Legal
Privacy policy
What this website collects, why it collects it, and what we will never do with it. Written in plain language, because that is how we write everything else.
Effective 6 Aug 2026
At a glance
The short version.
One form, seven fields
There is one form on this website and it sits on the homepage. It asks who you are, where you work, and how your plant prepares batch records today.
No trackers, no ad cookies
No advertising cookies, no cross-site tracking, no analytics of any kind at the time of writing. If that changes, this page changes first.
Your formula never comes here
No master formula, bill of materials or batch record passes through pharmasynapse.ai. Not for a demo, not for processing, not for storage.
We do not sell anything about you
No personal data is sold, and none is shared with anyone for their own marketing. Ever, and not as a matter of current practice — as a matter of policy.
This summary is written to be read in fifteen seconds and it is not the policy. Where the summary and the clauses below differ, the clauses govern.
01
Who we are, and what this policy covers
This website, pharmasynapse.ai, is operated by Brainy Neurals Private Limited, an AI engineering company incorporated in India on 23 November 2023. PharmaSynapse is a Brainy Neurals product, not a separate company. In this policy, “we” means Brainy Neurals.
Personal data is handled under India’s Digital Personal Data Protection Act, 2023 and the rules made under it. Where you are in the European Union or the United Kingdom, the rights described in clause 07 are the ones the GDPR and the UK GDPR give you, and we honour them.
This policy covers the website only: the pages you are reading, the one form on them, and the correspondence that follows. It does not cover data processed inside a deployed PharmaSynapse system. Deployments are single-tenant and run under each client’s own signed agreement, which governs that data entirely. The distinction is not a technicality and clause 04 sets it out.
02
What the early-access form collects
There is one form on this website. It sits at the foot of the homepage and it is the only place this site asks you for anything. Nothing is gated: no page, resource or download on this site requires an email address to read.
The form asks for seven things, and this is all of them:
Why we ask. The first three tell us who to reply to. The last three are commercial qualification: they tell us whether early access would be useful to you before we spend your time on a call. We are honest about that rather than describing it as personalisation.
What we do with it. Reply to you, decide whether to offer early access, and keep a record of the exchange. It is not used to build a profile, it is not enriched from third-party sources, and it is not passed to anyone for their own marketing.
What not to put in the free-text field. Do not send us a master formula, a batch record, or anything your document control would restrict. Controlled documents change hands only under a signed agreement with a defined handling procedure. Clause 04 explains why.
03
Correspondence and technical data
Correspondence. If we exchange emails after you write to us, we keep the thread, so the conversation has a record and neither side has to repeat itself.
Technical data. Like every website, our server records basic request data: IP address, browser type, pages requested, and timestamps. We use it to keep the site running and to detect abuse. It is not joined to form submissions and it is not used to identify individual readers.
Cookies and tracking
This site sets no advertising cookies and runs no cross-site tracking. At the time of writing it runs no analytics at all. If we ever add analytics it will measure pages in aggregate rather than people, and this policy will say so before it runs, not after.
The fonts, styles and scripts this site uses are served from our own domain. There is no third-party font, tag manager or embedded widget on any page, which means no third party learns that you visited.
04
Your formula never touches this website
A PharmaSynapse deployment handles master formulae, bills of materials and batch documentation. None of that data passes through pharmasynapse.ai — not for demonstrations, not for processing, not for storage.
Deployments are single-tenant, installed per client, and the data inside them belongs to and stays with that client under their own agreement. This website has no route into a deployment and holds no client document data of any kind.
The personal data a deployment does process is limited to client-employee data — the names and signatures of the people who prepare, review and approve records, because a GMP record is not a record without them. There is no patient data anywhere in the system.
05
Who else sees it
The only third parties that touch website data are the service providers that run it for us — hosting and email delivery. They act on our instructions and for the purposes described above, and nothing more.
We disclose personal data beyond that only where the law requires it. We do not sell personal data, we do not trade it, and we do not share it with anyone for their own marketing.
Where the data sits
We are an Indian company and website data is processed in India. If you are writing to us from the European Union, the United Kingdom or elsewhere, your submission crosses a border to reach us. That transfer happens because you chose to write to us, and the safeguards that apply are set out in your rights below.
06
How long we keep it
Form submissions and correspondence are kept while the conversation is live and for a reasonable period afterwards, then deleted. Server logs are kept briefly for security and then discarded. We keep nothing longer than its purpose justifies.
You can ask us to delete your submission at any point without giving a reason, and clause 07 explains how. We do not require you to have a reason and we do not ask for one.
07
Your rights, and how to use them
You can ask us what personal data we hold about you, ask us to correct it, or ask us to erase it. Where processing rests on your consent, you can withdraw that consent as easily as you gave it, and we stop.
- Under India’s Digital Personal Data Protection Act, 2023 you have the right to access, correction and erasure, the right to grievance redressal, and the right to nominate another person to exercise your rights on your behalf.
- Under the GDPR and the UK GDPR you have the rights of access, rectification, erasure, restriction, objection and data portability, and the right to complain to your supervisory authority without going through us first.
How to exercise them
Requests are read by a founder, not a queue. Where one concerns a record rather than this website, it goes to Kinjal Patel and the answer still comes from a person.
08
Children
This website is written for pharmaceutical professionals and is not directed at anyone under 18. We do not knowingly collect children’s data. If you believe a child has submitted data to us, write to us and we will delete it.
09
Changes to this policy
When this policy changes, the new version is published here with a new effective date. Earlier versions are available on request — we do not overwrite our own record, on this page or in the product.
If a change materially affects what we do with data you have already given us, we tell you before it takes effect rather than relying on you to re-read the page.
One form, seven fields, and no trackers. Your master formula never reaches this website — not for a demonstration, not for processing, not for storage.
Questions
A person answers these, not a queue.
Privacy questions go to the same two people everything else does. Kinjal reads the ones about records, Mitesh reads the ones about systems, and either can action a deletion.