1. Scope & Controller
PharmaCrux Limited is the data controller for personal information processed through the Services unless stated otherwise. We may also act as a data processor when we process data on behalf of our business customers (e.g., pharmacies, wholesalers). Where we act as a processor, our processing is governed by a Data Processing Addendum (DPA) with the relevant customer.
| Entity | Role | Contact |
|---|---|---|
| PharmaCrux Limited | Controller (B2C) and Processor (B2B) | privacy@PharmaCrux.ng |
Registered address: Abiola Court 5, Chevron Drive, Lekki, Lagos, Nigeria. Phone: +234 703 875 4361.
2. Key Definitions
- Personal Data: any information relating to an identified or identifiable natural person.
- Processing: any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.
- Controller: the party that determines the purposes and means of processing.
- Processor: the party that processes personal data on behalf of the controller.
- Special Category Data: sensitive data (e.g., health, biometric identifiers) which we generally do not collect unless a customer uploads it into the Services as part of their own operations.
Terms are used consistently with the Nigeria Data Protection Regulation (NDPR) and comparable laws where applicable.
3. Information We Collect
3.1 Information You Provide
- Account & Profile: name, business name, role, email, phone, username, password (hashed), preferences.
- Business Operations: product catalogs, pricing, inventory, purchase orders, sales records, supplier/customer details.
- Billing: billing address, transaction references, payment method tokens (we do not store full card numbers).
- Support: messages, attachments, troubleshooting details, feedback, survey responses.
- Consent Records: marketing preferences and opt-in/opt-out timestamps.
3.2 Information Collected Automatically
- Usage & Diagnostics: pages visited, features used, timestamps, clickstream, session duration.
- Device & Log: IP address, browser/OS type and version, language, device identifiers, crash logs.
- Cookies/Local Storage: authentication state, preferences, analytics.
3.3 Information from Third Parties
- Payment Providers: transaction confirmations, masked card details, dispute information.
- Logistics/Integrations: shipment events, tracking references, delivery confirmations.
- Identity/Anti‑Fraud: risk signals where legally permitted.
If you provide any information about other individuals (e.g., staff contacts), you must ensure you have a lawful basis to do so.
4. Sources of Information
- Directly from you when you create an account, use the Services, or communicate with us.
- Automatically through your device and our systems when you access the Services.
- From third parties that you connect or that support the Services (e.g., payment processors).
- From publicly available sources to verify business identity and compliance information.
5. Purposes & Legal Bases
We process personal data for the following purposes under recognized legal bases including contract performance, consent, legal obligation, and legitimate interests.
| Purpose | Examples | Legal Basis |
|---|---|---|
| Provide and operate the Services | Account provisioning, authentication, role‑based access, core app features | Contract; Legitimate interests (service functionality) |
| Billing & payments | Subscription management, invoicing, fraud monitoring | Contract; Legal obligation; Legitimate interests |
| Customer support & communications | Respond to inquiries, service notifications, incident alerts | Contract; Legitimate interests |
| Improvement & analytics | Usage analytics, A/B testing, diagnostics | Legitimate interests; Consent where required |
| Security & abuse prevention | Threat detection, access logs, audit trails | Legitimate interests; Legal obligation |
| Legal & compliance | Regulatory reporting, tax, record keeping | Legal obligation |
| Marketing | Newsletters, product updates, event invites | Consent; Legitimate interests (B2B) |
Where we rely on consent, you may withdraw it at any time using in‑product controls or by contacting privacy@PharmaCrux.ng. Withdrawal does not affect prior lawful processing.
7. Data Retention
We retain personal data for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by category and purpose (see Annex A).
- Active accounts: keep data for the life of the account.
- Closed accounts: archive core records typically for 6–7 years for tax/audit; delete or anonymize application content sooner unless required otherwise.
- Backups: stored for limited periods and then overwritten on a rolling basis.
8. Security Measures
We apply technical and organizational measures proportionate to risk, including but not limited to:
- Encryption in transit (TLS) and at rest for primary data stores.
- Role‑based access control, least privilege, and multi‑factor authentication for internal systems.
- Segregated environments for development, staging, and production.
- Audit logging, monitoring, and alerting.
- Secure software development lifecycle (code reviews, dependency scanning, vulnerability management).
- Regular backups and recovery testing.
- Employee security training and confidentiality commitments.
No method of transmission or storage is 100% secure. If we become aware of a breach affecting your personal data, we will notify you and regulators consistent with applicable law.
10. International Data Transfers
We may transfer, store, and process information outside your country. Where we transfer personal data internationally, we use appropriate safeguards (e.g., contractual clauses, adequacy mechanisms) consistent with applicable law. Sub‑processor locations are listed on our Sub‑processors page.
11. Your Rights & How to Exercise Them
Subject to legal limits, you may have the following rights under the NDPR and other laws:
- Access: request a copy of your personal data we hold.
- Rectification: request correction of inaccurate or incomplete data.
- Deletion: request deletion of your data where permitted.
- Restriction: ask us to limit processing in certain circumstances.
- Portability: receive your data in a portable format and transmit it to another controller.
- Objection: object to processing based on legitimate interests or direct marketing.
- Consent Withdrawal: withdraw consent at any time where processing is based on consent.
- Complaint: lodge a complaint with the relevant data protection authority.
How to Make a Request
Email privacy@PharmaCrux.ng with the subject line “Data Rights Request”. We may verify your identity and ownership of the account. Response times will follow applicable law. See Annex B for a sample template.
If your account is managed by a business customer, contact your account administrator first; we will support them in fulfilling your request.
12. Children’s Privacy
Our Services are designed for business use and are not directed to children. We do not knowingly collect personal data from children below the age threshold defined by applicable law. If you believe a child has provided us with personal data, contact us and we will take appropriate steps to remove such information.
13. Automated Decision‑Making & Profiling
We do not engage in solely automated decisions that produce legal or similarly significant effects about individuals. We may use analytics to understand product usage and to improve features; such processing does not have significant effects on individuals.
14. Third‑Party Links & Services
The Services may contain links to or allow you to connect with third‑party services. Their privacy practices are governed by their own policies. We encourage you to review those policies before interacting with such services.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new “Last Updated” date and, where appropriate, notify you through the Services or by email. Your continued use of the Services after an update constitutes acceptance of the revised policy.
Revision History
| Date | Version | Summary of Changes |
|---|---|---|
| 16 Aug 2025 | 1.0 | Initial long‑form plain‑style publication of the PharmaCrux Privacy Policy. |
16. Contact & Data Protection
PharmaCrux LimitedAbiola Court 5, Chevron Drive, Lekki, Lagos, Nigeria
Email: privacy@PharmaCrux.ng
Phone: +234 703 875 4361
If you have unresolved concerns, you may contact the relevant data protection authority in your jurisdiction.
For a Data Processing Addendum (DPA) or security documentation, email privacy@PharmaCrux.ng with “Request DPA” or “Security Pack”.
Annex A – Detailed Retention Schedule
| Data Category | Examples | Primary Purpose | Typical Retention | Notes |
|---|---|---|---|---|
| Account identifiers | Name, email, user ID, workspace membership | Service delivery | Life of account + 24 months | Deleted sooner on verified request unless legally required to retain |
| Authentication | Password hashes, MFA secrets, session tokens | Security | Rolling; session tokens vary by policy | Backups expire on schedule |
| Billing & transactions | Invoices, payment confirmations, refunds | Accounting & tax | 6–7 years | As required by applicable law |
| Operational content | Inventory, orders, sales records uploaded by customers | Core service | Life of account; then 30–180 days | Customer‑controlled retention where applicable |
| Support communications | Tickets, emails, attachments | Support & compliance | Up to 3 years after closure | Longer if incident‑related |
| Audit & security logs | Access logs, admin activity, API logs | Security & compliance | 90–365 days (typical) | Aggregated thereafter |
| Marketing preferences | Opt‑ins/opt‑outs | Compliance | Until you change your preference + 24 months | Proof of consent retained as required |
Annex B – Sample Data Subject Request Template
To: privacy@PharmaCrux.ng Subject: Data Rights Request – [Access/Deletion/Rectification/Portability] Hello PharmaCrux Privacy Team, I am submitting a request under applicable data protection law. I am requesting: [describe request]. Account email/ID: [your email] Workspace (if applicable): [name] Details to help locate my data: [context] I declare that the information provided is accurate and that I am the data subject or authorized agent. Kind regards, [Your name] [Contact number]
We may request additional information to verify your identity and secure your data.
Annex C – Cookies List (Illustrative)
| Name | Type | Purpose | Duration |
|---|---|---|---|
| _pc_auth | Strictly necessary | Keeps you signed in | Session / up to 30 days |
| _pc_prefs | Preference | Stores UI and locale settings | 180 days |
| _pc_analytics | Analytics | Helps us understand usage to improve the product | 13 months |
You can delete cookies at any time via your browser settings. Some features may not function without necessary cookies.