Last updated: November 16, 2025
Policy Version: 2.0 (GDPR Compliant)
MedsHood Pharmacy Private Limited ("MedsHood," "we," "us," or "our") is committed to protecting your privacy and complying with applicable data protection laws, including:
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal and health information when you use our online pharmacy and healthcare services.
Data Controller: MedsHood Pharmacy Private Limited
Registered Office: [Insert Address], India
Company Registration: [Insert CIN]
Email: privacy@medshood.com
Phone: +91 1800 123 456
Data Protection Officer (DPO): dpo@medshood.com
For EU/UK residents: You have the right to contact your local supervisory authority with any concerns about how we process your data.
⚠️ Sensitive Data - Enhanced Protection
The following health data is classified as "special category data" under GDPR Article 9 and receives enhanced protection:
We only process your personal data when we have a valid legal basis. For EU/UK customers, our legal bases are:
| Data Type | Legal Basis | Purpose |
|---|---|---|
| Personal Information | Contract Performance | To fulfill medication orders and provide services |
| Health Data (Prescriptions) | Explicit Consent + Legal Obligation | Pharmaceutical regulations require prescription verification |
| Payment Information | Contract Performance | To process payments for medication orders |
| Marketing Communications | Consent | To send promotional emails (opt-in only) |
| Usage Analytics | Legitimate Interest | To improve website performance and user experience |
| Fraud Prevention Data | Legitimate Interest | To protect against fraudulent transactions |
For Indian customers, processing is based on consent and legal obligations under the DPDP Act 2023.
We do NOT use fully automated decision-making or profiling that produces legal effects or similarly significant effects on you.
All prescription approvals are reviewed by licensed pharmacists. You have the right to request human intervention if you believe an automated system has been used incorrectly.
We do NOT sell your personal or health information to third parties.
We share your information only with trusted processors under strict data protection agreements (DPAs):
We may disclose your information when legally required:
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will notify you via email and prominent website notice 30 days before any such transfer.
Your data is primarily stored in India. For EU/UK customers, some data may be transferred to processors outside the EU/EEA/UK. We ensure adequate protection through:
You can request a copy of the safeguards in place by contacting dpo@medshood.com
We retain your data only as long as necessary for the purposes collected and to comply with legal obligations:
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Prescription Records | 7 years | Pharmaceutical regulations |
| Order History | 5 years | Tax compliance |
| Account Information | 30 days after account deletion request | Grace period for cancellation |
| Marketing Consent | Until withdrawn | Consent-based processing |
| Cookie Consent | 12 months | ePrivacy Directive |
| Audit Logs | 7 years | HIPAA compliance |
After retention periods expire, data is either securely deleted or anonymized for statistical purposes.
We implement state-of-the-art technical and organizational measures to protect your data:
⚠️ Data Breach Notification
In the unlikely event of a data breach, we will notify affected individuals and supervisory authorities within 72 hours as required by GDPR Article 33-34.
Under GDPR, UK GDPR, and DPDP Act 2023, you have the following rights:
Request a copy of all personal data we hold about you in machine-readable format (JSON).
→ Export Your DataRequest correction of inaccurate or incomplete data.
→ Request CorrectionRequest deletion of your data (subject to legal retention requirements). 30-day grace period applies.
→ Delete Your AccountRequest temporary suspension of data processing in certain circumstances.
→ Request RestrictionReceive your data in structured, machine-readable format and transfer to another service.
→ Export Your Data (JSON)Object to processing based on legitimate interests or for direct marketing purposes.
→ Manage PreferencesWithdraw consent for marketing, analytics, or other consent-based processing at any time.
→ Manage Cookie ConsentLodge a complaint with your local supervisory authority if you believe we've violated your rights.
→ Find Your Supervisory Authority (EU)Our services are NOT intended for individuals under 18 years of age.
We do not knowingly collect personal data from children. If you are a parent/guardian and believe your child has provided us with personal data, please contact us immediately at privacy@medshood.com, and we will delete it within 72 hours.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements.
Continued use of our services after changes indicates acceptance of the updated policy.
For questions, concerns, or to exercise your data protection rights, contact us:
General Privacy Inquiries:
📧 privacy@medshood.com
📞 +91 1800 123 456
Data Protection Officer (DPO):
📧 dpo@medshood.com
📞 +91 1800 123 457
Mailing Address:
MedsHood Pharmacy Private Limited
[Insert Complete Address]
City, State, PIN Code
India
Response Times: