ZymolentBiosciences
Bioenergy & BioethanolEnzymes for biofuel production Agricultural BiosolutionsMicrobe-based bioformulations MicroorganismsStrains for fermentation & agriculture Food & Beverage EnzymesJuice, starch, brewing & fermentation
About Insights
Contact us
Home / Privacy policy

Privacy policy.

How Zymolent Biosciences Private Limited collects, uses, shares and protects personal data — written to be read, not to be survived.

We ask for the least we need, keep it only while it is useful, and say plainly which is which.

On this page

    This notice

    @

    Questions, corrections, or a request about your data — office@zymolent.com
    See also our terms of use.

    The short version

    We are a business-to-business biotechnology company. Almost everything we hold is ordinary work-contact information — a name, an employer, a role, an email address — given to us by people who wanted to talk about enzymes, microbes or bioformulations.

    • We do not sell personal data. Not to anyone, in any form, at any price.
    • This website sets no cookies and runs no advertising or session-tracking scripts and no analytics. Two parties are contacted to serve a page, and what each of them does is set out under cookies and tracking.
    • You can ask what we hold, have it corrected, or have it erased. Write to office@zymolent.com and we answer within 30 days.

    This box is orientation only. The sections below are the notice itself, and they govern.

    Who we are, and what this notice covers

    Zymolent Biosciences Private Limited (“Zymolent”, “we”, “us”, “our”) is a company incorporated in India, with its registered office at Satrapara, Mirza, Guwahati 781125, Assam, and its laboratory and pilot plant at Ground Floor, Guwahati Biotech Park, near the SP Office, Amingaon, Guwahati 781031, Assam. We develop and manufacture industrial enzymes, microbial strains and agricultural bioformulations.

    For the personal data described here, Zymolent is the Data Fiduciary under Indian law and the data controller under European law. In plain terms: we are the ones who decide why your data is collected and what happens to it, and we are the ones you can hold to account for it.

    This notice covers personal data we handle when you:

    • visit this website or read something we have published;
    • contact us, request a sample, place an order, or deal with us as a customer, distributor, supplier or research partner;
    • visit our laboratory, pilot plant or registered office;
    • subscribe to our quarterly letter, or meet us at a conference or trade fair;
    • apply for a role with us.

    It does not cover our own employees and contractors, who receive a separate internal notice, and it does not cover third-party websites we link to. Once you follow a link away from this site, the notice of the destination applies.

    The law that applies to you

    We operate from India and sell into several countries, so more than one privacy regime can apply to a single relationship. Rather than publish one notice per jurisdiction, we have written one notice to the stricter standard and then told you which rights are yours.

    • India — the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the rules made under it, as and when they come into force, together with the Information Technology Act, 2000 and the Reasonable Security Practices and Sensitive Personal Data or Information Rules, 2011.
    • European Economic Area and the United Kingdom — the General Data Protection Regulation (EU 2016/679) and the UK GDPR, where we offer goods or services to people in those territories.
    • Elsewhere — we apply the substance of this notice as a floor, and comply with any additional local requirement that binds us.

    Where two regimes disagree, we follow the one that gives you more protection. Nothing here takes away a right the law gives you.

    A short glossary

    Privacy law has its own vocabulary, and hiding behind it is a way of not explaining things. Four terms are worth defining once:

    Personal data
    Any information about an identified or identifiable individual. A work email address is personal data; an anonymous count of page views is not.
    Data Principal India · “data subject” in the EU
    You — the person the data is about.
    Data Fiduciary India · “controller” in the EU
    Us — the organisation that decides why and how your data is processed, and answers for it.
    Data Processor
    A service provider that handles data strictly on our written instructions and for no purpose of its own — our email host, for instance.

    What we collect, and when

    We collect by relationship, not in bulk. The subsections below describe every category we hold and the situation that produces it. If your relationship with us is not listed, we are almost certainly holding nothing about you.

    Enquiries and ongoing business relationships

    When you write to us, complete the enquiry form, exchange cards at a trade fair, or become a named contact at a customer, distributor or supplier, we record your name, work email address and telephone number, your employer, job title and country, and the substance of the correspondence — what you asked, what we answered, what was agreed. Where a relationship continues, we keep an account history: quotations, technical discussions, meeting notes and the commercial terms that apply to you.

    Samples, trials and orders

    Requesting a sample or placing an order adds shipping and billing addresses; the consignee’s name and phone number, which carriers require; GSTIN or another tax registration; purchase-order and invoice references; payment details, which our bank and payment processors hold rather than us; and, for cross-border consignments, the customs, export-control and end-use declarations the law obliges us to obtain. We also screen counterparties against applicable sanctions and denied-party lists before shipping. That screening is a legal obligation, not a commercial preference.

    Technical support, safety and product stewardship

    Enzyme and microbial products carry handling obligations, so we keep a record of support requests, the dosing and process data you choose to share, complaints, and any report of an adverse reaction, spill, allergic response or other safety incident. A safety report may unavoidably contain health information about the person affected. We treat that as sensitive, restrict it to the smallest possible team, and keep it because product-safety law requires a traceable record — not because we want it.

    Visits to our laboratory, pilot plant or office

    Visitors to a working microbiology facility are registered: name, employer, host, and time in and out. Depending on the area you enter we may also record a vehicle number, a biosafety or confidentiality declaration, and — if we are feeding you — any allergy or dietary requirement you choose to tell us. Parts of the site are covered by CCTV for the safety of people, equipment and cultures; signage marks those areas, footage is kept briefly, and it is reviewed only after an incident.

    Using this website

    Our hosting provider records standard server logs for every request: an IP address, a timestamp, the page requested, the referring page, and a browser user-agent string. These logs exist to keep the site available and to defend it against abuse. We do not build profiles from them and we do not join them to any other record about you. Cookies and tracking, below, sets out precisely what the site loads.

    The quarterly letter and other marketing

    If you subscribe we keep your email address, the date and source of the subscription, and — so that we do not send a fourth message you never opened — whether our messages are being opened at all. We do not use tracking pixels to build a behavioural profile, and every message carries a one-click unsubscribe.

    Job applications

    If you apply to us we hold your CV and covering letter, contact details, qualifications and work history, your right to work where the role sits, interview notes, and references you have asked us to take up. Please do not send us caste, religion, health or other sensitive information in an application; if it arrives anyway, we redact it.

    Research collaborations and grant work

    Publicly funded and institutional research brings its own paperwork: the names, affiliations, ORCID or equivalent identifiers and roles of investigators, and whatever a funder, ethics committee or regulator obliges us to declare. Where a collaboration agreement imposes stricter terms than this notice, the agreement wins.

    What we deliberately do not collect

    We do not seek out, and ask you not to send us, data revealing racial or ethnic origin, caste or tribe, religious or political belief, trade-union membership, sex life or sexual orientation, genetic or biometric identifiers, or criminal records. The single exception is the health information that can appear in a product-safety report, which exists only because safety law requires it.

    We do not buy marketing lists, we do not scrape contact data, and we do not enrich what you give us with data bought from brokers.

    Why we process it, and on what legal basis

    Every processing activity needs a lawful reason. Ours are below. Under the DPDP Act our basis is your consent or a “legitimate use” recognised by section 7 of that Act; where the GDPR applies, the corresponding article is named alongside.

    What we doWhyLegal basis
    Answer an enquiry and run the relationshipYou asked us something, and a supplier who cannot remember the conversation is useless to youConsent; data given voluntarily for a stated purpose · GDPR Art. 6(1)(b), (f)
    Fulfil samples, trials and ordersTo ship the right product to the right place and be paid for itPerformance of a contract · GDPR Art. 6(1)(b)
    Technical support and product stewardshipTo make the product work in your process, and to act on safety reportsContract, legal obligation, vital interests · GDPR Art. 6(1)(b), (c), (d)
    Tax, customs, export-control and sanctions complianceBecause we are required toLegal obligation · GDPR Art. 6(1)(c)
    Site access control, biosafety and CCTVTo keep people, cultures and equipment safeLegitimate interest in facility safety · GDPR Art. 6(1)(f)
    Server logs, security monitoring, backupsTo keep our systems available and uncompromisedLegitimate interest in security · GDPR Art. 6(1)(f)
    The quarterly letter and other marketingBecause you asked to hear from usConsent, withdrawable at any time · GDPR Art. 6(1)(a)
    RecruitmentTo assess an application you submittedSteps prior to a contract · GDPR Art. 6(1)(b)
    Aggregate and statistical analysisTo understand demand and improve what we makeLegitimate interest — and the output is anonymised · GDPR Art. 6(1)(f)
    Establishing or defending a legal claimRare, but realLegal obligation and legitimate interest · GDPR Art. 6(1)(c), (f)

    Where we rely on a legitimate interest, we have weighed that interest against your rights and satisfied ourselves it does not override them. You are entitled to ask us to show that reasoning, and to object.

    If we ever want to use your data for something not described here, we will tell you first and, where the law requires it, ask.

    Where the data comes from

    • From you, directly — forms, email, telephone, purchase orders, a conversation at a stand, a visitor register, a job application. This is the overwhelming majority of what we hold.
    • Automatically — the server logs described under using this website, generated by the act of loading a page.
    • From your employer or a colleague — when someone at a customer, distributor or partner names you as the technical or commercial contact for an account.
    • From public and official sources — a company register, a GST portal, a sanctions or denied-party list, a published paper, or a public professional profile, used to verify a counterparty or to check something we are obliged to check.

    Where someone else gives us your details, we rely on their having been entitled to. If you would rather we did not hold them, say so and we will take you off the account record.

    If you would rather not give it

    Some data is unavoidable. We cannot ship an order without an address, invoice without a tax registration, or clear a border without an export declaration. Withholding it means we cannot do the thing you asked for, and we will say so plainly rather than fail quietly.

    Everything else is optional. You can read this entire website without identifying yourself, and declining to subscribe, to state a dietary preference or to answer an optional field costs you nothing.

    Cookies, tracking, and what this website actually loads

    A privacy notice ought to describe the site it sits on, so here is an account of what this one actually does, and of everything that leaves your browser when you load it.

    This site sets no cookies. There is no analytics package, no tag manager, no advertising or conversion pixel, no session recorder, no A/B testing tool, no social-media button that phones home, and no consent-management platform — with nothing to consent to, a cookie banner would be theatre.

    Loading a page does cause your browser to contact two parties, and each necessarily sees your IP address:

    • Our hosting provider serves the page and keeps the short-lived request logs described under using this website. Every typeface, script and stylesheet the page needs comes from this domain, so serving you a page requires no one else.
    • A cloud storage provider, in an Indian region, streams the background clip on our home page. It is requested on that page alone, and only on wider screens — a narrow screen, a metered or slow connection, or a “reduce motion” setting means it is never fetched at all.

    None of these requests carries an identifier we assigned to you, and none is used to profile you.

    We describe these providers by the job they do rather than by name. Naming the exact components of a system in public is an invitation to probe them, and the useful facts for you — what leaves your browser, who receives it, and what they may do with it — are all above. If you want to know precisely who serves a given request, ask us at office@zymolent.com and we will tell you; the same list goes to any regulator who asks, without their having to.

    Measuring how the site is used

    We do not, at present. No analytics package runs on this site, which means we can tell you how many requests our host logged and very little else. If we add one we will name it here, say what it records and how long it is kept, and date the change — and we will pick the least intrusive tool that answers the question. If it needs your consent, we will ask before it loads rather than after.

    Search engines, and what we publish about ourselves

    We would like to be found, so our pages carry the ordinary furniture of a public website: a title and a description for search results and link previews, an automatically generated sitemap, and — on our articles and legal pages — a canonical address and structured data describing the company and the piece you are reading. All of that describes us. It holds no personal data about visitors, it is identical for everyone who loads the page, and it is as visible to you as it is to a search engine — view the source and you have seen all of it.

    Search engines crawl the site as any visitor would, and our host logs their requests exactly as it logs yours. What a search engine then does with its own record of your search is governed by its notice, not by ours.

    Your browser’s Do Not Track and Global Privacy Control signals are honoured by default, for the straightforward reason that we were not tracking you to begin with.

    Who we share it with

    We do not sell, rent, licence or trade personal data, and we never will. We share it only where the work requires it, and only with:

    • Service providers acting on our instructions — email and document hosting, our website host, accounting and invoicing software, couriers and freight forwarders, payment processors. Each is bound by a written agreement confining it to our instructions, forbidding any use of its own, and obliging it to return or delete the data when the engagement ends.
    • Distribution and channel partners, where they are the ones actually serving you in your market.
    • Professional advisers — auditors, lawyers, tax advisers, insurers — under a duty of confidence.
    • Research partners and funders, to the extent a collaboration or grant obliges us to declare who is involved.
    • Public authorities — tax, customs, export control, pollution control, other regulators, courts and law enforcement — where we are legally required to disclose. We satisfy ourselves that a demand is lawful and properly served before acting on it, we disclose the narrowest set of data that answers it, and we tell you unless the law forbids us.
    • A successor, if the business or part of it is ever sold, merged or reorganised — in which case the data stays governed by a notice at least as protective as this one, and the change is announced here.

    A current list of the service providers we use, and the countries they operate from, is available on request to office@zymolent.com.

    Where it lives, and how long we keep it

    Storage and transfers across borders

    We prefer Indian data centres and use them wherever a provider offers the choice. Some of the services above nevertheless process data outside India, and some of our customers, partners and carriers are outside India, so a transfer is sometimes unavoidable.

    Transfers out of India are made in accordance with section 16 of the DPDP Act, and we do not transfer to a territory the Central Government has restricted. Transfers of EEA or UK personal data out of those territories are made under the European Commission’s Standard Contractual Clauses or the UK Addendum, supplemented where necessary by additional technical measures. A copy of the mechanism relied on for a particular transfer is available on request.

    Retention

    We keep personal data only as long as the purpose that justified collecting it survives, and then we delete it. Indicative periods:

    RecordKept for
    Enquiries that do not become a relationship24 months from the last contact
    Customer, supplier and partner account recordsThe relationship, plus 3 years
    Invoices, tax and statutory accounting records8 years, as Indian tax and company law requires
    Export, customs and sanctions-screening records5 years from the shipment
    Product-safety and complaint records10 years from the report, or the product’s regulatory life if longer
    Visitor register12 months
    CCTV footage30 days, unless held for a specific incident
    Website server logs90 days
    Newsletter subscriptionUntil you unsubscribe, plus a minimal suppression record so you are not re-added
    Unsuccessful job applications12 months, or longer if you ask us to keep you in mind

    A period may be extended where a live dispute, investigation or legal claim requires it. Backups age out on their own cycle, so a record erased from our live systems can persist in an encrypted backup for a short further period before it is overwritten. During that window it is not used for anything.

    Your rights

    These rights are yours whether you are a customer, a job applicant, or someone who wrote to us once. Exercising them is free and will never disadvantage you commercially.

    • Know and access — ask what personal data we hold about you, why, and who we have shared it with, and receive a copy.
    • Correct and complete — have inaccurate data corrected and incomplete data completed. This is the request we receive most; job titles change.
    • Erase — have your data deleted where we no longer need it and no law obliges us to keep it. Where a statutory retention period blocks erasure, we will tell you which one and when it expires.
    • Withdraw consent — at any time, and as easily as you gave it. Withdrawal stops future processing; it does not unwind processing that was lawful when it happened. Unsubscribing from marketing does not stop the operational messages an order requires.
    • Object — to processing based on a legitimate interest, and absolutely to direct marketing.
    • Restrict — ask us to pause processing while an accuracy dispute or an objection is resolved.
    • Portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it sent onward where that is technically feasible.
    • Nominate — under section 14 of the DPDP Act, name another person to exercise these rights on your behalf should you die or become incapable of exercising them yourself. Tell us the nominee and we will record it.
    • Grievance redressal — a direct first route of complaint to us, set out under complaints and the Grievance Officer, which you may use before approaching any regulator.
    • Complain to a regulator — always, and without asking us first.

    How to exercise them

    Write to office@zymolent.com, or post to the registered office given under contact us. Tell us which right you are exercising, and enough about your dealings with us for us to find the record.

    We will ask you to confirm your identity before we act — handing someone’s data to a stranger who asked confidently is itself a breach. We ask for the minimum needed, and we delete the verification material once the request is closed.

    We respond within 30 days. If a request is unusually complex we may extend that once, and we will tell you why before the first period runs out. If we decline a request, we will say which provision permits us to and how you can challenge that.

    One honest caveat: the DPDP Act expects good faith from you as well. Please do not file a knowingly false or impersonating request, or suppress information we need — the Act allows penalties for that, and it consumes the time of a small team who would rather be answering real ones.

    Security, and what happens if it fails

    We apply technical and organisational measures proportionate to the risk: encryption in transit and at rest, access granted on a need-to-know basis and reviewed when roles change, multi-factor authentication on business systems, physical access control at the laboratory and pilot plant, contractual confidentiality for everyone who touches the data, logging of administrative access, tested backups, and a written incident-response procedure.

    No system is perfect, and ordinary email in particular is not a secure channel. Please do not send us bank details, identity documents or anything genuinely sensitive by email; ask, and we will open a secure route.

    If a breach occurs and personal data is affected, we will investigate immediately, contain it, and notify the Data Protection Board of India — and, where the GDPR applies, the competent supervisory authority within 72 hours. We will tell affected individuals directly where the law requires it, and also where it does not but the risk to you makes telling you the right thing to do.

    If you believe you have found a vulnerability in this website or in one of our systems, report it to office@zymolent.com. We will acknowledge it, we will not pursue a good-faith researcher who acts proportionately and does not exfiltrate data, and we will credit you if you would like us to.

    Complaints and the Grievance Officer

    We would rather hear a complaint than have you take it elsewhere first, so there is a named route to someone who can actually resolve it.

    Grievance Officer & privacy contact

    Grievance Officer, Zymolent Biosciences Private Limited

    office@zymolent.com
    Satrapara, Mirza, Guwahati 781125, Assam, India
    +91 8399 8399 81

    Acknowledged within 3 working days · substantive response within 30 days

    If our answer does not satisfy you, you may complain to the Data Protection Board of India once it is constituted and accepting complaints. If you are in the EEA or the UK you may instead complain to the supervisory authority where you live, where you work, or where the issue arose. You are not required to come to us first, and we will not treat you differently for choosing either route.

    Two commitments worth stating outright

    Automated decisions and artificial intelligence

    We use computational and machine-learning methods in our science — strain selection, enzyme engineering, process modelling. Those models act on biological and process data, not on you.

    We do not make decisions about people by automated means alone where the decision has a legal or similarly significant effect: no algorithmic credit scoring, no automated rejection of a CV, no automated blocking of a customer. A person makes those calls and can explain them. Where we use a general-purpose AI assistant in day-to-day work, we do not paste customer personal data, applicant data or confidential technical information into a tool that would train on it.

    Children

    Our products and this website are directed at businesses and professionals, and we do not knowingly collect personal data from anyone under 18. Consistent with section 9 of the DPDP Act we do not track children, monitor their behaviour, or serve them targeted advertising — a commitment that costs us nothing, since we do none of those things to adults either. If you believe a child has given us personal data, write to office@zymolent.com and we will delete it.

    Contact us

    For anything in this notice — a question, a correction, a request about your data, or a disagreement with something we have done:

    Zymolent Biosciences Private Limited

    Registered office
    Satrapara, Mirza
    Guwahati 781125, Assam, India

    Laboratory & pilot plant
    Ground Floor, Guwahati Biotech Park
    Near SP Office, Amingaon
    Guwahati 781031, Assam, India

    office@zymolent.com
    +91 8399 8399 81

    You are also welcome to use the contact form — though please keep sensitive detail out of it and let us open a secure channel instead.

    Changes to this notice

    We review this notice at least once a year, and whenever something material changes — a new processing purpose, a new category of recipient, or a new transfer mechanism. The last typeface moved to our own servers on 02 September 2026, which is the sort of change we would rather report than promise.

    The current version and its effective date are stated at the top of this page. Substantive changes are announced here before they take effect, and where a change requires your consent we will ask for it rather than assume it. Continuing to use the website after a change means the updated notice applies to that use; it does not, by itself, amount to consent to anything new.

    Version 1.0 · effective 02 September 2026 · earlier versions available on request.

    This notice is published in English. Any translation is offered for convenience; if the two conflict, the English text governs.

    Tell us about your process, and we'll help you identify the right biosolution.

    Trial samples ship free to qualified industrial users — typically 250 g or 500 mL, with the matching spec sheet and SDS. Describe the application and we'll pick the formulation.

    Request a sample

    Or write to us directly — office@zymolent.com

    Solutions
    • Bioenergy & Bioethanol
    • Agricultural Biosolutions
    • Microorganisms
    • Food & Beverage Enzymes
    Company
    • About
    • Careers
    • Privacy policy
    • Terms of use
    Registered office
    Satrapara, Mirza
    Guwahati 781125
    Assam, India office@zymolent.com
    Pilot plant & lab
    Ground Floor, Guwahati Biotech Park
    Near SP Office, Amingaon
    Guwahati 781031, Assam +91 8399 8399 81
    ZymolentBiosciences © 2026 Zymolent Biosciences Pvt. Ltd. — All rights reserved. · Privacy · Terms