Privacy Policy
Last updated 29 August 2026
TechNest Pharma operates a private, invite-only sourcing platform used by pharmaceutical importers to find raw-material suppliers, run tenders, and correspond with those suppliers. This policy explains what the platform collects, why, and how long it is kept.
The platform is not a consumer service. Accounts exist only because an administrator created one; there is no public sign-up, and the platform is not directed at children.
1. Who we are
TechNest Pharma (“we”, “us”) operates this platform from Bangladesh and acts as the data controller for the information described below. You can reach us at privacy@technestpharma.cloud.
2. What the platform holds
- Account data — your name, work email address, role, profile photo if you upload one, and a hashed password. Passwords are stored using Argon2id and are never recoverable, by us or by anyone else.
- Usage and security data — sign-in sessions, the device and browser that created them, and an audit log of administrative actions. This is how account takeover is detected and how a user can revoke a session they do not recognise.
- Business records — suppliers, contacts, products, offers, tenders, and sourcing enquiries entered by your organisation, including business contact details for supplier personnel.
- Supplier correspondence — the email conversations described in section 3.
3. Data accessed through Google APIs
A user with the owner role may connect one Gmail account so that supplier enquiries are sent from the organisation’s own address and the replies come back onto the enquiry that produced them. Connecting is optional; the rest of the platform works without it. We request exactly two scopes:
gmail.send— to send the enquiry emails you compose and approve in the platform. It is used for nothing else, and no message is ever sent without a user pressing Send.gmail.readonly— to read the supplier’s replies to those enquiries. Read-only rather than a modify scope on purpose: a fault in our software cannot alter or delete anything in your mailbox.
From those threads, the platform stores:
- the message subject, body text, sender and recipient addresses, and the date it was sent or received;
- the Gmail message and thread identifiers, which is how a reply is matched to the enquiry that caused it;
- attachment metadata only — filename, file type, and size. Attachment contents are not copied into our systems; when someone opens one it is streamed from Gmail on demand and not retained.
The Google authorisation token that makes this possible is encrypted at rest (AES-128-CBC with HMAC-SHA256 authentication) using a key held outside the database, so a database backup is not a usable mailbox credential.
4. Google API Services Limited Use
Concretely, and without exception:
- we do not sell Google user data, and we do not transfer it to data brokers or information resellers;
- we do not use Google user data for advertising, ad targeting, or ad personalisation;
- we do not use Google user data to develop, train, improve, or fine-tune any artificial-intelligence or machine-learning model, whether ours or a third party's;
- no human at TechNest Pharma reads your Gmail data, except where you have given us explicit permission for a specific support issue, where it is necessary for security purposes such as investigating abuse, or where we are compelled to by law.
5. How the data is used
Everything above is used to operate the platform for the organisation that entered it: sending and tracking enquiries, matching supplier replies to the right enquiry, comparing quotations against a tender, and keeping the audit and security records that a regulated purchasing process needs. We do not use it to build profiles, and we do not use one customer’s data to serve another.
7. Retention and deletion
Business records and supplier correspondence are kept for as long as your organisation keeps its account, because a sourcing history is the point of the product — a quotation from two years ago is what this year’s price is judged against.
Disconnecting the mailbox in Settings → Email Config revokes our access at Google immediately and deletes the stored authorisation token. Messages already synced are kept, since they are part of the sourcing record — if you want those erased as well, email us and we will delete them.
You can also revoke our access at any time, without involving us, from your Google Account’s Third-party apps & services page.
8. Security
Access requires an account created by an administrator, and two-step verification is available and recommended. Traffic is encrypted in transit with TLS. Passwords are hashed with Argon2id; Google refresh tokens are encrypted at rest. Administrative actions are written to an audit log. No system is immune, and we do not claim otherwise — if a breach affects your data we will tell you and the relevant authority promptly.
9. Your rights
You may ask for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. Some records must be retained where we have a legal obligation to keep them. Write to privacy@technestpharma.cloud and we will respond within 30 days.
10. Changes to this policy
If we change what the platform collects or how it is used, this page is updated and the date at the top changes with it. Material changes affecting the Google data in section 3 will also be notified to account owners by email.
See also our Terms & Conditions.