Home About
HealNTrack VaidSetu Bizcare All Products
Healthcare Solutions Software Development Manufacturing ERP IT Consulting
Contact
Contact Us WhatsApp

Privacy Policy

How Galant Innovative Technologies LLP processes personal data on our corporate website, business communications, and recruitment.

Effective date: July 28, 2026  |  Last updated: July 28, 2026

1. About Galant IT and this policy

Galant Innovative Technologies LLP (“Galant IT,” “we,” “us” or “our”) provides software products and technology services, including HealNTrack, VaidSetu, Bizcare and related consulting services.

This Privacy Policy explains how we process personal data when you visit a Galant-operated corporate website, contact us, request a demonstration, communicate with our business or support teams, subscribe to communications, or apply for employment.

A separate Healthcare Product Privacy Notice applies to personal data processed through HealNTrack, VaidSetu and other customer deployments. When a hospital, clinic, employer or other customer determines why and how information in a Galant product is processed, that organisation normally acts as the Data Fiduciary or Controller and Galant normally acts as its Data Processor or Processor.

This policy is a privacy notice. Merely visiting the website does not constitute consent to every processing activity. Where consent is required, we request it separately and for a specified purpose.

2. Who is responsible for your data

For the corporate website, business communications, recruitment and Galant’s own account, billing, security and compliance activities, the responsible organisation is:

Galant Innovative Technologies LLP
Registered office: Rajamalli, Infopark Koratty, Thrissur, Kerala, India — 680308

For customer-controlled product data, contact the hospital, clinic, employer or organisation that provided your account. Galant will assist that organisation in accordance with the applicable agreement and law.

3. Personal data we collect

The information collected depends on how you interact with us.

3.1 Information you provide

We may collect:

  • your name, business email address, telephone number and organisation;
  • job title, role and area of interest;
  • the subject and content of your inquiry;
  • demo, proposal, implementation or support requirements;
  • communication preferences and consent records;
  • information you submit during recruitment, including your resume, qualifications, employment history, references and interview information; and
  • other information you choose to provide.

Please do not submit patient records, medical information, passwords, payment-card information, government identifiers or other sensitive information through the general contact form.

3.2 Information collected automatically

When you use our website, we may collect:

  • IP address;
  • browser, device and operating-system information;
  • date, time, pages viewed and referring source;
  • security, error and performance logs;
  • approximate location derived from IP address; and
  • cookie or similar identifiers where enabled.

We do not describe this information as anonymous unless it has been processed so that it cannot reasonably be linked to an identifiable person.

3.3 Information received from other sources

We may receive business contact information from your organisation, referrals, event organisers, recruitment providers, professional networks and public business sources where legally permitted.

4. Why we process personal data

We may process personal data to:

  • respond to inquiries and demo requests;
  • communicate about requested products, services and proposals;
  • provide and administer customer or partner relationships;
  • operate, protect, troubleshoot and improve the website;
  • detect security incidents, fraud, misuse and unauthorised activity;
  • process recruitment applications;
  • maintain business, contractual, tax and audit records;
  • send marketing communications where permitted;
  • establish, exercise or defend legal claims; and
  • comply with legal, regulatory and law-enforcement obligations.

Depending on the applicable law and context, processing may be based on consent, information voluntarily provided for a specified purpose, steps requested before entering a contract, performance of a contract, compliance with law, protection of systems and legal rights, legitimate interests where recognised, or another legally permitted ground.

Submitting a business inquiry does not automatically enrol you in unrelated marketing. Marketing messages include an unsubscribe or opt-out mechanism.

5. Cookies and similar technologies

We may use strictly necessary technologies for security and website operation. Preference, analytics, advertising or other non-essential technologies are used only where configured and legally permitted.

Where consent is required, non-essential technologies will not be activated before you make a choice. You may accept, reject or manage non-essential cookies through the . Further details are available in our Cookie Policy.

6. How we disclose personal data

We may disclose personal data to:

  • website hosting, cloud, email, communications, analytics, recruitment and support providers;
  • professional advisers, auditors and insurers;
  • authorised Galant personnel who need the information for their work;
  • government, regulatory, judicial or law-enforcement authorities where legally required;
  • parties involved in a proposed or completed merger, investment, restructuring or business transfer, subject to appropriate confidentiality and data-protection measures; and
  • another party authorised by you.

Service providers are required to process personal data only for authorised purposes and under appropriate confidentiality, security and data-processing terms.

We do not sell personal data. We do not provide identifiable patient or clinical information to advertising networks or data brokers.

7. International processing and transfers

Personal data may be processed in India and in countries where Galant, its customers or authorised service providers operate. Where a transfer is restricted, we use an appropriate contractual, organisational or technical safeguard required for the applicable transfer. Product contracts should identify the hosting region and material subprocessors.

For EU/EEA or UK personal data, Galant will use an applicable transfer mechanism where required, such as approved standard contractual clauses and supplementary safeguards. Galant will also comply with restrictions that may be imposed under Indian law.

8. Data security

We use administrative, technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. Depending on the system and deployment, measures may include encryption, access control, authentication, audit logging, monitoring, backup, secure development, vulnerability management and incident-response procedures.

Not every feature applies to every product or deployment. Public security statements must match controls actually implemented and maintained. No electronic system can be guaranteed to be completely secure.

9. Data retention

We retain personal data for the period reasonably necessary for the relevant purpose, contractual obligations, security, audit, legal requirements and legal claims.

Typical criteria include:

  • business inquiries: while the inquiry and reasonable follow-up remain active, then according to the approved business-record schedule;
  • recruitment: for the recruitment process and the applicable claims period; longer talent-pool retention requires an appropriate notice or consent where required;
  • marketing: until opt-out, withdrawal of consent or expiration under the approved inactivity schedule, with a limited suppression record retained to respect the opt-out;
  • security and technical logs: according to security, CERT-In and other legal requirements;
  • financial and contractual records: for statutory accounting, tax and claims periods; and
  • customer product data: according to the customer agreement, customer instructions and applicable healthcare or record-retention law.

We may retain limited information for fraud prevention, legal compliance, dispute resolution and enforcement even after another copy is deleted.

10. Your rights and choices

Depending on applicable law and Galant’s role, you may have the right to:

  • request information about personal data being processed;
  • access personal data;
  • correct, complete or update inaccurate data;
  • request erasure where retention is not required;
  • withdraw consent;
  • object to or restrict processing where applicable;
  • request portability where applicable;
  • opt out of marketing;
  • use Galant’s grievance-redressal process;
  • nominate another person to exercise applicable rights in the event of death or incapacity where provided by law; and
  • complain to a competent data-protection or regulatory authority.

To submit a request, contact us using the details below. We may request information reasonably necessary to verify your identity and authority. Rights are subject to legal exceptions and the rights of other persons.

When Galant processes information only for a customer, we may refer the request to that customer or assist the customer in responding. Product users should normally contact their hospital, clinic, employer or organisation administrator first.

11. Children and minors

The corporate website, sales forms and business-contact services are not directed to persons under 18, and we do not knowingly seek children’s personal data through general website forms.

Galant healthcare products may process information about children when used by hospitals, clinics, healthcare professionals, parents or guardians. That processing is governed by the customer’s notice and policies, applicable law and the product-specific privacy notice.

If you believe a child submitted personal data directly to Galant through a general website form without appropriate authorisation, contact us so that we can review the matter.

12. Third-party websites

The website may link to sites or services operated by unrelated third parties. Their privacy practices are governed by their own notices. A Galant product is not a third party merely because it is hosted on a separate Galant-operated domain; it should display the applicable Galant product notice.

13. Changes to this policy

We may update this policy to reflect changes in our services, processing or legal obligations. We will post the revised version with an updated date. Where a change materially affects how personal data is processed, we will provide additional notice and obtain fresh consent where required.

Continued use of the website will not be treated as consent to a new processing purpose where separate consent is required by law.

14. Contact and grievance redressal

Privacy and Grievance Contact: Privacy Officer, Galant IT
Privacy email: privacy@galantit.com
General email: info@galantit.com
Telephone: +91 99953 21999
Postal address: Rajamalli, Infopark Koratty, Thrissur, Kerala, India — 680308

We aim to acknowledge privacy requests promptly and respond within the period required by applicable law and our published grievance procedure.