Privacy policy
PRIVACY POLICY
This Privacy Policy (“Policy”) explains how B‑Arm Medical Technologies Private Limited (“B‑Arm”, “we”, “us”, “our”) collects, uses, discloses, and protects personal data when you access or use our website located at b‑arm.com and any associated mobile applications, products, or services (collectively, the “B‑Arm Site / Platform” or “Services”).
This Privacy Policy is formulated to comply with the following statutory requirements, among other applicable laws and regulations, as amended from time to time, to the extent they apply to B‑Arm.:
● Section 43A of the Information Technology Act, 2000;
● Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”);
● The principles of data protection embodied under the Digital Personal Data Protection Act, 2023.
By accessing or using the B‑Arm Site / Platform or Services, you agree to be bound by this Policy. If you do not agree to this Policy, please do not access or use the B‑Arm Site / Platform or Services.
- DEFINITIONS
For the purposes of this Policy:
● “Personal Information” / “Personal Data” means any information relating to an identified or identifiable individual and includes “personal information” as defined under the SPDI Rules and “personal data” under the DPDP Act.
● “Sensitive Personal Data or Information” (“SPDI”) has the meaning given in Rule 3 of the SPDI Rules and may include, as applicable:
○ Passwords;
○ Financial information (such as bank account or credit card details);
○ Physical, physiological and mental health condition;
○ Medical records and history;
○ Biometric information;
○ Any detail relating to the above as provided to us for providing services; and
○ Any of the above information received, stored, or processed by us.
● “Data Principal” means the individual to whom the personal data relates.
● “Data Fiduciary” means any person who alone or in conjunction with other persons determines the purpose and means of processing personal data (for most processing activities on the B‑Arm Site / Platform, B‑Arm is the Data Fiduciary).
- APPLICABILITY
This Policy applies to all users (“you”, “your”) who access or use the B‑Arm Site / Platform or otherwise interact with us in connection with our Services, including customers, visitors, vendors, partners, and any other individuals whose personal data we process.
This Policy is to be read together with and forms an integral part of the Terms of Use, and any other applicable terms, notices, or agreements that govern your relationship with B‑Arm.
- CATEGORIES OF INFORMATION WE COLLECT
We may collect and process the following categories of information:
3.1 Information You Provide to Us
This includes information you provide directly when you:
● Create or update your B‑Arm account (e.g., name, email address, mobile number, postal address, date of birth, login name and password, profile details).
● Place orders or use our Services (e.g., delivery address, payment or billing information, special instructions).
● Provide content to B‑Arm, which may include reviews, feedback, queries, support requests, or other content (“Your Content”).
● Participate in surveys, promotions, contests, or other interactive features.
● Communicate with us via email, phone, chat, or other channels.
● If you sign up as a partner or service provider, we may collect additional information such as government‑issued identification, business registration details, GST information, and address/location details.
Where required, we will clearly indicate which information is mandatory and which is optional. You may choose not to provide personal information or withdraw consent; however, this may prevent us from providing some or all Services.
3.2 Sensitive Personal Data or Information (SPDI)
In limited cases, we may process SPDI such as:
● Financial information (e.g., payment card or bank details) to facilitate payments.
● Health‑related information or medical records and complaint data where necessary for the purpose of providing the Services, complying with legal/regulatory requirements, addressing product‑related queries, adverse events, post-market surveillance, product safety monitoring, vigilance reporting, recalls and compliance with medical device regulations.
We will only collect SPDI where it is strictly necessary for a lawful purpose connected with our functions or activities and after obtaining your consent where required under applicable law.
3.3 Information We Collect Automatically
When you access or use the B‑Arm Site / Platform, we may automatically collect certain information, including:
● Usage information, such as pages viewed, features used, search queries, time and date of visits, referring URLs, and navigation paths.
● Device and technical information, such as IP address, browser type and version, time zone setting, operating system, device type, device identifiers, and mobile network information.
● Location information, where you permit us to access location services, either approximate (via IP) or precise (e.g., GPS data).
Some of this information may be collected using cookies and similar technologies (see Section 6 below).
3.4 Information from Third Parties
We may receive information about you from:
● Our partners, payment service providers, logistics / delivery partners, and other service providers.
● Social media platforms or other accounts you use to sign in or connect with the B‑Arm Site / Platform (subject to your privacy settings on those platforms).
● Marketing and analytics providers, who may provide aggregated or interest‑based information.
● Other users (for example, referrals, feedback about a service provider, or shared content).
Where we receive information from third parties, we will process such information in accordance with this Policy and applicable law.
- LEGAL BASIS AND PURPOSES OF PROCESSING
4.1 Legal Basis
We process your personal data based on one or more of the following legal bases (as applicable):
● Your consent, where required under the SPDI Rules and DPDP Act, particularly for processing SPDI and certain marketing activities.
● Performance of a contract or taking steps at your request prior to entering into a contract (for example, to provide our Services).
● Compliance with legal obligations, including tax, accounting, regulatory, and consumer protection laws.
● Legitimate uses under DPDP, such as improving our Services, preventing fraud and misuse, network and information security, and ensuring business continuity, provided these interests are not overridden by your rights.
4.2 Purposes of Processing
We may use your information for the following purposes:
● To provide, operate, and maintain the B‑Arm Site / Platform and Services, including order processing, delivery, payment processing, customer support, and other related activities.
● To personalise and improve your experience, including remembering your preferences, recommending products, and tailoring content and offers.
● To communicate with you, including sending service‑related communications (such as order confirmations, security alerts, technical notices, updates, and administrative messages).
● To conduct analytics, research, and statistical analysis to understand usage patterns, improve performance, and develop new features and Services.
● To ensure the security and integrity of our systems and Services, prevent fraud, detect and respond to security incidents, and manage risks.
● To comply with applicable laws, regulations, and legal processes, respond to lawful requests and orders from authorities, and protect our rights, property, and safety and that of our users and others.
● To send you marketing communications, promotions, surveys, and information about products and services that may be of interest to you, where permitted by law and subject to your choices.
● For any other purpose that we specifically disclose to you at the time of collection or for which we obtain your consent.
- CONSENT, WITHDRAWAL, AND CHOICES
Where required under the SPDI Rules or DPDP Act, we will obtain consent before collecting or processing your SPDI or before using personal data for specified purposes (such as marketing).
You may withdraw your consent for certain processing activities at any time by contacting us using the details in Section 13 below or by using available settings in your account or device. Please note that withdrawal of consent:
● Does not affect the lawfulness of processing based on consent before its withdrawal; and
● May limit or prevent your use of some or all Services if such processing is essential for providing the Services.
You may also manage your communication preferences (e.g., opt‑out of marketing emails or SMS) by using unsubscribe links or by contacting us.
- COOKIES AND SIMILAR TECHNOLOGIES
We may use cookies, pixel tags, web beacons, and other similar technologies (“Cookies”) to:
● Recognise you on subsequent visits.
● Understand and save your preferences.
● Analyse site traffic and usage patterns.
● Improve the performance, security, and functionality of the B‑Arm Site / Platform.
● Provide and measure advertisements, where applicable.
You can manage your cookie preferences through your browser or device settings. If you disable Cookies, some features of the B‑Arm Site / Platform may not function properly. For further details, please refer to our Cookie Policy (if any), which should be read along with this Policy.
- DISCLOSURE AND SHARING OF YOUR INFORMATION
We may share your information with the following categories of recipients, strictly on a need‑to‑know basis and for the purposes described in this Policy:
● Service providers and vendors: For example, payment processors, cloud hosting providers, IT and security service providers, analytics providers, communication service providers, and customer support partners.
● Logistics and delivery partners: To fulfil orders and provide delivery updates.
● Business and channel partners: For facilitating services you request, handling returns or recalls, or providing value‑added services.
● Group companies and affiliates: For internal administrative, operational, and business purposes, subject to appropriate safeguards.
● Legal, regulatory, and enforcement authorities: When we believe disclosure is required or appropriate to comply with law, legal process, or lawful requests, or to protect our rights, property, or safety or that of others.
● Business transfers: In connection with any merger, acquisition, sale of assets, financing, or similar transaction involving all or a part of our business, in which case personal data may be transferred as a business asset, subject to confidentiality obligations and applicable laws.
● With your consent: We may share your information for any other purpose disclosed to you and with your consent.
We do not sell your personal data to third parties.
- CROSS‑BORDER TRANSFERS
Your personal data may be stored and processed in India or in other jurisdictions where our or our service providers’ servers and facilities are located, subject to applicable law.
Where cross‑border transfers are undertaken, we will ensure that such transfers comply with applicable requirements under Indian law, including the SPDI Rules and DPDP Act (for example, by implementing contractual safeguards where required). The availability of cross‑border transfers may change depending on future rules/notifications under the DPDP Act.
- DATA SECURITY
In compliance with Rule 8 of the SPDI Rules, we maintain policies governing access management, incident response, vendor management, business continuity and risk management. We implement reasonable security practices and procedures to protect personal data and SPDI from unauthorised access, use, alteration, disclosure, or destruction. These may include, as appropriate:
● Administrative safeguards, such as policies, procedures, access controls, and user awareness and training.
● Technical safeguards, such as encryption, secure configuration, firewalls, access logging and monitoring, multi‑factor authentication (where applicable), and regular security updates.
● Physical safeguards, such as controlled access to facilities and secure storage of documents and media.
We endeavour to align our information security policies with recognised standards such as ISO/IEC 27001, on a risk‑based and proportionate basis.
While we strive to use commercially acceptable means to protect your data, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security. The security of your information also depends on your protection of your account credentials and your use of secure networks. Please do not share your account password or other authentication credentials with others and notify us promptly of any suspected unauthorised use of your account.
- DATA RETENTION
We retain your personal data for as long as necessary to fulfil the purposes for which it was collected or as required by applicable law, including:
● For the duration of your account and reasonable periods thereafter for business, legal, accounting, or reporting purposes.
● As necessary to comply with legal obligations, resolve disputes, and enforce our agreements.
When personal data is no longer required, we will delete, anonymise, or securely dispose of it, subject to any legal retention obligations.
- YOUR RIGHTS
Subject to applicable law, you may have the following rights in relation to your personal data:
● Right to access: To obtain confirmation whether we process your personal data and to request a copy.
● Right to correction: To request correction or updating of inaccurate or incomplete personal data.
● Right to withdraw consent: To withdraw consent for processing where processing is based on your consent, without affecting the lawfulness of processing before withdrawal.
● Right to grievance redressal: To raise concerns or complaints regarding processing of your personal data and to seek redressal within prescribed timelines.
● Other rights that may be notified under the DPDP Act and related rules from time to time.
To exercise these rights, please contact us using the details provided in Section 13 below. We may take reasonable steps to verify your identity before processing your request and may decline or limit requests as permitted by law.
- CHILDREN’S PRIVACY
The B‑Arm Site / Platform and Services are not intended for use by children below the age prescribed under applicable law without parental/guardian consent. We do not knowingly collect personal data from children without such legally valid consent.
If you are a parent or guardian and believe that your child has provided personal data to us without appropriate consent, please contact us using the details in Section 13, and we will take steps to delete such information as required by law.
If a Hospital inputs data regarding a minor, they represent that they have obtained verifiable parental consent as per the DPDP Act.
- GRIEVANCE OFFICER / DATA PROTECTION CONTACT
In accordance with the SPDI Rules and the DPDP Act, the details of the Grievance Officer / Data Protection Contact are as follows:
Name: Mr. Babu Krishnan
Designation: Grievance Officer / Data Protection Contact
Address: 2C, 35-36 GKD Nagar, Pappanaickenpalayam, Coimbatore, Tamil Nadu, India, 641037.
Email: info@barmenterprises.com
Phone: +91 9818172173
If you have questions, requests, or complaints regarding this Policy, our handling of your personal data, or any privacy‑related issues, you may contact the above officer. We will endeavour to acknowledge and respond to your concerns within the timelines specified under applicable law. If you are not satisfied with our response, you may have the right to approach the Data Protection Board of India as permitted by applicable law.
- THIRD‑PARTY SITES AND SERVICES
The B‑Arm Site / Platform may contain links to or integrations with third‑party websites, applications, or services that are not operated or controlled by B‑Arm. This Policy does not apply to such third‑party sites or services.
We are not responsible for the privacy practices, content, or security of any third‑party sites or services. We encourage you to review the privacy policies applicable to those third parties before providing your personal data to them.
- CHANGES TO THIS POLICY
We may update or modify this Policy from time to time to reflect changes in our practices, legal requirements, or other operational reasons. When we do so, where required by law, we will notify you through appropriate channels (for example, by posting a notice on the B‑Arm Site / Platform or via email).
To the extent permitted under applicable law, your continued use of the B‑Arm Site / Platform or Services after such changes become effective will constitute your acceptance of the updated Policy. We encourage you to review this Policy periodically.
