Trust & Data
How Pawra handles clinic records, pet-owner information, and consent. Last updated 31 August 2026.
Draft pending legal review. This document was prepared in good faith to describe how Pawra intends to operate, but it has not been reviewed by a lawyer. If you are relying on it for a compliance decision, ask us first — we would rather answer directly than have you act on an unreviewed page.
Client Privacy
Pawra is operated by Pawra Pvt Ltd., registered at Nagal Hatnala Road, Dehradun. Our data contact is support@pawra.in.
What we hold
To run a clinic’s records and reminders we store: the pet’s name, species, breed, age and sex; visit notes, prescriptions and vaccination dates supplied by the clinic; and the pet owner’s name and WhatsApp number. Where a vet sends a voice note or a photograph of a prescription, we store that media and the text we derive from it.
Why we hold it
Solely to provide the service to the clinic — maintaining the medical record and sending reminders the clinic has asked us to send. We do not sell personal data, we do not share it with advertisers, and we do not use pet-owner contact details to market anything of our own.
Messages travel over WhatsApp, which is operated by Meta and governed by its own terms and privacy policy. Message content passes through Meta’s systems as part of delivery. We cannot change that, and you should read Meta’s policy alongside this one.
How long we keep it
Clinical records are retained while the clinic’s account is active, and for 90 days after closure so records can be recovered or exported. Clinics can request earlier deletion at any time.
Your rights
Under India’s Digital Personal Data Protection Act, 2023, a person whose data we hold may ask for access to it, correction of it, or its erasure, and may withdraw consent. Because we process most data on behalf of the clinic, requests from pet owners are usually best raised with the clinic; write to us at support@pawra.in and we will help either way.
Consent Rules
Every message Pawra sends goes out under the clinic’s name, at the clinic’s instruction, to a person who has an existing relationship with that clinic.
- The clinic obtains consent. Before adding a pet owner, the clinic confirms the owner agreed to receive reminders about their pet on WhatsApp. We provide printable consent wording clinics can use at reception.
- Opting out is one message. Any recipient can reply STOP to stop receiving reminders. We honour it immediately and inform the clinic.
- Reminders only. We send vaccination and follow-up reminders, appointment confirmations, and records the owner asked for. We do not send promotional messages, and we do not let clinics use Pawra to message people who are not their own clients.
- We never contact your clients as Pawra. Not to upsell them, not to survey them, not to refer them anywhere.
Clinic Data Ownership
The records a clinic creates in Pawra belong to that clinic. Concretely:
- Export whenever you want. Ask and we will provide your full patient database in a standard, openly readable format (CSV and PDF, within seven working days). You do not have to be leaving to ask.
- Leaving costs nothing. No exit fee, no lock-in period, and no withholding of records pending payment.
- We do not operate clinics and we do not refer patients to other practices. Our business only works if your clinic keeps its clients.
- We do not sell or license your data to pharmaceutical companies, insurers, marketplaces, or anyone else.
- Deletion means deletion. On request we delete your data from live systems and, within 30 days, from backups.
Security
Pawra is an early-stage product. Rather than claim certifications we do not hold, here is what is true today and what we are committed to.
In place
- Data in transit is encrypted over HTTPS/TLS.
- Data at rest is encrypted by our hosting provider, Supabase, in its Mumbai (ap-south-1) region — so clinic records are stored on servers in India.
- Access to production data is limited to named staff who need it, and is used only to operate or support the service.
- Reminders are sent through the official WhatsApp Business API, not an unofficial automation of a personal account.
Not yet
- We do not hold ISO 27001, SOC 2, or any comparable certification, and we will not imply otherwise.
- We have not completed an independent penetration test.
If something goes wrong
If we become aware of a breach affecting your clinic’s data, we will tell you what happened, what was affected, and what we are doing about it — within 72 hours of confirming it — and we will notify the Data Protection Board where the law requires it. To report a vulnerability, write to support@pawra.in; we will not pursue action against good-faith researchers who report responsibly.