Privacy Policy
Last updated: 29 September 2026
This Privacy Policy explains how Pharma Mithra (operated by COMPLYNEX TECHNOLOGIES (OPC) PRIVATE LIMITED) collects, uses, and protects your information when you use our website, applications and services (the "Platform"). We process personal data in accordance with this Policy and the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian law. By creating an account and using the Platform you consent to the processing of your account data as described here.
Nature of the service. Pharma Mithra is a business-to-business (B2B) regulatory-compliance tool. Most of the information you look up — drug licences, GST and FSSAI registrations of businesses — is publicly-available regulatory information about business entities that has been made public by or under law, and is not your personal data. Under Section 3(c)(ii) of the DPDP Act, that Act does not apply to personal data that a person has made or caused to be made publicly available under a legal obligation. The personal data this Policy is chiefly concerned with is the limited account data you give us to sign in and use the service.
1. Information we collect
- Account & profile: your name, mobile number, business/shop name, city, state, preferred language, and optionally your email, your own drug-licence number and GSTIN.
- Verification activity: the licence numbers, GSTINs and FSSAI numbers you search, the results returned, and records you save. This is your search history and is linked to your account — see "Your activity" below for exactly what we do and do not do with it.
- How numbers are typed: separately from the above, we keep a record of the text entered in a lookup, its outcome, and which matching rule answered it, without your account identity. It is used only to make the matching better — licence numbers are printed in many different ways — and is deleted after 180 days.
- Photos you scan: when you photograph a licence, most reading happens on your device and the picture never leaves it. Two features are different and say so on screen — reading a messy or handwritten number, and the medicine price check — where the image is sent to our reading service, used only to produce the text, and not stored afterwards by us. We never use your photographs for advertising or to train anything of our own.
- Payment: when you subscribe, our payment provider processes your payment; we receive a transaction/payment reference but do not store your full card details.
- Technical: basic log and device data needed to operate and secure the service.
2. How we use your information
We use your information to provide and improve the service; to authenticate you via one-time password (OTP) sent over SMS/WhatsApp; to run and display verifications; to send you service, expiry and re-verification alerts (where your plan includes them); to process payments; to enforce plan limits and fair usage; and to comply with legal obligations.
3. Your activity — what we do, and what we will never do
Which licences you check reveals who you buy from, and that is your commercial information. We treat it that way. We never tell anyone whose licences you check, and we never show a business who checked it. We do not sell, licence or share your search history, and we do not build or supply any product that links a named buyer to a named supplier.
Your activity is used in exactly three ways:
- Shown back to you. Your own history and supplier network, visible only to you when signed in.
- Counts for a business about itself. If a business proves it holds a licence (by adding and verifying that licence on its own account), we may show it how many other users checked that licence, and in which states — never who they were, never their names, and a state is shown only when enough different users are present that no single one could be identified.
- Aggregate statistics. Market-level figures, such as the share of licences checked in a state that were close to expiry. A figure is published only when at least 25 different accounts contributed to it, and such statistics contain no licence numbers, no business names and no account identifiers.
We also use activity data internally to improve the service: to decide which official registers to collect next, and to improve how typed licence numbers are matched.
4. Legal basis for processing
We process your account data on the basis of your consent (given when you create an account and verify your mobile number) and, where applicable, for the performance of the service you request, for our legitimate business uses (such as securing the Platform and preventing misuse), and to comply with legal obligations. You may withdraw consent at any time by closing your account (see "Your rights"); withdrawal does not affect processing already carried out. Verification of publicly-available business records is carried out to enable your own regulatory compliance and is not dependent on the consent of the business being looked up.
5. Verification data & third parties
Verification results are retrieved from official government portals and trusted data sources and relate to businesses/regulated entities, not to you personally. We use trusted third-party processors to operate the Platform, including our cloud/database provider, our OTP/messaging provider, our payment provider, and the data sources used for verification. These providers process data only as needed to deliver their part of the service.
6. People named in official records
The official registers we check are about licensed businesses, but some of those businesses are run by individuals, and the registers sometimes also carry details about people. We show only what a buyer needs to act on a licence: the firm name, its address, the licence numbers, and the licence status as the licensing authority records it.
We do not show anyone's mobile number or e-mail address, the names of registered pharmacists or competent persons, or the names of individuals that appear in enforcement notes. These are removed from every answer before it leaves our systems, whichever source it came from — on the website, in the app, in bulk checks and through our business API. Checking whether a pharmacist is registered is a separate feature, and shows only what the state pharmacy council itself publishes for that purpose.
If you are named in a record we show and believe it is wrong or should not appear, write to the Grievance Officer (below). We will correct or withhold it where the law allows, and point you to the licensing authority where the official record itself needs correcting.
7. Data storage, retention & location
Your data is stored on secured cloud infrastructure hosted in India. We keep your verification history for as long as your account exists, so that your own records, reports and supplier history remain available to you, and as required for legal, accounting and legitimate business purposes. You can ask us to delete it, or close your account, at any time (see "Your rights") — we then delete your personal data and your history, except anything the law requires us to keep. The identity-free record of how numbers are typed is deleted after 180 days. We practise data minimisation — we collect only what is needed to provide the service and keep status-critical results only for short, functional cache periods. Some of our sub-processors (for example messaging or infrastructure providers) may process limited data outside India; we do so only where permitted and will not transfer personal data to any country restricted by notification under Section 16 of the DPDP Act.
8. Sharing
We do not sell your personal information and we do not use it for advertising. We share it only with the third-party processors described above (each acting as a Data Processor on our documented instructions), or where required by law, court order, or to protect our rights and the safety of the Platform and its users. In particular, we do not disclose which businesses you have checked to any other user, customer or third party, in any product, report or dataset — see "Your activity" above.
9. Security
We use reasonable technical and organisational measures (including access controls and row-level data isolation so users can only access their own records) to protect your information. No method of transmission or storage is fully secure, and we cannot guarantee absolute security.
10. Your rights as a Data Principal
Subject to applicable law, you have the right to: access a summary of the personal data we hold about you and how we process it; seek correction, completion or updating of your data (you can edit most profile fields yourself from the Settings page); seek erasure of your data and closure of your account; nominate another individual to exercise your rights in the event of your death or incapacity; and raise a grievance with us. To exercise any of these, contact our Grievance Officer (below). We will respond within the timelines required by applicable Indian law. Some information may be retained where the law requires us to keep it.
11. How to delete your account and data
You can delete your account and everything we hold for it, without installing or opening anything:
- In the app or on the website: Settings → Delete my account, and type DELETE to confirm.
- By email: write to support@pharmamithra.com from your registered email address, or quote your registered mobile number, asking us to delete your account.
What is deleted: your profile, your verification and search history, your saved licences and trackers, your alerts, reports and any uploaded documents — all of it, not deactivated but removed. What may be kept: payment and invoice records we are required to retain under tax and accounting law, and identity-free records that can no longer be linked to you (such as aggregate counts). Deletion is immediate and cannot be undone.
12. Cookies
We use only the cookies/local storage necessary to keep you signed in and to operate the Platform. We do not use them to build advertising profiles.
13. Changes
We may update this Policy from time to time; the "Last updated" date will change. Continued use after an update constitutes acceptance of the revised Policy.
14. Grievance / contact
For any privacy question, to exercise your rights, or to raise a grievance, contact our Grievance Officer at support@pharmamithra.com. We will acknowledge and address grievances within the timelines required by applicable Indian law, including the DPDP Act.