APPZCART  /  Investor Handbook
CHAPTER 05 · OPERATIONS

The machine.

The hiring plan, vendor stack, city-launch playbook, ABDM and DPDP compliance roadmap, and the honest accounting of what could kill us — with mitigations.

14 — OPERATIONS

The machine behind the product.

Hiring · infra · vendors · SOPs
HIRING PLAN

18-month role-by-role

M0–3: Product Manager, Senior Backend Engineer, Mobile Lead. M3–6: AI/ML Engineer, Growth Marketer, City Ops Manager #1. M6–12: City Ops #2, Customer Support Lead (3 agents), Compliance Officer. M12–18: CFO/Finance Head, Partnerships Lead, Data Analyst. Total: 14 hires.

SALARY BANDS

Capital-efficient compensation

Tier 2 hiring keeps costs 30–40% below Bangalore. Engineering leads ₹15–20 L. Mid-engineers ₹8–12 L. Ops/support ₹4–7 L. ESOP top-up for senior roles — cash conservation strategy. Founder takes minimal salary until Series A.

VENDOR STACK

Monthly recurring costs

AWS Mumbai ~₹1.5 L/mo (scales with users). Razorpay 2% MDR. WhatsApp Business API ₹50K/mo. Twilio SMS ₹30K/mo. Mixpanel + PostHog analytics ₹40K/mo. Sentry + Datadog monitoring ₹25K/mo. Zendesk support ₹20K/mo. Total infra ~₹3 L/mo at scale.

DATA RESIDENCY & DR

India-resident, redundant

Primary: AWS Mumbai. DR: AWS Hyderabad. Daily encrypted backups, 30-day retention, 1-hour RPO, 4-hour RTO. Vault data never leaves India. Disaster runbook tested quarterly. Compliant with DPDP Act 2023 data localization expectations.

CITY LAUNCH PLAYBOOK

The repeatable SOP

30-day launch sequence per city: (1) 5 clinic partnerships signed. (2) 1 diagnostic lab integrated. (3) 10 ASHA workers trained. (4) WhatsApp seed communities live (500 members). (5) Regional content calendar populated. (6) Local PR & influencer kickoff. (7) Launch event with first 100 families.

OFFICE & CULTURE

Hybrid, founder-led

Small HQ in India (low-cost Tier 2 city), remote-friendly for engineering. Quarterly all-hands. Asynchronous-first communication. Code reviews mandatory. Weekly product demos. Founder mindset embedded: "Think like a founder, code like an architect."

15 — COMPLIANCE

Regulation as moat.

ABDM · DPDP · IRDAI · SaMD
ABDM

ABDM milestone tracker

Phase 1 — ABHA registration support (M3). Phase 2 — ABDM sandbox integration (M4–6). Phase 3 — certification submission (M6–9). Phase 4 — production-grade ABDM-compliant vault (M9–12). Phase 5 — HPR/HFR provider integration (Y2).

DPDP ACT 2023

Data Protection compliance

Consent manager built in. Purpose limitation logged per data access. User rights: access, correction, erasure, portability. Data Protection Officer appointed by Series A. Breach notification protocol within 72 hours. Children's data (under 18) has verifiable parental consent gates.

TELEMEDICINE

Telemedicine Practice Guidelines

2020 MoHFW/MCI Telemedicine Guidelines compliance for doctor-consult feature. Doctor verification via NMC registration check. Prescription protocol — only RMPs prescribe. Documentation retained for 3 years. No prescribing of scheduled drugs via platform.

SaMD CLASSIFICATION

Software as Medical Device

Open question: do AI insights make us a SaMD under CDSCO? Position our AI as "wellness guidance, not diagnosis" to stay in Class A or non-device. Engage a regulatory consultant in Phase 1. If classification changes, prepare CDSCO Class A registration pathway.

IRDAI & INSURANCE

Insurance partnership regulation

We do not sell insurance — we're a tech platform partner. Revenue share arrangements with IRDAI-licensed insurers stay legal. If we ever facilitate sales, we register as an Insurance Web Aggregator. Roadmap option, not Day-1 requirement.

DRUG INTERACTIONS

Liability on medication intelligence

If we flag drug interactions or dosage issues, we carry medical-product liability. Mitigation: (1) clear "informational, consult pharmacist" framing. (2) sourced from licensed pharmacopeia databases. (3) clinical board signoff. (4) professional indemnity insurance.

CORPORATE COMPLIANCE

Statutory filings current

Appzcart Pvt Ltd: ADT-1, AOC-4, MGT-7, board resolutions, statutory audit. GST monthly. TDS quarterly. PF/ESI as headcount grows. ROC compliance via company secretary on retainer.

SECTION 8 (APPZCODE)

Non-profit governance separated

AppzCode AI Research Federation maintained as a clean Section 8 entity for grants and CSR — not for Appzcart product revenue. Clear arm's-length separation. Inter-entity transactions documented and at fair market value. Protects both entities under audit.

08 — RISKS

What could kill us, and how we hedge.

Honest founder math
Regulatory shift
ABDM policy or data-privacy regulation changes could break our integration or compliance model.
MitigationCompliance officer from day one. Modular architecture decouples ABDM layer from core product. Active dialogue with ABDM and state health departments.
Competitor entry
Apollo, Google, or a well-funded startup launches a family health vault before we hit critical mass.
MitigationGo deep in Tier 2 first — where they won't look. Lock in 50,000 families with sticky data before big players notice. Speed is our weapon.
Adoption slowdown
Tier 2 families don't convert to paid as projected; freemium-to-paid funnel collapses.
MitigationMultiple revenue streams — API licensing, insurance, employer wellness — reduce dependence on individual subscriptions. Pricing flexibility built into roadmap.
Trust & security breach
A health-data leak would be catastrophic for trust and could end the company.
MitigationBank-grade encryption, India data residency, third-party security audits, dedicated security ownership at engineering lead level, insurance against breach.
Founder key-person risk
Founder unavailability or burnout stalls the venture — the "hit by a bus" question.
MitigationDocumented vision, modular team ownership, board and advisors in place, succession planning. CTO can run the roadmap, Ops can scale, Marketing can run GTM.
Capital efficiency
Burn outpaces traction; runway runs out before Series A milestones.
Mitigation20-month runway on ₹5 Cr seed, weekly burn tracking, partnership-led GTM (low CAC), revenue from month 3, multiple parallel revenue streams.