PharmaSuite Data Processing Agreement
DRAFT — NOT LEGAL ADVICE
This is a starting template, not legal advice. Have a lawyer review this before relying on it, especially for compliance with Ghana's Data Protection Act 2012 (Act 843). It has not been reviewed by counsel. The company details, sub-processors, and security measures describe PharmaSuite as actually built; the retention periods and the liability position are reasonable defaults that must be confirmed against the main Terms of Service and the statutory minimums before this document is relied upon.
Last updated: 15 August 2026 (draft — pending legal review)
1. Parties and scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service between:
- Number Seven Solutions Ltd., of 84 Spintex Road, opp. Baatsonaa Total, Accra, Ghana ("PharmaSuite", "we", "us"), which operates the PharmaSuite PMD platform; and
- the pharmacy that has a PharmaSuite account ("the Pharmacy", "you").
It governs the processing of personal data that PharmaSuite carries out on the Pharmacy's behalf — principally the patient, prescription, and dispensing data the Pharmacy's staff enter into the service. Where there is any conflict between this DPA and the Terms of Service on the subject of that data, this DPA prevails.
This DPA does not cover the account data of pharmacy owners and staff (names, logins, contact details, billing). For that data PharmaSuite is the controller, and the Privacy Policy governs it.
2. Definitions
Terms such as personal data, data subject, processing, data controller, and data processor have the meanings given to them in Ghana's Data Protection Act 2012 (Act 843). "Applicable data protection law" means Act 843 and any regulations, directives, or guidance issued under it by Ghana's Data Protection Commission.
3. Roles of the parties
- The Pharmacy is the data controller for all patient, prescription, and dispensing data its staff enter into PharmaSuite. It decides what data to record and is responsible for having a lawful basis to collect and process it, for its accuracy, and for any notice or consent required under Act 843 or professional pharmacy standards.
- PharmaSuite is the data processor for that data. We process it only to provide the service, on the Pharmacy's documented instructions, and never for our own independent purposes.
4. Subject matter, nature, and purpose of processing
- Subject matter: provision of the PharmaSuite pharmacy-management service to the Pharmacy.
- Nature of processing: storage, organisation, retrieval, display, transmission between the Pharmacy's own devices (offline-capable sync), and — for controlled substances — maintenance of a tamper-evident controlled-drug register.
- Purpose: to enable the Pharmacy to dispense medicines, sell, keep inventory and customer/patient records, and meet its own regulatory record-keeping obligations.
- Duration: for as long as the Pharmacy has an active PharmaSuite account, subject to the return/deletion terms in Section 11.
The categories of data subjects and personal data are set out in Annex A.
5. PharmaSuite's obligations as processor
PharmaSuite will:
- Process only on instructions. Process the Pharmacy's patient data only on the Pharmacy's documented instructions — which the ordinary use of the service constitutes — and as required by Ghanaian law. If a law requires us to process the data otherwise, we will tell the Pharmacy first unless that law prohibits it.
- Confidentiality. Ensure that personnel authorised to process the data are bound by confidentiality obligations.
- Security. Implement the technical and organisational measures described in Annex C, appropriate to the risk.
- Sub-processors. Engage sub-processors only under Section 6.
- Assist the Pharmacy. Taking into account the nature of the processing, assist the Pharmacy — through appropriate technical and organisational measures, so far as possible — to respond to data-subject requests (Section 7) and to meet its own security, breach-notification, and (where applicable) impact-assessment obligations under Act 843.
- Breach notification. Notify the Pharmacy without undue delay after becoming aware of a personal-data breach affecting the Pharmacy's data, with the information the Pharmacy reasonably needs to meet its own notification duties to the Data Protection Commission and to data subjects (Section 8).
- Return or deletion. At the end of the service, return or delete the Pharmacy's patient data as set out in Section 11.
- Demonstrate compliance. Make available to the Pharmacy the information reasonably necessary to demonstrate compliance with this DPA, as described in Section 9.
6. Sub-processors
- The Pharmacy gives general authorisation for PharmaSuite to engage the sub-processors listed in Annex B to help provide the service.
- Each sub-processor is engaged under a contract imposing data-protection obligations that are, in substance, no less protective than those in this DPA, to the extent relevant to what that sub-processor does.
- PharmaSuite remains responsible to the Pharmacy for a sub-processor's performance of its data-protection obligations.
- If PharmaSuite intends to add or replace a sub-processor, it will give the Pharmacy reasonable prior notice, and the Pharmacy may object on reasonable data-protection grounds; the parties will then work in good faith to resolve the objection.
7. Data-subject requests
The service gives the Pharmacy direct access to the patient records it holds, so that the Pharmacy can respond to a data subject exercising rights under Act 843 (access, correction, and — subject to the Pharmacy's own retention obligations — deletion or objection). If a data subject contacts PharmaSuite directly about data held in a Pharmacy's records, we will not respond substantively except to direct them to the Pharmacy, and we will inform the Pharmacy. PharmaSuite will assist the Pharmacy in responding to such requests as a processor.
8. Personal-data breaches
On becoming aware of a breach affecting the Pharmacy's patient data, PharmaSuite will, without undue delay, notify the Pharmacy at the contact it holds for the account and provide the nature of the breach, the categories and approximate number of data subjects and records affected (so far as known), the likely consequences, and the measures taken or proposed. Act 843 places the primary notification duty on the controller; PharmaSuite's role is to give the Pharmacy what it needs to meet that duty.
9. Audit and information
PharmaSuite will make available to the Pharmacy, on reasonable written request and no more than once a year (or after a breach affecting the Pharmacy's data), a summary of the technical and organisational measures in Annex C sufficient to demonstrate compliance with this DPA, subject to confidentiality and to protecting other customers' data and the security of the service.
10. International transfers
PharmaSuite and its sub-processors may process the Pharmacy's data outside Ghana where a sub-processor listed in Annex B operates from another country. Any such transfer is carried out in accordance with Act 843, and PharmaSuite will put in place a lawful basis and appropriate safeguards for the transfer where the Act requires them. [The specific transfer mechanism should be confirmed by counsel against the current guidance of the Data Protection Commission.]
11. Return and deletion on termination
When the Pharmacy closes its account or this DPA otherwise ends:
- The Pharmacy's data remains available for export or reactivation for 30 days.
- After that, PharmaSuite deletes the Pharmacy's patient data from the live service, and it is purged from backups within approximately 35 days, except where PharmaSuite is required by Ghanaian law to retain specific records (for example, records tied to accounting/tax obligations, or controlled-drug register entries that regulation requires be preserved and remain auditable).
- On written request within the 30-day window, PharmaSuite will return the Pharmacy's data in a commonly used electronic format.
12. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. [Placeholder — the interaction between this clause and the main Terms' limitation of liability must be reviewed by counsel, together with any liability that cannot be excluded under Ghanaian law.]
13. Governing law
This DPA is governed by the laws of the Republic of Ghana and is subject to the same dispute-resolution provision as the Terms of Service.
14. Contact
Questions about this DPA, or notices under it, should go to:
Number Seven Solutions Ltd. 84 Spintex Road, opp. Baatsonaa Total, Accra, Ghana
Email: pharmasuite@nsslgh.com WhatsApp: +233 53 470 1707
Annex A — Categories of data subjects and personal data
Data subjects
- Patients and customers of the Pharmacy.
- Prescribers named on a prescription the Pharmacy dispenses.
Categories of personal data
- Patient/customer name and, where the Pharmacy records it, contact details.
- Prescription and dispensing details: medicines dispensed, quantities, dates, and prescriber information.
- Controlled-drug register entries required by law for controlled substances.
PharmaSuite does not require or expect the Pharmacy to enter special categories of data beyond what dispensing records inherently contain; the Pharmacy is responsible for limiting what it records to what it is lawfully entitled to process.
Annex B — Authorised sub-processors
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Paystack | Payment processing for subscriptions and reseller payouts | Billing/payment details (the Pharmacy's own account billing; not patient data) |
| mNotify | SMS delivery (one-time codes, transactional notifications) | Phone numbers and message content sent through the service |
| Namecheap | Hosting and domain services (application and database infrastructure) | All data stored by the service, at rest on the hosting infrastructure |
Paystack and mNotify process account/billing and messaging data rather than patient clinical records; Namecheap, as the hosting provider, holds the data at rest. Each is engaged under its own data-protection and confidentiality terms.
Annex C — Technical and organisational security measures
- Encryption in transit: all traffic to the service is served over HTTPS/TLS.
- Tenant isolation: each pharmacy's data is isolated at the database level using row-level security, so one pharmacy cannot access another's data.
- Credential protection: account passwords are stored only as salted hashes, never in plain text; device and API access uses hashed tokens.
- Access control and audit: the service records an audit trail of who recorded what and when; administrative access to infrastructure is limited to authorised personnel.
- Controlled-drug integrity: the controlled-drug register is maintained as a tamper-evident, hash-chained record.
- Backups: data is backed up on a rolling cycle and backups are overwritten within approximately 35 days.
- Monitoring: the service exposes health and metrics endpoints used to detect availability and performance problems.
[These measures describe the service as built; counsel and, where appropriate, a security reviewer should confirm they meet the standard Act 843 expects of a processor before this annex is relied upon.]