Privacy
Privacy Policy
Farmacy OS handles health-adjacent data for EU pharmacies, so privacy isn't a footnote — it's built into the architecture. This notice explains, in plain language, what we process, why, where it lives, and the rights you and your customers have.
Last updated 2 July 2026
At a glance
- EU-hosted in Ireland — data stays in the EU by default.
- Every pharmacy is an isolated tenant; no cross-tenant access.
- We're a processor for your customer data, a controller for account & billing data.
- Full GDPR rights + DSAR tooling, answered within 30 days.
- Named sub-processors — you're notified before we add one.
- Health-adjacent data is minimised and never sold.
On this page
Section 1
Who we are & what this notice covers
This policy is issued by [registered legal entity name][F] (“Farmacy OS”, “we”, “us”), registered at [registered EU business address][F]. It satisfies our transparency obligations under Articles 13 and 14 of the EU GDPR.
It covers personal data we handle when a pharmacy uses the Farmacy OSplatform, when we run the growth loop on a pharmacy’s behalf, and when anyone visits our marketing site or requests a demo. Cookies are covered separately in our Cookie Policy.
Founder action · [F]
Replace the entity name and registered address above with the real controller details, and appoint (and name here) an EU Article 27 representative and a DPO if your processing scale or special-category use requires one.
Section 2
Our two roles: processor and controller
Farmacy OS wears two hats, and it matters which one applies to a given piece of data:
- Processor— for the pharmacy’s own customer, order and clienteling data. The pharmacy is the controller; we act only on its documented instructions under a signed Data Processing Agreement.
- Controller — for the pharmacy account itself: the staff logins, billing records, product telemetry, security logs, and the aggregated learning loop we use to improve the platform.
Why the split matters
Section 3
What data we process
We keep collection tight. By category:
| Category | Examples | Role |
|---|---|---|
| Account | Staff names, work email, password hash, role/store | Controller |
| Billing | Company details, subscription tier, usage meters (via Stripe token — no raw card data) | Controller |
| Pharmacy customer ledger | Your customers' names, contacts, purchases, consent, follow-up state, routine context | Processor |
| Content & campaigns | Approved posts/ads, creative assets, performance metrics | Processor |
| Technical | IP, device/browser, session and audit logs | Controller |
| Support | Messages you send us and our replies | Controller |
Section 4
Health-adjacent & special-category data
A pharmacy’s customer records can imply health information, which may be special-category data under GDPR Article 9. We treat it accordingly:
- Data minimisation is mandatory — we collect the minimum that earns its keep.
- Processing needs both an Article 6 basis and an Article 9 condition, determined per purpose and country.
- We complete a DPIA before production processing and keep it living as workflows change.
- We never use a pharmacy's customer data to train shared models without a separate, documented basis.
We do not
Section 5
Legal bases we rely on
- Contract (Art. 6(1)(b)) — to provide the platform to your pharmacy.
- Legitimate interests (Art. 6(1)(f)) — security, fraud prevention, and improving the service, balanced against your rights.
- Legal obligation (Art. 6(1)(c)) — tax, accounting and regulatory record-keeping.
- Consent (Art. 6(1)(a) / Art. 9(2)(a)) — where required, e.g. non-essential analytics and certain customer communications; withdrawable at any time.
Section 6
Where your data lives — and how it stays separated
- EU residency. EU customer data is hosted in the EU — EU — Ireland (eu-west-1) — on managed Postgres.
- Tenant isolation.Every pharmacy is an isolated tenant. Access is enforced in application code and backstopped by Postgres Row-Level Security — one pharmacy can never read another’s data.
- Encryption. AES-256 at rest, TLS 1.3 in transit; the most sensitive fields use envelope encryption with keys held in a managed KMS.
- Dedicated option. Strict-residency tenants can be graduated to a dedicated EU database.
Section 7
Our sub-processors
We use a small set of vetted providers to run the platform. Each is bound by a DPA and, where relevant, EU Standard Contractual Clauses. This list is representative of our core stack; the live, maintained list governs.
| Sub-processor | Purpose | Region | Terms |
|---|---|---|---|
| Supabase | Managed Postgres, auth & vector store | EU (Ireland) | DPA |
| Vercel | Application hosting & edge delivery | EU region / global edge | DPA |
| OpenAI | LLM inference (via model router; zero-retention route for health-adjacent tasks) | US — SCCs | DPA |
| Stripe | Subscription billing & usage metering | EU / US — SCCs | DPA |
Changes & objection
Founder action · [F]
Confirm the exact production sub-processor set (ad platforms, WhatsApp/Meta, video/creative, email, analytics) and their regions before launch, and wire the “notify before change” mechanism (email + a public diff/RSS).
Section 8
How long we keep data
- Account & ledger data — for the life of the subscription, then deleted or returned per the DPA.
- Billing & tax records — as long as law requires (typically several years).
- Security & audit logs — a limited, defined window sufficient for investigation.
- Demo requests & marketing contacts — until you ask us to erase them, or they go stale.
Section 9
Your rights — and our DSAR process
Under GDPR you can exercise the rights to:
| Right | What it means |
|---|---|
| Access | Get a copy of the personal data we hold about you |
| Rectification | Correct data that's wrong or incomplete |
| Erasure | Have your data deleted where no lawful reason to keep it applies |
| Restriction | Pause processing while a concern is resolved |
| Portability | Receive your data in a structured, machine-readable format |
| Object | Object to processing based on legitimate interests, and to direct marketing |
How to exercise them
Section 10
International transfers
We keep EU data in the EU by default. Where a provider processes data outside the EU (for example, some AI inference), we rely on EU Standard Contractual Clauses, complete a transfer impact assessment, and apply supplementary measures such as encryption and, where offered, zero-data-retention routing. Special-category data does not leave the EU without these safeguards.
Section 11
How we protect data
- Encryption at rest and in transit; KMS-held keys for sensitive fields.
- Tenant-scoped access end to end — identity propagates through every service and tool call.
- Per-tenant, reason-logged audit trails; time-boxed break-glass support access, never silent cross-tenant reads.
- Least-privilege access, dependency scanning, and testing before scale.
- A breach-response process with notification without undue delay where required.
Section 12
Contact, DPO & complaints
Questions or requests: farmacie@farmacy-growth.com. Data-protection matters: farmacie@farmacy-growth.com.
You also have the right to lodge a complaint with your local supervisory authority. We’d appreciate the chance to resolve it with you first.
Founder action · [F]
Confirm whether a DPO and an Article 27 EU representative are legally required for your processing, and name the competent lead supervisory authority once the establishment is set.