Privacy policy
This policy explains what personal data Pharmizo handles, why, for how long, and what you can ask us to do about it.
Last updated 1 August 2026. This policy is published by [LEGAL ENTITY NAME] Private Limited, referred to below as “we”, “us” or “Pharmizo”.
1. Two different roles
Pharmizo handles personal data in two distinct capacities, and your rights differ depending on which applies to you.
- As a Data Fiduciary
- For people who deal with us directly — visitors to this website, prospects who contact sales, and the administrators of our customers — we decide how the data is used, and this policy governs it.
- As a Data Processor
- For data that a customer company loads into its own tenant — its employees, the doctors, chemists and stockists it records — the customer decides how that data is used and we act only on its instructions. If you are a doctor or an employee asking about records held about you, your request goes to that company, not to us. Tell us and we will route it to them.
2. What we collect
When you contact us
- Your name, work email address, telephone number, company and role.
- Whatever you choose to put in the body of your enquiry.
This site has no contact form and no analytics. Enquiries reach us as ordinary email, which means your message and address sit in our mail system in the normal way.
When you use the platform
- Account data — name, email address, role, the manager you report to and the organization you belong to. Your account is created by your employer, not by you.
- Authentication data — a hashed password (we never store or can read the plaintext) and session tokens held in secure, HTTP-only cookies.
- Activity records — an append-only log of privileged actions, recording who did what and when, together with the source IP address.
- Content you enter — whatever the modules your organization has enabled require. Your employer determines this, not us.
Cookies
We set only what is strictly necessary to keep you signed in and to protect forms against cross-site request forgery. No advertising cookies, no third-party trackers, no analytics beacons. Because none of it is optional or used for profiling, there is no consent banner — there would be nothing to decline.
3. Why we use it
- To provide the platform, authenticate you and enforce what your role may see.
- To bill your organization and keep the statutory records that requires.
- To keep the service secure, investigate abuse and diagnose faults.
- To answer your enquiries and support requests.
- To meet legal obligations, including tax and accounting.
We do not sell personal data, we do not share it with advertisers, and we do not use it to train machine-learning models.
4. Where it is stored, and for how long
The platform runs on dedicated infrastructure in Falkenstein, Germany, operated by Hetzner Online GmbH. Backups are streamed continuously to object storage in the same region. Personal data is therefore transferred outside India for storage and processing, which is permitted under section 16 of the Digital Personal Data Protection Act, 2023. Traffic to the platform is encrypted in transit with TLS.
- Account data
- Kept while your account exists. When it is deleted it is marked deleted and hidden rather than erased, so that it can be restored and so the audit trail stays coherent. It is purged on your organization’s instruction, or when its contract ends and the wind-down period has passed.
- Backups
- Retained on a rolling seven-day window and then automatically expired. A record deleted today may therefore persist in backups for up to seven days.
- Audit records
- Retained for the life of the organization’s account. These cannot be edited or deleted by anyone, including us — that is the point of them.
- Invoices and tax records
- Retained as long as Indian tax and companies legislation requires, independently of account deletion.
- Enquiry email
- Retained while a commercial conversation is live, and for a reasonable period after.
5. Who else sees it
We share personal data only with the processors we need to run the service, and only to the extent each needs:
- Hetzner Online GmbH (Germany) — hosting and object storage.
- [EMAIL PROVIDER] — transactional email such as password resets and notifications.
- [PAYMENT GATEWAY] — subscription payments. Card details go to the gateway, not to us; we never see or store them.
We may also disclose data where the law compels us to, and we will tell the affected organization unless we are prohibited from doing so.
6. Your rights
Under the Digital Personal Data Protection Act, 2023, where we act as Data Fiduciary you may ask us to:
- confirm what data we hold about you and give you a summary of it;
- correct, complete or update data that is inaccurate;
- erase data we no longer have a lawful reason to keep;
- nominate someone to exercise these rights if you die or become incapacitated;
- have a grievance addressed, before escalating to the Data Protection Board.
Write to [PRIVACY@EXAMPLE.COM]. We respond within 30 days. We may ask you to verify your identity first — we are not going to hand your record to whoever asks for it. Where the data belongs to a customer’s tenant, we forward your request to that customer and tell you we have.
7. Security
Passwords are hashed, sessions use secure HTTP-only cookies, all traffic is served over HTTPS with HSTS, each organization’s data is scoped to its own tenant, and privileged actions are written to an append-only log. Our security practices page has the detail. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you and the Data Protection Board as the Act requires.
8. Children
Pharmizo is a workplace tool and is not directed at children. We do not knowingly collect data about anyone under 18. If you believe we have, write to us and we will delete it.
9. Changes
If we change this policy we update the date at the top of this page, and for material changes we notify customer administrators by email before the change takes effect.
10. Contact
Privacy enquiries: [PRIVACY@EXAMPLE.COM]
Grievance Officer, as required by section 13 of the Act: [GRIEVANCE OFFICER NAME], [GRIEVANCE@EXAMPLE.COM]
[LEGAL ENTITY NAME] Private Limited, [REGISTERED ADDRESS, LINE 1], [LINE 2], [CITY, STATE — PIN], India