Griomed Global

Legal

DPDP Compliance

Digital Personal Data Protection Act, 2023 · Last updated: 13 August 2026

In one line

GRIOMED acts as a Data Processor. Your pharmacy is the Data Fiduciary for all customer / patient records uploaded into the system. We process this data strictly on your documented instructions.

Roles under the DPDP Act, 2023

Data Principal — the individual whose data is processed (the patient buying medicine from your pharmacy).

Data Fiduciary — the entity that determines the purpose and means of processing. For customer data uploaded into GRIOMED, the pharmacy is the Fiduciary.

Data Processor — the entity that processes data on behalf of the Fiduciary. GRIOMED acts as Processor under contract with the pharmacy.

Lawful basis for processing

  • Consent — for marketing SMS / WhatsApp messages (clearly opt-in at the POS).
  • Legitimate use under §7 — for issuing bills, processing payments, dispensing medicine, drug recall notifications, statutory tax reporting.
  • Legal compliance — for Schedule H1 / X register entries, GST returns, drug regulator inspections.

Your rights as a Data Principal

If you are a customer of a pharmacy that uses GRIOMED, you have the following rights:

  1. Right to access your data and processing details.
  2. Right to correction of inaccurate or misleading data.
  3. Right to erasure where data is no longer needed (subject to legal retention).
  4. Right to nominate another individual to exercise rights in case of death or incapacity.
  5. Right to grievance redressal — see contact details below.

To exercise these rights, contact the pharmacy that holds your data. They will action your request and, where required, instruct us as their Processor.

Our technical & organisational measures

Encryption

TLS 1.2+ in transit, AES-256 at rest. Field-level encryption for mobile numbers and prescription content.

Access control

Role-based permissions, MFA for admin roles, per-tenant data isolation enforced at the database row level.

Audit log

Every privileged action (export, delete, view PII) is logged with actor, timestamp and IP for 2 years.

Localisation

Data stored exclusively in AWS Mumbai (ap-south-1). No cross-border transfer.

Backups

Daily encrypted backups, 35-day retention, replicated within India.

Breach notification

Affected pharmacies notified within 72 hours; we will also report to the Data Protection Board as required.

Significant Data Fiduciary status

GRIOMED is not currently designated a Significant Data Fiduciary under §10 of the DPDP Act. We voluntarily implement the additional controls (DPO appointment, periodic audit, DPIA) as a matter of good practice.

Data Protection Officer

For DPDP-specific queries or to file a complaint:

Data Protection Officer

GRIOMED Technologies Pvt. Ltd.

Email: dpo@griomed.in

Response within 30 days as required under §13(4) of the DPDP Act.

Escalation to Data Protection Board of India

If you are not satisfied with our response, you may approach the Data Protection Board of India directly. Details will be published on the Board's official portal once notified.

See also: Privacy Policy · Terms of Service