1Who this Policy covers
Bioseed is a business application for planning, seed inventory and movement, field allocation, farmer and plot records, crop-stage work, quality and commercial workflows. This Policy covers the web console, mobile application, connected services and support channels that refer to it (collectively, the App).
The organisation that contracts for and administers Bioseed decides why its workforce and farmer records are entered into the App. Depending on the service arrangement and the data involved, Bioseed may act as a processor, data fiduciary or controller for a given deployment, and that role can differ between customers.
Controlling entity: Shriram Bioseed Genetics (a division of DCM Shriram Limited) is responsible for the personal data processed in the App, as data fiduciary. Contact details are in Contact us.
2Personal data we process
| Category | Examples used in Bioseed | Why it is used |
|---|---|---|
| Account and work identity | Examples used in BioseedName, work email, phone number, employee or user ID, role, reporting scope and Entra identity reference. | Why it is usedTo authenticate users, assign access, protect the App and contact an authorised user about work assigned to them. |
| Operational and agricultural records | Examples used in BioseedProduction plans, genetics and production codes, seed lots, quantities, acreage, dates, approvals, crop and quality records. | Why it is usedTo operate the seed-production lifecycle, calculate and reconcile inventory, and provide reporting. |
| Farmer and plot records | Examples used in BioseedFarmer name, parent or spouse name, phone number, date of birth where supplied, village, organiser, field officer, farmer code, plot and issued-seed information. | Why it is usedTo register growers, allocate seed, record field work and preserve lifecycle traceability. |
| Location and field measurements | Examples used in BioseedVillage and administrative area, plot boundaries, GPS points, location accuracy, measured area, capture time and device timezone. | Why it is usedTo measure and verify field area, link field work to the correct plot and support agronomic operations. |
| Evidence and attachments | Examples used in BioseedPhotographs, uploaded spreadsheets, documents, image metadata and workflow evidence. | Why it is usedTo support a submitted workflow step, investigate discrepancies and maintain an audit trail. |
| Usage and security records | Examples used in BioseedSign-in and access events, permissions, audit history, device push token, notification delivery status, error and service logs. | Why it is usedTo secure the App, investigate incidents, send task notifications and maintain reliable operations. |
| Technical and device data | Examples used in BioseedIP address, device and browser or app-version identifiers, operating system, network or telecom-provider information and approximate connection-based location. | Why it is usedTo operate the App reliably across devices and networks, diagnose faults and protect against misuse. |
Bioseed is designed so that a full Aadhaar number is not retained in the App. Where Aadhaar is used in the farmer-onboarding process, the service keeps only a masked last four digits and a protected one-way deduplication value. PAN is not an accepted Bioseed field.
3Principles we follow
- We collect personal data only for a lawful purpose connected to operating the App, and only where that collection is necessary for the purpose.
- We do not collect a category of personal data beyond what is listed in this Policy or the applicable customer agreement.
- We do not retain personal data for longer than it is needed for the purpose it was collected, or as a legal, audit or contractual requirement permits.
- We apply the security practices and access controls described in Section 9 (Security and offline use) to the personal data we hold.
- We handle any information that would qualify as sensitive personal data under applicable Indian law, such as an account password, with the corresponding safeguards under that law.
4How we collect data
- Directly from an authorised user or grower through a form, spreadsheet upload, photograph, GPS survey, support request or workflow action.
- From the customer organisation, such as user setup, reporting lines, location and master data, production data or identity-directory information.
- Automatically from the App and device, such as IP or service logs, session and access data, notification token and technical diagnostics.
- From connected services selected for the deployment, including identity, hosting, push-notification and offline-sync providers.
5Purposes and basis for processing
We process personal data only for a lawful business purpose connected to the App. This includes provisioning and authenticating accounts; applying role and location permissions; planning and executing seed-production workflows; registering farmers and plots; measuring fields; recording seed movements, approvals, quality and commercial outcomes; sending in-app and device notifications; providing support; preventing fraud, misuse and security incidents; meeting recordkeeping obligations; and improving reliability and usability.
Where consent is the appropriate basis, including a farmer-consent step in the onboarding workflow, Bioseed records that consent, its notice version and the channel through which it was given. The customer organisation and the user entering the data are responsible for giving farmers a notice they can understand, in a language used in field operations, before consent is recorded. Withdrawal does not affect processing that was lawful before withdrawal, nor data we must retain for a legal, audit, safety or dispute purpose.
6Location, camera and notifications
The mobile App asks for foreground location permission when a user chooses to measure a field or capture a GPS boundary. The App does not require background location tracking for its field-measurement function. A user can refuse or later change location permission in device settings; GPS-dependent functions may then be unavailable or less accurate.
The mobile App asks for camera or photo-library permission only when a user chooses to attach photo evidence. It asks for notification permission to deliver workflow, action-required and escalation alerts. A user can switch either permission off in device settings. Turning notifications off does not remove work obligations or in-app notifications.
7Sharing and service providers
We do not sell personal data or use it for behavioural advertising. We disclose data only to the people and organisations that need it for the purposes in this Policy, subject to access controls and applicable agreements.
| Recipient | Purpose |
|---|---|
| Authorised customer users | PurposeRole- and location-scoped access to plan, inventory, farmer, field and workflow records. |
| Hosting, storage and security providers | PurposeSecure operation, database, attachment storage, backups, monitoring and incident response. |
| Identity provider | PurposeWorkforce sign-in and account identity, including Microsoft Entra where configured. |
| Mobile notification and sync providers | PurposeDelivery of push notifications and authorised offline data synchronisation, including Firebase or Apple services and PowerSync where configured. |
| Legal, regulatory and professional recipients | PurposeWhere law requires it, to protect rights or safety, or to defend a claim. |
Some providers may process data outside the state or country where it was collected. We use appropriate contractual, technical and organisational safeguards for such transfers, taking account of the service arrangement and applicable law.
8Retention and deletion
Bioseed retains personal data for as long as needed to operate the App, preserve agricultural and inventory traceability, meet legal or contractual retention requirements, resolve a dispute, enforce an agreement or maintain security. Customer administrators may have additional retention instructions under their agreement. When data is no longer required, we delete, anonymise or securely isolate it in accordance with the applicable schedule and backup cycle.
A request to erase data may be limited where deleting the information would impair a required seed-lot, farm, accounting, quality, audit, legal or security record. In that case, we will explain the applicable limitation where required.
How to request deletion. To ask for your account or personal data to be deleted, email raviteja.kandavalli@bioseed.com with the subject “Data deletion request”, giving your name and the phone number or email used in the App, or ask your administrator. Farmers may make the request through the field officer or organiser who registered them, or by the same email. We will verify the request and delete or anonymise the data, subject to the limits above.
9Security and offline use
Bioseed uses role- and location-based access controls, authenticated API access, audit trails, access logging, input validation, controlled attachment handling and operational monitoring. No system can promise absolute security. Users must protect their device, passcode and account, avoid sharing credentials, use current App versions and report suspected unauthorised access promptly.
The mobile App may store work data locally to support offline use and later synchronisation. Logging out is designed to clear local Bioseed data. A shared or lost device can still create risk, so users must use device-level security and notify their administrator if a device is lost, replaced or reassigned.
10Your rights and complaints
Subject to applicable law and the role of the customer organisation, a person may request access to, correction of, completion of, erasure of, or a summary of personal data; withdraw consent where processing relies on consent; nominate another person where permitted; and raise a grievance. For farmer records, requests may be made through the customer organisation. We may need to verify identity and authority before acting.
Where the Digital Personal Data Protection Act, 2023 (India) and its rules are in force and apply to a deployment, we will honour the rights and grievance-redressal routes it provides once those provisions have commenced, in addition to the rights described in this Policy.
If a person remains dissatisfied, they may use the escalation route available under applicable law, including the Data Protection Board of India where relevant and applicable.
To make a request or raise a grievance, use the details in Contact us.
11Children and sensitive entries
Bioseed is a workplace and agricultural-operations application and is not directed to children. Do not enter unnecessary identity, financial, health or other sensitive information. Full Aadhaar and PAN must not be entered except where a permitted, controlled workflow specifically instructs otherwise; full Aadhaar is designed to be immediately transformed rather than retained.
12Governing law and disputes
This Policy is governed by the law identified as the governing law of the applicable customer agreement. Any dispute about this Policy or the App is resolved as that agreement provides, without limiting a person's statutory rights or complaint routes under applicable data-protection law.
13Changes to this Policy
We may update this Policy to reflect changes in law, the App or our processing. The current version and effective date will be made available through the App, website or the customer administrator. Where required, we will give additional notice or seek consent before a material new use of personal data.
Contact us
For privacy questions, data requests or grievances about the Bioseed App, contact:
- Organisation
- Shriram Bioseed Genetics (a division of DCM Shriram Limited)
- Grievance / privacy contact
- Legal Cell
- raviteja.kandavalli@bioseed.com
- Postal address
- Shriram Bioseed Genetics (A Division of DCM Shriram Limited)
Plot No. 234, B Block Phase II, Kavuri Hills, Madhapur
Hyderabad – 500 033, Telangana, India