Privacy Policy

Embolo Technologies Private Limited
Website: https://embolo.in

Effective Date: 1 July 2026  |  Last Updated: 1 July 2026  |  Version: 2.0


Governing Law

This Policy is designed to comply with the Digital Personal Data Protection Act, 2023 (DPDPA) and the Digital Personal Data Protection Rules, 2025 (DPDP Rules), notified on 13 November 2025 by the Ministry of Electronics and Information Technology (MeitY), Government of India — including all three phases of phased implementation up to and including Phase 3 (effective May 2027). Existing obligations under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules) continue to apply until formally repealed.


1. Introduction

Welcome to embolo.in (“Embolo”, “we”, “us”, or “our”), a B2B pharmaceutical SaaS ecosystem operated by Embolo Technologies Private Limited. Embolo is a pure technology platform — we provide software that connects chemists, wholesalers and distributors to manage orders, inventory, ERP and supply chain operations digitally. We do not buy, hold, sell, or distribute medicines or pharmaceutical products ourselves.

This Privacy Policy (“Policy”) explains how we collect, use, process, store, disclose, and protect the personal data of every individual (“Data Principal” or “You”) who interacts with our platform, website, or mobile applications (“Service”).

By accessing or using our Service, you acknowledge that you have read and understood this Policy and consent to the collection and processing of your personal data as described herein. If you do not agree, please discontinue use of the Service.

2. Nature of Our Platform

Embolo operates as a SaaS intermediary. We provide technology infrastructure — including order management, inventory, ERP and supply chain optimisation tools — to registered pharmaceutical businesses. We do not hold drug licences, trade in pharmaceutical products, or act as a buyer or seller in any pharmaceutical transaction. All regulatory obligations relating to pharmaceutical trade (drug licences, Form 20/21, GST, etc.) rest with the businesses using our platform, not with Embolo.

This distinction is important for data retention: the documents you upload to our platform (such as KYC documents and drug licences) are stored solely to enable our software features, and the associated retention timelines are governed by standard data protection and business record principles, not by pharmaceutical trade regulations.

3. Definitions

The following capitalised terms have the meanings set out below, consistent with the DPDPA 2023 and DPDP Rules 2025:

  • “Child” — Any individual below the age of 18 years, as defined under the Juvenile Justice (Care and Protection of Children) Act, 2015, and consistent with Section 9 of the DPDPA.
  • “Consent” — A free, specific, informed, unconditional, and unambiguous indication of the Data Principal’s agreement to the processing of their personal data for a specified purpose, as required under Section 6 of the DPDPA.
  • “Data Fiduciary” — Embolo, as the entity that determines the purpose and means of processing personal data.
  • “Data Principal” — You, the individual to whom personal data relates. In the case of a Child, this includes the parent or lawful guardian.
  • “Data Processor” — Any third party that processes personal data on Embolo’s behalf.
  • “Data Protection Board” — The Data Protection Board of India (DPBI), constituted under Section 18 of the DPDPA.
  • “Personal Data” — Any data about an individual who is identifiable by or in relation to such data.
  • “Personal Data Breach” — Any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data that compromises its confidentiality, integrity, or availability.
  • “Significant Data Fiduciary (SDF)” — A category of Data Fiduciary as may be designated by the Central Government under Section 10 of the DPDPA based on volume or sensitivity of data processed. Embolo will comply with SDF obligations if and when so designated.
  • “Service” — The Embolo platform, including the website, web application, and all mobile applications.

4. Consent — How We Obtain, Manage, and Record It

4.1 Basis for Processing

We process your personal data only on one of the following lawful bases:

  • (a) Consent: You have given free, specific, informed, unconditional, and affirmative consent for one or more specified purposes before we process your data.
  • (b) Legitimate Use: Processing is necessary for a specific legitimate use recognised under Section 7 of the DPDPA, including compliance with legal obligations, State functions, or processing data you have voluntarily made publicly available.

4.2 How Consent Is Obtained

Before or at the time of data collection, we will present you with a clear, plain-language consent notice that:

  • Specifies the exact personal data we intend to collect.
  • States the specific purpose(s) for which the data will be processed.
  • Identifies any third parties or categories of Data Processors with whom data may be shared.
  • Informs you of your right to withdraw consent at any time.
  • Is available in English and, on request, in other Indian languages as technically feasible.

Consent is obtained through a clear affirmative action (such as ticking a checkbox or clicking ‘I Agree’) and never through pre-ticked boxes, inactivity, or bundled consent.

4.3 Withdrawal of Consent

You may withdraw your consent at any time, as easily as it was given. Simply go to My Profile > Delete My Account within the app. Upon account deletion, we will cease processing your personal data for the stated purposes, except where continued processing is required by law. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Please note that certain features of the Service will no longer be available after withdrawal.

4.4 Record of Consent

We maintain a record of every consent given, modified, or withdrawn — including the timestamp, the notice presented, and the purpose consented to. These records are retained for a minimum of seven (7) years.

5. Personal Data We Collect

5.1 Data You Provide Directly

  • Contact details: full name, email address, phone number, postal address.
  • Business information: company name, GSTIN, KYC documents, drug licences, GST certificates (uploaded by you to enable platform features).
  • Account credentials: username and password (stored encrypted/hashed).
  • Transactional data: order history, supply chain records, payment references.

5.2 Usage Data (Automatically Collected)

  • Log data: IP address, browser type and version, pages visited, timestamps, referring URLs, device identifiers.
  • Device data: device model, operating system version, mobile browser type, network information.
  • App interaction data: feature usage, session duration, error logs.

5.3 Location Data

Driver App: Because live location is central to the delivery service, the app collects your GPS location continuously during an active delivery shift — including when the app is minimised or your screen is off. This data is transmitted to our servers in real time to enable shipment tracking, route optimisation, distance-based payout calculation, and delivery confirmation for vendors and recipients. You will be asked to grant location access explicitly before the service begins. You can turn it off at any time in your device settings, but doing so will stop the delivery tracking service.

Chemist & Salesperson Apps: Location is accessed only while the app is open and in active use, to help verify your registered shop address or confirm a sales visit. We do not access your location when these apps are closed or running in the background.

5.4 App Features and Device Access

Our applications request access to certain device features to deliver their core functions. You will be asked to grant each access explicitly, and you can change these permissions at any time from your device settings. Declining access will only affect the specific feature that depends on it.

Vendor App — Distributors and Wholesalers

  • Notifications: We send you alerts for new orders placed by chemists, order status changes, and important account messages. You can manage notification preferences from your device settings.

Chemist App

  • Location (while using the app): When you use the app, we may access your approximate location to help verify your registered shop address. We do not access your location when the app is closed.
  • Camera: You can use your camera to scan product codes for faster ordering, or to photograph and upload registration documents such as your drug licence. Camera access is only used when you actively initiate a scan or upload.
  • Wireless Printer: If you connect a wireless printer, the app sends formatted invoice or receipt data to that printer. No personal information is shared with the printer.
  • App Analytics: We collect anonymised information about how the app is used to identify errors, improve performance, and understand feature adoption. This data does not identify you personally.
  • Notifications: We send order confirmations, status updates, and relevant service alerts.

Salesperson App

  • Voice Order Entry (optional): If you choose to use the voice order feature, the app will access your microphone only while you are actively speaking an order. Your voice input is used to create the order record and is not retained after the order is processed.
  • App Analytics: Same as described above for the Chemist App.
  • Notifications: You receive order-related alerts and operational updates.

Driver App

  • Location (continuous, including in background): Live location is a core requirement of the delivery service. The app collects your GPS location throughout an active delivery shift, including when you are not actively using the app. See Section 5.3 for full details. You will be asked to grant this access before your first delivery.
  • Camera: You use your camera to photograph a completed delivery as confirmation. These photos are uploaded to our servers and are visible to the associated vendor.
  • Notifications: Delivery assignments and urgent operational alerts are sent to your device. These alerts may appear even when you are using other applications, so you do not miss an assignment.

Vendor Fleet App — Distributor Operations

  • Camera: You use your camera to scan product codes when recording medicine expiry returns or processing batch claims. The app reads the code from your camera; no photographs are saved.
  • Notifications: You receive alerts for pending expiry claims, returns, and operational tasks.

Vendor Dashboard — Desktop Application

  • Internet: The application connects to our servers to sync your orders, inventory, and business data in real time.
  • Local File Access: When you choose to export an invoice or report, the application saves that file to a location on your computer that you select. We do not read, copy, or transmit any other files from your computer.

5.5 Third-Party and Social Login Data

If you register or log in via Google, Facebook, Instagram, Twitter/X, or LinkedIn, we may receive associated profile data (name, email, profile picture) as permitted by your settings on those platforms and with your explicit consent at the time of linking.

5.6 Communications Data

We may send OTPs or service notifications via SMS or WhatsApp using authorised third-party communication providers. We do not access, read, or store your WhatsApp messages or contact list. Any message-reading permissions (e.g., for OTP auto-fill) are used solely for that purpose.

6. How We Use Your Personal Data (Purpose Limitation)

We process personal data only for the specific purposes stated at the time of collection or as permitted by law. We do not use your data for any purpose incompatible with the stated purpose, except with your renewed consent or as required by law.

  • Service Operation: Processing orders, managing inventory, coordinating supply chain workflows, and — for the Driver App — real-time tracking, proof-of-delivery, route optimisation and payout calculation.
  • Account Management: Authentication, account creation and maintenance, KYC verification, customer support.
  • Legal & Regulatory Compliance: GST compliance, court orders, responding to lawful government requests.
  • Security & Fraud Prevention: Detecting and preventing unauthorised access, fraud, and abuse.
  • Service Improvement: Analytics, performance monitoring, bug fixes, product development (on anonymised or aggregated data where feasible).
  • Communication: Service alerts, order updates, OTPs, support responses, policy change notifications.
  • Marketing: Promotional offers and newsletters, only with your explicit consent; opt out at any time via unsubscribe links or account settings.
  • Grievance Redressal: Handling complaints, exercising Data Principal rights, responding to Data Protection Board proceedings.

7. Processing of Personal Data of Children

⚠ IMPORTANT: Under the DPDPA, a “Child” is any individual below 18 years of age. This is the applicable threshold under Indian law.

Our Service is a B2B pharmaceutical SaaS ecosystem intended for registered businesses and adult professionals. It is not designed for or directed at individuals below the age of 18.

7.1 Verifiable Parental / Guardian Consent

We do not knowingly collect or process personal data of any individual below 18 years of age without first obtaining verifiable consent from a parent or lawful guardian. Verification of the parent or guardian’s identity and adult status will be conducted using one or more of the following methods:

  • Government-issued identity documents voluntarily provided.
  • Virtual tokens or verification via DigiLocker or other government-authorised digital identity services.
  • Such other verification mechanisms as may be prescribed by the Data Protection Board.

7.2 Prohibitions

Where we process data of a Child, we strictly prohibit: behavioural tracking or monitoring of children; targeted advertising directed at children; and any processing likely to cause harm to the child’s well-being.

7.3 Discovery of Underage Data

If we discover that personal data of a Child under 18 has been collected without appropriate verifiable parental consent, we will immediately cease processing and delete the data, unless we are legally required to retain it. Parents or guardians may contact our Grievance Officer to request deletion of a Child’s personal data.

8. Disclosure of Personal Data

We do not sell your personal data. We share data only in the following circumstances and only to the extent necessary:

8.1 Service Providers (Data Processors)

We engage third-party companies as Data Processors for functions such as cloud hosting, analytics, payment gateways, and IT support. All Data Processors are bound by written agreements that restrict use of data to the stated purpose, require equivalent security safeguards, prohibit unauthorised sub-processing, and require cessation of processing upon termination of our instruction.

8.2 Affiliates and Business Partners

We may share data with entities affiliated with Embolo for purposes consistent with this Policy, disclosed to you at the time of collection or consent.

8.3 Secondary Sales and Stock Data

Where you authorise us to do so, we may share aggregated or anonymised secondary sales and stock data with your business partners (such as pharmaceutical brands or distributors) on their written request. Such data will not personally identify any individual customer.

8.4 Legal Authorities

We may disclose personal data to government authorities, courts, tribunals, or law enforcement agencies when required by applicable law or court order, or to protect our legal rights and those of our users.

8.5 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of assets, your personal data may be transferred to the successor entity. We will provide advance notice via email or a prominent website notice before such a transfer occurs.

8.6 With Your Consent

We may share your data with other parties with your explicit, prior, specific consent.

9. Cross-Border Data Transfers

Your personal data may be processed or stored on servers located outside India by our cloud service providers and technology partners. All cross-border transfers are subject to the following safeguards:

  • Transfers are made only to countries, entities, or under conditions as notified or approved by the Central Government under Section 16 of the DPDPA.
  • Data Processor agreements include contractual clauses requiring recipient parties to maintain equivalent data protection standards.
  • We will update this section promptly upon the Central Government notifying permissible or restricted cross-border transfer jurisdictions.

Your data is primarily stored on India-based servers where technically feasible, and we are committed to complying with any data localisation mandates as and when notified.

10. Data Retention and Erasure

10.1 Retention Principles

We retain personal data only for as long as necessary to fulfil the specific purpose for which it was collected, or as required by law, whichever is longer.

10.2 Retention Schedule

Data Category Retention Period
Account and Profile Data Duration of active account + 3 years after account closure or last interaction
Transaction and Order Records 7 years from the date of transaction (GST Act compliance)
Delivery and Location Logs 90 days from delivery completion, unless required for an active dispute
Driver Location Data (real-time) Processed in real time; historical records retained for 90 days for payout verification and dispute resolution
Proof of Delivery (POD) Images 1 year from delivery date, or the duration of the contractual obligation with the vendor, whichever is longer
Uploaded Business Documents (KYC, drug licences, GST certificates) Duration of active account + 1 year, or as required by applicable law
Communication Logs (OTP, alerts) 30 days
Security and Audit Logs Minimum 1 year, as required by DPDP Rules for breach detection and investigation
Consent Records 7 years from the date consent is given, modified, or withdrawn
Marketing Opt-in Records Until withdrawal + 1 year

10.3 Erasure Notification

Where we intend to delete your personal data at the end of a retention period, we will provide you with at least 48 hours’ prior notice via your registered email address or in-app notification, unless deletion is required immediately by law or for security purposes.

11. Your Rights as a Data Principal

The DPDPA grants you the following rights over your personal data. You may exercise these rights at any time by contacting our Grievance Officer using the details in Section 13. We will acknowledge your request within 48 hours and respond substantively within the timelines below. There is no fee for exercising your rights, unless requests are manifestly unfounded or excessive.

11.1 Right of Access and Summary

You have the right to obtain a summary of the personal data we hold about you, the purposes for which it is processed, and the identities of all Data Processors who have access to your data. We will respond within 7 days of a valid request.

11.2 Right to Correction and Updating

You have the right to request correction of inaccurate personal data and completion of incomplete data. We will act on this within 7 days of a valid request.

11.3 Right to Erasure

You have the right to request erasure of your personal data when it is no longer necessary for the purpose for which it was collected, or upon withdrawal of consent, subject to overriding legal retention obligations. We will respond within 30 days.

11.4 Right to Withdraw Consent

You may withdraw consent for any specific purpose at any time (see Section 4.3). Withdrawal does not affect the lawfulness of past processing.

11.5 Right to Grievance Redressal

You have the right to have any grievance regarding our data processing addressed by our Grievance Officer within 30 days. If not resolved satisfactorily, you may escalate to the Data Protection Board of India.

11.6 Right to Nominate

You have the right to nominate another individual to exercise your DPDPA rights on your behalf in the event of your death or incapacity. To register a nominee, please contact the Grievance Officer.

To exercise any of these rights, please contact:
Email: customersupport@embolo.in (Subject: “DPDPA Privacy Request”)
Website: https://embolo.in/contact/

12. Security of Personal Data

We implement and maintain reasonable security safeguards to protect your personal data against unauthorised access, disclosure, alteration, destruction, or loss, consistent with DPDP Rules 2025 requirements. These measures include:

  • Encryption of personal data in transit (TLS/HTTPS) and at rest (AES-256 or equivalent).
  • Obfuscation and masking of sensitive fields in databases.
  • Role-based access controls limiting data access to authorised personnel on a need-to-know basis.
  • Access logging, monitoring, and regular review of access logs.
  • Regular data backups to ensure continuity of processing.
  • Contractual obligations on all Data Processors to maintain equivalent security standards.
  • Periodic internal security assessments.

No system is 100% secure. In the event of a Personal Data Breach, we will:

  • Immediately notify affected Data Principals and the Data Protection Board of India upon discovery.
  • Submit a detailed breach report to the Data Protection Board within 72 hours of discovery.
  • Take prompt remediation steps to contain the breach and prevent recurrence.

13. Grievance Officer

In accordance with the DPDPA and DPDP Rules 2025, Embolo has designated a Grievance Officer to address all queries, complaints, and data rights requests. (Note: A full Data Protection Officer (DPO) is only mandatory for entities designated as Significant Data Fiduciaries by the Central Government. Embolo is not currently so designated. We will appoint a resident DPO and comply with all enhanced SDF obligations if and when designated.)

Grievance Officer
Embolo Technologies Private Limited

Email: customersupport@embolo.in (Subject: “DPDPA Privacy Request”)
Website: https://embolo.in/contact/

Response Time: Acknowledgement within 48 hours  |  Substantive response within 30 days.

If your complaint is not resolved to your satisfaction within 30 days, you may escalate to:
Data Protection Board of Indiahttps://www.meity.gov.in

14. Cookies and Tracking Technologies

We use cookies, web beacons, and similar technologies on our website and applications:

  • Essential Cookies: Strictly necessary for the Service to function (login sessions, security tokens). These cannot be disabled.
  • Functionality Cookies: Remember your preferences and settings. Disabled by default until consent is obtained.
  • Analytics Cookies: Understand how you use the Service. Require your consent before activation.
  • Marketing Cookies: Currently not deployed on embolo.in. Will require explicit consent if deployed in future.

You may manage cookie preferences via your browser settings or through our website. Our full Cookie Policy is available at https://embolo.in/cookie-policy.html.

15. Third-Party Links

Our Service may contain links to third-party websites or applications. This Policy does not apply to those services. We encourage you to read their privacy policies before providing any personal data.

16. Changes to This Privacy Policy

We may update this Policy from time to time to reflect changes in law, technology, or our data practices. When we make material changes, we will:

  • Send an email notification to your registered email address.
  • Display a prominent notice on our website and within the application for a minimum of 30 days before the changes take effect.
  • Update the “Last Updated” and “Effective Date” at the top of this document.

Continued use of the Service after the effective date constitutes acceptance of the revised Policy.

This Policy is drafted to be forward-compatible with all three phases of DPDPA/DPDP Rules implementation. We are committed to updating our operational procedures (consent notices, records, breach reporting) to be fully active by May 2027, and will update this Policy as implementing notifications are issued by the Central Government or the Data Protection Board.

17. DPDPA Phased Implementation — Our Commitments

  • Phase 1 Active (from November 2025): Data Protection Board of India constituted. Administrative provisions in force. Embolo acknowledges the regulatory authority of the DPBI.
  • Phase 2 November 2026: Consent Manager registration opens. Embolo will evaluate and integrate with registered Consent Managers to enable seamless consent management and withdrawal for users.
  • Phase 3 May 2027 (Full Enforcement): All substantive obligations in force — consent notices, data principal rights, security safeguards, breach notifications, children’s data rules, and cross-border transfer restrictions. Embolo commits to full operational compliance by this date.

If Designated as SDF: We will appoint a resident Data Protection Officer, conduct annual Data Protection Impact Assessments and independent audits, and comply with all enhanced SDF obligations as required.

18. Miscellaneous

18.1 Governing Law and Jurisdiction

This Policy shall be governed by and construed in accordance with the laws of India, including the DPDPA and applicable IT laws. Disputes shall be subject to the jurisdiction of the Data Protection Board of India and, on appeal, the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).

18.2 Severability

If any provision of this Policy is found invalid or unenforceable, the remaining provisions shall continue in full force and effect.

18.3 Language

This Policy is published in English. In the event of any conflict between the English version and any translated version, the English version shall prevail.


Contact Details

Embolo Technologies Private Limited
Website: https://embolo.in

Privacy / Grievance Contact: customersupport@embolo.in
Contact Form: https://embolo.in/contact/

© 2026 Embolo Technologies Private Limited. All rights reserved.
This Privacy Policy was last updated on 1 July 2026 (Version 2.0).