Privacy Policy
Last updated: May 12, 2026
1. Introduction
Elox Tech Private Limited ("Company", "we", "us", or "our") operates the Certiphy platform (certiphy.app) — a cloud-based pharmaceutical compliance and eLogbook management system. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
2. Information We Collect
2.1 Account Information
When you register, we collect: name, email address, company name, and password (stored in encrypted form).
2.2 Usage Data
We automatically collect: IP addresses, browser type, device information, pages visited, timestamps of actions, and audit trail data generated through platform use.
2.3 Customer Content
Data you enter into the platform including SOP templates, log entries, documents, and any other content created within your company workspace. This data belongs to you.
3. How We Use Your Information
- To provide, maintain, and improve the Certiphy platform
- To authenticate users and maintain security
- To generate audit trails as required for regulatory compliance
- To send transactional emails (verification, password reset, notifications)
- To provide customer support
- To comply with legal obligations
4. Data Ownership & Tenancy
Your company's data is logically isolated from other customers through multi-tenant architecture. Each company's data is accessible only to authorized users within that company. You retain full ownership of all content you create on the platform.
5. Data Security
We implement industry-standard security measures including:
- Encryption of data in transit (TLS/HTTPS)
- Encrypted password storage (bcrypt hashing)
- Multi-factor authentication support
- Role-based access control
- Immutable audit logs
- Regular security updates and monitoring
- Infrastructure hosted on secure cloud providers
6. Data Retention
We retain your data for as long as your account is active or as needed to provide services. Audit trail data is retained permanently as required for regulatory compliance. Upon account termination, we will provide a data export and delete your data within 90 days, unless retention is required by law.
7. Data Sharing
We do not sell, trade, or rent your personal information. We may share data only in the following circumstances:
- With your consent
- To comply with legal obligations or valid legal processes
- With service providers who assist in operating our platform (hosting, email delivery) under strict confidentiality agreements
- To protect the rights, property, or safety of Elox Tech Private Limited, our users, or the public
8. Cookies
We use essential cookies for authentication and session management. We do not use third-party tracking cookies or advertising cookies.
9. Your Rights
You have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your account (subject to regulatory retention requirements)
- Export your data in a machine-readable format
- Withdraw consent for optional communications
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Continued use of the platform after changes constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
Elox Tech Private Limited
Email: privacy@certiphy.app