Security policy v1 · 01 Aug 2026
How we protect your data
This is the security policy referred to in the Wellness DNA Test consent form. It sets out the
reasonable security safeguards we are required to keep under section 8(5) of the Digital Personal Data
Protection Act, 2023 — written so you can actually check whether we are doing what we said.
- In transit and at rest
- Everything you type here travels over HTTPS (TLS 1.2 or better). Your details, your answers and your signature are stored encrypted on servers located in India, and backups are encrypted the same way.
- Your DNA data is kept apart from your name
- The moment your sample reaches the lab it is labelled with a barcode, not your name. Genetic data is stored under that barcode in a separate system; the key that links barcode to person is held by a small number of named staff and every use of it is logged.
- Who can see it
- Access is granted by role and reviewed every quarter. Only the lab and reporting staff working on your test can open your record, each with their own account and two-factor login. We do not use your data to train any model, and we never sell it.
- Our partners
- Sequencing and IT partners process data for us under written contracts that bind them to these same standards, forbid any attempt to re-identify you, and require them to delete their copy when the work is done.
- Deletion is real deletion
- Your physical sample is destroyed after testing. If you asked us to delete your DNA data after your report, it is erased from live systems within 30 days and from encrypted backups within 90 days as they roll over. If you chose five-year storage, the same erasure runs automatically at the end of that period, or sooner if you ask.
- If something goes wrong
- We keep an incident response plan and test it. If a breach affects your data we will tell you and the Data Protection Board of India without delay, in plain language: what happened, what it means for you, and what we have done about it.
- Telling us about a problem
- Found a security flaw? Write to our security contact. We will not pursue anyone who reports a genuine issue to us in good faith and gives us a reasonable chance to fix it.
Your rights, and who to ask
- Ask for a copy of the data we hold about you, or have it corrected.
- Have it erased once our retention period ends — or sooner, by withdrawing consent.
- Nominate someone to exercise these rights on your behalf if you cannot.
- Withdraw any consent by emailing privacy@dromicslabs.com with your Customer ID.
Data Fiduciary: Dr.Omics Labs ·
Privacy: privacy@dromicslabs.com ·
Security: security@dromicslabs.com
Complaints go to Grievance Officer, Dr.Omics Labs at
grievance@dromicslabs.com. If we do not resolve it,
you can complain to the Data Protection Board of India.
Security policy v1 · 01 Aug 2026 ·
Read alongside the full privacy notice.
← Back to the consent form