Legal

Privacy Policy

Version 2.0.0Updated 29 May 2026

Effective: 29 May 2026 · Version: 2.0.0

_This document is a template prepared by Pond Care's product team. For binding clauses please consult your counsel. We will publish a counsel-reviewed version no later than 90 days after 29 May 2026._

1. Data fiduciary

Under the Digital Personal Data Protection Act 2023 (DPDP Act), Pond Care Veterinary Pvt. Ltd. is the Data Fiduciary for the personal data you provide via this app. Our contact for privacy matters is privacy@pondcarevet.com. The Grievance Cell handles escalations (see Section 11).

2. What we collect

Account data:

  • Name, phone, email (optional for farmers), role.
  • GSTIN, state, and PAN where applicable (manufacturers, clinics,

pharmacies, investors).

  • VCI registration number for Fish Vets.
  • KYC documents you choose to upload for verified-pond status or

investor onboarding.

Pond + farming data:

  • Pond name, species, location (latitude / longitude), tier, stocking

date, area.

  • Daily logs (pH, temperature, DO, salinity, ammonia, plankton,

behaviour notes).

  • Feed, seed, sample, product, and harvest entries.
  • Photographs you upload of your pond, fish, or supporting documents.
  • Voice recordings captured by Talk-to-Pond and Farm Diary

features (used for transcription only; we do not retain raw audio longer than 90 days).

  • Lab reports, FC visit findings, Schedule-H digital prescriptions.
  • AI Vet conversation history and feedback signals.

Payment data:

  • Invoice references, transaction IDs, payment status, payer identity

(farmer or linked investor). All card / UPI tokenisation happens inside Razorpay; Pond Care does not see your card number, CVV, or banking credentials.

Device + technical data:

  • Browser type, OS, IP address (used for security, fraud prevention,

and error diagnostics).

  • A short-lived trace identifier is attached to every API request

so we can correlate errors with logs (kept for 30 days).

  • Service-worker offline cache state (your browser, not our servers).

3. Sensitive personal data (DPDP §2(t))

We treat the following categories with heightened protection:

  • KYC documents (Aadhaar, PAN where uploaded).
  • VCI registration certificates.
  • Schedule-H prescription details (a category of medical record).
  • Banking and UPI payment metadata.

We collect these only when required for the relevant service (KYC verification, VCI-eligible prescription issuance, payments).

4. How we use your data

  • Run the service — deliver advice, take payments, send invoices,

ship pharmacy orders, schedule visits.

  • Send transactional SMS via Twilio (OTP, payment confirmations,

pond manager assignments, delivery alerts). Twilio is a US-based processor — see Section 7 for cross-border details.

  • Send transactional emails via Titan SMTP (invoices, monthly

reports, password resets, support replies).

  • Generate **AI Vet recommendations using LLMs from Google Gemini,

Anthropic Claude, and OpenAI** (via the Emergent Integrations gateway). We pass only the minimum context needed; we never pass your name, phone, or KYC documents to LLM providers.

  • Voice transcription via OpenAI Whisper for Talk-to-Pond and

Farm Diary. Audio is sent to the transcription endpoint, the text is returned, and the raw audio is deleted within 90 days.

  • Investor monthly portfolio reports: if you are an investor,

we generate a PDF on the 1st of each month summarising the previous month's spend, ROI, and per-pond performance, and email it to your registered email address.

  • Aggregated industry insights (e.g. average pH per region,

average ROI per species) are computed without your name attached and shared in anonymised form with research/insurance partners.

5. Sharing

We share only what's necessary with the following parties:

  • Pond Clinics see lab reports they filed for your pond.
  • Field Coordinators assigned to your pond see your daily logs

and visit history.

  • Pond Managers (PM-Manage employees allotted by Pond Care SA, and

PM-Self employees recruited by the linked Investor) see operational data on the ponds they are assigned to.

  • Pharmacy partners see your delivery address and order details

for fulfilment.

  • Linked Investors see the dashboard view of the farmer's pond

KPIs they have funded, including the monthly PDF report.

  • Tax authorities receive GSTR-1, GSTR-3B, and other filings as

required by Indian tax law.

  • Payment processor (Razorpay) receives the amount and customer

identifier needed to process the transaction.

We do not sell your data to advertisers or data brokers.

6. Operator access for error diagnostics

When a request to our backend fails with a 5xx error, the following non-PII fields are logged to our internal error log and may be forwarded by email to the support team:

  • HTTP path, status code, exception class
  • A short trace identifier
  • Your user identifier and role (so support can call you back about

the problem)

We do not log request or response bodies. The error log is purged after 30 days.

7. Cross-border processors

The following processors receive specific data outside India:

  • Twilio (USA) — SMS message body, to-phone, sender ID.
  • Google Gemini / OpenAI (USA) — text-only prompts (no PII) for

AI Vet replies and Whisper transcription.

  • Razorpay (India + region-specific data centres) — payment data.

By using the relevant feature, you consent to this processing. You can disable AI Vet voice features from your profile to opt out of Whisper transcription specifically.

8. Storage + security

  • Primary data is stored on MongoDB Atlas in an Indian region.
  • All API traffic is HTTPS-only (TLS 1.2+).
  • Passwords are hashed with bcrypt; OTP codes are hashed before

storage and discarded 5 minutes after issue.

  • We rate-limit and brute-force-protect all authentication endpoints.
  • Card data never touches our servers — it's tokenised by

Razorpay.

9. Your rights under DPDP Act

  • Access: Download your data anytime from Profile → Data Vault.
  • Correction: Edit profile or pond details anytime.
  • Erasure: Request account deletion via Profile → Data Vault →

Delete. We retain GST-mandated invoice records and digital prescriptions for the legal minimum (typically 7 years) — these records are anonymised after your erasure.

  • Portability: Export as JSON.
  • Withdraw consent: Stop the AI Vet, disable voice features, or

unsubscribe from non-transactional emails from Profile → Settings.

  • Grievance: Email grievance@pondcarevet.com (response within

24 hours, resolution within 15 working days).

  • DPB complaint: If unsatisfied with our resolution, you may

approach the Data Protection Board of India under the DPDP Act.

10. Audit trail of acceptance

Each time you accept (or re-accept) these legal documents, we record: your user identifier, the version number you accepted, the date and time, your IP address, and your browser user-agent string. This audit trail is retained for the lifetime of your account so that we can demonstrate consent in case of dispute.

11. Cookies + local storage

  • We use localStorage for: session token, language preference,

draft logs (so your work isn't lost if you go offline), and the service-worker offline cache.

  • We do not use third-party tracking cookies, analytics pixels,

or ad networks.

12. Children

Pond Care is not intended for users under 18. If we discover an account belongs to a minor, we will close it and erase the data.

13. Updates

This policy can be updated. Material changes (new processors, new sensitive-data categories) require you to re-accept on next login. Minor changes surface as a soft banner. We notify via in-app banner and, where applicable, SMS at least 14 days in advance.

14. Contact

  • Privacy: privacy@pondcarevet.com
  • Support: akbar@pondcarevet.com
  • WhatsApp: +91 90009 48599
  • Grievance Cell: grievance@pondcarevet.com
  • Data Protection Board (regulator): contact details at dpbi.gov.in