Legal · Privacy Policy

Privacy Policy

Effective date[Effective Date]
Last updated[Last Updated Date]

[Company Legal Name] ("POSify Rx," "we," "us," or "our") provides an AI-native, offline-first point-of-sale and pharmacy management platform ("Service"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the choices you have.

This Policy applies to pharmacy owners, pharmacists, cashiers, and other staff who use the Service ("Users"), as well as, indirectly, the end customers of pharmacies that use the Service ("Patrons"), whose data may be entered into the Service by Users.

If you do not agree with this Policy, please do not use the Service.


01 Who This Policy Covers

02 Information We Collect

Information you provide directly

Account informationName, email, phone number, role (owner/pharmacist/cashier), pharmacy name, and license or registration details.
Business & compliance informationPharmacy license numbers, DGDA registration details, and other regulatory documentation you upload to the Regulatory Center.
Transaction & inventory dataSales, refunds, batch numbers, expiry dates, stock levels, pricing, and supplier information.
Patron data entered by UsersTo the extent your pharmacy chooses to record it — e.g. a Patron's name or phone number for loyalty tracking, or purchase history. We do not require pharmacies to collect any particular category of Patron data, and pharmacies should avoid entering sensitive health data about Patrons beyond what is necessary for dispensing and regulatory records.
Staff attendance dataClock-in/clock-out timestamps tied to staff accounts.
Support communicationsMessages sent to our AI chatbot or human support team, including ticket content and attachments.
Payment informationIf you subscribe to paid features, billing details are collected and processed by our payment processor; we do not store full card numbers ourselves.

Information collected automatically

Information from AI features

When you use the AI chatbot or request AI insights, the relevant data (e.g., your question, relevant stock and sales data needed to answer it) is processed to generate a response. See Section 5 for details on AI processing.

03 How We Use Information

We use the information described above to:

  1. Provide, operate, and maintain the Service, including offline functionality and background synchronization;
  2. Process transactions, manage inventory, and generate receipts;
  3. Generate AI insights (e.g., expiry alerts, demand forecasts, anomaly detection) and power the AI chatbot;
  4. Provide customer support, including AI-assisted and human-escalated support tickets;
  5. Maintain audit logs and compliance records to support your DGDA-aligned reporting;
  6. Detect, investigate, and prevent fraud, abuse, security incidents, and technical issues;
  7. Communicate with you about your account, updates, and service notices;
  8. Improve and develop the Service, including training or tuning AI features using de-identified or aggregated data where possible;
  9. Comply with legal obligations, including tax and pharmaceutical regulatory recordkeeping requirements.

We do not sell personal data to third parties.

04 Legal Bases (Where Applicable)

Where data protection law requires a legal basis for processing, we rely on: performance of our contract with you (providing the Service), your consent (e.g., for optional communications), our legitimate interests (e.g., security, service improvement), and compliance with legal obligations (e.g., regulatory recordkeeping).

05 AI Features and Data Processing

AI insights and the AI chatbot process the data necessary to generate a relevant response — for example, your pharmacy's stock levels and expiry dates to flag near-expiry batches, or sales history to forecast demand.

We take reasonable steps to limit AI processing to your own pharmacy's data; AI insights for one pharmacy are not generated using another pharmacy's identifiable Customer Data.

We may use aggregated or de-identified data from multiple pharmacies to improve the general accuracy of AI models, but we do not use identifiable data from one pharmacy to generate insights shown to a different pharmacy.

AI outputs are generated automatically and may be imperfect. Do not submit sensitive Patron health information to the AI chatbot beyond what is necessary for the query, and always verify AI-generated guidance before relying on it for dispensing, dosage, or compliance decisions.

06 How We Share Information

We share information only as follows:

We do not share Customer Data across unrelated pharmacy accounts.

07 Data Retention

We retain personal data for as long as your account is active and as needed to provide the Service. After account closure, we retain Customer Data for a limited period (see Terms of Service, Section 15) to allow export, and thereafter delete or de-identify it, except where longer retention is required by law (for example, DGDA-related recordkeeping obligations, tax law, or to resolve disputes).

Locally cached offline data (IndexedDB) remains on the device until it syncs or is cleared; clearing browser data or uninstalling the app removes locally stored records that have not yet synced.

08 Cookies and Similar Technologies

We use essential cookies or local browser storage to keep you logged in and remember basic preferences, and may use limited analytics cookies to understand feature usage. You can control cookies through your browser settings; disabling essential cookies may prevent the Service from functioning correctly, including offline sync.

09 Pharmacy Responsibilities Regarding Patron Data

If you (the pharmacy) enter Patron information into the Service (e.g., for loyalty tracking or dispensing records), you are responsible for:

We act as a data processor/service provider with respect to Patron data you input, processing it only as needed to provide the Service to you.

10 Data Security

We use administrative, technical, and physical safeguards designed to protect personal data, including encryption in transit, access controls, and audit logging of account activity. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security, particularly for data cached locally on a device before it syncs. You are responsible for securing devices running the Service, including physical access and screen-lock controls at the counter.

If we become aware of a security incident affecting your personal data, we will notify you and relevant authorities as required by applicable law.

11 International Data Transfers

Our infrastructure may be hosted in Bangladesh or in other countries via cloud service providers. Where data is transferred outside Bangladesh, we take reasonable steps to ensure it receives an adequate level of protection consistent with this Policy and applicable law.

12 Your Rights and Choices

Depending on applicable law, you may have rights to access, correct, export, or request deletion of your personal data, or to object to or restrict certain processing. To exercise these rights, contact us at [Support Email]. We will respond within a reasonable time and may need to verify your identity and role (e.g., confirming you are the pharmacy owner) before acting on a request, particularly where it involves Patron data controlled by the pharmacy.

Note that some data (e.g., transaction records needed for DGDA compliance or tax purposes) may need to be retained even after a deletion request, as required by law.

13 Children's Data

The Service is intended for business use by adult staff of licensed pharmacies. We do not knowingly collect personal data from children. Patron records should not include information about children beyond what is strictly necessary for a dispensing transaction (e.g., a prescription made out to a minor, entered by pharmacy staff), and pharmacies are responsible for handling any such data in compliance with applicable law.

14 Third-Party Links and Integrations

The Service may link to or integrate with third-party websites, hardware, or services (e.g., payment processors, printer drivers). This Policy does not cover the privacy practices of those third parties; please review their own privacy policies.

15 Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the "Last updated" date and, where required, through additional notice (e.g., in-app or email notice). Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

16 Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact:

[Company Legal Name]
[Registered Address]
Email: [Privacy/Support Email]
Phone: [Support Phone]

Before you publish This document is a general template and does not constitute legal advice. Bangladesh's data protection framework (including any applicable rules under the ICT Act and forthcoming data protection legislation) and DGDA pharmacy recordkeeping requirements should be reviewed with a qualified lawyer before publishing this policy, and every bracketed placeholder above should be replaced.