Trust & Data
How Pawra handles clinic records, pet-owner information, and consent. Last updated [DATE].
Draft pending legal review. This document was prepared in good faith to describe how Pawra intends to operate, but it has not been reviewed by a lawyer. If you are relying on it for a compliance decision, ask us first — we would rather answer directly than have you act on an unreviewed page.
Client Privacy
Pawra is operated by [COMPANY LEGAL NAME], registered at [REGISTERED ADDRESS]. Our data contact is [PRIVACY EMAIL].
What we hold
To run a clinic’s records and reminders we store: the pet’s name, species, breed, age and sex; visit notes, prescriptions and vaccination dates supplied by the clinic; and the pet owner’s name and WhatsApp number. Where a vet sends a voice note or a photograph of a prescription, we store that media and the text we derive from it.
Why we hold it
Solely to provide the service to the clinic — maintaining the medical record and sending reminders the clinic has asked us to send. We do not sell personal data, we do not share it with advertisers, and we do not use pet-owner contact details to market anything of our own.
Messages travel over WhatsApp, which is operated by Meta and governed by its own terms and privacy policy. Message content passes through Meta’s systems as part of delivery. We cannot change that, and you should read Meta’s policy alongside this one.
How long we keep it
Clinical records are retained while the clinic’s account is active, and for [RETENTION PERIOD] after closure so records can be recovered or exported. Clinics can request earlier deletion at any time.
Your rights
Under India’s Digital Personal Data Protection Act, 2023, a person whose data we hold may ask for access to it, correction of it, or its erasure, and may withdraw consent. Because we process most data on behalf of the clinic, requests from pet owners are usually best raised with the clinic; write to us at [PRIVACY EMAIL] and we will help either way.
Consent Rules
Every message Pawra sends goes out under the clinic’s name, at the clinic’s instruction, to a person who has an existing relationship with that clinic.
- The clinic obtains consent. Before adding a pet owner, the clinic confirms the owner agreed to receive reminders about their pet on WhatsApp. We provide printable consent wording clinics can use at reception.
- Opting out is one message. Any recipient can reply STOP to stop receiving reminders. We honour it immediately and inform the clinic.
- Reminders only. We send vaccination and follow-up reminders, appointment confirmations, and records the owner asked for. We do not send promotional messages, and we do not let clinics use Pawra to message people who are not their own clients.
- We never contact your clients as Pawra. Not to upsell them, not to survey them, not to refer them anywhere.
Clinic Data Ownership
The records a clinic creates in Pawra belong to that clinic. Concretely:
- Export whenever you want. Ask and we will provide your full patient database in a standard, openly readable format ([FORMAT + TURNAROUND]). You do not have to be leaving to ask.
- Leaving costs nothing. No exit fee, no lock-in period, and no withholding of records pending payment.
- We do not operate clinics and we do not refer patients to other practices. Our business only works if your clinic keeps its clients.
- We do not sell or license your data to pharmaceutical companies, insurers, marketplaces, or anyone else.
- Deletion means deletion. On request we delete your data from live systems and, within [BACKUP CYCLE], from backups.
Security
Pawra is an early-stage product. Rather than claim certifications we do not hold, here is what is true today and what we are committed to.
In place
- Data in transit is encrypted over HTTPS/TLS.
- Data at rest is encrypted by our hosting provider, [HOSTING PROVIDER + REGION].
- Access to production data is limited to named staff who need it, and is used only to operate or support the service.
- Reminders are sent through the official WhatsApp Business API, not an unofficial automation of a personal account.
Not yet
- We do not hold ISO 27001, SOC 2, or any comparable certification, and we will not imply otherwise.
- We have not completed an independent penetration test. [TARGET DATE, IF ANY]
If something goes wrong
If we become aware of a breach affecting your clinic’s data, we will tell you what happened, what was affected, and what we are doing about it — within [NOTIFICATION WINDOW] of confirming it — and we will notify the Data Protection Board where the law requires it. To report a vulnerability, write to [SECURITY EMAIL]; we will not pursue action against good-faith researchers who report responsibly.