PharmaSuite Legal

PharmaSuite Data Processing Agreement


DRAFT — NOT LEGAL ADVICE

This is a starting template, not legal advice. Have a lawyer review this before relying on it, especially for compliance with Ghana's Data Protection Act 2012 (Act 843). It has not been reviewed by counsel. The company details, sub-processors, and security measures describe PharmaSuite as actually built; the retention periods and the liability position are reasonable defaults that must be confirmed against the main Terms of Service and the statutory minimums before this document is relied upon.


Last updated: 15 August 2026 (draft — pending legal review)

1. Parties and scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service between:

It governs the processing of personal data that PharmaSuite carries out on the Pharmacy's behalf — principally the patient, prescription, and dispensing data the Pharmacy's staff enter into the service. Where there is any conflict between this DPA and the Terms of Service on the subject of that data, this DPA prevails.

This DPA does not cover the account data of pharmacy owners and staff (names, logins, contact details, billing). For that data PharmaSuite is the controller, and the Privacy Policy governs it.

2. Definitions

Terms such as personal data, data subject, processing, data controller, and data processor have the meanings given to them in Ghana's Data Protection Act 2012 (Act 843). "Applicable data protection law" means Act 843 and any regulations, directives, or guidance issued under it by Ghana's Data Protection Commission.

3. Roles of the parties

4. Subject matter, nature, and purpose of processing

The categories of data subjects and personal data are set out in Annex A.

5. PharmaSuite's obligations as processor

PharmaSuite will:

  1. Process only on instructions. Process the Pharmacy's patient data only on the Pharmacy's documented instructions — which the ordinary use of the service constitutes — and as required by Ghanaian law. If a law requires us to process the data otherwise, we will tell the Pharmacy first unless that law prohibits it.
  2. Confidentiality. Ensure that personnel authorised to process the data are bound by confidentiality obligations.
  3. Security. Implement the technical and organisational measures described in Annex C, appropriate to the risk.
  4. Sub-processors. Engage sub-processors only under Section 6.
  5. Assist the Pharmacy. Taking into account the nature of the processing, assist the Pharmacy — through appropriate technical and organisational measures, so far as possible — to respond to data-subject requests (Section 7) and to meet its own security, breach-notification, and (where applicable) impact-assessment obligations under Act 843.
  6. Breach notification. Notify the Pharmacy without undue delay after becoming aware of a personal-data breach affecting the Pharmacy's data, with the information the Pharmacy reasonably needs to meet its own notification duties to the Data Protection Commission and to data subjects (Section 8).
  7. Return or deletion. At the end of the service, return or delete the Pharmacy's patient data as set out in Section 11.
  8. Demonstrate compliance. Make available to the Pharmacy the information reasonably necessary to demonstrate compliance with this DPA, as described in Section 9.

6. Sub-processors

7. Data-subject requests

The service gives the Pharmacy direct access to the patient records it holds, so that the Pharmacy can respond to a data subject exercising rights under Act 843 (access, correction, and — subject to the Pharmacy's own retention obligations — deletion or objection). If a data subject contacts PharmaSuite directly about data held in a Pharmacy's records, we will not respond substantively except to direct them to the Pharmacy, and we will inform the Pharmacy. PharmaSuite will assist the Pharmacy in responding to such requests as a processor.

8. Personal-data breaches

On becoming aware of a breach affecting the Pharmacy's patient data, PharmaSuite will, without undue delay, notify the Pharmacy at the contact it holds for the account and provide the nature of the breach, the categories and approximate number of data subjects and records affected (so far as known), the likely consequences, and the measures taken or proposed. Act 843 places the primary notification duty on the controller; PharmaSuite's role is to give the Pharmacy what it needs to meet that duty.

9. Audit and information

PharmaSuite will make available to the Pharmacy, on reasonable written request and no more than once a year (or after a breach affecting the Pharmacy's data), a summary of the technical and organisational measures in Annex C sufficient to demonstrate compliance with this DPA, subject to confidentiality and to protecting other customers' data and the security of the service.

10. International transfers

PharmaSuite and its sub-processors may process the Pharmacy's data outside Ghana where a sub-processor listed in Annex B operates from another country. Any such transfer is carried out in accordance with Act 843, and PharmaSuite will put in place a lawful basis and appropriate safeguards for the transfer where the Act requires them. [The specific transfer mechanism should be confirmed by counsel against the current guidance of the Data Protection Commission.]

11. Return and deletion on termination

When the Pharmacy closes its account or this DPA otherwise ends:

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. [Placeholder — the interaction between this clause and the main Terms' limitation of liability must be reviewed by counsel, together with any liability that cannot be excluded under Ghanaian law.]

13. Governing law

This DPA is governed by the laws of the Republic of Ghana and is subject to the same dispute-resolution provision as the Terms of Service.

14. Contact

Questions about this DPA, or notices under it, should go to:

Number Seven Solutions Ltd. 84 Spintex Road, opp. Baatsonaa Total, Accra, Ghana

Email: pharmasuite@nsslgh.com WhatsApp: +233 53 470 1707


Annex A — Categories of data subjects and personal data

Data subjects

Categories of personal data

PharmaSuite does not require or expect the Pharmacy to enter special categories of data beyond what dispensing records inherently contain; the Pharmacy is responsible for limiting what it records to what it is lawfully entitled to process.

Annex B — Authorised sub-processors

Sub-processorPurposeData involved
PaystackPayment processing for subscriptions and reseller payoutsBilling/payment details (the Pharmacy's own account billing; not patient data)
mNotifySMS delivery (one-time codes, transactional notifications)Phone numbers and message content sent through the service
NamecheapHosting and domain services (application and database infrastructure)All data stored by the service, at rest on the hosting infrastructure

Paystack and mNotify process account/billing and messaging data rather than patient clinical records; Namecheap, as the hosting provider, holds the data at rest. Each is engaged under its own data-protection and confidentiality terms.

Annex C — Technical and organisational security measures

[These measures describe the service as built; counsel and, where appropriate, a security reviewer should confirm they meet the standard Act 843 expects of a processor before this annex is relied upon.]