PillZet Pharmacy Partner Privacy & Data Protection Policy
Effective Date: 01/03/2026
Last Updated: 01/03/2026
(Applicable to all registered Pharmacy / Store Partners of PillZet)
1. Introduction & Purpose
PillZet (“Platform”), operated by VN Globe Tech Pvt Ltd, connects customers with registered pharmacy partners for medicine ordering and delivery.
During this process, pharmacy partners may gain limited access to customer personal data and sensitive health information.
The purpose of this Policy is to:
- Protect customer privacy and confidentiality
- Define clear rules for data handling by pharmacy partners
- Ensure compliance with Indian data protection and healthcare laws
- Prevent misuse, leakage, or unauthorized disclosure of data
This Policy is mandatory and forms an integral part of the Store Partner Agreement and Pharmacy Handbook.
2. Applicability & Responsibility
This Policy applies to:
- Pharmacy owners and partners
- Registered pharmacists
- Store staff handling PillZet orders
- Any authorized person accessing PillZet systems or order information
The pharmacy partner is fully responsible for ensuring compliance with this Policy by its employees and representatives.
3. Definitions
- Customer Data: Any information relating to an identifiable customer, including personal and medical details
- Sensitive Data: Prescription information, diagnosis, medicine details, and health-related records
- Processing: Collection, access, viewing, verification, storage, transmission, or deletion of data
- Data Breach: Any unauthorized access, disclosure, loss, misuse, or compromise of customer data
4. Categories of Data Accessed
Pharmacy partners may access the following strictly through PillZet systems:
- Customer name, phone number, and delivery address
- Prescription images or prescription details
- Ordered medicine details and quantities
- Invoice and fulfilment-related data
⚠️ Prescription and health-related data are classified as Sensitive Personal Data and require enhanced protection.
5. Lawful Basis & Purpose Limitation
Customer data is shared with pharmacy partners strictly for lawful purposes, including:
- Order processing and fulfilment
- Prescription validation where legally required
- Medicine packaging and invoicing
- Statutory and regulatory compliance
🚫 Any use of customer data beyond the above purposes is strictly prohibited.
6. Prohibited Activities
Pharmacy partners shall NOT:
- Use customer data for advertising, promotions, or loyalty programs
- Contact customers for non-order-related purposes
- Store customer data independently or permanently
- Create customer lists or internal databases
- Share customer information with third parties
- Take screenshots, photographs, or downloads of customer data
- Share order details via WhatsApp groups, social media, or public forums
7. Data Storage & Retention Controls
- Customer data must not be retained beyond order fulfilment
- No offline or personal device storage is permitted
- Physical records (if legally required) must be securely stored
- Retention must be limited strictly to statutory timelines
- Data must be deleted or destroyed once retention obligations expire
8. Data Security Measures
Pharmacy partners must implement reasonable security safeguards, including:
- Restricting data access to authorized personnel only
- Using password-protected systems and devices
- Secure handling of prescription copies
- Preventing unauthorized viewing, copying, or sharing
- Periodic staff awareness on data confidentiality obligations
9. Staff Training & Awareness
Pharmacy partners must:
- Train staff on privacy and confidentiality obligations
- Ensure only trained personnel handle PillZet orders
- Maintain internal discipline for data handling violations
10. Confidentiality Obligations
All customer data and PillZet business information shall be treated as strictly confidential.
Confidentiality obligations:
- Continue even after order completion
- Survive termination of the partnership
- Apply regardless of employment or contractual status of staff
11. Data Breach Management & Reporting
In the event of a suspected or actual data breach, accidental disclosure, misuse, or loss of devices or records containing customer data, the pharmacy partner must:
- Notify PillZet immediately
- Provide complete details of the incident
- Cooperate fully in investigation and remediation
- Implement corrective and preventive measures
12. Legal & Regulatory Compliance
Pharmacy partners must comply with all applicable laws, including:
- Information Technology Act, 2000
- Digital Personal Data Protection Act, 2023
- Drugs & Cosmetics Act and Rules
- Pharmacy Council of India guidelines
- Any applicable future data protection or healthcare laws
13. Audits & Monitoring
PillZet reserves the right to:
- Conduct audits or compliance reviews
- Request compliance confirmations
- Suspend access pending investigation
Failure to cooperate may result in action under the applicable Agreement.
14. Breach, Liability & Indemnity
Any violation of this Policy constitutes a material breach, including:
- Unauthorized use of customer data
- Confidentiality violations
- Regulatory non-compliance
Consequences may include:
- Immediate suspension or termination of partnership
- Indemnification of PillZet for losses or claims
- Legal or regulatory reporting
- Recovery of damages
15. Policy Updates & Amendments
PillZet may revise this Policy from time to time with reasonable notice. Continued participation on the Platform constitutes acceptance of updated terms.
16. Acceptance & Binding Effect
By onboarding and continuing as a PillZet Pharmacy Partner, the pharmacy:
- Acknowledges receipt and understanding of this Policy
- Agrees to comply fully with its terms
- Accepts responsibility for staff compliance