Legal
Privacy policy
What PharmeXa collects, why, and what rights you have over it. PharmeXa is operated by Evyasys and governed principally by India's Digital Personal Data Protection Act, 2023.
Last updated July 2026
- Scope
- Distribution data — stock and sales movement only.
- Our role
- Processor for customer data, controller for enquiries.
- Sold or shared
- Never sold. No advertising, no profiling.
- Governing law
- Digital Personal Data Protection Act, 2023 (India).
Draft — not reviewed by counsel
This text was drafted to the right structure and describes how PharmeXa actually works, but it has not been through legal review. It should not be relied on as it stands, and must be reviewed before the site goes live.
Who we are
PharmeXa is a product of Evyasys, at 418, STC, South Bopal, Ahmedabad, Gujarat, India. Evyasys is the legal entity behind the service, which is why correspondence, invoicing and support all come from an evyasys.com address.
For any question about this policy, or to exercise a right described below, write to ankur.patel@pharmexa.in. Requests are handled by a named person rather than a ticket queue.
The two kinds of data involved
It matters which of these you are asking about, because our role — and therefore your route to a remedy — differs between them.
Customer data
Stockist stock statements, product masters, and the Medical Representative and Area Manager records belonging to a customer’s deployment. Here we act as a data processor: the pharmaceutical company is the controller, the data is theirs, and we process it on their instructions under our agreement with them. If you are an MR or Area Manager asking about your own records, your employer is the controller — we will refer you to them, and help them answer you.
Website and enquiry data
Information you give us directly through the demo request form, or by emailing or messaging us. Here we act as the controller, and everything below about rights applies to us directly.
What we collect, and why
- Enquiry details — name, work email, company, role, and the MR and stockist counts you tell us. Used to respond to your enquiry and prepare a relevant demonstration rather than a generic one. Lawful basis: your consent, given by submitting the form.
- Correspondence — emails and messages you send us, retained so we can pick up a conversation where it left off rather than asking you to repeat yourself.
- Platform data — within a customer deployment: submitted statements, the records extracted from them, product mappings, and the identity and activity of the users who submitted and approved them. Processed on the customer’s instructions, for the purposes they set.
- Technical data — standard server request information such as IP address, user agent and the page requested, produced by the act of serving a page. This site sets no advertising or profiling cookies.
The scope of the data
PharmeXa is a distribution data platform. What it holds is stock and sales movement between a pharmaceutical company and its stockists: product, quantity, value, batch, expiry, rate and period, plus the identity of the people who submitted and approved each statement.
That is the whole scope, and it is a deliberate boundary rather than a gap. Everything the platform produces — the reports, the KPIs, the forecasting and inventory views — is derived from those fields. Nothing in its design requires or accepts anything beyond them, which is usually what an IT or compliance team is really asking when they ask what we store.
How submissions reach us
Statements are uploaded directly to the platform over an encrypted connection by a signed-in user. The original file is retained alongside the records extracted from it, so any figure can be traced back to the document it came from. No third-party messaging service carries customer data — WhatsApp appears on this site only as a way to reach our team, never as a route for statements.
How long we keep it
Enquiry data is kept while we are in conversation with you and for a reasonable period afterwards, then deleted. Customer platform data is retained for the term of the customer’s agreement and deleted or returned afterwards in line with it. The specific retention window is stated on the security page rather than here, so there is one number to keep current instead of two.
Your rights
Under the Digital Personal Data Protection Act, 2023 you may:
- ask what personal data of yours we hold, and why
- ask us to correct or complete it
- ask us to erase it, where we have no continuing basis to keep it
- withdraw consent you previously gave
- nominate someone to exercise these rights on your behalf
- raise a grievance with us, and escalate it to the Data Protection Board of India
Write to ankur.patel@pharmexa.in and we will respond within the period the Act requires. If your request concerns data inside a customer’s deployment, we will refer you to that company as the controller and assist them in answering you.
Data outside India
Where a sub-processor operates outside India, that transfer is made in accordance with the Act and the restrictions applying at the time. Processing locations are listed on the security page.
Visitors from the EU and UK
If you contact us from the EU or UK, we handle your enquiry data on the same basis set out above and will honour GDPR and UK GDPR rights — access, rectification, erasure, restriction, portability and objection — on request to the same address.
Changes to this policy
If this policy changes materially we will update the date at the top and, where the change affects customers, notify them directly rather than relying on this page being re-read.
Questions about any of this?
Legal and data questions go to the same address as everything else, and get a real answer from a person rather than a form response.
ankur.patel@pharmexa.inThe other policies
Also relevant: security and data handling, which states where data is hosted, how it is encrypted and how long it is kept.