โ€” where you have consented, as described in the cookie policy.
  • Professional advisers โ€” accountants, auditors and lawyers, where required.
  • Public authorities โ€” where we are under a legal obligation to disclose.

Where a recipient processes data on our behalf, a written contract requires the processing to be carried out only on our documented instructions and subject to appropriate technical and organisational measures.

We do not sell personal data, and we do not share it with third parties for their own marketing purposes.

05

Transfers outside India

Where data may be processed abroad.

Certain infrastructure and communication providers used in delivering the platform operate outside India. Personal data may therefore be processed outside India in the course of providing a service you have purchased.

Such transfers are made only to jurisdictions not restricted by the Central Government, and under contractual arrangements requiring standards of protection equivalent to those applied here.

06

Retention

How long we keep data, and why.
Account and profile dataFor the life of the account, then 12 months after closure.
Order and transaction records6 years from the end of the accounting period, as required by law.
Certification recordsRetained indefinitely, so that certification can be verified on request.
Correspondence and supportThree years from the date of the last exchange.
Complaint records6 years from resolution.
Marketing consentsUntil withdrawn, and a record of the withdrawal thereafter.
Analytics data26 months from collection.

At the end of a retention period data is deleted or anonymised so that it can no longer be associated with you.

07

Your rights

What you may require us to do, and how.

Subject to the conditions set out in applicable law, you have the right to:

  • Access a summary of the personal data we hold about you and the processing undertaken.
  • Correction of inaccurate or misleading data, and completion of incomplete data.
  • Erasure of data no longer necessary for the purpose for which it was collected.
  • Nominate another individual to exercise your rights in the event of death or incapacity.
  • Withdraw consent at any time, where processing is based on consent.
  • Grievance redressal in respect of any act or omission regarding your data.

To exercise a right, write to smo@nthrys.com. We will respond within one month. That period may be extended where a request is complex, and we will tell you within one month if that is the case.

Grievance redressal. Grievances concerning the handling of your personal data should be addressed to smo@nthrys.com and will be acknowledged within 5 working days. Where a grievance remains unresolved you may escalate it to the Data Protection Board of India.

08

Security

Measures taken to protect your data.

We apply technical and organisational measures appropriate to the risk, including encryption of data in transit, hashed storage of credentials, access control on a least-privilege basis, logging of administrative access, and segregation of production data from development environments.

No transmission over the internet can be guaranteed entirely secure. Where a personal data breach occurs we will notify the Data Protection Board of India and affected individuals without undue delay, as required by law.

09

Cookies and changes

Related material and amendment of this notice.

Cookies and similar technologies are addressed separately in the cookie policy, which sets out the categories used, their purpose and duration, and how consent may be given or withdrawn.

We may amend this notice to reflect changes in our processing, in the services we provide or in applicable law. The date at the head of this page indicates when it was last revised. Where a change is material we will notify registered account holders directly.

NTHRYS is a trading name of NTHRYS Biotech Labs.