Privacy Policy

Last updated: May 12, 2026

1. Introduction

Elox Tech Private Limited ("Company", "we", "us", or "our") operates the Certiphy platform (certiphy.app) — a cloud-based pharmaceutical compliance and eLogbook management system. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.

2. Information We Collect

2.1 Account Information

When you register, we collect: name, email address, company name, and password (stored in encrypted form).

2.2 Usage Data

We automatically collect: IP addresses, browser type, device information, pages visited, timestamps of actions, and audit trail data generated through platform use.

2.3 Customer Content

Data you enter into the platform including SOP templates, log entries, documents, and any other content created within your company workspace. This data belongs to you.

3. How We Use Your Information

  • To provide, maintain, and improve the Certiphy platform
  • To authenticate users and maintain security
  • To generate audit trails as required for regulatory compliance
  • To send transactional emails (verification, password reset, notifications)
  • To provide customer support
  • To comply with legal obligations

4. Data Ownership & Tenancy

Your company's data is logically isolated from other customers through multi-tenant architecture. Each company's data is accessible only to authorized users within that company. You retain full ownership of all content you create on the platform.

5. Data Security

We implement industry-standard security measures including:

  • Encryption of data in transit (TLS/HTTPS)
  • Encrypted password storage (bcrypt hashing)
  • Multi-factor authentication support
  • Role-based access control
  • Immutable audit logs
  • Regular security updates and monitoring
  • Infrastructure hosted on secure cloud providers

6. Data Retention

We retain your data for as long as your account is active or as needed to provide services. Audit trail data is retained permanently as required for regulatory compliance. Upon account termination, we will provide a data export and delete your data within 90 days, unless retention is required by law.

7. Data Sharing

We do not sell, trade, or rent your personal information. We may share data only in the following circumstances:

  • With your consent
  • To comply with legal obligations or valid legal processes
  • With service providers who assist in operating our platform (hosting, email delivery) under strict confidentiality agreements
  • To protect the rights, property, or safety of Elox Tech Private Limited, our users, or the public

8. Cookies

We use essential cookies for authentication and session management. We do not use third-party tracking cookies or advertising cookies.

9. Your Rights

You have the right to:

  • Access your personal data
  • Request correction of inaccurate data
  • Request deletion of your account (subject to regulatory retention requirements)
  • Export your data in a machine-readable format
  • Withdraw consent for optional communications

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Continued use of the platform after changes constitutes acceptance of the revised policy.

11. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Elox Tech Private Limited

Email: privacy@certiphy.app