1. Overview
The National Health Supply Chain Council (“NHSCC,” “we,” “us,” or “our”) is committed to protecting the privacy and personal information of our members, website visitors, event participants, and all individuals who interact with our services. This Privacy Policy explains our practices regarding the collection, use, disclosure, and safeguarding of your information when you visit our website, register as a member, attend our events, or use any of our services.
NHSCC is a not-for-profit organization registered in India. We operate in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and applicable provisions of the Digital Personal Data Protection Act, 2023 (DPDPA) as they come into effect.
By using our website or services, you consent to the data practices described in this policy. If you do not agree, please discontinue use of our services.
2. Information We Collect
2.1 Information You Provide Directly
- Registration Data: Name, email address, phone number, password, current professional experience/designation, organization name, and organization type when you create a member account.
- Profile Information: Any additional details you choose to add to your member profile, including professional bio, LinkedIn profile URL, and profile photograph.
- Event Registration: Information submitted when registering for NHSCC events, workshops, webinars, or summits, including dietary preferences or accessibility requirements.
- Communications: Content of emails, contact form submissions, feedback, survey responses, and any other correspondence you send to us.
- Testimonials & Content: Quotes, video testimonials, photographs, or written content you voluntarily provide for publication on our website or social media channels.
2.2 Information Collected Automatically
- Device & Browser Data: IP address, browser type and version, operating system, device type, screen resolution, and language preferences.
- Usage Data: Pages visited, time spent on pages, referring URL, click patterns, and navigation paths through our website.
- Cookies & Tracking: Information collected through cookies, web beacons, and similar technologies as described in Section 8.
2.3 Information from Third Parties
We may receive limited information about you from publicly available professional sources (e.g., LinkedIn public profiles) to verify membership eligibility, or from event co-hosts where you have consented to share your information.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Membership Management: To create and manage your account, verify your identity through OTP, and maintain your member profile.
- Service Delivery: To provide access to member resources, events, knowledge content, and networking opportunities.
- Communications: To send membership confirmations, event invitations, newsletters, program updates, and operational notices via email or SMS.
- Community Building: To display approved member profiles in our directory, facilitate peer connections, and highlight member achievements (with consent).
- Analytics & Improvement: To analyze website usage patterns, measure event effectiveness, and improve our services, content, and user experience.
- Industry Insights: To produce aggregated, anonymized reports and benchmarking data for the benefit of the healthcare supply chain community.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes, and to protect NHSCC’s rights and safety.
4. Information Sharing & Disclosure
NHSCC does not sell, rent, or trade your personal information to third parties for commercial purposes. We may share information in the following limited circumstances:
- Member Directory: If you choose to make your profile visible, your name, designation, and organization will appear in the public members directory.
- Service Providers: We engage trusted third-party service providers (hosting, email delivery, analytics) who process data on our behalf under strict confidentiality agreements.
- Event Partners: When you register for co-hosted events, your registration details may be shared with the co-hosting organization, clearly disclosed at the time of registration.
- Aggregated Data: We may share anonymized, aggregated statistical data for industry reports and benchmarking purposes. No individual is identifiable from such data.
- Legal Requirements: We may disclose information when required by law, court order, or governmental regulation, or when necessary to protect NHSCC’s rights, safety, or property.
5. Data Security
We implement industry-standard security measures to protect your personal information:
- All passwords are stored using bcrypt one-way hashing — we never store plaintext passwords.
- Our website uses HTTPS/TLS encryption for all data transmitted between your browser and our servers.
- Access to member data is restricted to authorized NHSCC administrators on a need-to-know basis.
- We conduct periodic security reviews and apply patches to our server infrastructure.
- Database backups are encrypted and stored securely with limited access controls.
While we take reasonable precautions, no method of electronic storage or internet transmission is 100% secure. We cannot guarantee absolute security but are committed to maintaining safeguards appropriate to the sensitivity of the information.
6. Data Retention
We retain your personal information for as long as your membership is active or as needed to provide our services:
- Active Members: Data is retained for the duration of your membership and for 2 years following account deactivation to allow for reactivation.
- Event Data: Event registration records are retained for 3 years for historical and benchmarking purposes.
- Communications: Contact form inquiries and correspondence are retained for 1 year.
- Analytics Data: Anonymized usage data may be retained indefinitely for trend analysis.
You may request deletion of your data at any time by contacting us (see Section 10).
7. Your Rights
Under applicable Indian data protection laws, you have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete information via your profile settings or by contacting us.
- Deletion: Request deletion of your personal data, subject to legal retention obligations.
- Withdrawal of Consent: Withdraw consent for data processing at any time. This does not affect the lawfulness of prior processing.
- Opt-Out: Unsubscribe from marketing communications at any time using the unsubscribe link in our emails.
- Data Portability: Request your data in a structured, commonly used format.
- Grievance Redressal: Lodge a complaint with our designated Grievance Officer (see Section 10).
8. Cookies & Tracking Technologies
Our website uses cookies and similar technologies to enhance your experience:
- Essential Cookies: Required for website functionality, session management, and authentication. These cannot be disabled.
- Analytics Cookies: Help us understand how visitors use our website (pages visited, time on site). Data is used in aggregate to improve services.
- Preference Cookies: Remember your settings and preferences for a better experience across sessions.
You can manage cookie preferences through your browser settings. Disabling certain cookies may affect website functionality.
9. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or organizational policies. When we make material changes, we will:
- Update the “Last Updated” date at the top of this page.
- Notify active members via email for significant changes.
- Post a visible notice on our website for a reasonable period.
Continued use of our services after changes constitutes acceptance of the updated policy.
10. Contact Us
For any questions, concerns, or requests related to this Privacy Policy or your personal data, please contact:
NHSCC Privacy & Data Protection Office
National Health Supply Chain Council
Email: privacy@nhscc.in
Website: Contact Page
We aim to respond to all privacy-related inquiries within 15 business days.