Kolkata Chat with us +91 8017540000 inquiry@somnetics.in
Privacy Policy

How Somnetics collects, uses and protects personal data through this website and our services.

AT A GLANCE

Who we are

Som Imaging Informatics Private Limited (“Somnetics”) is a private company limited by shares, incorporated in India and registered with the Registrar of Companies, Kolkata. Our Corporate Identity Number is U72200WB2011PTC162108 and our registration number is 162108.

How to reach us

  • Registered office: Tower 1, Unit 1904, PS Srijan Corporate Park, Sector V, Kolkata 700091, India.
  • Engineering centre: SDF Building, Module 430, 3rd Floor, Sector V, Kolkata 700091, India.
  • Canada office: 25 McCallum Ct, Brampton, ON L6W 3M4, Canada.
  • Telephone: +91 8017540000 (India) · +1 647-904-6916 (Canada)
  • Email: inquiry@somnetics.in
  • Website: somneticstech.com

For personal data collected through this website and through our services, we act as the data fiduciary under the Digital Personal Data Protection Act 2023 (India) and as the data controller under the UK and EU General Data Protection Regulation. Where we process personal data on behalf of a client under a services agreement, we act as a data processor and that agreement governs.

What this policy covers

This policy covers personal data we collect through somneticstech.com, through the forms on it, through our recruitment process, and through direct correspondence. Our products deployed inside a client environment are governed by the contract with that client, not by this policy.

What we collect
  • Information you give us through a form: name, email address, telephone number, company, subject, message, product of interest, and any file you attach. Our contact form accepts file uploads, so anything you attach is collected.
  • Information you give us when you apply for a role: CV, contact details, and anything else in your application.
  • Information collected automatically: IP address, browser and device type, pages viewed, referring page, and interaction data collected by the analytics and session tools listed in our Cookie Policy.
  • Correspondence: the content of emails and messages you send us.

We do not operate a shop. We take no payments through this website and we do not collect card or payment details on it.

Why we process it, and on what legal basis

Under the GDPR we rely on the bases in the table below. Under the DPDP Act 2023 we rely on your consent, or on a legitimate use permitted by that Act where one applies. Under the UAE PDPL we rely on consent or on a lawful basis permitted by Article 5.

Purposes and lawful bases

Purpose Data used GDPR lawful basis
Answering an enquiry or demo request Form data, attachments, correspondence Legitimate interests - responding to a business enquiry; or steps prior to a contract
Delivering services under a contract Contact and project data Performance of a contract
Recruitment Application data Steps prior to a contract; legitimate interests
Marketing email to an existing contact Name, email Consent, or legitimate interests where permitted - withdrawable at any time
Website analytics and session analysis Cookie and usage data Consent
Security, fraud prevention, access logging IP address, log data Legitimate interests
Meeting legal and regulatory obligations As required Legal obligation
Cookies and analytics

We use cookies and similar technologies. The tools currently running on this site are Google Tag Manager, Google Analytics and Hotjar. Google Analytics tells us how the site is used in aggregate; Hotjar records how visitors interact with individual pages.

Non-essential cookies are set only after you consent through our cookie banner, and you can change or withdraw that consent at any time. Our Cookie Policy lists every cookie, the tool that sets it, its purpose and its duration.

Who we share it with

We do not sell personal data and we do not trade it. We share it with:

  • Service providers who process data on our behalf under written contract. The ones operating on this website are Google, for Tag Manager and Analytics, and Hotjar. Where a project requires others, they are engaged under contract with equivalent obligations. You can request our current sub-processor list at any time from the Grievance Officer in section 13, and we will send it to you.
  • Professional advisers, auditors and insurers, where necessary.
  • Authorities, where we are legally required to disclose.
  • An acquirer, in the event of a merger or sale of the business.

If you contact us on WhatsApp

The “Chat with us” link on this site opens a WhatsApp conversation with our India number. Anything you send there is handled by WhatsApp under its own terms and privacy policy, not this one. If you would rather not use it, email or the contact form reach the same team.

International transfers

We operate from India, with offices and presence in Kolkata, Bangalore, Pune, Guwahati, the USA, Canada, Zambia, the UAE and Australia. Personal data may therefore be transferred outside the country where it was collected.

India is not covered by a European Commission adequacy decision, so transfers of personal data from the EEA to us are made under the European Commission's Standard Contractual Clauses. Transfers from the UK are made under the same clauses together with the UK International Data Transfer Addendum. We apply any supplementary measures a transfer risk assessment identifies. A copy of the clauses we use is available on request from the Grievance Officer in section 13.

How long we keep it

We keep personal data only as long as we need it for the purpose we collected it for, and no longer than the law requires us to keep it. Where we cannot give a fixed period in advance, we set out the criteria we use to decide.

If you ask us to delete your data we will do so, unless we are legally required to keep it. Data removed from our live systems remains in encrypted backups until those backups are overwritten in the normal rotation, after which it is gone.

Retention periods and the criteria behind them

Category How long we keep it What decides that
Enquiry and demo form submissions, including attachments While we are in contact with you about your enquiry, and for 24 months after our last contact. If the enquiry becomes a contract, the record moves to the row below. Long enough to pick up a conversation that pauses, short enough that dormant enquiries do not accumulate.
Client contract and project records For the life of the contract, and for eight financial years after the year in which it ends. The statutory period for keeping books of account under the Companies Act 2013, which is longer than the limitation period for a contract claim.
Tax, GST and statutory filing records containing personal data For the period the relevant tax and companies legislation requires, counted from the end of the financial year concerned. Set by statute, not by us.
Recruitment applications, unsuccessful 12 months from the decision, unless you ask us to delete sooner, or agree to stay on file for future roles. Time to consider you for another opening, and to answer a question about the decision.
Marketing contact records Until you unsubscribe or withdraw consent. We also review the list every 24 months and remove contacts who have not engaged. Consent is the basis, so it ends when consent does.
Website analytics and session data For the retention period configured in each tool, which we set to the shortest option that still allows year-on-year comparison. Configured in Google Analytics and Hotjar. The current settings are listed in our Cookie Policy.
Security and access logs 12 months, unless a specific log is needed for an investigation that is still open. Long enough to investigate an incident found late, short enough not to become a liability itself.
How we protect it

We hold ISO 9001, ISO 27001 and ISO 20000 certification. ISO 27001 in particular means we operate a certified information security management system, audited by an external body, covering access control, risk assessment, incident management, supplier security and staff awareness training.

This website is served over HTTPS, so data you submit through it is encrypted in transit.

We do not publish the detail of our security testing on this page. If you are assessing us as a vendor and need our certification scope, testing regime or a completed security questionnaire, request it from the Grievance Officer in section 13 and we will provide it under the appropriate agreement.

No system is perfectly secure, and we cannot guarantee absolute security.

Your Rights

Depending on where you are, you have some or all of the following rights: to access your data; to have inaccurate data corrected; to have data erased; to restrict or object to processing; to data portability; to withdraw consent at any time without affecting processing already carried out; and to nominate another person to exercise your rights on your behalf in the event of death or incapacity, as provided under the DPDP Act.

To exercise any of these, email our Grievance Officer at tandra.dey@somnetics.in, or use the full contact details in section 13. We acknowledge your request when we receive it and respond within the period the applicable law sets, and in any event no later than one month from receipt. If a request is unusually complex we will tell you before that month is up, explain why, and give you a date.

We do not charge for this, and we will not ask you to justify the request. We may ask for enough information to confirm who you are, so that we do not disclose your data to someone else.

If you are not satisfied with our response, you may complain to the Data Protection Board of India, or to your local supervisory authority in the EEA or the UK, or to the UAE Data Office.

Personal data breaches

If a breach occurs we will notify the relevant supervisory authority and affected individuals within the periods set by the applicable law: under the GDPR, the supervisory authority without undue delay and where feasible within 72 hours; under the DPDP Act 2023, the Data Protection Board and each affected Data Principal in the form and time the Act and its rules require; and under the UAE PDPL as that law requires. We do not apply a fixed period of our own choosing.

Children

This is a business website and it is not directed at children. We do not knowingly collect personal data from a child. Under the DPDP Act 2023 a child is anyone under eighteen, and processing a child’s data requires verifiable parental consent. If you believe a child has given us personal data, contact us & we will delete it.

Contact
Changes to this policy

We update this policy when our processing changes or the law does. The date at the top shows when it last changed. Material changes will be notified on this page before they take effect.