Legal · Privacy Policy

Privacy Policy

What we collect when a pharmacy runs on POSify Rx, why we collect it, and where the line sits between what we control and what the pharmacy controls about its own customers.

Effective date27th July 2026
Last updated11th August 2026
Version1.0
Applicable frameworkBangladesh PDPA, 2026

POSify Rx ("POSify Rx," "we," "us," or "our") provides an AI-native, offline-first point-of-sale and pharmacy management platform ("Service"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the choices available to you, in a manner consistent with the Personal Data Protection Act, 2026.

This Policy applies to pharmacy owners, pharmacists, cashiers, and other staff who use the Service ("Users"), as well as, indirectly, the end customers of pharmacies that use the Service ("Patrons"), whose data may be entered into the Service by Users. If you do not agree with this Policy, please do not use the Service.

01 Who this policy covers

  • Users — people who create an account to operate the Service (owners, pharmacists, cashiers, other staff).
  • Patrons — customers of the pharmacy whose purchase, refund, or loyalty data may be recorded by Users in the Service. Patrons typically do not interact with us directly; under the Personal Data Protection Act, 2026, the pharmacy acts as the data controller for its own customers' data and is responsible for informing Patrons about this processing, subject to Section 9 below.

02 Information we collect

Information you provide directly

Account informationName, email, phone number, role (owner/pharmacist/cashier), pharmacy name, and license or registration details.
Business & compliance informationPharmacy trade license numbers, DGDA drug sale license details under the Drug and Cosmetics Act, 2023, and other regulatory documentation you upload to the Regulatory Center.
Transaction & inventory dataSales, refunds, batch numbers, expiry dates, stock levels, pricing, and supplier information.
Patron data entered by UsersTo the extent your pharmacy chooses to record it — e.g. a Patron's name or phone number for loyalty tracking, or purchase history that may reveal health-related information. This is treated as sensitive personal data under the Personal Data Protection Act, 2026. We do not require pharmacies to collect any particular category of Patron data, and pharmacies should avoid entering health data about Patrons beyond what dispensing and DGDA record-keeping require.
Staff attendance dataClock-in/clock-out timestamps tied to staff accounts.
Support communicationsMessages sent to our AI chatbot or human support team, including ticket content and attachments.
Payment informationIf you subscribe to paid features, billing details are collected and processed by our payment processor — which may include mobile financial services such as bKash or Nagad — and we do not store full card numbers ourselves.

Information collected automatically

  • Device and usage data: browser type, operating system, IP address, device identifiers, and general usage patterns (e.g., feature usage, session timing), collected when the Service is online.
  • Local offline storage: while offline, transaction and inventory data are stored locally on the device using IndexedDB until the device reconnects and syncs to our servers.
  • Printer and hardware access: if you connect a barcode scanner or ESC/POS printer, we access those devices only as needed to send print jobs or read scans; we do not collect data from unrelated hardware.
  • Cookies and similar technologies: we may use cookies or local browser storage (distinct from IndexedDB business data) for session management and basic analytics. See Section 8.

Information from AI features

When you use the AI chatbot or request AI insights, the relevant data — for example, your question and the stock or sales data needed to answer it — is processed to generate a response. See Section 5 for details on AI processing.

03 How we use information

We use the information described above to:

  1. Provide, operate, and maintain the Service, including offline functionality and background synchronization;
  2. Process transactions, manage inventory, and generate receipts;
  3. Generate AI insights (e.g., expiry alerts, demand forecasts, anomaly detection) and power the AI chatbot;
  4. Provide customer support, including AI-assisted and human-escalated support tickets;
  5. Maintain audit logs and compliance records to support your DGDA-aligned reporting;
  6. Detect, investigate, and prevent fraud, abuse, security incidents, and technical issues;
  7. Communicate with you about your account, updates, and service notices;
  8. Improve and develop the Service, including tuning AI features using de-identified or aggregated data where possible;
  9. Comply with legal obligations, including tax and pharmaceutical regulatory recordkeeping requirements.

We do not sell personal data to third parties.

04 Legal bases

Personal Data Protection Act, 2026

Where the Personal Data Protection Act, 2026 or another applicable law requires a legal basis for processing, we rely on: performance of our contract with you (providing the Service), your or the pharmacy's consent (e.g., for optional communications or for entering Patron data), our legitimate interests (e.g., security, fraud prevention, service improvement), and compliance with legal obligations (e.g., DGDA and tax recordkeeping).

Where we act as a data controller (for User account data) we take on the associated obligations directly. Where we process Patron data on a pharmacy's instructions, we act as a data processor/service provider and the pharmacy remains the controller responsible for its own legal basis — see Section 9.

05 AI features and data processing

AI insights and the AI chatbot process the data necessary to generate a relevant response — for example, your pharmacy's stock levels and expiry dates to flag near-expiry batches, or sales history to forecast demand.

We take reasonable steps to limit AI processing to your own pharmacy's data; AI insights for one pharmacy are not generated using another pharmacy's identifiable Customer Data.

We may use aggregated or de-identified data from multiple pharmacies to improve the general accuracy of AI models, but we do not use identifiable data from one pharmacy to generate insights shown to a different pharmacy.

AI outputs are generated automatically and may be imperfect. Do not submit sensitive Patron health information to the AI chatbot beyond what is necessary for the query, and always verify AI-generated guidance before relying on it for dispensing, dosage, or compliance decisions.

06 How we share information

We share information only as follows:

  • Within your pharmacy: owners, pharmacists, and cashiers see data appropriate to their role, as configured by the pharmacy owner.
  • Service providers: cloud hosting and database providers, payment processors, SMS/email delivery providers, and customer support tooling, under contracts requiring them to protect your data and use it only to provide services to us.
  • Legal and safety reasons: if required by law, regulation, legal process, or a lawful request from a governmental authority — including the DGDA, the National Data Governance Authority established under the Personal Data Protection Act, 2026, or an agency acting under the Cyber Security Ordinance, 2025 — or to protect the rights, safety, or property of POSify Rx, our users, or the public.
  • Business transfers: if we are involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy or a policy at least as protective.
  • With your direction: where you affirmatively direct us to share data (e.g., exporting a report to a third party you designate).

We do not share Customer Data across unrelated pharmacy accounts.

07 Data retention

We retain personal data for as long as your account is active and as needed to provide the Service. After account closure, we retain Customer Data for a limited period (see Terms of Service, Section 15) to allow export, and thereafter delete or de-identify it, except where longer retention is required by law — for example, DGDA-related recordkeeping obligations under the Drug and Cosmetics Act, 2023, tax law, or to resolve disputes.

Locally cached offline data (IndexedDB) remains on the device until it syncs or is cleared; clearing browser data or uninstalling the app removes locally stored records that have not yet synced.

08 Cookies and similar technologies

We use essential cookies or local browser storage to keep you logged in and remember basic preferences, and may use limited analytics cookies to understand feature usage. You can control cookies through your browser settings; disabling essential cookies may prevent the Service from functioning correctly, including offline sync.

09 Pharmacy responsibilities regarding Patron data

Controller vs. processor For Patron data, the law generally treats your pharmacy as the data controller and treats us as the data processor carrying out your instructions. That split is the reason the obligations below sit with you.

If you (the pharmacy) enter Patron information into the Service — for loyalty tracking or dispensing records, for example — you are responsible for:

  • Having a lawful basis to collect and process that Patron data, including notice or consent as required under the Personal Data Protection Act, 2026;
  • Only collecting Patron data that is necessary and appropriate for the purpose (e.g., dispensing, loyalty, refunds);
  • Responding to Patron requests regarding their data, to the extent legally required, and contacting us at info@posifyrx.com if you need our assistance — for example, to delete a specific Patron record from our systems.

We act as a data processor/service provider with respect to Patron data you input, processing it only as needed to provide the Service to you.

10 Data security

Cyber Security Ordinance, 2025

We use administrative, technical, and physical safeguards designed to protect personal data, including encryption in transit, access controls, and audit logging of account activity. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security, particularly for data cached locally on a device before it syncs. You are responsible for securing devices running the Service, including physical access and screen-lock controls at the counter.

If we become aware of a security incident affecting your personal data, we will notify affected pharmacies and, where required, the relevant authority under the Cyber Security Ordinance, 2025 or the Personal Data Protection Act, 2026, within the timeframe applicable law requires.

11 International data transfers

Our infrastructure may be hosted in Bangladesh or in other countries via cloud service providers. Where personal data is transferred outside Bangladesh, we take reasonable steps to ensure it receives a level of protection consistent with this Policy and with the cross-border transfer requirements of the Personal Data Protection Act, 2026, once those provisions take effect on their statutory timeline.

12 Your rights and choices

Subject to the Personal Data Protection Act, 2026 and its phased commencement, you may have rights including:

AccessGet a copy of the personal data we hold about you.
CorrectionFix inaccurate or incomplete data.
ExportReceive your data in a portable format.
DeletionAsk us to erase data we no longer need to keep.
ObjectionObject to or restrict certain processing.
Withdraw consentWithdraw consent previously given, where consent is the basis for processing.

To exercise these rights, contact us at info@posifyrx.com. We will respond within a reasonable time and may need to verify your identity and role — for example, confirming you are the pharmacy owner — before acting on a request, particularly where it involves Patron data controlled by the pharmacy.

Note that some data — such as transaction records needed for DGDA compliance or tax purposes — may need to be retained even after a deletion request, as required by law.

13 Children's data

The Service is intended for business use by adult staff of licensed pharmacies. We do not knowingly collect personal data from children. Patron records should not include information about children beyond what is strictly necessary for a dispensing transaction — for example, a prescription made out to a minor, entered by pharmacy staff — and pharmacies are responsible for handling any such data in compliance with applicable law.

14 Third-party links and integrations

The Service may link to or integrate with third-party websites, hardware, or services — payment processors and printer drivers, for example. This Policy does not cover the privacy practices of those third parties; please review their own privacy policies.

15 Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the "Last updated" date and, where required, through additional notice such as an in-app or email notice. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

16 Contact us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact:

POSify Rx
Uttara, Dhaka, Bangladesh
Email: info@posifyrx.com
Phone: +8801601-178041