Legal

Privacy Policy

Leighton Systems is committed to protecting the privacy and personal data of every individual whose personal information is processed by us.

This Privacy Notice explains how we collect, use, store, disclose, and otherwise process your personal data. It provides information about the nature, scope, and purposes of our data processing activities, as well as your rights under applicable data protection laws.

This Privacy Notice applies to the websites operated by Leighton Systems and all affiliated companies that reference this Privacy Notice on their websites outside the European market. It does not apply to Leighton Systems websites, products, services, or functionalities that are governed by and expressly reference a separate privacy notice.

For information regarding the identity of the data controller (Leighton Systems or we ) within the meaning of applicable data protection laws, please refer to our Provider Identification. Not with standing the foregoing, where goods or services are provided pursuant to a contractual relationship, the Leighton Systems entity that is your contractual partner shall be the data controller responsible for processing your personal data in connection with the provision of those goods or services. Information identifying the relevant Leighton Systems entity can be found in the applicable terms and conditions governing the respective goods or services.

  • Distribution and supply of medical equipment and medical devices
  • Participation in Government procurement, tenders and public sector projects
  • Retail sale of fashion eyewear
  • Installation, commissioning, preventive maintenance, repair and after-sales services
  • Operation of the Company's website, digital platforms and customer support services.

The Company processes personal data in accordance with applicable laws, including the Digital Personal Data Protection Act, 2023, and other applicable statutory, contractual and regulatory requirements.

2. Scope

This Policy applies to personal data processed by the Company relating to:

  • Customers.
  • Prospective customers.
  • Hospitals, clinics and healthcare institutions.
  • Government departments and public authorities.
  • Vendors, suppliers and contractors.
  • Business partners and distributors.
  • Employees and job applicants.
  • Visitors to the Company's website.

This Policy applies irrespective of whether personal data is collected electronically, physically, verbally or through third parties authorized to share such information.

3. Definitions

For the purposes of this Policy:

Personal Data means any data about an individual who is identifiable by or in relation to such data.

Processing means any operation performed on personal data, including collection, recording, storage, organization, use, sharing, retrieval, disclosure, correction, anonymisation or deletion.

Data Principal shall have the meaning assigned under the Digital Personal Data Protection Act, 2023.

4. Categories of Personal Data Collected

Depending upon the nature of our relationship, we may collect:

Identity Information

  • Name
  • Photograph (where required)
  • Date of birth
  • Government-issued identification details where legally required

Contact Information

  • Postal address
  • Email address
  • Mobile number
  • Telephone number

Business Information

  • Organisation name
  • Department
  • Designation
  • GST or tax registration details
  • Procurement information
  • Contractual documentation

Transaction Information

  • Purchase orders
  • Quotations
  • Invoices
  • Delivery information
  • Payment references
  • Warranty registration
  • Service records

Technical Information

When you access our website or digital platforms, we may collect:

  • IP address
  • Browser type
  • Device information
  • Operating system
  • Website usage logs
  • Cookies
  • Session identifiers

Medical Device Information

Where necessary for regulatory compliance, product safety or after-sales service:

  • Equipment serial numbers
  • Installation reports
  • Calibration records
  • Maintenance history
  • Product complaints
  • Recall information

5. How We Collect Personal Data

Personal data may be collected:

  • Directly from customers and business representatives.
  • Through purchase orders and contractual documents.
  • During installation, servicing or maintenance visits.
  • Through our website, email or customer support channels.
  • During participation in government procurement processes.
  • From authorised dealers or distributors.
  • From publicly available sources where permitted by law.

6. Purpose of Processing

Personal data is processed only for lawful and legitimate business purposes, including:

  • Supplying products and services.
  • Processing quotations, tenders and purchase orders.
  • Executing contracts.
  • Delivering products.
  • Installation and commissioning.
  • Warranty administration.
  • Preventive maintenance and repair.
  • Customer relationship management.
  • Product traceability.
  • Product safety notifications and recalls.
  • Technical support.
  • Processing payments.
  • Maintaining statutory records.
  • Regulatory reporting.
  • Government audit requirements.
  • Internal compliance and risk management.
  • Fraud prevention.
  • Information security.
  • Improving our products, services and customer experience.

The Company processes only the minimum personal data necessary for these purposes.

8. Government Projects and Public Procurement

In connection with Government contracts, tenders and procurement activities, the Company may process personal data necessary for:

  • Vendor registration;
  • Bid submission;
  • Contract execution;
  • Project implementation;
  • Regulatory inspections;
  • Government audits;
  • Financial reporting;
  • Statutory compliance.

Personal data is disclosed only where required by applicable law, contractual obligations or directions of competent authorities.

9. Disclosure of Personal Data

The Company does not sell or commercially exploit personal data.

Personal data may be shared only where necessary with:

  • Logistics and transportation providers.
  • Installation and maintenance engineers.
  • Payment service providers.
  • Professional advisers.
  • Auditors.
  • Insurance providers.
  • Regulatory authorities.
  • Government departments.
  • Courts and law enforcement agencies.
  • Technology service providers acting under contractual confidentiality obligations.

Each recipient receives only the information necessary to perform the relevant function.

10. Data Security

The Company maintains appropriate technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, destruction or loss.

Such measures include, where appropriate:

  • Role-based access controls.
  • Password-protected systems.
  • Encryption of sensitive data during transmission where feasible.
  • Secure storage of physical records.
  • Employee confidentiality obligations.
  • Periodic security reviews.
  • Backup and disaster recovery procedures.
  • Controlled access to company premises and information systems.

11. Data Retention

Personal data is retained only for the period necessary to:

  • Fulfil contractual obligations.
  • Provide warranty and after-sales services.
  • Comply with statutory record-keeping requirements.
  • Meet regulatory obligations relating to medical devices.
  • Resolve disputes.
  • Defend legal claims.

Upon expiry of the applicable retention period, personal data is securely deleted, anonymised or archived in accordance with applicable legal requirements.

12. Rights of Individuals

Subject to applicable law, individuals may have the right to:

  • Obtain information regarding processing of their personal data.
  • Request correction or updating of inaccurate personal data.
  • Request erasure of personal data where legally permissible.
  • Withdraw consent where processing is based on consent.
  • Seek redress of grievances through the Company's designated grievance mechanism.

Requests shall be processed in accordance with applicable legal requirements.

13. Cookies and Website Analytics

The Company's website may use cookies and similar technologies to:

  • Ensure website functionality.
  • Improve user experience.
  • Analyse website performance.
  • Enhance security.
  • Remember user preferences.

Users may configure their browser settings to refuse cookies; however, certain website features may not function as intended.

14. Third-Party Websites

The Company's website may contain links to external websites operated by third parties. The Company is not responsible for the privacy practices, content or security of such websites.

15. Cross-Border Data Transfers

Where personal data is transferred outside India, such transfers shall be undertaken only in accordance with applicable legal requirements and subject to appropriate safeguards.

16. Amendments

The Company reserves the right to amend this Privacy Policy from time to time to reflect changes in applicable law, business operations or regulatory requirements. The updated version shall be published on the Company's website and shall become effective from the date specified therein.

17. Grievance

In accordance with applicable law, the Company has designated a Grievance Cell to address concerns relating to personal data.

Email: info@leighton.in

18. Contact

For any questions regarding this Privacy Policy or the processing of personal data, please contact the Company using the details provided above.

Approval

This Privacy Policy has been approved by the Management of Leighton Systems and shall be reviewed periodically to ensure continued compliance with applicable laws, regulatory requirements and industry best practices.