How Somnetics collects, uses and protects personal data through this website and our services.
Som Imaging Informatics Private Limited (“Somnetics”) is a private company limited by shares, incorporated in India and registered with the Registrar of Companies, Kolkata. Our Corporate Identity Number is U72200WB2011PTC162108 and our registration number is 162108.
- Registered office: Tower 1, Unit 1904, PS Srijan Corporate Park, Sector V, Kolkata 700091, India.
- Engineering centre: SDF Building, Module 430, 3rd Floor, Sector V, Kolkata 700091, India.
- Canada office: 25 McCallum Ct, Brampton, ON L6W 3M4, Canada.
- Telephone: +91 8017540000 (India) · +1 647-904-6916 (Canada)
- Email: inquiry@somnetics.in
- Website: somneticstech.com
For personal data collected through this website and through our services, we act as the data fiduciary under the Digital Personal Data Protection Act 2023 (India) and as the data controller under the UK and EU General Data Protection Regulation. Where we process personal data on behalf of a client under a services agreement, we act as a data processor and that agreement governs.
This policy covers personal data we collect through somneticstech.com, through the forms on it, through our recruitment process, and through direct correspondence. Our products deployed inside a client environment are governed by the contract with that client, not by this policy.
- Information you give us through a form: name, email address, telephone number, company, subject, message, product of interest, and any file you attach. Our contact form accepts file uploads, so anything you attach is collected.
- Information you give us when you apply for a role: CV, contact details, and anything else in your application.
- Information collected automatically: IP address, browser and device type, pages viewed, referring page, and interaction data collected by the analytics and session tools listed in our Cookie Policy.
- Correspondence: the content of emails and messages you send us.
We do not operate a shop. We take no payments through this website and we do not collect card or payment details on it.
Under the GDPR we rely on the bases in the table below. Under the DPDP Act 2023 we rely on your consent, or on a legitimate use permitted by that Act where one applies. Under the UAE PDPL we rely on consent or on a lawful basis permitted by Article 5.
We operate from India, with offices and presence in Kolkata, Bangalore, Pune, Guwahati, the USA, Canada, Zambia, the UAE and Australia. Personal data may therefore be transferred outside the country where it was collected.
India is not covered by a European Commission adequacy decision, so transfers of personal data from the EEA to us are made under the European Commission's Standard Contractual Clauses. Transfers from the UK are made under the same clauses together with the UK International Data Transfer Addendum. We apply any supplementary measures a transfer risk assessment identifies. A copy of the clauses we use is available on request from the Grievance Officer in section 13.
We keep personal data only as long as we need it for the purpose we collected it for, and no longer than the law requires us to keep it. Where we cannot give a fixed period in advance, we set out the criteria we use to decide.
If you ask us to delete your data we will do so, unless we are legally required to keep it. Data removed from our live systems remains in encrypted backups until those backups are overwritten in the normal rotation, after which it is gone.
We hold ISO 9001, ISO 27001 and ISO 20000 certification. ISO 27001 in particular means we operate a certified information security management system, audited by an external body, covering access control, risk assessment, incident management, supplier security and staff awareness training.
This website is served over HTTPS, so data you submit through it is encrypted in transit.
We do not publish the detail of our security testing on this page. If you are assessing us as a vendor and need our certification scope, testing regime or a completed security questionnaire, request it from the Grievance Officer in section 13 and we will provide it under the appropriate agreement.
No system is perfectly secure, and we cannot guarantee absolute security.
Depending on where you are, you have some or all of the following rights: to access your data; to have inaccurate data corrected; to have data erased; to restrict or object to processing; to data portability; to withdraw consent at any time without affecting processing already carried out; and to nominate another person to exercise your rights on your behalf in the event of death or incapacity, as provided under the DPDP Act.
To exercise any of these, email our Grievance Officer at tandra.dey@somnetics.in, or use the full contact details in section 13. We acknowledge your request when we receive it and respond within the period the applicable law sets, and in any event no later than one month from receipt. If a request is unusually complex we will tell you before that month is up, explain why, and give you a date.
We do not charge for this, and we will not ask you to justify the request. We may ask for enough information to confirm who you are, so that we do not disclose your data to someone else.
If you are not satisfied with our response, you may complain to the Data Protection Board of India, or to your local supervisory authority in the EEA or the UK, or to the UAE Data Office.
If a breach occurs we will notify the relevant supervisory authority and affected individuals within the periods set by the applicable law: under the GDPR, the supervisory authority without undue delay and where feasible within 72 hours; under the DPDP Act 2023, the Data Protection Board and each affected Data Principal in the form and time the Act and its rules require; and under the UAE PDPL as that law requires. We do not apply a fixed period of our own choosing.
This is a business website and it is not directed at children. We do not knowingly collect personal data from a child. Under the DPDP Act 2023 a child is anyone under eighteen, and processing a child’s data requires verifiable parental consent. If you believe a child has given us personal data, contact us & we will delete it.
We update this policy when our processing changes or the law does. The date at the top shows when it last changed. Material changes will be notified on this page before they take effect.