1. Legal Scope & Introduction
This Privacy Policy governs the collection, processing, and management of data by myRxSetu ("Platform"), which is owned and operated by GlobalHope Biotech OPC Private Limited ("Company", "we", "our", or "us"), incorporated under the Companies Act, 2013, in India.
This policy is specifically written to comply with the Digital Personal Data Protection (DPDP) Act, 2026, the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the statutory requirements of the Drugs and Cosmetics Rules, 1945.
This document describes our practices when you visit our website, register a pharmacy tenant account, purchase subscription plans, use our offline-first point-of-sale (POS) systems, or integrate your WhatsApp Business Account (WABA) using our Tech Provider tools.
2. Data Roles & Definitions
To ensure transparency under Indian data protection laws, we define the respective data roles as follows:
- Data Fiduciary: Your registered pharmacy is the Data Fiduciary for the personal data of patients you upload, manage, or contact through the platform. You determine the purpose and means of processing this data.
- Data Processor: The Company acts as the Data Processor for patient records and billing histories. We process this data strictly on your behalf and under your written instructions.
- Co-Data Fiduciary / Sole Data Fiduciary: The Company acts as a Data Fiduciary for your business registration details, billing information, user accounts, and support tickets where we determine the processing purpose.
- Data Principal: The individual pharmacy owners, staff members, pharmacists, and end-patients whose personal data is processed on our platform.
3. Legal Basis of Processing under DPDP Act, 2026
We process personal data only when a valid legal basis exists. Under the DPDP Act, 2026, the primary grounds are:
- Explicit Consent: Where the data principal has given clear, affirmative, specific, and revocable consent (e.g., opting in to receive digital receipts via WhatsApp or connecting a Google account).
- Contractual Obligation: Where processing is necessary to perform our obligations under the SaaS subscription terms (e.g., executing inventory sync, generating invoices, processing wallet credits, and providing technical support).
- Compliance with Law: Where we must retain or share records to satisfy statutory requirements (e.g., maintaining sales records of Schedule H drugs, GST invoice audits, and tax reporting).
4. Detailed Data Collections
4.1 Business & Pharmacy Account Information
To verify and maintain your pharmacy subscription, we collect the following business details:
- Identity Verification: Full name of the owner, managing pharmacist, drug license registration certificates (specifically Form 20 and Form 21, along with the validity dates), and professional pharmacist registration numbers.
- Tax and Corporate Registry: Goods and Services Tax Identification Number (GSTIN), Corporate Identity Number (CIN) for corporate chains, and business registration certificate copies.
- Contact Details: Pharmacy physical address, billing address, pin code, business email addresses, and active mobile numbers.
- Payment Logs: Subscription transaction references, subscription plan tiers, and Setu Wallet top-up details. We do not store raw card numbers or Net Banking credentials on our servers. All transactions are securely routed through certified Indian payment gateways.
4.2 Patient & Prescription Information
When your staff uses our billing, POS, and digital prescription tools, they input data on our servers. We process this strictly under your instruction:
- Patient Identity: Full name, age, gender, mobile number, and active WhatsApp account indicators.
- Clinical Records: Digital images of prescriptions, doctor names, hospital details, diagnostic summaries (if noted on the prescription), and full lists of dispensed drugs (including batch number, manufacturing date, expiry date, composition, and salt details).
4.3 Technical & Usage Data
We automatically capture system metrics when you use our cloud or offline-first web interface:
- Device Information: Browser type, operating system version, local database sync status, screen resolution, and IP address.
- Usage Logs: Action timestamps, page views, search queries made in the medicine catalog, sync latencies, and transaction volumes.
5. Google OAuth & Access Scope
Our Platform offers optional Google OAuth integration to simplify account verification:
- Google Sign-In: If you choose to log in using Google, Google shares your primary email address, name, profile picture, and account ID. This data is used solely to authenticate your identity and link your staff profile to your pharmacy tenant.
- No Intrusion: We do not ask for, read, or store data from other Google services, such as Google Drive, Contacts, or Calendar. Your authorization is managed via secure, encrypted OAuth tokens that you can revoke at any time from your Google Account Security Dashboard.
6. WhatsApp Integration & India Data Residency
When utilizing the WhatsApp Setu module to transmit digital bills and notifications, we implement the following technical data protection standards:
All WhatsApp phone numbers and configuration variables managed through our integration are stored locally within Indian boundaries. The Graph API requests explicitly configure data_localization_region: "IN" to ensure patient phone numbers and template texts are localized.
Patient message histories, transaction logs, and WABA credentials are isolated in a physically separate SQLite/LibSQL database per pharmacy tenant. We do not co-mingle healthcare metrics or chat strings across different subscribers.
Prescription images, PDF bills, and medical media files transmitted by patients are stored in local, secure cloud storage buckets (Cloudflare R2 India). Storage download links generated expire automatically within 30 days of transmission.
7. Purpose & Use of Data
We process your personal and business data for the following specific purposes:
- To provision and maintain the offline-first pharmacy billing, catalog search, and inventory dashboard.
- To execute transaction updates, tax summaries, and low-stock alerts.
- To deliver automated patient notices (refills, payment confirmations, order status) via WhatsApp or SMS, as configured by the pharmacy.
- To secure our infrastructure, prevent fraudulent sign-ups, and verify the validity of drug license credentials.
9. Retention & Statutory Mandates
We retain personal data only as long as necessary to fulfill the purposes outlined in this policy or as required by applicable laws:
- Account Records: Tenant profile details are maintained for the active duration of the subscription and are archived for 180 days post-termination before permanent deletion.
- Setu Wallet Logs: Transaction ledgers and UPI records are preserved for 7 years to comply with Indian financial reporting laws.
- Prescription Records: In compliance with the Drugs and Cosmetics Rules, 1945, records of prescriptions and schedule drug logs must be preserved by retail pharmacies for a minimum statutory period. We maintain these digital archives for the pharmacy tenant and do not delete them immediately upon account suspension unless mandated by court order.
10. Technical Security & Tenant Isolation
We implement robust security practices to safeguard data:
- Transit Security: All connections to our servers are encrypted using TLS 1.3 / HTTPS. All browser sessions are guarded by authenticated JWT tokens.
- Database Encryption: Per-tenant SQLite/LibSQL databases are encrypted at rest using AES-256 with key management isolated from the storage layer.
- Physical Isolation: We do not utilize shared database schemas for different tenants. Patient logs, inventory tables, and WABA credentials are contained within dedicated database volumes.
11. Data Principal Rights under DPDP Act, 2026
Indian data principals (including your pharmacy staff and patients) have the following legal rights:
- Right to Access: You can request a summary of the personal data we hold about your business or patients.
- Right to Correction: You can request that we update outdated or incorrect registration details (GSTIN, license numbers, etc.).
- Right to Erasure: You can request the deletion of your account and associated contact history, subject to the retention exemptions defined in Section 9.
- Right to Withdraw Consent: You can withdraw consent for voluntary processing paths (e.g., SMS alerts) at any time.
12. Data Grievance Redressal & Contact
If you have questions, security concerns, or wish to file a formal complaint regarding data management, please contact our designated Grievance Officer directly: