PharmIT
Legal

Privacy policy

This policy explains what personal data we collect when you use PharmIT products, how we use it, who we share it with, and the rights you have under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”).

Effective from 12 July 2026

1. About this policy

PharmIT Services Private Limited (“PharmIT”, “we”, “us”) provides a suite of software for pharmaceutical distribution, including the PharmIT ERP web console (pharmit.live) and the PharmIT ERP field-sales mobile application (the “App”). This policy applies to all personal data we handle in connection with these products, our marketing website, and our sales and support activities.

2. Who we are (Data Fiduciary)

For the purposes of the DPDP Act, PharmIT Services Private Limited is the Data Fiduciary for personal data provided directly to us (for example, prospects contacting our sales team, or visitors to our marketing website).

For personal data uploaded or created by our customers (pharmaceutical distributors, C&F agents, super-stockists, chains and hospitals) inside their PharmIT tenant, our customer is the Data Fiduciary, and PharmIT acts as a Data Processor on their behalf under the Master Services Agreement executed with that customer.

3. Scope

This policy covers personal data collected via:

  • Our marketing and product websites, including pharmit.live.
  • The PharmIT ERP field-sales mobile application on iOS and Android.
  • The PharmIT ERP admin, universal-layer and console web applications.
  • Sales, onboarding, support and billing interactions over email, phone or in person.

It does not cover third-party websites, apps or services that we link to. Please read those parties’ privacy notices separately.

4. Personal data we collect

4.1 Data you give us directly

  • Identity and contact: name, employer / organisation name, designation, business email, business mobile number, and postal address.
  • Account credentials: username, password (stored in salted, hashed form), MPIN (stored hashed, never in plain text), OTP verification data.
  • Employee records (when you use HR-Payroll or SFA modules): government identifiers such as PAN and the last four digits of Aadhaar, date of joining, headquarters, territory, target and payout data. Sensitive identifiers are encrypted at rest.
  • Business records: parties, products, invoices, purchase orders, receipts, GST filings, e-Way Bills and other operational records your organisation creates in its PharmIT tenant.
  • Communications: the content of tickets, emails, chat messages and calls with our support and sales teams.

4.2 Data collected automatically

  • Device and app diagnostics: device model, operating system version, app version, crash reports, and coarse network information used to keep the service reliable.
  • Location (mobile app): if your organisation admin enables field-force tracking, the App records approximate or precise location during working hours for compliance and coverage reporting. You will be prompted to grant location permission before any data is collected.
  • Usage: pages viewed, features used, sync timestamps, IP address and timestamps — used for security, debugging and product improvement.
  • Cookies: a small set of first-party cookies necessary to keep you signed in. See section 13.

4.3 Data from third parties

  • Public government portals we query on your behalf (for example, the GSTN portal for GSTIN validation, e-Way Bill and e-Invoicing).
  • Payment processors, when a subscription is purchased through them.

5. How we use your data

We use personal data for a limited set of purposes, each tied to a lawful basis (see section 6):

  • To provide, operate, secure and improve PharmIT products.
  • To authenticate you, protect against fraud, and prevent unauthorised access.
  • To generate business records, filings and reports that your organisation is legally required to keep.
  • To communicate service updates, security notices and, where you have opted in, product news.
  • To answer your sales, support and grievance requests.
  • To comply with applicable law, respond to lawful requests from public authorities, and enforce our Terms.

6. Lawful basis

Depending on the interaction, we rely on one or more of:

  • Contract: where processing is necessary to deliver the services you or your organisation have contracted for.
  • Legitimate business use (including “certain legitimate uses” permitted under the DPDP Act) for security, fraud prevention, service improvement and internal record-keeping.
  • Consent: for optional marketing communications and for certain device permissions on the mobile app (for example, camera, contacts, location).
  • Legal obligation: for records we are required to retain under Indian tax, GST, corporate and drug-control laws.

7. Sharing and disclosure

We do not sell your personal data. We share it only with:

  • Your own organisation: administrators of your PharmIT tenant will see the data you generate inside the tenant. Please refer to your organisation’s internal privacy notice for how they use it.
  • Sub-processors we engage under contract to run PharmIT reliably: cloud infrastructure and object storage providers, transactional email providers, SMS and WhatsApp providers, payment processors, and analytics / error-monitoring tools. Each sub-processor is bound to confidentiality and data-protection obligations at least as strict as those in this policy.
  • Government and regulatory bodies when required by law (for example, GST filings via authorised GSPs, e-Way Bill / e-Invoicing platforms, and lawful requests from investigating agencies).
  • Professional advisors such as auditors, lawyers and bankers, under duty of confidentiality.
  • In connection with a corporate transaction (merger, acquisition, restructuring) — only with confidentiality controls in place and only to the extent needed.

8. Cross-border transfers

Personal data for Indian customers is primarily stored in data centres located in India. A small number of ancillary tools we use (for example, email delivery, error monitoring) may process metadata outside India. We will only transfer personal data outside India in accordance with the DPDP Act and applicable government notifications, and under contractual safeguards with the receiving party.

9. How long we keep data

We keep personal data only for as long as we need it for the purposes above, or as required by law:

  • Statutory business records (invoices, GST filings, e-Way Bills, employee tax records): retained for the minimum period required under the applicable Indian law — typically 8 years for GST and income-tax records.
  • Active account data: retained for the duration of your organisation’s subscription, plus a short window afterwards to allow for export and reactivation.
  • Support tickets and correspondence: up to 3 years from the date of resolution.
  • Marketing website analytics: up to 24 months.

After the retention period, personal data is deleted or securely anonymised.

10. Security

We take reasonable and appropriate technical and organisational measures to protect personal data, including:

  • Transport encryption (TLS 1.2+) for all traffic to and from PharmIT services.
  • Encryption at rest for sensitive fields, including salted-hashed passwords and MPINs, and AES-encrypted government identifiers such as PAN and Aadhaar last-4.
  • Role-based access controls, least-privilege internal access, and audit logging of privileged operations.
  • Backups, disaster-recovery drills, and continuous monitoring of production infrastructure.
  • Vendor risk assessment for sub-processors.

No system can be guaranteed to be 100 % secure. If we become aware of a personal data breach affecting your data, we will notify you and the Data Protection Board of India in accordance with the DPDP Act.

11. Your rights

Under the DPDP Act, you have the right to:

  • Ask for a summary of the personal data we process about you and the processing activities we undertake.
  • Ask us to correct or update inaccurate or incomplete data, or complete data that is misleading.
  • Ask us to erase personal data that is no longer necessary for the purpose it was collected.
  • Nominate another person to exercise these rights in the event of your death or incapacity.
  • Withdraw a consent you previously gave us, at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • Raise a grievance with our Grievance Officer (see section 12).

To exercise these rights, please write to us at hello@pharmit.live. We will verify your identity before acting on your request and respond within a reasonable time and, in any case, within the timelines required by law.

If the personal data was uploaded by your organisation to its PharmIT tenant, we will pass your request to that organisation’s designated point-of-contact, since they are the Data Fiduciary for that data.

12. Grievance officer

You can reach our Grievance Officer at:

  • Name: The Grievance Officer, PharmIT Services Private Limited
  • Email: hello@pharmit.live (subject: “Grievance — PharmIT”)
  • Phone: +91 63600 37010 (Mon – Sat, 10am to 7pm IST)
  • Address: 1362, Sri Bhuvaneshvari Complex, 3rd Floor, East End Main Road, Jayanagar 9th Block, Bengaluru — 560069, Karnataka, India.

We aim to acknowledge grievances within 2 business days and resolve them within 30 days, unless a shorter period is required by law.

13. Cookies and analytics

Our marketing website uses a small number of first-party cookies:

  • Session: to keep you signed in and secure your session.
  • Preferences: to remember basic UI preferences.
  • Analytics: aggregated, privacy-respecting analytics to understand how visitors use our website. IP addresses are truncated or anonymised where the analytics tool supports it.

You can control cookies through your browser settings. Disabling essential cookies may affect your ability to sign in.

14. Children

PharmIT products are intended for use by businesses and their staff. We do not knowingly collect personal data of children (under 18 years of age). If you believe we have inadvertently collected such data, please contact us and we will delete it.

15. Changes to this policy

We may update this policy from time to time to reflect changes in our services, in the law or in industry practice. When we do, we will change the “Effective from” date at the top and, for material changes, notify you by email or through a prominent notice on the product.

16. Contact

Questions about this policy or our data practices are welcome:

  • Email: hello@pharmit.live or info@pharmit.in
  • Phone: +91 63600 37010
  • Post: PharmIT Services Private Limited, 1362, Sri Bhuvaneshvari Complex, 3rd Floor, East End Main Road, Jayanagar 9th Block, Bengaluru — 560069, Karnataka.

PHARMIT SERVICES PRIVATE LIMITED · GSTIN 29AALCP6561H1ZW · Bengaluru, India