Privacy Policy

Last updated: 14 July 2026

This Privacy Policy explains how Pharma Mithra (operated by [Operating Legal Entity — insert registered company name]) collects, uses, and protects your information when you use our website, applications and services (the "Platform"). We process personal data in accordance with this Policy and the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian law. By creating an account and using the Platform you consent to the processing of your account data as described here.

Nature of the service. Pharma Mithra is a business-to-business (B2B) regulatory-compliance tool. Most of the information you look up — drug licences, GST and FSSAI registrations of businesses — is publicly-available regulatory information about business entities that has been made public by or under law, and is not your personal data. Under Section 3(c)(ii) of the DPDP Act, that Act does not apply to personal data that a person has made or caused to be made publicly available under a legal obligation. The personal data this Policy is chiefly concerned with is the limited account data you give us to sign in and use the service.

1. Information we collect

2. How we use your information

We use your information to provide and improve the service; to authenticate you via one-time password (OTP) sent over SMS/WhatsApp; to run and display verifications; to send you service, expiry and re-verification alerts (where your plan includes them); to process payments; to enforce plan limits and fair usage; and to comply with legal obligations.

3. Legal basis for processing

We process your account data on the basis of your consent (given when you create an account and verify your mobile number) and, where applicable, for the performance of the service you request, for our legitimate business uses (such as securing the Platform and preventing misuse), and to comply with legal obligations. You may withdraw consent at any time by closing your account (see "Your rights"); withdrawal does not affect processing already carried out. Verification of publicly-available business records is carried out to enable your own regulatory compliance and is not dependent on the consent of the business being looked up.

4. Verification data & third parties

Verification results are retrieved from official government portals and trusted data sources and relate to businesses/regulated entities, not to you personally. We use trusted third-party processors to operate the Platform, including our cloud/database provider, our OTP/messaging provider, our payment provider, and the data sources used for verification. These providers process data only as needed to deliver their part of the service.

5. Data storage, retention & location

Your data is stored on secured cloud infrastructure hosted in India. We retain your account and verification records for as long as your account is active and as required for legal, accounting and legitimate business purposes, after which we delete or anonymise them. We practise data minimisation — we collect only what is needed to provide the service and keep status-critical results only for short, functional cache periods. Some of our sub-processors (for example messaging or infrastructure providers) may process limited data outside India; we do so only where permitted and will not transfer personal data to any country restricted by notification under Section 16 of the DPDP Act.

6. Sharing

We do not sell your personal information and we do not use it for advertising. We share it only with the third-party processors described above (each acting as a Data Processor on our documented instructions), or where required by law, court order, or to protect our rights and the safety of the Platform and its users.

7. Security

We use reasonable technical and organisational measures (including access controls and row-level data isolation so users can only access their own records) to protect your information. No method of transmission or storage is fully secure, and we cannot guarantee absolute security.

8. Your rights as a Data Principal

Subject to applicable law, you have the right to: access a summary of the personal data we hold about you and how we process it; seek correction, completion or updating of your data (you can edit most profile fields yourself from the Settings page); seek erasure of your data and closure of your account; nominate another individual to exercise your rights in the event of your death or incapacity; and raise a grievance with us. To exercise any of these, contact our Grievance Officer (below). We will respond within the timelines required by applicable Indian law. Some information may be retained where the law requires us to keep it.

9. Cookies

We use only the cookies/local storage necessary to keep you signed in and to operate the Platform. We do not use them to build advertising profiles.

10. Changes

We may update this Policy from time to time; the "Last updated" date will change. Continued use after an update constitutes acceptance of the revised Policy.

11. Grievance / contact

For any privacy question, to exercise your rights, or to raise a grievance, contact our Grievance Officer at grievance@pharmamithra.com [insert Grievance Officer name & postal address]. We will acknowledge and address grievances within the timelines required by applicable Indian law, including the DPDP Act.

Note: This document is a general template and not legal advice. Please have it reviewed by a qualified lawyer and insert your registered legal entity, grievance officer details, and jurisdiction, and align it with the Digital Personal Data Protection Act, 2023 and applicable IT rules before going live.