This Privacy Policy (“Policy”) governs the manner in which Medcords Healthcare Solutions Private Limited collects, uses, maintains and discloses information collected from its users or visitors (each referred to as a "User") through its website(s), mobile applications, devices, products, services, and online marketplace (hereinafter collectively referred to as the “Platform”).


I)        DEFINITIONS        1

II)        GENERAL DISCLAIMER        3



V)        APP PERMISSIONS        5

VI)        USE OF COOKIES        6



IX)        SHARING USER DATA        8

X)        THIRD PARTY WEBSITES        10

XI)        USER COVENANTS        10





XVI)        SEVERABILITY        12



  1. “Medcords” or “Company” or “We/we” or “Us/us” or “Our/our” is Medcords Healthcare Solutions Private Limited, a company registered as per the laws of India
  2. “Website” is our website at the address 
  3. “Aayu App” is a mobile application and its related sub-domains and sites as owned and run by MedCords which facilitates provision of healthcare services to its users
  4. “Aayu Chemist app” or “App” is a mobile application and its related sub-domains and sites as owned and run by MedCords, including sites created for Chemists
  5. “Platform” is the collective reference made to the website, the app, devices, products, services, and online marketplace of MedCords
  6. “User” or “Visitor” or “’You/Your” is any Person accessing our Website or App or Platform, irrespective of their registration status on our Platform.
  7. “Person” means any natural person, limited or unlimited liability company, corporation, partnership (whether limited or unlimited), proprietorship, Hindu undivided family, trust, union, association, government or any agency or political subdivision thereof or any other entity that may be treated as a Person under Applicable Law.
  8. “Service(s)” are services and products listed on the Aayu Chemist App like accepting delivery orders for pharmaceutical drugs, nutraceutical, and over the counter (OTC) products, facilitating diagnostic tests,and telemedicine and consultation, and any such other products as ordered by the users of Aayu app, connecting with users of the Aayu app, purchase of products from Distributors or Brand Associates, availing personal or business loans and finance services, etc
  9.  “Chemists” are retail chemists or pharmacies or medical stores or general retailers who access the Aayu Chemist app for facilitation of services of the Aayu app, including but not limited to, selling medicines and wellness products
  10.  “Medical Practitioner(s)” is a person who is a registered medical practitioner enrolled in the State Medical Register or the Indian Medical Register under the Indian Medical Council Act 1956
  11. “Healthcare Professional(s)” is a Person working in the healthcare industry like medical professionals, doctors, mental health advisors, dieticians, fitness experts, lab assistants, technicians, diagnostic centre staff etc, who aid in facilitation of services of the Aayu app
  12. “Distributor(s)” are Persons who have we have partnered with for facilitation of our Services like for purchase of bulk medicines and wellness products
  13. “Brand Associates” are Persons who sell branded products and who have we have partnered with for facilitation of our Services like for purchase of bulk medicines, wellness products etc from a specific brand
  14. “Financial Institutes” are Persons like banks or NBFCs who have we have partnered with for facilitation of our Services like availing loans, financial services etc
  15. “Service Providers” are trusted third party service providers (other than Distributors or Brand Associates or Financial Institutes) who assist and help us in facilitation of our Services like payment gateways, cloud servers, business partners, agents, trusted affiliates and advertisers etc
  16. “Channel Partner(s)” refers to a Person appointed or partnered by Medcords to facilitate the performance of the Services provided on the Platform, including but not limited to, Distributors and/or Brand Associates and/or Financial Institutes and/or other Service Providers as appointed by MedCords.
  17. “Telemedicine” refers to the delivery of healthcare services by all health care professionals using information, communication technologies and our Platform for the exchange of valid information for diagnosis, treatment and prevention of disease and injuries, research and evaluation, all in the interests of advancing the health of individuals

  1. “User Data” collectively refers to Personal Information, Sensitive Personal Data or Information and Non-Personal Information of an User, each described in detail in this Policy


This Privacy Policy applies to all the products and services offered on our Platform and describes what information of MedCords Healthcare Solutions Private Limited, as the operator of the Platform and, as owner of the Platform, may collect from a User, on or through our website or mobile applications, including but not limited to the Aayu Chemist app, directly or in relation to the Services otherwise rendered by Us, including Our facilitation through the Platform, for Our Services and how We use, process, disclose and try to protect such information.

You agree and understand that MedCords is responsible for operation and maintenance of the Platform and all information collected and processed on the Platform is collected and processed by Us strictly in relation to Our business.

By using Our Platform, or the Services, You confirm that You have read, understood, and agree with the privacy practices as described in this Privacy Policy, and the Terms of Use (the “Terms”) and the collection, storage and processing of Your information in accordance with them.

This Privacy Policy is incorporated by reference into the Terms. Any capitalized terms used but not defined in this Privacy Policy have the meaning given to them in the Terms. Any words importing singular shall include plural and vice versa and the headings are for convenience or reference only and shall not be used in and shall not affect the construction or interpretation of this Policy.

This Privacy Policy is published in compliance with, inter alia:

  1. Section 43A of the Information Technology Act, 2000 (“IT Act”);
  2. Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Information) Rules, 2011 (“SPDI Rules”); and
  3. Regulation 3(1) of the Information Technology (Intermediaries Guidelines and Digital Media Ethics Code) Rules, 2021 (“Intermediaries Guidelines”).


During your use of this Platform, we collect certain personal identification information from you in a variety of ways, including, but not limited to, when you visit our Platform, register on the Platform, respond to a survey, fill out a form, and in connection with other activities, services, features or resources we make available on our Platform. This information may be of the following nature:-

  1. “Personal Information” is that information which can be used to directly or indirectly identify you. It includes de-identified data that, when linked to other information available to us, would enable us to identify you. Personal Information does not include data that has been irreversibly anonymized or aggregated so that we cannot identify you through it, even in conjugation conjunction with other information.
  2. “Sensitive Personal Data or Information” (“SPDI”) means Personal Information of any individual relating to password; financial information such as bank account or credit card or debit card or other payment instrument details; physical, physiological and mental health condition; sexual orientation; medical records and history; biometric information; any detail relating to the above as provided to or received by MedCords for processing or storage.

We may also collect other Sensitive Personal Data or Information about You when you use Our Services on the Platform. This information includes health information we receive from You or, on Your behalf, such as information or records relating to your medical or health history, health status and laboratory testing results, details of medical practitioner issuing the prescription, details of treatment plans and medication prescribed by a Medical Practitioner, dosage details such as frequency of dosage, alternative medication, medicines ordered by You through the Platform, diagnostic results, other health-related information and any other information inferred there from. We may also collect payment information such as Your payment card number, expiration date, billing and shipping address.

We may also store and process medical prescriptions, treatment notes, recommendations and other data generated by Medical Practitioners and Healthcare Professionals; on or through the Platform, and data shared by third parties such as diagnostics related information; prescription related information etc maybe retained on our records for the duration of you availing the Services or for any such period required or permitted under applicable law. However, any data/ information relating to an individual that is freely available or accessible in public domain or furnished under the Right to Information Act, 2005 or any other law shall not qualify as Sensitive Personal Data or Information.

We receive and store any information you enter on Our Platform or provide us in any other way. When you register on the Platform, we collect registration details such as phone number, name, geographical address and email address. We verify your phone number with the help of a one-time password sent to your phone number.

We may also collect information required for providing you Services on the Platform including, items you place in the cart, pharmaceutical, nutraceutical products including prescription drugs or over the counter (OTC) products you may order, facilitating booking a consultation with a Medical Practitioner, running diagnostic tests, etc. Further, we may also access and collect User interactions with our Channel Partners.

Further, we may also receive your corporate or business details like business registration licenses, personal identification documents, drug licence details, your sale and purchase history through our Platform, information related to your loan requests, any other financial information as provided by you on the Platform, and your interactions with the users of Aayu app.

We will collect personal identification information from Users only if they voluntarily submit such information to us. Users can always refuse to supply personally identification information, except that it may prevent them from engaging in certain Platform related activities.


We may collect Non-Personal Identification Information about Users whenever they interact with our Platform. Non-Personal Identification Information may include the browser name, the type of device and technical information about Users means of connection to our Platform, such as the operating system and the Internet service providers utilized and other similar information.


We may ask for the following app permissions from your device while you use or register on the Platform;

It is recommended that you set your location sharing 'Always' as it helps us to show you location specific data like availability of Services at your geographical area. This can be changed anytime in your device settings.

This helps us take a picture of You for photo identification and any document for directly uploading it to the App.

This access permission is needed to store and retrieve your uploads such as photo identifications, any document uploads, etc on your device.

This helps in assisting you with sharing content from our Platform to your contacts, make calls to Channel Partners, etc

This supports automatic OTP confirmation, so that you don't have to enter the authentication code manually and for us to send you payment related SMS confirmations.

This helps us to optimize your experience based on the WiFi’s strength and signals.

This helps to enable video consultations with users of Aayu app

This helps us to ensure that you receive instant updates about your orders, delivery time, our Services, etc


Our Platform may use "cookies" to enhance User experience. User's web browser places cookies on their device for record-keeping purposes and sometimes to track information about them. User may choose to set their web browser to refuse cookies, or to alert you when cookies are being sent. If they do so, note that some parts of the Platform may not function properly.

Kindly refer to our Cookies Policy separately for more information on how we use cookies.


MedCords may collect and use User Data for the following purposes:

  1. To improve customer service: Information you provide helps us respond to your customer service requests and support needs more efficiently.
  2. To personalize user experience: We may use information in the aggregate to understand how our Users as a group use the services and resources provided on our Platform.
  3. To improve our Platform: We may use feedback you provide to improve our products and services.
  4. To process payments: We may use the information Users provide about themselves when placing an order only to provide service to that order. We do not share this information with outside parties except to the extent necessary to provide the service.
  5. To run a promotion, contest, survey, offers or other Platform feature
  6. To send Users information they agreed to receive about topics we think will be of interest to them
  7. To send periodic emails: We may use the email address to send User information and updates pertaining to their order. It may also be used to respond to their inquiries, questions, and/or other requests. If User decides to opt-in to our mailing list, they will receive emails that may include company news, updates, related product or service information, etc. If at any time the User would like to unsubscribe from receiving future emails, they may do so by contacting us via our Platform.


It is of utmost importance to us that any information or data related to You is securely stored, in lines with the applicable laws of land. User Data is contained within secured cloud networks of a third party Service Provider in an electronic form and is only accessible by a limited number of authorized persons who have access rights to such systems or otherwise require such information for the purposes provided in this Privacy Policy. Such User Data may also be converted to physical form from time to time. MedCords takes all necessary precautions to protect your User Data both online and offline, and implements reasonable security practices and measures including certain managerial, technical, operational and physical security control measures that are commensurate with respect to the information being collected and the nature of MedCords’ business. To protect the security of User Data during transmission, we use all the latest technical data security measures to prevent any breach of data.

No administrator or employee or staff at MedCords will have knowledge of your password. It is important for you to protect against unauthorised access to your account, password, and device. Be sure to log off from the Platform when finished. MedCords does not undertake any liability for any unauthorised use of your account and password. If you suspect any unauthorised use of your account, you must immediately notify MedCords by sending an email to our contact email id. You shall be liable to indemnify MedCords due to any loss suffered by it due to such unauthorised use of your account and password.

We make all User Data accessible to our employees or Channel Partners only on a need-to-know basis, and bind all each of them to strict confidentiality obligations. MedCords may, therefore, retain and submit all such records to the appropriate authorities and our Channel Partners, who request access to such information. We also assist Users and help in accessing information related to them. Therefore, we may retain and submit all such records to the relevant Users.

Although we make best possible efforts to transmit and store all the User Data and information provided by you in a secure operating environment that is not open to public, you understand and acknowledge that there is no such thing as complete security and we do not guarantee that there will be no unintended disclosures of any User Data, information and potential security breaches. MedCords does not warrant any liability of any possible data or security breaches of its’ Service Provider who is appointed to store and process User Data.

Thus, notwithstanding the above, MedCords is not responsible for the confidentiality, security or distribution of User Data by our Channel Partners or any third parties outside the scope of our agreement with each of them. Further, you agree not to hold MedCords responsible for any breach of security or for any action of any third parties that receive your Personal Information or User Data or events that are beyond our reasonable control including, acts of government, computer hacking, unauthorized access to computer data and storage device, computer crashes, breach of security and encryption, poor quality of internet service or telephone service of the User etc.


We may store and access User Data regularly but MedCords does not engage in any practices which require analysis of User Data for any other purposes than necessary for facilitation of our Services. Our Platform is strictly an aggregator between Users, our Channel Partners and users of the Aayu App.

We do not sell, trade, or rent User Data to others. We may share generic aggregated demographic information not linked to any personal identification information regarding visitors and users with our select Channel Partners for the purposes outlined in Clause VII above. We may use third party Service Providers to help us operate our business and the Platform or administer activities on our behalf, such as sending out newsletters or surveys. We may share your information with these third parties for those limited purposes provided that you have given us your permission.

Users are entitled to delete their account at any time by writing or calling to our contact details mentioned in this Policy.

Upon deletion of a User’s account, MedCords shall delete User Data available on the account at the request of the User but certain information pertaining to User Data might be retained by MedCords or its Channel Partners for our internal business use only.

Subject to above, it is pertinent to note that any information about You and the other Users of the Platform forms an integral part of Our business. We only share the User Data, as described below, after ensuring that such third party has implemented measures to assure data protection measures and that are either subject to this Privacy Policy or follow practices at least as protective as those described in this Privacy Policy. We have arrangements with third parties (including as mentioned below) such as affiliates or group companies, service providers, retailers, payment gateways, logistics partners who are the intended recipients and may have access to the User Data but shall not disclose such information including SPDI further to any other individual / entity. Some of the third parties include:

  1. Channel Partners: We may share User Data with our Channel Partners like affiliated retailers, the Distributors who supply and service your order, Financial Institutes who assist you in accessing loan services, third party Service Providers . You can identify when a third party is involved in your transactions, and we share User Data for those transactions with that third party. Further, they must process the Personal Information in accordance with this Privacy Policy and as permitted by applicable law. It is clarified that we will not be responsible and liable for the acts of omissions and commissions of such Channel Partners associated with us. However, we may facilitate resolving any issue you may face with such Channel Partners.
  2. Legal Obligations: We may release account and other User Data when We believe in good faith that such release is appropriate to comply with applicable law including to: (i) conform to legal requirements or comply with legal process; (ii) protect rights or property or affiliated companies; (iii) prevent a crime or in interest of national security; or (iv) protect personal safety of our Users or the public. We may also disclose your Personal Information to enforce or apply Our Terms and other agreements; or protect the rights, property or our safety, safety of our Users or others. This includes exchanging information with other companies, organisations, government or regulatory authorities for fraud protection and credit risk reduction.
  3. Sharing Upon Merger Or Amalgamation Or Intra-Group Transfer: Any third party to which We transfer or sell Our assets, merge or consolidate with, will have the right to continue to use the information (including SPDI) provided to Us by You, in accordance with the Terms and this Privacy Policy. We may disclose information to Our partners, affiliates, subsidiaries, group entities, investors, stakeholders or potential associates in an anonymized and aggregate manner, so that they too may understand how Users use Our Platform and enable Us to create a better overall experience for You.
  4. Improving Our Business: You acknowledge that We have a right to use a recorded copy of your telephonic conversation, your order details, your loan application details, etc for improving our Services, marketing and promotional efforts, customize your experience and aiding you in procuring targeted consultation for any underlying medical condition. These uses improve the Platform and the Services, and better tailor it to meet your needs, so as to provide you with an efficient, safe and customized experience. We may transfer such User Data to a third party, including persons outside India, to improve product and Service offerings while taking commercially reasonable steps to try and ensure, that the recipient adheres to the applicable laws for ensuring data protection as is adhered by us.


Users may find advertising or other content on our Platform that link to the sites and services of our partners, suppliers, advertisers, sponsors, licensors and other third parties. We do not control the content or links that appear on these sites and are not responsible for the practices employed by websites linked to or from our Platform. In addition, these sites or services, including their content and links, may be constantly changing. These sites and services may have their own privacy policies and customer service policies. Browsing and interaction on any other website, including websites which have a link to our Platform, is subject to that website's own terms and policies.


Subject to the terms set in this Privacy Policy and Rule 3 (1)(b) of  the Information Technology  (Intermediary Guidelines and  Digital Media Ethics Code)  Rules, 2021, You agree and undertake that You shall not host, display,  upload, modify, publish,  transmit, store, update or share  any information that, (i) belongs to another person  and to which the You do not  have any right; (ii) is  defamatory, obscene,  pornographic, paedophilic,  invasive of another’s privacy,  including bodily privacy,  insulting or harassing on the  basis of gender, libellous,  racially or ethnically  objectionable, relating or  encouraging money laundering  or gambling, or otherwise  inconsistent with or contrary to the laws in force; (iii) is harmful  to child; (iv) infringes any  patent, trademark, copyright or  other proprietary rights; (v)  violates any law for the time being in force; (vi) deceives or  misleads the addressee about  the origin of the message or  knowingly and intentionally  communicates any information  which is patently false or  misleading in nature but may  reasonably be perceived as a  fact; (vii) impersonates another  person; (viii) threatens the  unity, integrity, defence,  security or sovereignty of India,  friendly relations with foreign  States, or public order, or  causes incitement to the  commission of any cognisable  offence or prevents investigation  of any offence or is insulting  other nation; (ix) contains  software virus or any other  computer code, file or program  designed to interrupt, destroy or  limit the functionality of any  computer resource; (x) is  patently false and untrue, and is  written or published in any  form, with the intent to mislead  or harass a person, entity or  agency for financial gain or to  cause any injury to any person.

MedCords is at complete discretion to delete any information which violates the above term and/or may even restrict the responsible User to access the Platform with immediate effect for any or all future uses.


MedCords has the discretion to update this Privacy Policy at any time. When we do, we may post a notification on the main page of our Platform or send you an email. We encourage Users to frequently check this page for any changes to stay informed about how we are helping to protect the User Data we collect. You acknowledge and agree that it is your responsibility to review this Privacy Policy periodically and become aware of the modifications.

You may review, correct, update, change the information that you have provided by logging into Your account. However, You are not permitted to delete any part of the Personal Information or any other information generated on the Platform. You may request Us to delete the same. You may update Your information at any point by writing to Us at the details indicated below in the contact section.


By agreeing to create an account after downloading the App or proceeding to the Website, and/or using our Services you represent that you voluntarily provide us with personal information including medical and financial information and consent to their collection, use and disclosure, recording, and storage in accordance with this Privacy Policy. You also represent that you are duly authorised by any third party (including a child or an employer) whose information you share with us. We shall act as per your representation of authority and shall not make any independent enquiries to ascertain the veracity of your authorisation. In the event you do not have sufficient authorisation you shall be solely responsible for your acts and omissions including sharing of information with us by you and the consequential processing and actions taken by us in accordance with this Privacy Policy. Your usage of this Platform signifies your acceptance of this Privacy Policy and the terms and conditions contained herein.

If you do not agree to this Policy, please do not use our Platform. Your continued use of the Platform following the posting of changes to this Policy will be deemed as your acceptance to those changes.

You acknowledge that, notwithstanding this Privacy Policy, we have at all times the right to disclose your User Data to any legal, regulatory, governmental, tax, law enforcement or other authorities pursuant to applicable law and our legal obligations. This may arise from any investigation, order, or request by such parties. To the furthest extent permissible by law, you agree not to take any action and/or waive your rights to take any action against us for the disclosure of your User Data in these circumstances.


You may communicate your objection to our continual use and/or disclosure of your Personal Information and SPDI for any of the purposes and in the manner as stated above at any time by contacting us at the details indicated below.

If you do not wish for us to continue using your information, and/or disclose your Personal Information and SPDI for any of the purposes and in the manner as stated above at any time, you may opt out of providing the same by contacting us at the details indicated below. 

If you have any questions about this Privacy Policy, the practices of this Platform, or your dealings with this Platform, please contact us at:

MedCords Healthcare Solutions Private Limited,

Plot no. 2 Basant Vihar Main Road,

Dadabari Ext. Kota Rajasthan - 324009

Email ID - 

MedCords Helpline- 781-681-1111


In accordance with the Information Technology Act, 2000 and Rules made thereunder, the name and contact details of the Grievance Officer are provided below:

Name:                Vipin Verma

Address:        Third floor, 1-ka-22, Kalptaru, Vigyan Nagar, Kota,

                        Kota, Rajasthan, 324005

Cell:                 9571224686


For registering your complaint, please write to the Grievance Officer at the above-mentioned email address in relation to any violation of this Policy or the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.The Grievance Officer shall redress the complaint in accordance with the provisions of the Information Technology Act, 2000 and Rules made thereunder.


In the event that any provision and/or clause and/or term of this Policy is found to be invalid, void and unenforceable by a Court of any competent jurisdiction, then the remaining provisions will remain in force in accordance with the original intention of MedCords.


This Policy shall be governed by and interpreted and construed in accordance with the laws of India. The place of jurisdiction shall exclusively be in Kota, Rajasthan. In the event of any dispute arising out of this Policy the same shall be settled by a binding arbitration conducted by a sole arbitrator, appointed jointly by both parties and governed by the Arbitration and Conciliation Act, 1996 thereto and shall be conducted by the Arco Dispute Resolution Private Limited in accordance with their Arbitration Rules. The arbitral award will be final and binding upon the Parties. The seat and venue of arbitration shall be Kota, Rajasthan. The Parties can also opt to resolve the dispute(s) in order to reach amicable resolution through online mode via ODR/ Zoom/ Google Meet platform