Legal
DPDP Compliance
Digital Personal Data Protection Act, 2023 · Last updated: 13 August 2026
In one line
GRIOMED acts as a Data Processor. Your pharmacy is the Data Fiduciary for all customer / patient records uploaded into the system. We process this data strictly on your documented instructions.
Roles under the DPDP Act, 2023
Data Principal — the individual whose data is processed (the patient buying medicine from your pharmacy).
Data Fiduciary — the entity that determines the purpose and means of processing. For customer data uploaded into GRIOMED, the pharmacy is the Fiduciary.
Data Processor — the entity that processes data on behalf of the Fiduciary. GRIOMED acts as Processor under contract with the pharmacy.
Lawful basis for processing
- Consent — for marketing SMS / WhatsApp messages (clearly opt-in at the POS).
- Legitimate use under §7 — for issuing bills, processing payments, dispensing medicine, drug recall notifications, statutory tax reporting.
- Legal compliance — for Schedule H1 / X register entries, GST returns, drug regulator inspections.
Your rights as a Data Principal
If you are a customer of a pharmacy that uses GRIOMED, you have the following rights:
- Right to access your data and processing details.
- Right to correction of inaccurate or misleading data.
- Right to erasure where data is no longer needed (subject to legal retention).
- Right to nominate another individual to exercise rights in case of death or incapacity.
- Right to grievance redressal — see contact details below.
To exercise these rights, contact the pharmacy that holds your data. They will action your request and, where required, instruct us as their Processor.
Our technical & organisational measures
Encryption
TLS 1.2+ in transit, AES-256 at rest. Field-level encryption for mobile numbers and prescription content.
Access control
Role-based permissions, MFA for admin roles, per-tenant data isolation enforced at the database row level.
Audit log
Every privileged action (export, delete, view PII) is logged with actor, timestamp and IP for 2 years.
Localisation
Data stored exclusively in AWS Mumbai (ap-south-1). No cross-border transfer.
Backups
Daily encrypted backups, 35-day retention, replicated within India.
Breach notification
Affected pharmacies notified within 72 hours; we will also report to the Data Protection Board as required.
Significant Data Fiduciary status
GRIOMED is not currently designated a Significant Data Fiduciary under §10 of the DPDP Act. We voluntarily implement the additional controls (DPO appointment, periodic audit, DPIA) as a matter of good practice.
Data Protection Officer
For DPDP-specific queries or to file a complaint:
Data Protection Officer
GRIOMED Technologies Pvt. Ltd.
Email: dpo@griomed.in
Response within 30 days as required under §13(4) of the DPDP Act.
Escalation to Data Protection Board of India
If you are not satisfied with our response, you may approach the Data Protection Board of India directly. Details will be published on the Board's official portal once notified.
See also: Privacy Policy · Terms of Service