Privacy Policy
Who We Are
WeDose (wedose.in and platform.wedose.in, together the “Platform”) is a cloud pharmacy management platform for hospitals, nursing homes, and clinics in India, owned and operated by Thinkwarelabs IT Private Limited (GSTIN: 06AANCT2275Q1ZK), registered office at Shri Ram Vichar Vatika, Radaur, Haryana, India – 135133 (“WeDose”, “we”, “us”).
This Privacy Policy is published in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025, and the Information Technology Act, 2000.
Our Two Roles — Read This First
WeDose handles personal data in two distinct capacities under Indian data protection law:
- As a Data Fiduciary: For the data of our direct customers and website visitors — pharmacy owners, hospital administrators, staff users, and demo enquiries. For this data, this Policy applies in full.
- As a Data Processor: For the data that pharmacies enter into the Platform — patient names, doctor names, prescription references, and billing records (“Pharmacy Data”). Each subscribing pharmacy is the Data Fiduciary for its own Pharmacy Data. We process it only on the pharmacy's instructions, under our Data Processing Addendum, and never use it for our own purposes. Patients seeking access, correction, or erasure of their data should contact the pharmacy where they were billed; we will assist that pharmacy in fulfilling such requests.
Data We Collect as a Fiduciary
When you interact with WeDose or subscribe to our Platform, we collect:
- Account data: Name, email, phone number, pharmacy/hospital name, drug licence number, GSTIN, and billing details of the subscribing pharmacy.
- Staff user data: Names, email/phone, and role, as created by the pharmacy's administrator.
- WhatsApp alert numbers: Designated phone numbers configured to receive the daily digest.
- Enquiry data: Information you submit when booking a demo or contacting us.
- Usage and log data: Pages visited, features used, device/browser information, IP address, and access timestamps — used for security, support, and product improvement.
Pharmacy Data We Process on Instructions
When a pharmacy uses the Platform, the following data is processed within that pharmacy's isolated tenant: patient names and billing details, doctor names, prescription references and Schedule H1/X flags, medicine/batch/stock records, supplier details, and sales/GST records.
This data belongs entirely to the pharmacy. We access it only to operate the service, provide requested support, comply with law, or as instructed by the pharmacy. We do not sell it, advertise with it, or use it to train AI/ML models.
Purposes and Legal Basis
We process fiduciary data to: create and administer accounts; provide, secure, and improve the Platform; deliver WhatsApp alerts and service communications; process subscription payments and issue GST invoices; provide customer support; and comply with legal obligations.
Processing is based on your consent and on legitimate uses recognised under the DPDP Act 2023. You may withdraw consent at any time by writing to hello@wedose.in; this may limit our ability to provide the service.
Data Residency and Sub-processors
All Platform data, including Pharmacy Data, is hosted in India — on India-region infrastructure (AWS Mumbai, ap-south-1). We use a small set of vetted service providers to run WeDose:
- Cloud hosting & database: AWS Mumbai (ap-south-1) / India region infrastructure
- WhatsApp alerts: Indian WhatsApp Business Solution Provider (Interakt / AiSensy) — receives only the destination number and digest content
- Payments: Razorpay (PCI-DSS compliant) — we do not store card or banking credentials
- Transactional email: AWS SES / Postmark (India/global compliant)
Sub-processors are bound by contracts requiring confidentiality and security no less protective than this Policy. A current list is available on request.
Security
We implement robust technical and organizational security measures:
- Each pharmacy's data lives in its own isolated database schema — no shared tables across tenants.
- Encryption in transit (TLS 1.3) for all connections and encrypted at rest for all database backups.
- Role-based access controls for staff accounts; every stock adjustment and edit is captured in an immutable audit log with user ID, timestamp, and reason.
- Offline billing data is held temporarily in the browser's local storage on the pharmacy's own device and syncs to the pharmacy's tenant when connectivity returns.
In the event of a personal data breach, we will notify affected pharmacies without undue delay and inform the Data Protection Board of India and affected individuals as required by the DPDP Act.
Retention
Account and billing data is retained for the duration of the subscription and thereafter as required by statutory tax and company laws in India.
Pharmacy Data is retained while the subscription is active. On termination, the pharmacy may export its data for 30 days, after which it is deleted from production systems within 90 days — except records the pharmacy is legally required to preserve (such as the prescription register under the Drugs and Cosmetics Act, 1940), which we delete only on the pharmacy's confirmed instruction or export.
Your Rights
If we are the Data Fiduciary for your personal data, you have the following rights under the DPDP Act 2023:
- Access a summary of your personal data being processed;
- Correct, complete, or update inaccurate personal data;
- Request erasure of your personal data (subject to statutory retention obligations);
- Nominate another individual to exercise your data rights in the event of death or incapacity;
- Withdraw consent previously provided;
- Lodge a grievance with our Grievance Officer.
Write to hello@wedose.in with subject “Data Request”. If unsatisfied with our response, you may complain to the Data Protection Board of India.
Grievance Officer
In accordance with the DPDP Act 2023 and IT Act 2000, details of the Grievance Officer are:
Designation: Grievance Officer, Thinkwarelabs IT Private Limited (WeDose)
Email: grievance@wedose.in
Address: Shri Ram Vichar Vatika, Radaur, Haryana, India – 135133
Cookies, Children, and Changes
Cookie use is described in our Cookie Policy. The Platform is a business operations tool intended for users aged 18 and above; we do not knowingly collect children's personal data.
We may update this Privacy Policy from time to time; material changes will be notified through the Platform or by email.
