Plain-language summary
This policy explains how GRIINWARE handles the information you and your pharmacy enter into the system, and how we protect it.
Your pharmacy owns its records. Stock, sales, expenses, and client information remain your business data.
We collect only what is needed to operate the platform. This includes account details, staff access, product records, sales transactions, and technical logs.
We do not sell your data. We use it only to provide the service, maintain security, and meet legal obligations.
Client data is treated as sensitive. We apply access controls, audit logging, and security safeguards to protect it.
You can request access, correction, or export. You can review and manage the data you enter through your account and support channels.
Rwandan law applies. Our processing is aligned with the Law on Personal Data Protection and Privacy in Rwanda.
This is a practical privacy notice tailored to the GRIINWARE pharmacy platform. It is not a substitute for professional legal review.
1.Introduction & Scope
This Privacy Policy explains how Griin Company Ltd ("we", "us", or "our") collects, uses, stores, shares, and protects personal data when you use the GRIINWARE pharmacy management platform and related services (the "Service").
GRIINWARE is designed for pharmacies, drug stores, and healthcare-adjacent businesses in Rwanda and other jurisdictions. Because the platform handles business records, staff account details, inventory activity, sales, client records, and sometimes sensitive health-adjacent information, this policy is written to be clear and specific to the way the system works.
By creating an account, logging in, entering records, or otherwise using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, do not use the Service.
2.What Data We Collect
We may collect different categories of data depending on your role and the features you use. The main categories are:
- Account and identity data: name, email address, phone number, username, password hash, business name, Tax Identification Number (TIN), and role within the pharmacy account.
- Pharmacy business data: product names, product categories, batch records, expiry dates, stock quantities, cost prices, selling prices, supplier records, purchase orders, expenses, sales, reconciliation notes, and reports.
- Client and customer data: names, phone numbers, addresses, dates of birth, gender, insurance provider information, purchase history, prescription or transaction notes where entered by your pharmacy, and related records needed for pharmacy operations.
- Administrative and security data: user role assignments, audit logs, login activity, device/browser information, IP address, session tokens, password reset requests, and support request details.
- Communication data: messages sent through the Service, support tickets, notification preferences, and email/SMS-related metadata where applicable.
3.How We Use Your Data
We use personal data and business records for the following purposes:
- To create and manage your pharmacy account and staff access.
- To operate the core features of GRIINWARE, including stock management, sales, expenses, reporting, reconciliation, pricing, and client records.
- To send system notifications, alerts, password resets, support replies, and account-related communications.
- To maintain security, detect abuse, investigate incidents, and keep audit trails for account activity.
- To troubleshoot technical issues, improve reliability, and maintain service performance.
- To comply with legal, regulatory, tax, or accounting obligations that apply to our business or to your pharmacy's use of the Service.
We do not use your data for unrelated marketing or sale to third parties. We may use aggregate, de-identified, or statistical information for service improvement, but this does not identify you or your pharmacy.
4.What We Collect From Pharmacy Operations
Because GRIINWARE is a pharmacy management system, the platform may process information that is particularly relevant to dispensing, stock control, payments, and client service. The following examples are especially important:
- Inventory and batch data: product names, batch numbers, expiry dates, quantities on hand, and cost price information.
- Sales and financial records: transaction totals, payment methods, refunds, discounts, insurer co-payment details, VAT-related configuration, and reconciliation records.
- Client records: names, phone numbers, insurance information, purchase history, and notes entered by your staff for service or operational purposes.
- Staff management data: role assignments, permission levels, account status, and audit events showing who created, edited, or deleted records.
- Support and compliance data: information provided when requesting help, reporting a problem, or responding to a compliance or security issue.
Your pharmacy is responsible for ensuring that any data you enter is necessary, accurate, and lawful for the purpose for which it is used.
5.How We Share Data
We do not sell or rent your pharmacy data to third parties for their own purposes. We may share data only in limited circumstances:
- Within your pharmacy: administrators and staff users may access data according to their assigned roles and permissions.
- With our service providers: we may share data with hosting, cloud, backup, support, analytics, or communication providers that help us run the Service. These providers are bound to protect your data and may only use it to perform services for us.
- With regulators or legal authorities: we may disclose data where required by law, a court order, a regulator, a tax authority, or a valid legal process.
- With your consent or as necessary for a transaction: for example, if you ask us to integrate with a third-party billing or insurer-related workflow, we may share the minimum data needed to complete that task.
We do not share one pharmacy's data with another pharmacy. We also do not use your records for advertising or unrelated commercial purposes.
6.Data Retention & Deletion
We retain data for as long as needed to provide the Service, satisfy legal obligations, resolve disputes, and enforce our agreements. In practice:
- Active account data is retained while your pharmacy account remains active.
- Account data may be retained for a period after account closure where required for backup, legal retention, security investigations, or tax/accounting purposes.
- You may export your records at any time through the features available in the Service, and we recommend keeping your own backup copies for business continuity.
- If you request deletion, we will assess whether retention is required by law or necessary for security, fraud prevention, or contractual obligations before acting on the request.
7.Security Measures
We take reasonable technical and organizational steps to protect the data we process. These measures may include:
- Access controls and role-based permissions so that staff only see what their role allows.
- Session-based authentication and password security measures.
- Audit logging of key actions such as logins, record edits, sales, stock adjustments, and user management changes.
- Secure hosting, backups, and monitoring practices.
- Restricted internal access for support personnel, limited to what is necessary to diagnose issues or comply with a legal obligation.
No system is perfect, and no security measure can guarantee absolute protection. If a security incident affects data we control, we will take appropriate steps to contain it, investigate it, and notify affected parties where required by law.
8.Your Rights & Choices
Depending on applicable law and the role you hold in the system, you may have rights regarding your personal data and the data you enter for your pharmacy. These may include:
- The right to access the personal data we hold about you or your pharmacy account.
- The right to request correction of inaccurate or incomplete data.
- The right to request deletion or restriction of processing in certain circumstances.
- The right to object to certain processing where applicable.
- The right to receive a copy of your data in a portable format where available.
- The right to lodge a complaint with the relevant data protection authority in Rwanda.
To exercise these rights, contact us using the details below. We may ask you to verify your identity and, where relevant, confirm your authority to act on behalf of a pharmacy account. Some requests may be limited where we must preserve data for legal, security, or operational reasons.
9.Cookies, Sessions & Device Information
The Service may use session tokens, browser storage, and similar technologies to keep you logged in, protect your account, and maintain your current work session. These tools may collect technical data such as device type, browser version, and session activity.
We may also use cookies or local storage for authentication, preference settings, and security purposes. If you disable cookies in your browser, some parts of the Service may not work properly or may require you to log in again more frequently.
10.Third-Party Services
GRIINWARE may integrate with third-party services such as email providers, SMS gateways, cloud hosting providers, payment processors, analytics services, or backup systems. These providers process data on our behalf or on your behalf under their own terms and privacy practices.
We remain responsible for ensuring that such providers are appropriate and that your data is protected. We do not control the policies of third parties, so you should read their privacy notices where relevant.
11.International Transfers
Some of the systems that support the Service may be hosted or operated from outside Rwanda, or may use cloud infrastructure located in multiple jurisdictions. If your data is transferred outside Rwanda, we will take reasonable steps to ensure that the transfer is lawful and that your data remains protected to an appropriate standard.
12.Children & Sensitive Data
GRIINWARE is not intended for the collection of children's data for general consumer purposes. If your pharmacy uses the Service to process patient or client records, including sensitive health-adjacent data, you must ensure that you have a lawful basis to do so and that you only collect what is necessary for legitimate pharmacy operations.
Where sensitive data is processed, we recommend that your pharmacy designate a responsible contact person and apply appropriate internal controls, access restrictions, and retention rules.
13.Contact & Complaints
If you have questions about this Privacy Policy, wish to exercise a right, or want to report a privacy or security concern, contact us at:
Griin Company LtdEmail: info@griincompanyltd.com
[Address Line 1]
[City], Rwanda
If you believe your privacy rights have been affected, you may also contact the relevant data protection authority in Rwanda.
14.Legal References
This policy is designed to be consistent with Rwanda's data protection framework, including the Law No. 058/2021 of 13/10/2021 relating to the protection of personal data and privacy and related oversight by the National Cyber Security Authority (NCSA).
- Rwanda Law No. 058/2021 on Personal Data Protection and Privacy.
- Applicable electronic transactions and communications law where account creation, authentication, and electronic notices are involved.
- Any other applicable pharmacy, tax, insurance, or business-record obligations under Rwandan law.
This policy is a practical privacy notice and not legal advice. We recommend that it be reviewed by qualified Rwandan counsel before publication or broad deployment.