Stocure

Privacy Policy

Last updated: 6 July 2026

Matrix Therapeutics Private Limited(“Matrix”, “we”, “us”, “our”) operates the Stocure platform — an inventory and distribution management system for hospital medical devices. This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use Stocure, in compliance with the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable laws of India.

1. Contact

Matrix Therapeutics Private Limited

[Address line 1], [Address line 2], Hyderabad, Telangana [PIN], India

Email: [Contact Email]

Phone: [Contact Number]

2. What we collect

  • Account data: name, email, phone, username, role, login and activity logs, session cookies.
  • Hospital and business data: hospital names, addresses, contacts, purchase orders, delivery instructions.
  • Operational data: inventory, batches, serial numbers, delivery challans, invoices, and usage records.
  • Patient-related data (where entered by authorised users): patient name, IP number, doctor name, and product usage submitted via hospital workflows or WhatsApp integrations.
  • Rider data: GPS location during active delivery tasks, shift and task status.
  • Communications: messages and metadata when you interact with our WhatsApp or email integrations.
  • Technical data: IP address, browser/device type, and system logs for security and troubleshooting.

3. How we use data

  • Operate Stocure (inventory, orders, distribution, billing, and compliance records).
  • Coordinate with manufacturers and hospital partners for product availability and delivery.
  • Provide customer support and system security.
  • Meet legal and regulatory obligations for medical device distribution in India.

4. Sharing

We may share data with manufacturer partners (e.g. Boston Scientific), hospitals receiving devices, service providers (cloud hosting, IT support, logistics), and authorities when required by law. We do not sell personal data.

5. Cross-border transfers

Some partners or cloud services may process data outside India. Where this occurs, we apply appropriate safeguards in line with DPDPA requirements.

6. Retention

  • Transaction and device batch records: as required by company law and medical device regulations (typically up to 8 years where applicable).
  • User accounts: until deletion request or relationship ends, plus a short backup period.
  • Hospital contact data: for the duration of the business relationship plus a reasonable period thereafter.

7. Security

  • Encryption in transit (HTTPS) and access controls within Stocure.
  • Role-based permissions for ERP users.
  • Multi-factor authentication may be enabled where configured.
  • Hosting on secured cloud infrastructure with monitoring and audit logging.

8. Your rights (DPDPA)

You may request access, correction, erasure (where permitted), grievance redressal, or withdrawal of consent by contacting [Contact Email].

9. Children

Stocure is not intended for individuals under 18. We do not knowingly collect data from minors.

10. Breaches

We maintain an incident response process. Significant breaches will be reported to the Data Protection Board and affected individuals where required by law.

11. Data Protection Officer

[DPO Name]

Data Protection Officer, Matrix Therapeutics Private Limited

Email: [DPO Email] · Phone: [DPO Phone]

12. Changes

We may update this policy. The “Last updated” date above will change when we do.