💊
FlashMed

Privacy Policy

Effective Date: 1 June 2025  |  Issued by Flashverse Labs Private Limited (CIN: U73100WB2026PTC276243)

1. SCOPE AND CONSENT

This Privacy Policy applies to the FlashMed mobile application, website (flashmed.in), and all related services operated by Flashverse Labs Private Limited ("FlashMed", "we", "us").

By using FlashMed, you explicitly consent to the collection and processing of your personal data as described herein, in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000.

2. WHAT DATA WE COLLECT

2.1 Identity Data: Full name, date of birth, gender.

2.2 Contact Data: Mobile number, email address, delivery address, billing address.

2.3 Health Data: Prescription images (uploaded solely for the Pharmacy Partner's verification), product order history, blood type (voluntary, for Blood SOS), known allergies (voluntary).

2.4 Location Data: Real‑time GPS with explicit consent, used only for delivery coordination and proximity‑based Blood SOS alerts. Approximate location may be used to find nearby Pharmacy/Lab Partners.

2.5 Payment Data: Transaction references, UPI IDs, payment tokens. We NEVER store full card numbers, CVV, expiry, or banking passwords. All payment processing is handled by Cashfree Payments, an RBI‑authorised PCI‑DSS compliant aggregator.

2.6 Device Data: Device ID, OS version, app version, push notification token, crash logs – for technical support and performance improvement only.

2.7 We explicitly DO NOT collect: Aadhaar number, PAN, biometric data, racial/ethnic origin, religious or political beliefs, sexual orientation, or any data unnecessary for the described services.

3. HOW WE USE YOUR DATA

3.1 Order Fulfillment: To transmit your order and prescription to licensed Pharmacy Partners, coordinate delivery, and process payments.

3.2 Blood SOS Alerts: To send time‑bound alerts to voluntary donors within a 5‑km radius. Location data is used only during the SOS event and not retained beyond its duration.

3.3 Customer Support: To resolve grievances, process refunds, and investigate disputes.

3.4 Safety & Compliance: To prevent fraud, detect fake prescriptions, comply with legal obligations (including lawful government requests under the Code of Criminal Procedure, 1973), and enforce our Terms.

3.5 Service Improvement: Only anonymised, aggregated statistics for app performance. No individual profiling or automated decision‑making is performed for advertising.

3.6 ABSOLUTE PROHIBITION ON SALE OF DATA: We will never sell, rent, trade, or monetise your personal data to any third party for any commercial purpose.

4. DATA STORAGE AND LOCALISATION

4.1 All personal data is stored exclusively on servers located within India, in compliance with the DPDP Act, 2023, and RBI's data localisation directives.

4.2 Primary storage: User data, order records, and transaction history are stored in encrypted PostgreSQL databases hosted on cloud infrastructure within India. Firebase (asia‑south1 / Mumbai region) is used for real-time communication, push notifications, and authentication only. Prescription images are stored on Cloudinary (India region). All data is encrypted at rest using AES‑256 and in transit using TLS 1.3.

4.3 Data Retention Schedule:
• Order data: 7 years (statutory requirement)
• Account data: Until deletion request is processed
• Location data: Deleted within 24 hours of order completion/SOS closure
• Prescription images: Deleted 90 days after order completion
• Crash logs: 90 days

5. DATA SHARING — LIMITED AND PURPOSEFUL

5.1 Pharmacy Partners: Name, delivery address, prescription image, contact number – solely for order fulfilment.

5.2 Delivery Partners: Name, address, contact number – only for the specific delivery.

5.3 Lab Partners: Name, contact, address (for home collection), test requirements – for the booked service only.

5.4 Payment Processors (Cashfree): Only payment amount and transaction metadata; never prescription or health data.

5.5 Government Authorities: Disclosure only when required by a legally valid order under Indian law.

5.6 No commercial disclosure: Prescriptions, health history, blood type, or medical information will never be shared with third‑party marketers.

6. YOUR RIGHTS UNDER DPDP ACT 2023

As a data principal, you have the right to:

6.1 Access – Obtain a copy of your personal data.

6.2 Correction – Correct inaccurate or misleading data.

6.3 Erasure – Request deletion (subject to legal retention).

6.4 Grievance Redressal – File a complaint with our Grievance Officer.

6.5 How to exercise: Email support@flashmed.in with subject "DPDP Rights Request – [Your Phone Number]". We will respond within 30 days.

7. CHILDREN'S PRIVACY

FlashMed services are not directed at persons under 18. If we inadvertently collect data from a minor, we will delete it within 72 hours of discovery.

8. DATA BREACH NOTIFICATION

In case of a personal data breach, we will notify the Data Protection Board of India and all affected users within 72 hours, as required by Rule 9 of the DPDP Rules.

9. GRIEVANCE OFFICER — PRIVACY

Name: Nahid Hasan

Designation: Director, Chairman & CEO, Flashverse Labs Private Limited

Email: support@flashmed.in

Phone: +91 9144150105

Address: 12 Md Asfaque Akhtar, New Dakbanglow Bus Stand, Dhuliyan, Murshidabad, West Bengal — 742202

Response Time: Acknowledgment within 24 hours; resolution aimed within 7 days.

10. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. Material changes will be notified via app notification or email at least 7 days before they take effect.

← Back to Home