Last updated: February 16, 2026
Policy Version: 2.0 (GDPR Compliant)
MedsHood Pharmacy Private Limited ("MedsHood," "we," "us," or "our") is committed to protecting your privacy and complying with applicable data protection laws, including:
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal and health information when you use our online pharmacy and healthcare services.
Data Controller: Access Biopharma
Registered Office: NO 3-6-365/C/301, Pavani Estates Himayath Nagar 500029 - Hyderabad Telangana, India
Email: info@medshood.com
Phone: +91 9063295781
Data Protection Officer (DPO): info@medshood.com
⚠️ Sensitive Data - Enhanced Protection
The following health data is classified as "special category data" under GDPR Article 9 and receives enhanced protection:
We only process your personal data when we have a valid legal basis. For EU/UK customers, our legal bases are:
| Data Type | Legal Basis | Purpose |
|---|---|---|
| Personal Information | Contract Performance | To fulfill medication orders and provide services |
| Health Data (Prescriptions) | Explicit Consent + Legal Obligation | Pharmaceutical regulations require prescription verification |
| Payment Information | Contract Performance | To process payments for medication orders |
| Marketing Communications | Consent | To send promotional emails (opt-in only) |
| Usage Analytics | Legitimate Interest | To improve website performance and user experience |
| Fraud Prevention Data | Legitimate Interest | To protect against fraudulent transactions |
For Indian customers, processing is based on consent and legal obligations under the DPDP Act 2023.
We do NOT use fully automated decision-making or profiling that produces legal effects or similarly significant effects on you.
All prescription approvals are reviewed by licensed pharmacists. You have the right to request human intervention if you believe an automated system has been used incorrectly.
We do NOT sell your personal or health information to third parties.
We share your information only with trusted processors under strict data protection agreements (DPAs):
We may disclose your information when legally required:
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will notify you via email and prominent website notice 30 days before any such transfer.
Your data is primarily stored in India. For EU/UK customers, some data may be transferred to processors outside the EU/EEA/UK. We ensure adequate protection through:
You can request a copy of the safeguards in place by contacting info@medshood.com
We retain your data only as long as necessary for the purposes collected and to comply with legal obligations:
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Prescription Records | 7 years | Pharmaceutical regulations |
| Order History | 5 years | Tax compliance |
| Account Information | 30 days after account deletion request | Grace period for cancellation |
| Marketing Consent | Until withdrawn | Consent-based processing |
| Cookie Consent | 12 months | ePrivacy Directive |
| Audit Logs | 7 years | HIPAA compliance |
After retention periods expire, data is either securely deleted or anonymized for statistical purposes.
We implement state-of-the-art technical and organizational measures to protect your data:
⚠️ Data Breach Notification
In the unlikely event of a data breach, we will notify affected individuals and supervisory authorities within 72 hours as required by GDPR Article 33-34.
Under GDPR, UK GDPR, and DPDP Act 2023, you have the following rights:
Request a copy of all personal data we hold about you in machine-readable format (JSON).
→ Export Your DataRequest correction of inaccurate or incomplete data.
→ Request CorrectionRequest deletion of your data (subject to legal retention requirements). 30-day grace period applies.
→ Delete Your AccountRequest temporary suspension of data processing in certain circumstances.
→ Request RestrictionLodge a complaint with your local supervisory authority if you believe we've violated your rights.
→ Find Your Supervisory Authority (EU)Our services are NOT intended for individuals under 18 years of age.
We do not knowingly collect personal data from children. If you are a parent/guardian and believe your child has provided us with personal data, please contact us immediately at info@medshood.com, and we will delete it within 72 hours.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements.
Continued use of our services after changes indicates acceptance of the updated policy.
For questions, concerns, or to exercise your data protection rights, contact us:
General Privacy Inquiries:
📧 info@medshood.com
📞 +91 9063295781
Data Protection Officer (DPO):
📧 info@medshood.com
📞 +91 9063295781
Mailing Address:
NO 3-6-365/C/301, Pavani Estates, Himayath Nagar, 500029 - Hyderabad, Telangana, India
Response Times: