💊
FlashMed

FLASHMED™ PRIVACY POLICY

CIN: U73100WB2026PTC276243 | UDYAM: WB-13-0148760 | Effective Date: 20 May 2026 | Version 3.0
FlashMed™ is a product of Flashverse Labs Private Limited
Compliant with: Information Technology Act, 2000 | Digital Personal Data Protection Act, 2023

1. WHO WE ARE — TECHNOLOGY AGGREGATOR AND CONNECTOR

FlashMed™ is a product and registered trademark of Flashverse Labs Private Limited, a company incorporated under the Companies Act, 2013, with CIN: U73100WB2026PTC276243 and UDYAM Registration No. WB-13-0148760. FlashMed™ operates exclusively as a technology aggregator and connector platform under Section 79 of the Information Technology Act, 2000, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

FLASHMED™ IS NOT AN E-PHARMACY. FlashMed™ does not hold any drug licence and does not engage in any activity requiring one. FlashMed™ does not procure, stock, store, dispense, or sell any medicine or pharmaceutical product. All such activities are performed exclusively by independent licensed Pharmacy Partners in their own capacity as licensed retailers under the Drugs and Cosmetics Act, 1940, and the Pharmacy Act, 1948. FlashMed™ merely provides a technology platform for customers to discover and connect with such pharmacies.

Registered Office: 12 Md Asfaque Akhtar, New Dakbanglow Bus Stand, Dhuliyan, Murshidabad, West Bengal — 742202, India.

Contact for Privacy Matters: support@flashmed.in

FlashMed™'s sole role is to connect customers with independent licensed Pharmacy Partners, diagnostic laboratories, and registered medical practitioners; coordinate delivery through independent Delivery Partners; and facilitate emergency blood request alerts. FlashMed™ is a technology aggregator and connector — not a principal in any healthcare transaction, and does not practice pharmacy or medicine.

2. WHAT DATA WE COLLECT

2.1 Identity Data: Full name, date of birth, gender.

2.2 Contact Data: Mobile number, email address, delivery address, billing address.

2.3 Health Data: Prescription images (uploaded solely for the Pharmacy Partner's verification), product order history, blood type (voluntary, for Blood SOS), known allergies (voluntary).

2.4 Location Data: Real‑time GPS with explicit consent, used only for delivery coordination and proximity‑based Blood SOS alerts. Approximate location may be used to find nearby Pharmacy/Lab Partners.

2.5 Payment Data: Transaction references, UPI IDs, payment tokens. We NEVER store full card numbers, CVV, expiry, or banking passwords. All payment processing is handled by Cashfree Payments, an RBI‑authorised PCI‑DSS compliant aggregator.

2.6 Device Data: Device ID, OS version, app version, push notification token, crash logs – for technical support and performance improvement only.

2.7 We explicitly DO NOT collect: Aadhaar number, PAN, biometric data, racial/ethnic origin, religious or political beliefs, sexual orientation, or any data unnecessary for the described services.

3. HOW WE USE YOUR DATA

3.1 Order Fulfillment: To transmit your order and prescription to licensed Pharmacy Partners, coordinate delivery, and process payments.

3.2 Blood SOS Alerts: To send time‑bound alerts to voluntary donors within a 5‑km radius. Location data is used only during the SOS event and not retained beyond its duration.

3.3 Customer Support: To resolve grievances, process refunds, and investigate disputes.

3.4 Safety & Compliance: To prevent fraud, detect fake prescriptions, comply with legal obligations (including lawful government requests under the Code of Criminal Procedure, 1973), and enforce our Terms.

3.5 Service Improvement: Only anonymised, aggregated statistics for app performance. No individual profiling or automated decision‑making is performed for advertising.

3.6 ABSOLUTE PROHIBITION ON SALE OF DATA: We will never sell, rent, trade, or monetise your personal data to any third party for any commercial purpose.

4. DATA STORAGE AND LOCALISATION

4.1 All personal data is stored exclusively on servers located within India, in compliance with the DPDP Act, 2023, and RBI's data localisation directives.

4.2 Primary storage: User data, order records, and transaction history are stored in encrypted PostgreSQL databases hosted on cloud infrastructure within India. Firebase (asia‑south1 / Mumbai region) is used for real-time communication, push notifications, and authentication only. Prescription images are stored on Cloudinary (India region). All data is encrypted at rest using AES‑256 and in transit using TLS 1.3.

4.3 Data Retention Schedule:
• Order data: 7 years (statutory requirement)
• Account data: Until deletion request is processed
• Location data: Deleted within 24 hours of order completion/SOS closure
• Prescription images: Deleted 90 days after order completion, unless needed for dispute resolution
• Crash logs: 90 days

4.4 Cross‑border transfer: We do not transfer personal data outside India except where technically necessary (e.g., Firebase backend) and only with appropriate DPDP‑compliant safeguards.

5. DATA SHARING — LIMITED AND PURPOSEFUL

5.1 Pharmacy Partners: Name, delivery address, prescription image, contact number – solely for order fulfilment. They are contractually bound to use this data only for that purpose.

5.2 Delivery Partners: Name, address, contact number – only for the specific delivery. They are prohibited from retaining or reusing this data.

5.3 Lab Partners: Name, contact, address (for home collection), test requirements – for the booked service only.

5.4 Payment Processors (Cashfree): Only payment amount and transaction metadata; never prescription or health data.

5.5 Government Authorities: Disclosure only when required by a legally valid order under Indian law.

5.6 No commercial disclosure: Prescriptions, health history, blood type, or medical information will never be shared with third‑party marketers.

6. YOUR RIGHTS UNDER DPDP ACT 2023

As a data principal, you have the right to:

6.1 Access – Obtain a copy of your personal data.

6.2 Correction – Correct inaccurate or misleading data.

6.3 Erasure – Request deletion (subject to legal retention).

6.4 Grievance Redressal – File a complaint with our Grievance Officer.

6.5 Nomination – Nominate an individual to exercise rights on your behalf.

6.6 How to exercise: Email support@flashmed.in with subject "DPDP Rights Request – [Your Phone Number]". We will respond within 30 days.

7. CHILDREN'S PRIVACY

FlashMed services are not directed at persons under 18. If we inadvertently collect data from a minor, we will delete it within 72 hours of discovery.

8. COOKIES AND TRACKING

Our app does not use traditional cookies. We use Firebase Analytics for anonymised usage statistics; you can disable analytics in your device settings.

9. DATA BREACH NOTIFICATION

In case of a personal data breach, we will notify the Data Protection Board of India and all affected users within 72 hours, as required by Rule 9 of the DPDP Rules.

10. GRIEVANCE OFFICER — PRIVACY

Name: Nahid Hasan

Designation: Director, Chairman & CEO, Flashverse Labs Private Limited

Email: support@flashmed.in

Phone: +91 9144150105

Address: 12 Md Asfaque Akhtar, New Dakbanglow Bus Stand, Dhuliyan, Murshidabad, West Bengal — 742202

Response Time: Acknowledgment within 24 hours; resolution aimed within 7 days.

11. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. Material changes will be notified via app notification or email at least 7 days before they take effect.

← Back to Home