Farmacy OS

Privacy

Privacy Policy

Farmacy OS handles health-adjacent data for EU pharmacies, so privacy isn't a footnote — it's built into the architecture. This notice explains, in plain language, what we process, why, where it lives, and the rights you and your customers have.

Last updated 2 July 2026

At a glance

  • EU-hosted in Ireland — data stays in the EU by default.
  • Every pharmacy is an isolated tenant; no cross-tenant access.
  • We're a processor for your customer data, a controller for account & billing data.
  • Full GDPR rights + DSAR tooling, answered within 30 days.
  • Named sub-processors — you're notified before we add one.
  • Health-adjacent data is minimised and never sold.
On this page

Section 1

Who we are & what this notice covers

This policy is issued by [registered legal entity name][F] (“Farmacy OS”, “we”, “us”), registered at [registered EU business address][F]. It satisfies our transparency obligations under Articles 13 and 14 of the EU GDPR.

It covers personal data we handle when a pharmacy uses the Farmacy OSplatform, when we run the growth loop on a pharmacy’s behalf, and when anyone visits our marketing site or requests a demo. Cookies are covered separately in our Cookie Policy.

Founder action · [F]

Replace the entity name and registered address above with the real controller details, and appoint (and name here) an EU Article 27 representative and a DPO if your processing scale or special-category use requires one.

Section 2

Our two roles: processor and controller

Farmacy OS wears two hats, and it matters which one applies to a given piece of data:

  • Processor— for the pharmacy’s own customer, order and clienteling data. The pharmacy is the controller; we act only on its documented instructions under a signed Data Processing Agreement.
  • Controller — for the pharmacy account itself: the staff logins, billing records, product telemetry, security logs, and the aggregated learning loop we use to improve the platform.

Why the split matters

When you exercise your rights, the route differs: your pharmacy’s customers exercise their rights through the pharmacy (we assist); you exercise your rights over account data directly with us.

Section 3

What data we process

We keep collection tight. By category:

CategoryExamplesRole
AccountStaff names, work email, password hash, role/storeController
BillingCompany details, subscription tier, usage meters (via Stripe token — no raw card data)Controller
Pharmacy customer ledgerYour customers' names, contacts, purchases, consent, follow-up state, routine contextProcessor
Content & campaignsApproved posts/ads, creative assets, performance metricsProcessor
TechnicalIP, device/browser, session and audit logsController
SupportMessages you send us and our repliesController

Section 4

Health-adjacent & special-category data

A pharmacy’s customer records can imply health information, which may be special-category data under GDPR Article 9. We treat it accordingly:

  • Data minimisation is mandatory — we collect the minimum that earns its keep.
  • Processing needs both an Article 6 basis and an Article 9 condition, determined per purpose and country.
  • We complete a DPIA before production processing and keep it living as workflows change.
  • We never use a pharmacy's customer data to train shared models without a separate, documented basis.

We do not

sell personal data, use it for our own advertising, or move special-category data outside the EU without SCCs and a transfer assessment.

Section 5

Legal bases we rely on

  • Contract (Art. 6(1)(b)) — to provide the platform to your pharmacy.
  • Legitimate interests (Art. 6(1)(f)) — security, fraud prevention, and improving the service, balanced against your rights.
  • Legal obligation (Art. 6(1)(c)) — tax, accounting and regulatory record-keeping.
  • Consent (Art. 6(1)(a) / Art. 9(2)(a)) — where required, e.g. non-essential analytics and certain customer communications; withdrawable at any time.

Section 6

Where your data lives — and how it stays separated

  • EU residency. EU customer data is hosted in the EU — EU — Ireland (eu-west-1) — on managed Postgres.
  • Tenant isolation.Every pharmacy is an isolated tenant. Access is enforced in application code and backstopped by Postgres Row-Level Security — one pharmacy can never read another’s data.
  • Encryption. AES-256 at rest, TLS 1.3 in transit; the most sensitive fields use envelope encryption with keys held in a managed KMS.
  • Dedicated option. Strict-residency tenants can be graduated to a dedicated EU database.

Section 7

Our sub-processors

We use a small set of vetted providers to run the platform. Each is bound by a DPA and, where relevant, EU Standard Contractual Clauses. This list is representative of our core stack; the live, maintained list governs.

Sub-processorPurposeRegionTerms
SupabaseManaged Postgres, auth & vector storeEU (Ireland)DPA
VercelApplication hosting & edge deliveryEU region / global edgeDPA
OpenAILLM inference (via model router; zero-retention route for health-adjacent tasks)US — SCCsDPA
StripeSubscription billing & usage meteringEU / US — SCCsDPA

Changes & objection

We publish and maintain this list, and notify tenants before adding a sub-processor so your team can object within the window set in the DPA. AI providers sit behind swappable adapters; health-adjacent tasks are routed to zero-data-retention endpoints where offered.

Founder action · [F]

Confirm the exact production sub-processor set (ad platforms, WhatsApp/Meta, video/creative, email, analytics) and their regions before launch, and wire the “notify before change” mechanism (email + a public diff/RSS).

Section 8

How long we keep data

  • Account & ledger data — for the life of the subscription, then deleted or returned per the DPA.
  • Billing & tax records — as long as law requires (typically several years).
  • Security & audit logs — a limited, defined window sufficient for investigation.
  • Demo requests & marketing contacts — until you ask us to erase them, or they go stale.

Section 9

Your rights — and our DSAR process

Under GDPR you can exercise the rights to:

RightWhat it means
AccessGet a copy of the personal data we hold about you
RectificationCorrect data that's wrong or incomplete
ErasureHave your data deleted where no lawful reason to keep it applies
RestrictionPause processing while a concern is resolved
PortabilityReceive your data in a structured, machine-readable format
ObjectObject to processing based on legitimate interests, and to direct marketing

How to exercise them

Email farmacie@farmacy-growth.com. We verify identity, then respond within 30 days. For a pharmacy’s own customers, we support the pharmacy’s DSAR handling through per-tenant export and deletion tooling.

Section 10

International transfers

We keep EU data in the EU by default. Where a provider processes data outside the EU (for example, some AI inference), we rely on EU Standard Contractual Clauses, complete a transfer impact assessment, and apply supplementary measures such as encryption and, where offered, zero-data-retention routing. Special-category data does not leave the EU without these safeguards.

Section 11

How we protect data

  • Encryption at rest and in transit; KMS-held keys for sensitive fields.
  • Tenant-scoped access end to end — identity propagates through every service and tool call.
  • Per-tenant, reason-logged audit trails; time-boxed break-glass support access, never silent cross-tenant reads.
  • Least-privilege access, dependency scanning, and testing before scale.
  • A breach-response process with notification without undue delay where required.

Section 12

Contact, DPO & complaints

Questions or requests: farmacie@farmacy-growth.com. Data-protection matters: farmacie@farmacy-growth.com.

You also have the right to lodge a complaint with your local supervisory authority. We’d appreciate the chance to resolve it with you first.

Founder action · [F]

Confirm whether a DPO and an Article 27 EU representative are legally required for your processing, and name the competent lead supervisory authority once the establishment is set.