DPDPA 2023 · compliance statement
How we meet India's data protection law.
The Digital Personal Data Protection Act, 2023 came into force to give Indian users meaningful rights over how their data is processed. This page is our public statement of how Pia complies, role by role, right by right.
Who is who
- Data fiduciary
- Pia Prescience Private Limited. We decide the purpose and means of processing for everything that happens through Pia.
- Data processor
- Our infrastructure and integration vendors, contractually bound to process only what we instruct them to.
- Data principal
- Every individual whose personal data we process — pharmacy owners, employees, customers of pharmacies whose data flows through Pia.
- Grievance officer
- Akshat Gupta, Grievance Officer, reachable at [email protected].
Lawful basis for processing
We process personal data under one of three bases, recorded explicitly per category in our internal records of processing activities:
- Consent — for anything optional: marketing communication, opt-in features, model improvement contributions.
- Legitimate use (specified uses) — the data subject voluntarily provides data to receive a service they have asked for. The product workflow itself.
- Legal obligation — GST records, drug-regulator-mandated retention, lawful directives.
We do not rely on bundled or implied consent. A separately-collected, granular consent is required for anything outside the immediate service.
Your rights, with mechanics
| Right | How to exercise |
|---|---|
| Access — copy of your data | Email [email protected] and we will put it together for you. Your statutory reports (GST returns, registers) can be downloaded from the app's Reports at any time; account and shop deletion requests go through delete account. |
| Correction & updation | Most fields are editable in the app; for anything you cannot change yourself, email us. |
| Erasure | Delete your account in the app (Me → Account; owners also get Workspace → Danger zone for a location or the whole shop), or email with subject line “Erasure request.” We verify ownership, then schedule it. You have 90 days to change your mind by signing in; after that, erasure begins and cannot be reversed. We cite specifically anything the law requires us to keep. |
| Withdrawal of consent | Turn the feature off, or email us. We will confirm what it changes about the service. |
| Grievance | Email [email protected] with subject line “Grievance.” The Act gives us 30 days; we aim to be much faster. |
| Nomination | Send us a signed instrument naming your nominee. We will record it against your account. |
There is no charge for any of these requests in normal circumstances. We reserve the right to charge a reasonable fee only for manifestly unfounded or excessive repeat requests, and we'll always explain in writing what we're charging and why.
We reply to every message within a working day. Where a request takes longer to fulfil than to acknowledge, we tell you what we're doing and when it will be done.
Notice obligations
Per Section 5 of the Act, we provide notice in plain language at or before the point of collection — the categories of personal data we collect, the purposes, your rights, and how to exercise them. The privacy policy is that notice, and it is linked from the app and from every page of this site.
Cross-border transfers
Your shop's database runs in Cloudflare's Asia-Pacific region. Some processing happens outside India — principally the AI processing described in the privacy policy, which names every processor we use and what each one receives. In each case the destination is among those permitted under the Act's Section 16 framework, and the processor is contractually bound to the same standards we hold ourselves to.
Security & breach
Reasonable security safeguards include encryption of everything in transit, structural separation of each shop's data from every other shop's, role-based access control, owner approval before a new device can reach shop data, an immediate sign-out-everywhere control, and a recorded trail of consequential actions. Our security page describes what is in place.
In the event of a personal-data breach, we notify the Data Protection Board of India and affected data principals as required by the Act, within the timelines the Act prescribes.
Children
We do not knowingly process personal data of individuals below 18 as direct Pia users without verifiable parental consent. The product is designed for business use.
Significant Data Fiduciary status
We are not currently classified as a Significant Data Fiduciary under Section 10 of the Act. If that changes — for instance, if we cross a relevant threshold of personal data processed — we will update this page, appoint a Data Protection Officer, conduct mandatory Data Protection Impact Assessments, and submit to periodic audits as the Act requires.
Escalation
If we cannot resolve a grievance to your satisfaction within 30 days, you may approach the Data Protection Board of India under Section 27 of the Act for redress.