GDPR Compliance Policy - SaziBox Health
Data Protection Regulation

SaziBox Health GDPR Compliance Policy

Regulation: EU GDPR (Regulation 2016/679) Controller: SaziBox Health Last Updated: 2026

1. Introduction

Welcome to SaziBox Health. We are committed to upholding the highest standards of data privacy, confidentiality, and institutional data governance. This policy articulates how we collect, process, store, and safeguard personal and clinical telemetry data in full compliance with the General Data Protection Regulation (GDPR - Regulation EU 2016/679).

2. Data Controller Identification

SaziBox Health serves as the designated Data Controller responsible for determining the purposes and means of processing your personal data.

Designated Controller Entity: SaziBox Health

Official Inquiries: info@saziboxfam.com

Registered Office: 137, Green Castle, A1, First Floor, House 5A Rd 136, Dhaka 1212

3. Categories of Personal Data Collected

Contact Information

Full Name, Professional / Institutional Email Address, Phone Number, WhatsApp touchpoint, and Organization.

Clinical & Research Data

Protocol abstracts, statistical parameters, and study datasets submitted strictly under Mutual NDA covenants.

Usage & Technical Telemetry

IP Address, browser environment, referral logs, latency statistics, and session duration data.

4. Legal Grounds for Data Processing

Under Article 6 of the GDPR, SaziBox Health processes personal data relying upon the following lawful bases:

Article 6(1)(a)

Explicit Consent

You have provided unambiguous consent for consultation assessment or newsletter communications.

Article 6(1)(b)

Contractual Duty

Processing is required to execute research advisory agreements, biostatistics, or manuscript audits.

Article 6(1)(c)

Legal Obligation

Processing is necessary to comply with statutory accounting and regulatory transparency mandates.

Article 6(1)(f)

Legitimate Interests

Required to protect infrastructure against cyber threats and optimize research portal response times.

5. Processing, Security & Data Retention

  • Data Purpose: We use your data to evaluate clinical studies, deliver biostatistical solutions, and communicate securely.
  • Zero Commercial Data Sale: We never sell, monetize, or broker personal research data. Third-party infrastructure providers are bound by strict Data Processing Agreements (DPAs).
  • Security Standards: We enforce AES 256-bit encryption, role-based access tokens, SSL/TLS transport layer security, and periodic vulnerability audits.
  • Data Retention & Deletion: Research records are retained only for the duration of the engagement or statutory limitation periods, after which they are irreversibly anonymized or expunged.

9. Your Statutory GDPR Rights

As a data subject under GDPR, you possess the following enforceable rights regarding your information:

1. Right to Access (Article 15)

Request confirmation and an electronic copy of all personal records we hold concerning you.

2. Right to Rectification (Article 16)

Require prompt correction of incomplete, inaccurate, or outdated contact and research profile data.

3. Right to Erasure / Forgotten (Article 17)

Request the permanent deletion of your personal records where no overriding legal obligation exists.

4. Right to Restrict Processing (Article 18)

Request the temporary freezing of data processing during verification of contestation disputes.

5. Right to Data Portability (Article 20)

Receive your provided data in a structured, commonly used, and machine-readable format (JSON/CSV).

6. Right to Object (Article 21)

Object at any time to the processing of your personal information based on legitimate interest.

7. Right to Withdraw Consent (Article 7)

Revoke previously granted consent without impacting the lawfulness of past processing.

11. Exercise Your GDPR Rights or Contact DPO

To submit a Subject Access Request (SAR) or exercise any statutory GDPR rights, contact our Data Protection desk directly.

137, Green Castle, A1, First Floor, House 5A Rd 136, Dhaka 1212
Submit Official GDPR Request