Privacy Policy — Pharmia
Effective date: December 1, 2025
Last updated : March 10, 2026
1. Overview
Pharmia collects and processes personal and clinical information to automate patient intake, pre-analyze cases, and deliver structured files to pharmacists. We prioritize patient confidentiality, data minimization, and compliance with Canadian and Québec privacy rules (including PIPEDA and Québec privacy reforms).
Contact DPO / privacy officer: [email protected]
2. What we collect
We collect only the personal information necessary to deliver the Pharmia Service and support pharmacy operations. This includes identification and contact information, health and clinical information provided during the consultation process, information exchanged with our AI assistant or recorded by pharmacy staff, technical and device data collected automatically for security and performance (such as IP address and browser information), and general usage or analytics data that may be anonymized or aggregated to improve the platform.
3. Legal basis & consent
We collect, use and disclose personal information with the individual’s free and informed consent (express or implied, as appropriate for the context), and where necessary to provide the requested clinical service. For pharmacy workflows, the pharmacy often obtains consent and makes patients aware that the pharmacy uses Pharmia to process intake data.
Pharmia’s processing is necessary to provide the Service and for legitimate interests related to delivering clinical support; where special categories of health data are processed, we rely on explicit consent and applicable legal bases under Québec and federal law.
4. How we use the data
-
Provide the core service: capture intake data, analyze it, and deliver a structured clinical file to the pharmacist.
-
Improve the Service: training and telemetry on de-identified or aggregated data.
-
Security, fraud prevention, and support.
-
Compliance with legal obligations (e.g., audits, regulatory requests). Third parties (e.g., cloud host, AI provider) process data under contract to Pharmia and only as instructed. See third-party section below.
5. Sharing & recipients
-
Pharmacists / pharmacies: patient consultation data is shared with the treating pharmacist as part of care. Pharmacists are bound by professional secrecy.
-
Service providers / vendors: cloud hosting, AI/ML providers, analytics, maintenance — only the minimum data required. Contractual safeguards and confidentiality obligations are in place.
-
Research & anonymized data: anonymized / de-identified data may be used for research or product improvement. We will not publish data that enables re-identification.
-
Legal requests: we may disclose information to comply with laws, court orders, or to defend legal claims.
6. Data localization & retention
Data is stored on secure servers located in Canada by default. We retain personal data only as long as necessary for the purposes stated and as required by law; anonymized data may be retained indefinitely for analytics and research.
7. Security measures
We implement administrative, technical and organizational measures (access controls, encryption in transit and at rest, logging, staff confidentiality obligations, vendor contracts). However no system is invulnerable; in the event of a breach we will follow applicable notification rules and notify affected individuals and authorities as required.
8. Rights of individuals
Depending on jurisdiction, individuals have rights including:
-
Access to their personal information;
-
Correction or rectification;
-
Deletion / withdrawal of consent (subject to operational and legal limits);
-
Portability of computerized personal information;
-
Complaint to supervisory authority.
Under Québec Law 25 and federal rules, organizations must facilitate these rights; exercise of certain rights may be subject to verification and exceptions for professional secrecy or safety. We will respond to requests through the pharmacy (operational flow) or directly where appropriate.
9. Minors & third-party use
If a third party uses Pharmia on behalf of a patient (e.g., caregiver), the pharmacy must ensure valid consent. Special rules apply for minors; collection and use must be in the minor’s best interest and consistent with applicable law.
10. Cookies & tracking
We use cookies and similar technologies for session management, analytics and security. We may also use device signals to maintain your session across visits, prevent fraud, and ensure the security and continuity of your account.
11. AI transparency & model use
Pharmia uses AI models to collect information and pre-analyze cases. We will:
-
Inform the user that an AI assistant performs the intake;
-
Identify that outputs are decision-support only and require pharmacist review;
-
Maintain records of AI outputs and the inputs used to produce them for auditability and safety;
-
Use de-identification and aggregation for model improvement unless explicit consent for training on identifiable data is obtained.
12. Security incidents & breach notification
We have an incident response plan. In case of a breach affecting personal information, we will assess impact, contain the incident, notify affected individuals and authorities when required by law, and take remediation steps. Notification timelines will follow applicable laws (PIPEDA, Québec Law 25).
13. Data processors & international transfers
Where vendors process data outside Canada, we use contractual safeguards and transfer mechanisms. We will inform customers which categories of vendors may process data outside Canada and obtain necessary consents. Vendors are contractually bound to confidentiality and security obligations.
14. Changes to this Privacy Policy
We may update this policy. Material changes will be notified via email or the platform directly and the effective date updated. By using or submitting any information, you are consenting to the changes.
15. Contact & complaints
For questions, access requests or complaints: [email protected]. Individuals may also contact the Office of the Privacy Commissioner of Canada or the Commission d’accès à l’information (Quebec) for unresolved complaints.