Griomed Global

Legal

Privacy Policy

Last updated: 13 August 2026

GRIOMED Technologies Pvt. Ltd. ("we") respects your privacy. This Policy explains what personal data we collect, how we use it, and the rights available to you under the Digital Personal Data Protection Act, 2023 (DPDP Act).

1. Data we collect

From pharmacy operators (account holders): name, email, mobile, address, GSTIN, drug licence number, business legal name, payment method tokens (no full card numbers).

From end-customers (your patients): name, mobile, optional email, optional date of birth, allergies, prescriptions, purchase history, loyalty balance. This data is uploaded by the pharmacy on the customer's behalf — we are the processor, the pharmacy is the data fiduciary.

Automatically: IP address, browser type, pages visited, request timestamps. Stored in audit logs for security and DPDP compliance.

2. How we use it

  • To provide and operate the Service.
  • To send transactional emails / SMS (bill, OTP, recall notice, subscription invoice).
  • To detect fraud, abuse and security incidents.
  • To comply with legal obligations (GST returns, drug regulator audits).
  • To improve the product — aggregated, non-identifying usage stats only.

We do not sell personal data. We do not show advertising. We do not share customer data with third parties for marketing.

3. Where data is stored

All data is hosted on AWS Mumbai region (ap-south-1). Backups are encrypted at rest using AES-256 and replicated within India. Field-level encryption is applied to mobile numbers and prescription content. Data does not leave India.

4. Sub-processors

We use the following sub-processors, each contractually bound to DPDP-equivalent obligations: Amazon Web Services (hosting), Razorpay (subscription payments), MSG91 / Gupshup (SMS), Meta WhatsApp Cloud (WhatsApp messaging), NIC IRP & NIC EWB (e-invoice, e-way bill — only when the pharmacy enables those modules).

5. Retention

Account data is retained while the subscription is active and for 30 days thereafter for export. Transactional / accounting records are retained for 8 years (tax law). Audit logs are retained for 2 years. End-customer data is retained per the pharmacy's instructions, subject to applicable law.

6. Your rights

Under the DPDP Act you have the right to: (a) access your data, (b) correct inaccurate data, (c) erase data not needed for legal compliance, (d) nominate a successor, (e) grievance redressal. See our DPDP Compliance page for how to exercise these rights.

7. Cookies

We use only first-party cookies strictly necessary for session management, CSRF protection and remembering your preferences. No third-party analytics or advertising cookies.

8. Children

The Service is intended for adult pharmacy operators. We do not knowingly collect data from children under 18 as account holders. End-customer prescriptions of minors are handled by the pharmacy under existing healthcare law.

9. Security

We follow industry-standard practices: TLS 1.2+ in transit, AES-256 at rest, MFA for admin accounts, daily encrypted backups, role-based access control, audit logging of every privileged action. In the event of a breach affecting your data, you will be notified within 72 hours.

10. Contact

Privacy queries: privacy@griomed.in
Data Protection Officer: see DPDP page for details.