Subprocessors
This list identifies the third-party services that PharmIT Services Private Limited engages as subprocessors to provide the PharmIT Platform. Each subprocessor is bound by written terms imposing data-protection obligations no less protective than our Data Processing Agreement. Engaging a new subprocessor is announced here at least 14 days in advance — Tenants who object on data-protection grounds may follow the process in DPA §5.
Active subprocessors
| Subprocessor | Purpose | Data categories | Region |
|---|---|---|---|
| Hosting / IaaS provider | Compute, storage, network for the production environment | All Tenant Data at rest and in transit (encrypted) | India |
| Let's Encrypt (ISRG) | TLS certificate issuance for pharmit.live | Domain name only — no Tenant Data | USA (cert issuance only; data does not leave India) |
| NIC GSP — Protean eGov Technologies / similar | GST e-invoice IRN, e-Way Bill API, GSTR data exchange | Invoice / e-Way bill metadata as required by GSTN | India |
| Zoho ZeptoMail | Transactional email delivery (OTP, alerts, password reset) | Recipient email, message body, send metadata | India |
| Razorpay | Payment processing, UPI QR, subscription billing | Payment metadata, payer email / phone, transaction reference (no PCI data on PharmIT) | India |
| Anthropic (Claude) | AI inference — when Tenant configures Claude as their AI provider with their own key | Input prompts at inference time; zero-retention mode where available | USA / EU (under contract); enable only with informed Tenant choice |
| OpenAI | AI inference — when Tenant configures OpenAI with their own key | Input prompts at inference time; zero-retention mode where available | USA |
| Google (Gemini) | AI inference — when Tenant configures Gemini with their own key | Input prompts at inference time | USA / EU |
| WhatsApp Business API (Meta) / 360dialog / Twilio (where used) | WhatsApp delivery (only where Tenant enables and configures) | Recipient phone number, template variables, send metadata | USA / Germany / India depending on the BSP |
| SMS gateway (Tenant-selected) | SMS delivery | Recipient phone number, message body, send metadata | India |
Planned (not yet engaged)
- Off-site backup target (S3-compatible) — region: India
- Monitoring / observability — preference for self-hosted or India-resident SaaS
- Incident-management tooling — to be selected
Note on AI providers
AI integrations are opt-in per Tenant. They are configured by the Tenant's SuperAdmin with the Tenant's own API keys. Personal data is sent to the AI provider only at the moment of inference; the Company contractually requires zero-retention / no-training-on-customer-data terms wherever the provider supports them. Tenants who require all data to stay in India may disable AI features entirely.
Notification of changes
Subscribe to privacy@pharmit.in to receive proactive notice of subprocessor additions or removals.