PharmaSuite Privacy Policy
DRAFT — NOT LEGAL ADVICE
This is a starting template, not legal advice. Have a lawyer review this before relying on it, especially for compliance with Ghana's Data Protection Act 2012 (Act 843). It has not been reviewed by counsel and has not yet been registered with Ghana's Data Protection Commission. The company and contact details are real; the data-retention periods in Section 6 are drafted as reasonable defaults and must be confirmed against the statutory minimums before this document is relied upon.
Last updated: 15 August 2026 (draft — pending legal review)
1. Who this policy covers
PharmaSuite PMD is operated by Number Seven Solutions Ltd. ("PharmaSuite", "we", "us"), a company registered in Ghana, which provides software-as-a-service pharmacy management tools to independent pharmacies in Ghana — inventory, point-of-sale, billing, purchasing, and regulatory record-keeping (including the controlled-drug register).
This policy explains what personal data PharmaSuite collects, why, and what happens to it. It covers two very different categories of people, treated differently below:
- Pharmacy owners and staff who sign up for and use PharmaSuite directly — for this group, PharmaSuite is the data controller.
- Patients whose prescription and dispensing records a pharmacy's own staff enter into PharmaSuite — for this group, PharmaSuite is only a data processor acting on the pharmacy's instructions. See Section 5.
2. Information we collect
2.1 From the pharmacy owner, at signup and afterward
- Full name, email address, phone number, and a password (stored as a salted hash, never in plain text).
- Pharmacy business details: business name, and whatever company profile information the owner later fills in (address, tax details, branch information).
- Anything sent to verify an email or phone number (a one-time code, sent once — see Section 4 on mNotify and email delivery).
2.2 From pharmacy staff, during ordinary use
- Name, role, and login credentials for each staff account the owner creates.
- Actions taken in the system (an audit trail of who recorded what, and when) — this exists for accountability and regulatory record-keeping (e.g. the controlled-drug register), not for monitoring staff.
2.3 Patient / prescription data entered by the pharmacy
A pharmacy's own staff may enter, as part of ordinary dispensing and sales workflow:
- Patient name and, where the pharmacy chooses to record it, contact details.
- Prescription and dispensing details: medicines dispensed, quantities, prescriber information, and — for controlled substances — the legally-required controlled-drug register entries.
PharmaSuite does not decide to collect this data, and does not use it for its own purposes. It is entered by the pharmacy's staff, for the pharmacy's own recordkeeping and regulatory compliance. See Section 5.
2.4 Billing information
Card and mobile-money payment details are collected and processed directly by Paystack, our payment processor — PharmaSuite never sees or stores full card numbers. We do store the outcome (amount, date, status, and a reference number) needed for invoicing and accounting.
2.5 Technical data
Standard technical data any web/API service collects: IP address, request timestamps, and device/browser information from logs, kept for security and troubleshooting.
3. Why we collect it
- To create and operate an owner's or staff member's account, and to let a pharmacy run its business through PharmaSuite (inventory, sales, billing, purchasing, regulatory records).
- To send OTP codes for signup/verification, and transactional notifications (e.g. billing reminders).
- To process subscription payments.
- To maintain the regulatory records Ghanaian pharmacy law requires (e.g. the controlled-drug register), on the pharmacy's behalf.
- To keep the service secure and to diagnose problems.
- We do not sell personal data, and we do not use patient data collected on a pharmacy's behalf for advertising, profiling, or any purpose beyond providing the service to that pharmacy.
4. Who we share data with
- Paystack — our payment processor, for subscription billing and reseller payouts. Paystack has its own privacy policy governing the payment details it collects directly.
- mNotify — our SMS provider, used to deliver OTP codes and SMS notifications to phone numbers, only for that purpose.
- Namecheap — our hosting and domain provider, on whose infrastructure the application and database run, under its own confidentiality and security obligations; it does not access the data except as needed to provide that hosting.
- Ghana's regulatory authorities, where a pharmacy or PharmaSuite is legally required to produce records (e.g. controlled-drug register inspections).
- We do not share personal data with any other third party for their own marketing purposes.
5. Patient data: PharmaSuite as processor, the pharmacy as controller
This is the most important distinction in this policy.
For account data (Section 2.1–2.2), PharmaSuite is the controller: we decide why and how that data is processed, and this policy is our commitment to that data's owners.
For patient data entered by a pharmacy's staff (Section 2.3), the pharmacy is the data controller and PharmaSuite is only a data processor. In practice, this means:
- The pharmacy decides what patient data it records, and is responsible for having a lawful basis to collect and process it (e.g. providing pharmaceutical care, complying with Ghanaian pharmacy law).
- PharmaSuite processes that data only as instructed by the pharmacy, through the ordinary functioning of the software — we do not access, use, or repurpose it independently, except as needed to operate, secure, or support the service, or as required by law.
- A patient with a question about their own data held in a pharmacy's PharmaSuite records should contact that pharmacy directly — they are the controller responsible for handling data subject requests.
- PharmaSuite will assist a pharmacy in responding to a lawful patient data request, and will cooperate with Ghana's Data Protection Commission where required.
This division of responsibility is set out in full in our Data Processing Agreement, which forms part of the contract between PharmaSuite and each pharmacy customer and governs how PharmaSuite processes patient data on the pharmacy's behalf.
6. Data retention
The periods below are our current retention defaults. They are drafted to match ordinary Ghanaian business-record obligations and should be confirmed against the exact statutory minimums by counsel.
- Account and profile data (owner and staff names, email, phone) is kept for as long as the account is active. After an account is closed, this profile data is deleted within 90 days, except where it forms part of a financial record covered below.
- Invoicing and payment records (amounts, dates, statuses, references) are retained for 6 years after the transaction, to meet business accounting and tax record-keeping obligations under Ghanaian law (e.g. the Companies Act 2019 (Act 992) and applicable tax legislation), then deleted.
- One-time verification codes are deleted as soon as they are used or expire.
- Technical logs (IP address, request logs) are kept for around 90 days for security and troubleshooting, then discarded.
- Backups are held on a rolling cycle and overwritten within approximately 35 days; data deleted from the live service is purged from backups within that window.
- Patient and controlled-drug register data is processed on the pharmacy's behalf and retained for as long as the pharmacy's own retention policy and Ghanaian pharmacy/controlled-drug regulations require — the controlled-drug register in particular is a tamper-evident record that must remain retained and auditable. When a pharmacy closes its account, this data is returned or deleted as set out in the Data Processing Agreement, unless the pharmacy is legally required to retain it for longer.
[These periods are reasonable defaults, not counsel-confirmed minimums. A lawyer should verify them against Act 843, the Companies Act 2019, tax record-keeping rules, and Ghana's pharmacy/controlled-substance regulations before publication.]
7. Security
We apply reasonable technical and organizational measures: encrypted connections, hashed/salted passwords, per-pharmacy data isolation at the database level, and access logging. No system is perfectly secure, and we will notify affected parties and the Data Protection Commission as required by law in the event of a data breach affecting personal data.
8. Your rights under Ghana's Data Protection Act 2012 (Act 843)
Subject to Act 843, a data subject has rights including access to their own personal data, correction of inaccurate data, and objection to certain processing. For account-holder data, contact PharmaSuite directly (Section 9). For patient data held in a specific pharmacy's records, contact that pharmacy first, as described in Section 5.
9. Contact
For any question about this policy, or to exercise a data protection right regarding your own PharmaSuite account data:
Number Seven Solutions Ltd. 84 Spintex Road, opp. Baatsonaa Total, Accra, Ghana
Email: pharmasuite@nsslgh.com WhatsApp: +233 53 470 1707
10. Changes to this policy
We may update this policy as the service evolves. Material changes will be communicated to account holders before they take effect.