Privacy Policy

Effective Date: 7/12/2026

Last Updated: 7/12/2026

Version: 1.1

1. Identity and Contact Details

[Full Legal Entity Name, e.g., Eiffel Life Sciences Sp. z o.o.] ("we," "us," or "our") acts as the Data Controller for the personal data collected through this website and our related business operations.

  • Registered Office Address: [Registered Address Placeholder]
  • Company Registration Number: [Registration Number Placeholder]
  • VAT Number: [VAT Number Placeholder, if applicable]

We are headquartered in Warsaw, Poland, and maintain an operational office in Bangalore, India.

  • General Inquiries: mail@eiffellifesciences.com
  • Privacy and Data Protection Enquiries: mail@eiffellifesciences.com

2. What Personal Data We Collect

We may collect and process the following categories of personal data depending on your interactions with us:

  • Contact Information: Name, email address, telephone number, country, and any information you provide when filling out our contact forms.
  • Professional Information: Company name, job title, and related business details.
  • Newsletter Data: Email addresses provided when signing up for our communications.
  • Technical and Analytics Data: IP addresses, device information, browser information, cookie identifiers, and website usage data collected via cookies (if you have consented to non-essential cookies).

2.1 Data Sources

Your personal data may be collected through:

  • Contact forms on our website
  • Email communications
  • Newsletter subscriptions
  • Website cookies and similar technologies
  • Recruitment enquiries
  • Business communications
  • LinkedIn or other professional networking platforms
  • Direct interactions at events or meetings

2.2 Mandatory vs. Optional Information

Where we request personal data from you, we will indicate whether the provision of the data is mandatory. Information required to provide a requested service, fulfill a contract, or comply with a legal obligation is mandatory. Failure to provide such information may prevent us from providing the requested services or responding to your enquiries. All other information is provided on a voluntary (optional) basis.

3. Legal Basis and Purpose of Processing

PurposeData CategoryLegal Basis (GDPR)
Responding to inquiriesContact & Professional InformationContract / Pre-contractual measures (Art. 6(1)(b)) or Legitimate Interest (Art. 6(1)(f))
Business relationship managementContact & Professional InformationLegitimate Interest (Art. 6(1)(f)) or Contract (Art. 6(1)(b))
RecruitmentContact & Professional InformationPre-contractual measures (Art. 6(1)(b)) / Consent (Art. 6(1)(a))
Marketing & NewslettersNewsletter DataExplicit Consent (Art. 6(1)(a))
Website Analytics & CustomizationTechnical and Analytics DataConsent (Art. 6(1)(a)) / Legitimate Interest (Art. 6(1)(f))
Website security and Fraud preventionTechnical and Analytics DataLegitimate Interest (Art. 6(1)(f))
Legal complianceVariousLegal Obligation (Art. 6(1)(c))

4. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Contact inquiries: Retained for 2 years after the last communication.
  • Newsletter subscriptions: Retained until you withdraw consent (unsubscribe).
  • Analytics data: Aggregated and retained up to 14 months.

Longer retention periods may apply where required by applicable law or where necessary to establish, exercise, or defend legal claims.

5. Third-Party Processors and Data Transfers

We do not sell your personal data. We may share your data with trusted third-party processors who assist us in operating our website and business, acting under strict contractual obligations to ensure the confidentiality and security of your data. These may include:

  • Cloud Hosting: Secure hosting environments and infrastructure providers.
  • CRM Systems: For managing client relationships and business communications.
  • Email Providers: For managing communications and newsletters.
  • Analytics Providers: For analyzing website traffic and performance.
  • Security Providers: For protecting our systems against threats.
  • Payment Providers: (if applicable) For processing transactions securely.

If data is transferred outside the European Economic Area (EEA), such as to our operations in India or to US-based service providers, we ensure adequate safeguards are in place. Such international transfers are conducted subject to the European Commission's Standard Contractual Clauses (SCCs), reliance on Adequacy Decisions, and the implementation of additional technical and organizational safeguards where necessary.

6. Your Data Subject Rights

Under the GDPR and other applicable laws, you have the following rights regarding your personal data:

  • Right of Access: Request a copy of the data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your data.
  • Right to Restriction: Request limitation of data processing.
  • Right to Data Portability: Request to receive your data in a structured format.
  • Right to Object: Object to processing based on legitimate interests or direct marketing.
  • Right to Withdraw Consent: Withdraw your consent at any time. Please note that withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority before exercising other legal remedies.

To exercise any of these rights, please contact us at mail@eiffellifesciences.com. We may require identity verification before processing your request. We will respond to your request within 30 days, though this response period may be extended by a further two months where legally permitted and necessary due to the complexity or number of requests.

7. Automated Decision-Making

We do not engage in any automated decision-making. No profiling producing legal effects or similarly significant effects is carried out using your personal data.

8. Right to Lodge a Complaint

If you believe our processing of your personal data violates data protection laws, you have the right to lodge a complaint with a supervisory authority. You may file a complaint with the supervisory authority in the EU Member State of your habitual residence, your place of work, or the place of the alleged infringement. Alternatively, where applicable, you may lodge a complaint directly with the Polish Personal Data Protection Office (UODO).

9. Cookies and Tracking Technologies

Our website utilizes cookies and similar tracking technologies to function effectively and improve your experience. Our use of cookies is fully compatible with Google Consent Mode v2. We utilize the following categories:

  • Essential Cookies: Strictly necessary for the website to function properly and securely.
  • Analytics Cookies: Used to collect aggregated data on website traffic and usage.
  • Marketing Cookies: Used to deliver relevant advertisements and track ad campaign performance.

You can manage your consent preferences or withdraw your consent at any time via our Cookie Settings panel, accessible from the website footer. For more detailed information, a separate Cookie Policy may also apply.

10. Security Measures

We implement appropriate, reasonable technical and organizational measures to ensure a level of security appropriate to the risk of processing your personal data. These measures include, but are not limited to:

  • Data encryption in transit and at rest
  • Strict access controls and least privilege access principles
  • Secure authentication mechanisms
  • Secure hosting infrastructure and firewalls
  • Regular security reviews and vulnerability assessments

11. Children's Privacy

Our website and B2B services are not intended for children under the age of 16. We do not knowingly collect or solicit personal data from children. If we become aware that we have collected personal data from a child under 16 without verified parental consent, we will take steps to delete that information promptly.

12. Changes to this Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal obligations. The "Last Updated" and "Effective Date" at the top of this policy will be revised accordingly. Any significant changes to this policy will be communicated to you appropriately, such as through a prominent notice on our website or via email.