Privacy policy

Last updated: 20 July 2026

This policy explains what SyrupDesk does with data. SyrupDesk is pharmacy management software operated by Clino Health, at Sky Loft, opposite Golf Course, Shastrinagar, Yerawada, Pune, Maharashtra 411006. It covers both this website and the SyrupDesk application.

We have tried to write it in plain language. Where a term has a specific meaning under Indian law we have said so rather than hiding it.

Two different kinds of data

This is the most important section, because the answers below depend on it.

Your pharmacy’s own data.Your name, your shop’s name and address, your phone number and email, your licence details, your billing information. For this data we decide how it is used, which under the Digital Personal Data Protection Act 2023 makes us the Data Fiduciary.

Your customers’ data. The patient names, phone numbers, prescriptions and purchase history that you enter while running your shop. We only hold this because you put it there. You decide what to collect and why, which makes you the Data Fiduciary for it and makes us your Data Processor. We act on your instructions.

In practice this means we do not sell, mine, rent or market to your customer list. We do not contact your customers. We do not use their records to build products, and we do not use them to train machine-learning models.

What we collect

From you, when you sign up and use the product:

  • Account details — name, pharmacy name, address, phone number, email.
  • Licence and tax identifiers you choose to store, such as your GSTIN and drug licence number, because invoices and GST returns require them.
  • Operational records you create — stock, batches and expiry dates, purchase bills, sales invoices, returns, suppliers.
  • Payment information if you are on a paid plan. Card details are handled by our payment provider; we do not store full card numbers.
  • Technical logs — IP address, device and browser type, timestamps and error traces. These exist so we can keep the service running and investigate faults.

From your customers, entered by you:

  • Name and contact number.
  • Purchase history, and prescription details where you record them. Health-related information deserves particular care and we treat it accordingly.

From visitors to this website:

  • Basic analytics about pages visited and how you arrived. Anything you type into the contact form, so we can reply.

Why we process it

  • To provide the service — billing, inventory, reporting, backups.
  • To support you when you ask for help.
  • To take payment and issue our own invoices to you.
  • To keep the service secure and reliable, including investigating abuse and faults.
  • To meet our own legal obligations — for example retaining our accounting records for the period Indian tax law requires.

We do not use your operational data for advertising, and we do not build profiles of your customers.

Who else can see it

We share data with service providers who help us run SyrupDesk — hosting, backups, payment processing, email delivery and error monitoring. They are bound to use it only to provide that service to us.

We will also disclose data where we are legally required to — a valid order from a court or a regulator, for example. If that happens and we are permitted to tell you, we will.

We do not sell personal data. We have never done so and the business does not depend on it.

How long we keep it

While your account is active, we keep your data so the product works. Records like invoices and GST filings need to be retained for the periods Indian tax law sets, and both you and we are bound by that — those cannot simply be deleted on request.

If you close your account, you can export your data first (see our terms). After closure we retain records only for as long as we have a legal reason to, then delete or anonymise them. Backups are overwritten on a rolling cycle.

Security

Data is encrypted in transit. Access inside our team is limited to the people who need it to support you, and support access to your account is logged. We take regular backups.

No system is perfectly secure, and we would rather say that than imply otherwise. If a breach affects your data we will notify you and the Data Protection Board as the DPDP Act requires.

Your rights

Under the DPDP Act 2023 you may:

  • Ask what personal data of yours we hold, and why.
  • Ask us to correct it if it is wrong, or complete it if it is partial.
  • Ask us to erase it, where we have no legal obligation to keep it and no ongoing need for it.
  • Withdraw consent you previously gave, without affecting past processing.
  • Nominate someone to exercise these rights if you die or become incapacitated.
  • Complain to us, and escalate to the Data Protection Board if unsatisfied.

If your customer contacts us directly about their data, we will point them to you, because you are the Data Fiduciary for it. We will help you respond.

Children

SyrupDesk is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 18.

Changes

If we change this policy we will update the date at the top. For changes that materially affect you, we will tell you in the product or by email rather than relying on you to notice.

Contact us

For any question about this policy, or to exercise the rights above, contact us at support@syrupdesk.com or +91 87667 42410. Our postal address is Sky Loft, opposite Golf Course, Shastrinagar, Yerawada, Pune, Maharashtra 411006.

We aim to respond within a reasonable period and in any case within the timelines Indian law sets.