A prescription can reveal identity, medical conditions, medicines and practitioner details. It should be collected only when necessary and handled as sensitive information.
Consultation comes first
Sanan Organix does not advertise a public prescription-upload URL. The customer first completes the consultation form. If a prescription is required, the team then privately arranges its submission.
This reduces unnecessary document collection and allows the customer to receive context before sharing.
Purpose limitation
Before collection, the customer should be told:
- Why the prescription is needed.
- Which order or consultation it relates to.
- Who will review it.
- Whether a service provider processes it.
- What happens if it is not supplied.
The document should not be reused for unrelated marketing or profiling without an appropriate lawful basis and clear choice.
Collect only what is necessary
The process should request only information needed for consultation, verification, dispensing, safety and required records.
Customers should not be encouraged to send unrelated medical files. If an irrelevant document is received, staff should follow a defined handling and deletion process.
Authorised submission channel
The team should provide the approved submission method after consultation. Customers should avoid sending prescriptions to:
- Unverified social-media accounts.
- Personal staff accounts.
- Public comments.
- Unauthorised messaging numbers.
- Unknown file-sharing links.
Any supported channel and its security properties must be documented internally.
Access control
Access should be limited to authorised people who need the information for their role. Sanan Organix should confirm:
- Which roles can view a prescription.
- How access is granted and removed.
- Whether access is logged.
- How staff are trained.
- How inappropriate access is investigated.
“Only our team sees it” is too vague for a public assurance.
Storage and transmission
Before claiming that information is encrypted or stored in a particular country, the company must verify the actual systems and vendor contracts.
The approved process should address:
- Transmission protection.
- Storage protection.
- Account security.
- Backups.
- Device access.
- Vendor access.
- Breach response.
Do not publish technical claims that have not been tested.
Retention and deletion
The company should define how long prescriptions are kept and why. Requirements may differ for consultation, dispensing, tax, complaint and legal records.
The public notice should explain:
- Retention criteria.
- Deletion or anonymisation.
- Backup handling.
- Legal holds.
- How a customer can submit a request.
“Deleted immediately” should not be claimed if backups or legal records remain.
Customer rights and contact
Customers need a clear contact for:
- Access requests.
- Corrections.
- Withdrawal of consent where applicable.
- Deletion requests.
- Complaints.
- Security concerns.
The response process and identity verification should be documented.
Incident response
Sanan Organix should maintain a plan for misdirected messages, unauthorised access, lost devices, vendor incidents and other privacy events. The plan should define containment, assessment, documentation and required notifications.
Customer safety checklist
- Start from the official consultation page.
- Confirm the authorised submission channel.
- Do not post prescriptions publicly.
- Send only requested pages.
- Keep the consultation or order reference.
- Report a mistaken submission promptly.
Begin with the official consultation form
References
- Digital Personal Data Protection Act, 2023, India Code: https://www.indiacode.nic.in/
- CERT-In cyber-security resources: https://www.cert-in.org.in/
Privacy disclaimer
Explore a related Sanan Organix option
If a qualified clinician determines that a cannabinoid product is appropriate for you, review VijayaAmritX Full Spectrum Vijaya Oil. Read the label and complete any required consultation or prescription before use.