SaziBox Health GDPR Compliance Policy
1. Introduction
Welcome to SaziBox Health. We are committed to upholding the highest standards of data privacy, confidentiality, and institutional data governance. This policy articulates how we collect, process, store, and safeguard personal and clinical telemetry data in full compliance with the General Data Protection Regulation (GDPR - Regulation EU 2016/679).
2. Data Controller Identification
SaziBox Health serves as the designated Data Controller responsible for determining the purposes and means of processing your personal data.
Designated Controller Entity: SaziBox Health
Official Inquiries: info@saziboxfam.com
Registered Office: 137, Green Castle, A1, First Floor, House 5A Rd 136, Dhaka 1212
3. Categories of Personal Data Collected
Contact Information
Full Name, Professional / Institutional Email Address, Phone Number, WhatsApp touchpoint, and Organization.
Clinical & Research Data
Protocol abstracts, statistical parameters, and study datasets submitted strictly under Mutual NDA covenants.
Usage & Technical Telemetry
IP Address, browser environment, referral logs, latency statistics, and session duration data.
4. Legal Grounds for Data Processing
Under Article 6 of the GDPR, SaziBox Health processes personal data relying upon the following lawful bases:
Explicit Consent
You have provided unambiguous consent for consultation assessment or newsletter communications.
Contractual Duty
Processing is required to execute research advisory agreements, biostatistics, or manuscript audits.
Legal Obligation
Processing is necessary to comply with statutory accounting and regulatory transparency mandates.
Legitimate Interests
Required to protect infrastructure against cyber threats and optimize research portal response times.
5. Processing, Security & Data Retention
- Data Purpose: We use your data to evaluate clinical studies, deliver biostatistical solutions, and communicate securely.
- Zero Commercial Data Sale: We never sell, monetize, or broker personal research data. Third-party infrastructure providers are bound by strict Data Processing Agreements (DPAs).
- Security Standards: We enforce AES 256-bit encryption, role-based access tokens, SSL/TLS transport layer security, and periodic vulnerability audits.
- Data Retention & Deletion: Research records are retained only for the duration of the engagement or statutory limitation periods, after which they are irreversibly anonymized or expunged.
9. Your Statutory GDPR Rights
As a data subject under GDPR, you possess the following enforceable rights regarding your information:
Request confirmation and an electronic copy of all personal records we hold concerning you.
Require prompt correction of incomplete, inaccurate, or outdated contact and research profile data.
Request the permanent deletion of your personal records where no overriding legal obligation exists.
Request the temporary freezing of data processing during verification of contestation disputes.
Receive your provided data in a structured, commonly used, and machine-readable format (JSON/CSV).
Object at any time to the processing of your personal information based on legitimate interest.
Revoke previously granted consent without impacting the lawfulness of past processing.
11. Exercise Your GDPR Rights or Contact DPO
To submit a Subject Access Request (SAR) or exercise any statutory GDPR rights, contact our Data Protection desk directly.
