GW GRIINWARE

Data Processing Agreement

Effective date: [[EFFECTIVE_DATE]]  ·  Operator: Griin Company Ltd  ·  Governing law: Republic of Rwanda

Plain-language summary

This agreement sets out how GRIINWARE handles pharmacy data when the platform is used as a software service.

The pharmacy remains the controller. The pharmacy decides what data it collects and why.

GRIINWARE acts only as the processor. We use the data only to provide and secure the Service.

Security is a shared responsibility. We apply technical and organizational safeguards for the platform.

Data must be returned or deleted on termination. The pharmacy can export its data and request secure deletion.

This document is designed for SaaS use of the GRIINWARE platform and should be read together with the Terms and Privacy Policy.

1.Introduction & Scope

This Data Processing Agreement ("DPA") is entered into between Griin Company Ltd ("GRIINWARE" or "Processor") and the pharmacy, clinic, or business using the GRIINWARE platform ("Controller" or "Customer").

This DPA sets out the responsibilities of the parties for the processing of personal data and business records through the GRIINWARE pharmacy management platform and related services.

Where the Customer uses the Service to manage patient, client, or staff information, this DPA governs the processing relationship between the parties and supplements the main service agreement.

2.Definitions

Controller
The pharmacy or business that determines the purposes and means of processing personal data.
Processor
GRIINWARE, which processes personal data on behalf of the Controller solely to provide the Service.
Personal Data
Any information relating to an identified or identifiable natural person, including client, patient, staff, or contact data.
Service Data
Data entered into or generated by the Service in the course of operating the pharmacy platform, including stock, sales, client, pricing, expense, and audit data.
Sub-processor
A third party engaged by GRIINWARE to assist with hosting, support, communications, backup, monitoring, or other service functions.

3.Roles of the Parties

The Customer, as the pharmacy or authorized business operator, remains the data controller for the personal data it enters into the Service.

  • The Customer decides what data to collect, for what purpose, and who may access it within the pharmacy.
  • GRIINWARE acts as a data processor and processes the data only on documented instructions from the Customer or as required by law.
  • GRIINWARE does not use the Customer's data for its own unrelated commercial purposes, advertising, or sharing with other pharmacies.

4.Subject Matter & Purpose

The subject matter of this DPA is the processing of personal data and related business records through the GRIINWARE platform for the purpose of providing pharmacy management services.

Examples include stock management, supplier and purchase ordering, sales and billing, client records, expenses, reconciliation, reporting, notifications, audit logging, and account support.

5.Categories of Data

The Customer may process and store the following categories of data through the Service:

  • Account and identity details of pharmacy staff and admins.
  • Client or patient names, phone numbers, addresses, dates of birth, and insurance-related information where entered by the pharmacy.
  • Product, batch, expiry, stock, sales, pricing, supplier, and expense data.
  • Audit logs, security events, support communications, and device/session metadata.

The Customer warrants that it has a lawful basis for collecting and entering such data and that it will use the Service in accordance with applicable law.

6.Processing Instructions

GRIINWARE will process Service Data only for the following purposes:

  • To provide, maintain, secure, and support the platform.
  • To perform system operations such as backup, monitoring, authentication, reporting, and audit logging.
  • To respond to support requests and investigate technical issues.
  • To comply with legal obligations where required by law or valid legal process.

GRIINWARE will not process Service Data for any other purpose unless the Customer provides clear written instructions or the processing is required by law.

7.Security Obligations

GRIINWARE will implement reasonable technical and organizational measures appropriate to the nature of the data and the risks involved, including:

  • Access control and role-based permissions.
  • Secure authentication, session management, and password protection.
  • Audit logging for key account and data actions.
  • Secure hosting, backups, monitoring, and restricted support access.

The Customer is responsible for keeping its own account credentials secure, assigning appropriate staff permissions, and ensuring that only authorized personnel access the Service.

8.Confidentiality & Access Controls

GRIINWARE will keep Service Data confidential and will limit access to personnel who need it to provide the Service, investigate issues, or comply with a legal obligation.

  • Access is granted on a need-to-know basis.
  • Support personnel are subject to confidentiality obligations.
  • The Customer must configure access rights carefully to reduce unnecessary exposure.

GRIINWARE will not disclose Service Data to third parties except as permitted by this DPA, the main agreement, or applicable law.

9.Sub-processors & Third Parties

GRIINWARE may engage sub-processors to assist with hosting, support, cloud infrastructure, backup, analytics, communications, or security monitoring.

Where such sub-processors are used, GRIINWARE will ensure that they offer an appropriate level of confidentiality and security and will remain responsible for their compliance with the terms of this DPA.

10.Data Subject Requests

The Customer is responsible for deciding the lawful basis for processing and for responding to requests from data subjects where applicable.

GRIINWARE will assist the Customer by providing reasonable access to relevant records, export capability, and technical information needed to respond to data access, correction, or deletion requests, subject to applicable law and the limits of the Service.

11.Breach Notification

If GRIINWARE becomes aware of a security incident affecting Service Data under its control, it will promptly investigate the matter and notify the Customer as soon as reasonably possible.

The parties will cooperate to contain the incident, assess its impact, and take appropriate remedial action. GRIINWARE will provide the information reasonably necessary for the Customer to meet its own legal and contractual reporting obligations.

12.International Transfers

Where Service Data is transferred outside Rwanda, GRIINWARE will take reasonable steps to ensure that the transfer is lawful and that the data remains protected to an appropriate standard.

13.Retention & Deletion

The Customer may export or back up its data at any time through the Service or by request.

On termination of the Service, GRIINWARE will, at the Customer's instruction, return or securely delete the Service Data in accordance with the agreement and applicable law, subject to any legal retention period or backup exception.

14.Audit & Compliance

GRIINWARE will maintain reasonable records of its processing activities and security measures relevant to the Service.

The Customer may request reasonable information about the measures applied to the Service, and GRIINWARE will provide such information in a practical and commercially reasonable manner.

15.Contact & Governing Law

For questions about this DPA, data handling, or security concerns, contact us at:

Griin Company Ltd
Email: info@griincompanyltd.com
[Address Line 1]
[City], Rwanda

This DPA is governed by the laws of the Republic of Rwanda and should be read together with the Terms and Privacy Policy.