Security
Overview
Bhargava Phytolab Pvt Ltd takes the security of your data, credentials, and personal information seriously. This Security Policy describes the technical and organizational measures we implement to protect the Doctor Portal and its users, and the responsibilities you accept as a registered doctor user in maintaining the security of your account.
1. Data Security Measures
1.1 Encrypted Data Transmission
All data transmitted between your device and the Doctor Portal is encrypted using industry-standard SSL/TLS protocols, ensuring your login credentials, order data, and personal information are protected during transmission.
1.2 Secure Data Storage
All personal data is stored on secure servers with restricted access. We implement access controls, firewalls, and intrusion detection systems to prevent unauthorized access to our systems.
1.3 Password Hashing
Passwords are never stored in plain text. All passwords are processed using industry-standard one-way hashing algorithms before storage, ensuring your password cannot be recovered even in the event of a data breach.
1.4 Payment Security
All payment transactions processed through the Portal are handled by PCI-DSS compliant payment gateways. We do not store your payment card details on our servers at any point.
1.5 Regular Security Reviews
We conduct periodic security assessments of our platform infrastructure, including vulnerability scanning and review of access logs, to identify and address potential security risks proactively.
2. Account Security — Your Responsibilities
Your account security is a shared responsibility. As a registered user of the Doctor Portal, you agree to:
- Change your one-time password immediately upon first login.
- Use a strong, unique password for your Doctor Portal account — one not shared with other websites or applications.
- Never share your User ID (DB-XXXXX) or password with any other person.
- Not allow any unauthorized person to access the Portal using your credentials.
- Log out of your account after each session, especially when accessing from a shared or public device.
- Report any suspected unauthorized access immediately to d2d@bhargavaphytolab.com.
3. Credential Delivery Security
Upon successful verification, your login credentials are shared via two channels — a direct call to your registered mobile number and a WhatsApp message. This dual-channel delivery ensures that credentials reach only the verified account holder. You are responsible for keeping your registered mobile number secure and up to date.
4. Suspicious Activity & Reporting
4.1 Reporting Obligations
If you notice any suspicious activity on your account — unrecognized orders, changes to your profile, or login alerts you did not initiate — report this immediately by contacting d2d@bhargavaphytolab.com or calling our helpline.
4.2 Account Suspension on Breach
Where we detect unusual or potentially fraudulent activity on a registered account, we reserve the right to temporarily suspend access pending investigation. You will be notified and guided through the account recovery process.
4.3 Phishing Awareness
Bhargava Phytolab will never ask for your password via email, SMS, WhatsApp, or phone call after initial credential delivery. If you receive any such request purportedly from us, treat it as fraudulent and report it immediately.
5. Data Breach Response
In the event of a data breach that poses a risk to your personal data, we will notify affected users promptly via their registered contact details, notify the relevant regulatory authorities as required by applicable law, and take all necessary steps to contain, investigate, and remediate the breach.
6. Third-Party Security
We share your data with select third parties (logistics, payment processors, customer support) who are contractually required to maintain appropriate security standards. We conduct due diligence on all third-party partners to ensure compliance with applicable data security requirements.
7. Security Updates
Our security measures are reviewed and updated regularly in response to emerging threats and evolving best practices. Material changes to our security posture that affect your rights or experience will be communicated via the Portal or your registered contact details.