Privacy Policy - Genericart Medicines

Genericart Medicines Pvt. Ltd. (hereinafter referred to as “the Company”), on behalf of itself and its affiliates under the brand "Genericart Medicines", is the creator, owner and publisher of the mobile application Genericart Medicineand web application www.genericartmedicine.com (collectively referred to as “the Platform” or “Online Platform” and referred to as “Us” , “us” or “we” in this Privacy Policy). The Company owns and operates the services, software and applications provided on the Platform.

This Privacy Policy explains how we collect, use, share, disclose and protect Personal and/or Sensitive Information pertaining to all Users of the Services, including Franchise Holders (referred to as “You” , “you” or “Users” or “End-User” in this Privacy Policy). “Services” refers to the services made available to Users through the Platform and further defined in the Terms and Conditions governing access and use of the Platform.

Your use of and access to the Online Platform and Services is subject to this Privacy Policy and Terms and Conditions. All statements in this Privacy Policy apply to all Users who must read and understand this Privacy Policy prior to using the Services and/or providing information to the Company. This Privacy Policy shall be treated as a part of the Terms and Conditions of the Platform and shall be read in conjunction with the Terms and Conditions.

Eligibility

The Platform is intended for all persons who are:

  • interested in procuring information regarding availability and pricing of generic medicines from the nearest Genericart medicine shop along with geographical location of such shop;
  • interested in consulting with registered medical practitioners via third party online platform(s);
  • interested in acquiring the Company franchise or business opportunities

Legal Compliance

This Privacy Policy is published in compliance with:

  • Information Technology Act, 2000;
  • Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Information) Rules, 2011 (the “SPI Rules”);
  • Information Technology (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules, 2009
  • Information Technology (Procedure and Safeguards for Monitoring and Collecting Traffic Data or Information ) Rules 2009
  • Information Technology (Intermediaries Guidelines) Rules, 2011.

By using the Services or by otherwise giving us your information, you will be deemed to have read, understood and agreed to be bound by the terms, practices and policies outlined in this Privacy Policy. You hereby consent to our collection, use, sharing and disclosure of your information as described in this Privacy Policy. The Company reserves the right to change, modify, add or delete portions of this Privacy Policy, at its sole discretion, at any time. Please read this Privacy Policy in its entirety. If you do not agree with this Privacy Policy at any time, you are not authorized to use any of the Services or the Online Platform, and you must not provide us with any of your information. If you use the Services or the Online Platform on behalf of another individual or entity, you represent to us that you are authorized by such individual or entity to accept this Privacy Policy on such individual’s or entity’s behalf, and consent on behalf of such individual or entity to our collection, use and disclosure of such individual’s or entity’s information in accordance with this Privacy Policy.
This Privacy Policy contains the policies and practices that the Company follows with respect to:

  • the type of information collected from the Users.
  • the purpose, means and modes of collection, usage, processing, retention and destruction of such information.
  • disclosure of such information.
  • security of your personal, sensitive and financial legal information.

Information Collected by the Company

When You visit the Platform, we receive information that is directly provided to Us by You, such as personal and/or sensitive information, as well as information that is passively or automatically collected from You, such as that collected from the browser or device You use to access the Platform or Services. In this Privacy Policy, we refer to all this as the ‘User Information’.

Personal Data or Personal Information

Data provided by You includes Personal Data or Information which is defined under the SPI Rules to mean any information that relates to a natural person, which either directly or indirectly, in combination with other information available or likely to be available to a body corporate, is capable of identifying such person. Personal Information includes information such as your name, residential address, contact number and email address, which personally identifies you.

Sensitive Data or Sensitive Personal Information

Data provided by You also includes Sensitive Personal Data or Information, which is defined under the SPI Rules as information about a person relating to his or her:

  • physical, physiological and mental health condition;
  • health records, genuine prescriptions and other information related to health and/or such other personal information like the medicines previously searched for and added as favourites, medicines usually ordered etc;
  • medical records and history;
  • financial information such as bank accounts, credit and debit card details or other payment instrument details and/or medical insurance detail.
  • business-sensitive information such as financial records, accounts, information relating to legal and quasi-legal matters.

Commercial Data

  • records of products purchased, obtained, or considered;
  • purchase histories including the Franchises/shops selected for the purpose of selecting the medicines to be ordered, their locations, the Users previous interactions with such Franchises/shops etc;
  • such other relevant information with respect to customer requirements, choices, surveys and orders.

Internet or Other Electronic Network Activity Information

  • page views;
  • site browsing history;
  • IP address of your device;
  • information about your interaction with our Platform.

Automatically Collected Information is information is information about your use of the Services on the Platform. Similar to other services, we record Automatically Collected Information based on your Platform activity and use of the Services. For example, when you use the Platform, we automatically collect information on the type of device you use and the device identifier. We do this to analyze trends, administer the Services, troubleshoot any user problems, and to enhance and update the Platform and Services. We may also use the Automatically Collected Information for our business purposes, such as to report aggregate, non-Personal Information about the use of the Services.

We may collect the following types of Automatically Collected Information, which we may share with third parties, such as service providers and associates, business partners and such other entities, to help us operate the Services and Platform:

  • Aggregated Data: We collect user information and content to compile aggregate data as you use the Platform to analyze our overall user demographics and usage patterns.
  • Server Logs: We collect information from our server logs. These logs may include information such as your Internet Protocol address, browser details, the date and time of your request and certain information about your usage of the Services and the Platform.
  • Cookies, Pixels, Ad Tags, Web Beacons, or Unique Device Identifiers: We may use advertising technologies such as pixels, ad tags, Web beacons and unique device identifiers. We may also place a text file called a "cookie" on your device. This cookie cannot retrieve Personal Information from your device. Such technologies enable us to relate your use of the Services and the Platform to information that you have specifically and knowingly provided. You can refuse cookies by turning them off in your browser.
  • Links. We may track whether links to external third-party applications (such as payment applications, third-party registered medical practitioners’ platform(s)) are clicked.
  • One Time Password: We may track and detect the One Time Passwords that are sent to your device in order to enable automation in their usage by You, thus ensuring faster access to the Platform.
  • Location Tracking. We may collect the physical location of your mobile device and use it to provide you with personalized location-based Services. In some instances, you may be permitted to allow or deny such use of your device's location, but if you choose to deny such use, we may not be able to provide you with personalized Service.

If you are a Franchisee holder or a proposed Franchisee Holder, you may be called upon by the Company, for the purpose of registering the Franchisee Account, to furnish additional information including but not limited to your educational qualifications, your permissions and licenses to operate, your financial information, along with affidavits or declarations pertaining to the same. Such information shall be bound by the same terms of privacy as any other personal data of individuals stored on the website and shall be disclosed to third parties or on the Platform only in accordance with the clauses of this Privacy Policy relating to Disclosure of Information collected from Franchisee Holder. Further information about the Franchisee Account is available in the Terms and Conditions.

Usage of Information Collected

You understand that all Information provided by you to the Company is voluntary. You understand that the Company may use this Information:

  • to provide the Services;
  • to ensure effective and efficient performance and usage of Services;
  • to improve the Services, including customizing your experience and resolving support-related issues;
  • to identify and resolve any technical issues;
  • for research, statistical analysis and business intelligence purposes, including sale thereof to a third party;
  • to identify you as an authorized User, to secure your account and prevent fraud;
  • to communicate with you about updates, new releases/products/services, feedback, transactions;
  • to enforce the legal terms that govern our Platform and Services.

In this process, we also may use third-party services and tools, where necessary, such as Google analytics and One-Time-Password generating-applications. The Company does not use Personal or Sensitive data provided by you for any purpose other than those which are detailed in this Privacy Policy.

If you are a Franchisee holder or proposed Franchise Holder your Information (including but not limited to educational qualifications, licenses, permissions and certifications, business-related photos, business address, business registration details, etc.) may be used by the Platform for the following purposes:

  • to publicize the Platform and the Services provided;
  • to communicate with the You about new products, services, releases, updates and User feedback provided by the Company;
  • to update and inform you about information relating to your business i.e. earnings, profits, business structure, new compliances required etc.
  • to analyze platform usage and other analytical functions;

and such other purposes.
If you wish to cancel your account or request that we no longer use your Information to provide you Services, or have inadvertently submitted any such Information or do not agree in the manner in which such Information is collected, stored or processed, please contact us through http://genericartmedicine.com/contact-us. After your account has been deactivated, we will hold on to your Information on an anonymous basis, to be used solely for analytical and business improvement purposes.

Disclosure of Information Collected

The Company implements effective security policies and measures to protect your Information from unauthorized access, use, destruction and disclosure from the point of collection to destruction. In the event that any data is lost through unauthorized access from the Your device(s) through which You avail Services, the Company shall not be held liable for any loss whatsoever incurred by You.

The Information provided by you will be disclosed to and be accessible by only authorized personnel within the Company who are bound by strict rules of privacy and have the obligation to uphold the confidentiality of every User’s Information. The User’s Information including but not limited to prescriptions, may be shared with Franchise holders, Shop owners or company representatives in order to facilitate the communication to such Franchise/Company Shop about the User’s selection of medicines and pharmaceutical products that shall be sold to it offline by the Franchisee/Company Shop . The User’s Information, including but not limited to prescriptions, also be shared with third-party registered medical practitioners’ platform. Some of the data may also be shared with designated service or solution providers who act as sub-processors for specific purposes, such as sending emails, analytics, monitoring, IT support, troubleshooting, professional advisors such as lawyers, auditors, etc. We contractually require our agents, service providers, and affiliates who may process personal data related to the services to provide the same level of protection for personal or sensitive data as required under the applicable laws and regulations. We use the personal data for our legitimate business purposes only as part of services and deliverables. In accordance with our legal obligations, we may also transfer such data, subject to lawful requests and requirements, to public authorities for law enforcement or national security purposes, where required and applicable. We may also disclose Information to governmental or statutory authorities or other entities, where required by law currently in force in India.

Storage of Information Collected

The Information collected will be stored in the secure servers and systems either owned by the Company or retained by the Company on a trusted third-party platform or secure server through the means of a written document which shall govern the storage of the Information on such platform or server, for the purposes of storing the Data collected. Currently, the Company has retained the servers provided by amazon web services to store a copy of the Data. AWS is bound by terms of strict privacy with respect to any data stored on its services. The terms of privacy and use of servers of AWS for storing the data can be found here.

The data might be stored and/or transferred in order to fulfil the agreed and lawful processing. Any transfer of data outside the region of data subjects will be done in compliance with the applicable Privacy acts and regulations.

Retention Period of Information Collected

The Information will be collected for as long as is required to fulfil the purpose for which it was collected and in accordance with tax, legal and regulatory requirements. The Information will be retained by us unless you request the removal of the Information via a specific request or there is a business/regulatory requirement requiring us to do so.

Your Rights with Respect to Information Stored

Subject to applicable law(s) and regulations in accordance with the laws in India, you may have some or all of the following rights available to you in respect of your Personal or Sensitive data that is residing with us:

  • to obtain a copy of your personal data together with information about how and on what basis that data is processed;
  • to rectify inaccurate Information (including the right to have incomplete personal data completed);
  • to request for erasing or updating your Information residing with us, subject to specific context and terms and conditions;
  • to request restriction on processing of your Information under certain circumstances;
  • to withdraw your consent to our processing of your Information (where that processing is based on your consent);
  • to lodge a complaint with the relevant regulatory authority in your region.

Security of Information Stored

We make reasonable efforts to restrict access to Information to only those employees, contractors, service providers, agents and affiliates who need such access in order to operate, develop, improve, or deliver the Services. We have implemented administrative, technical, and physical security measures to help prevent unauthorized access. Despite these measures, no data transmission over the Internet can be entirely secure, and we cannot guarantee or warrant the security of any Information You transmit via our Platform.

We maintain your Information in electronic form on its equipment, which may be converted to physical form from time to time. The Company takes all necessary precautions to protect your Information and implements reasonable security practices and measures, including certain managerial, technical, operational and physical security control measures that are commensurate with respect to the Information being collected and the nature of the Company’s business. No administrator at the Company will have knowledge of your password. It is important for you to protect against unauthorized access to your password, your computer and your mobile phone. Be sure to log off from the Platform when finished. The Company does not undertake any liability for any unauthorized use of your account and password. If you suspect any unauthorized use of your account, you must immediately notify the Company by sending an email to http://genericartmedicine.com/contact-us .You shall be liable to indemnify the Company due to any loss suffered by it due to such unauthorized use of your account and password.

Breach by Third Parties

The Company is not responsible for the confidentiality, security or distribution of your Information by our partners and third parties outside the scope of our agreement with such partners and third parties. Further, the Company shall not be responsible for any breach of security or for any actions of any third parties or events that are beyond the reasonable control of the Company including but not limited to, acts of government, computer hacking, unauthorized access to computer data and storage device, computer crashes, breach of security and encryption, poor quality of Internet service or telephone service of the User.

Minors

You must be 18 years of age or older to access the Services. By accessing the Services and providing Information to us you represent and warrant to Us that You are 18 years of age or older and that you have the legal right, authority and capacity to use all or part of the Services. Whilst the Services are not intended for use by minors, the Company recognizes and respects the privacy of minors who may inadvertently use our Services. It is strongly recommended that parents and guardians supervise the online activities of minors/children and use parental control tools to help promote a safe environment for their children.

Casual Visitors

No Information is automatically collected by the Company from any casual visitors of this website, who are merely perusing the website, however, such casual visitors are also required to read and understand this Privacy Policy. If as a casual visitor you disagree with the manner in which the Company uses the “clear cookies”, it is recommended that you update the functionality of your browsers to ensure such deletion of cookies. Upon reading of this Privacy Policy and submission of Personal and/or Sensitive Information to the Company, visitors will be deemed to be Users for the purpose of this Privacy Policy.

Linked Services

Our Platform may contain links to or integrations with other services such as Facebook, Twitter, LinkedIn, and other media services and platforms whose information practices may be different from ours. Visitors should consult these other services' privacy notices as we have no control over information that is submitted to, or collected by, these third parties.

Changes to This Policy

From time to time, we may amend or update this Privacy Policy. If this Privacy Policy changes in any way, we will post an updated version on the Platform. We recommend you regularly review the Platform to ensure that you are always aware of our practices and any changes. Any changes to this Policy will be effective upon posting to the Online Platform. Your consent to the updated Privacy Policy shall be assumed by Your continued use of the Platform.

Further Information

If you have any questions or information regarding this Privacy Policy, you may contact us via the means provided on the Platform, including via emailing us on support@genericartmedicine.com.

Consent to this Privacy Policy

You acknowledge that this Privacy Policy is a part of the Terms of Use of the Platform and the Services. You unconditionally agree that becoming a User signifies your (i) assent to this Privacy Policy, and (ii) consent to Company using, collecting, processing and/or disclosing your Information in the manner and for the purposes set out in this Privacy Policy. Your use of the Platform and Services is subject to this Privacy Policy and the Terms of Use.

You are under no obligation to provide Information to us. However, when registering on our Platform, or from time to time during your relationship with us, you may opt in or out of certain types of communications that may affect the Information we gather. We reserve the right to inform you that such opting out may prevent you from enjoying the full benefits of our Platform.