Privacy Policy
Last updated: May 30, 2026
PharmaSense is a Software-as-a-Service product operated from Cyprus that helps licensed pharmacies monitor inventory expiry and reduce waste. This Privacy Policy explains what personal data we collect, how we use it, the lawful bases we rely on, with whom we share it, and the rights you have under the EU General Data Protection Regulation (GDPR) and Cyprus law.
Data Controller
PharmaSense, Cyprus. For any privacy-related question, you can contact us at support@pharmasense.co. We act as a data controller for account information and as a data processor for the inventory data you upload.
Information We Collect
We collect only the information needed to provide and operate the service:
- Account information: full name, email address, hashed password (bcrypt cost 12) — never stored in plain text.
- Pharmacy information: pharmacy name, license number, city, plan, language preference.
- Inventory data: product names, barcodes, batch numbers, expiry dates, quantities, purchase and selling prices, suppliers, and categories.
- Sales data: actions you record on alerts (discounts, transfers, returns, disposals).
- Payment information: handled by Stripe — we never see or store full card numbers. We retain only Stripe customer and subscription identifiers.
- Optional contact data: phone number, used only if you opt in to SMS alerts.
- Technical data: IP address, browser, operating system, timestamps, and minimal request logs needed to operate the service securely.
Legal Basis (GDPR Art. 6)
We process your personal data on the following lawful bases:
- Performance of a contract — to deliver the PharmaSense service you subscribed to.
- Consent — for optional features such as SMS alerts. You can withdraw consent at any time.
- Legal obligation — for invoicing, tax records, and other obligations under Cyprus and EU law.
- Legitimate interest — to keep the service secure, prevent abuse, and improve reliability.
Third-Party Processors
We share data only with sub-processors necessary to run the service. They are bound by data-processing agreements and appropriate safeguards.
| Processor | Purpose | Location |
|---|---|---|
| Railway | Application hosting and database | EU (Frankfurt) |
| Resend | Transactional email delivery | EU |
| Stripe | Payment processing | EU / US (SCCs) |
| Twilio | SMS alerts (optional) | EU / US (SCCs) |
Pharmacy Inventory Data
- Inventory data is owned by the pharmacy that uploads it.
- It is never shared with other pharmacies on the platform.
- It is never used to market products to patients or end customers.
- We do NOT process patient or customer data of pharmacies. PharmaSense is not a patient-facing system.
Data Retention
- Active accounts: data is retained for as long as your subscription remains active.
- After cancellation: account and inventory data are deleted within 90 days, unless longer retention is required by law.
- Tax and invoicing records: retained for 7 years as required by Cyprus and EU tax law.
- Backups: residual encrypted backups may persist for up to 35 days before being overwritten.
Security
- All traffic is encrypted in transit using HTTPS/TLS 1.2 or higher.
- Data at rest is encrypted with AES-256 on managed Railway storage.
- Passwords are hashed with bcrypt (cost factor 12) — we cannot recover them.
- Session tokens are JWTs with a 24-hour lifetime.
- The application enforces strict multi-tenant isolation: each pharmacy can access only its own data.
Your GDPR Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access — obtain a copy of the personal data we hold about you.
- Right to rectification — correct inaccurate or incomplete information.
- Right to erasure — request deletion of your personal data ("right to be forgotten").
- Right to restriction — limit how we process your data in certain cases.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interest.
- Right to withdraw consent — at any time, where consent is the legal basis.
- Right to lodge a complaint — with the Office of the Commissioner for Personal Data Protection of Cyprus.
To exercise any of these rights, email support@pharmasense.co. We respond within 30 days.
Cookies
We use only strictly necessary cookies (session token, locale preference). We do not use tracking, advertising, or analytics cookies, and no cookie consent banner is required under GDPR/ePrivacy. See our Cookie Policy for details.
International Transfers
Where data is processed outside the European Economic Area (e.g. by Stripe or Twilio US entities), we rely on the European Commission's Standard Contractual Clauses (SCCs) and equivalent safeguards to ensure your data continues to be protected.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified to active users by email at least 30 days before they take effect.
Contact
Questions, requests, or complaints about privacy can be sent to support@pharmasense.co.