What we collect when a pharmacy runs on POSify Rx, why we collect it, and where the line sits between what we control and what the pharmacy controls about its own customers.
POSify Rx ("POSify Rx," "we," "us," or "our") provides an AI-native, offline-first point-of-sale and pharmacy management platform ("Service"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the choices available to you, in a manner consistent with the Personal Data Protection Act, 2026.
This Policy applies to pharmacy owners, pharmacists, cashiers, and other staff who use the Service ("Users"), as well as, indirectly, the end customers of pharmacies that use the Service ("Patrons"), whose data may be entered into the Service by Users. If you do not agree with this Policy, please do not use the Service.
When you use the AI chatbot or request AI insights, the relevant data — for example, your question and the stock or sales data needed to answer it — is processed to generate a response. See Section 5 for details on AI processing.
We use the information described above to:
We do not sell personal data to third parties.
Where the Personal Data Protection Act, 2026 or another applicable law requires a legal basis for processing, we rely on: performance of our contract with you (providing the Service), your or the pharmacy's consent (e.g., for optional communications or for entering Patron data), our legitimate interests (e.g., security, fraud prevention, service improvement), and compliance with legal obligations (e.g., DGDA and tax recordkeeping).
Where we act as a data controller (for User account data) we take on the associated obligations directly. Where we process Patron data on a pharmacy's instructions, we act as a data processor/service provider and the pharmacy remains the controller responsible for its own legal basis — see Section 9.
AI insights and the AI chatbot process the data necessary to generate a relevant response — for example, your pharmacy's stock levels and expiry dates to flag near-expiry batches, or sales history to forecast demand.
We take reasonable steps to limit AI processing to your own pharmacy's data; AI insights for one pharmacy are not generated using another pharmacy's identifiable Customer Data.
We may use aggregated or de-identified data from multiple pharmacies to improve the general accuracy of AI models, but we do not use identifiable data from one pharmacy to generate insights shown to a different pharmacy.
AI outputs are generated automatically and may be imperfect. Do not submit sensitive Patron health information to the AI chatbot beyond what is necessary for the query, and always verify AI-generated guidance before relying on it for dispensing, dosage, or compliance decisions.
We share information only as follows:
We do not share Customer Data across unrelated pharmacy accounts.
We retain personal data for as long as your account is active and as needed to provide the Service. After account closure, we retain Customer Data for a limited period (see Terms of Service, Section 15) to allow export, and thereafter delete or de-identify it, except where longer retention is required by law — for example, DGDA-related recordkeeping obligations under the Drug and Cosmetics Act, 2023, tax law, or to resolve disputes.
Locally cached offline data (IndexedDB) remains on the device until it syncs or is cleared; clearing browser data or uninstalling the app removes locally stored records that have not yet synced.
We use essential cookies or local browser storage to keep you logged in and remember basic preferences, and may use limited analytics cookies to understand feature usage. You can control cookies through your browser settings; disabling essential cookies may prevent the Service from functioning correctly, including offline sync.
If you (the pharmacy) enter Patron information into the Service — for loyalty tracking or dispensing records, for example — you are responsible for:
We act as a data processor/service provider with respect to Patron data you input, processing it only as needed to provide the Service to you.
We use administrative, technical, and physical safeguards designed to protect personal data, including encryption in transit, access controls, and audit logging of account activity. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security, particularly for data cached locally on a device before it syncs. You are responsible for securing devices running the Service, including physical access and screen-lock controls at the counter.
If we become aware of a security incident affecting your personal data, we will notify affected pharmacies and, where required, the relevant authority under the Cyber Security Ordinance, 2025 or the Personal Data Protection Act, 2026, within the timeframe applicable law requires.
Our infrastructure may be hosted in Bangladesh or in other countries via cloud service providers. Where personal data is transferred outside Bangladesh, we take reasonable steps to ensure it receives a level of protection consistent with this Policy and with the cross-border transfer requirements of the Personal Data Protection Act, 2026, once those provisions take effect on their statutory timeline.
Subject to the Personal Data Protection Act, 2026 and its phased commencement, you may have rights including:
To exercise these rights, contact us at info@posifyrx.com. We will respond within a reasonable time and may need to verify your identity and role — for example, confirming you are the pharmacy owner — before acting on a request, particularly where it involves Patron data controlled by the pharmacy.
Note that some data — such as transaction records needed for DGDA compliance or tax purposes — may need to be retained even after a deletion request, as required by law.
The Service is intended for business use by adult staff of licensed pharmacies. We do not knowingly collect personal data from children. Patron records should not include information about children beyond what is strictly necessary for a dispensing transaction — for example, a prescription made out to a minor, entered by pharmacy staff — and pharmacies are responsible for handling any such data in compliance with applicable law.
The Service may link to or integrate with third-party websites, hardware, or services — payment processors and printer drivers, for example. This Policy does not cover the privacy practices of those third parties; please review their own privacy policies.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the "Last updated" date and, where required, through additional notice such as an in-app or email notice. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
If you have questions about this Privacy Policy or wish to exercise your data rights, contact:
POSify Rx
Uttara, Dhaka, Bangladesh
Email: info@posifyrx.com
Phone: +8801601-178041