Plain-language summary
This box is a friendly overview only. The numbered sections below are what actually governs your use of the Service.
One account per pharmacy. Your pharmacy's owner/admin is responsible for every staff account created under it.
You own your data. Stock, sales, and client records belong to your pharmacy — we just host and process them for you.
You must check your own numbers. Stock levels, prices, VAT, and reconciliation figures come from what your staff enter — verify them before relying on them.
Client data is sensitive. Names, insurer details, and purchase history must be handled with the same confidentiality your profession already requires.
We log activity for security. Logins, sales, and edits are recorded against the staff account that performed them.
You can export your data anytime. Back it up yourself — we're not liable for data you didn't export before closing an account.
This isn't a substitute for professional judgment. Rwanda FDA and Pharmacy Council rules still apply to how you actually dispense medicine.
Rwandan law governs this agreement, including our data protection, tax, and consumer protection obligations — see Section 27 for citations.
This is a legal template grounded in current Rwandan legislation as of mid-2026. It is not a substitute for review by a qualified Rwandan lawyer before publication.
1.Introduction & Acceptance
These Terms and Conditions ("Terms") govern access to and use of the GRIINWARE pharmacy management platform and related services (the "Service"), provided by Griin Company Ltd ("GRIINWARE", "we", "us", or "our").
By registering a pharmacy account, creating a staff account, logging in, or otherwise using the Service, you agree to be bound by these Terms on behalf of yourself and, where applicable, the pharmacy business you represent. If you do not agree, you must not use the Service.
These Terms should be read together with our Privacy Policy, which explains in more detail how we collect, use, and protect personal data.
2.Definitions
- Pharmacy Account
- The organizational account registered under a pharmacy's legal name and Tax Identification Number (TIN). All staff users, stock, sales, and records belong to a single Pharmacy Account.
- Staff User / User
- An individual granted login access under a Pharmacy Account, assigned a role (e.g. Admin, Cashier, Viewer) that determines what they can see and do.
- Admin
- The staff user (typically the pharmacy owner) with full access to a Pharmacy Account, including the ability to create, modify, and remove other Staff Users.
- Content
- Data entered into or generated by the Service on behalf of a Pharmacy Account — including product and batch records, pricing, sales transactions, client/patient records, supplier and purchase order data, expenses, and reports.
- Client
- An individual patient or customer record maintained within a Pharmacy Account, which may include name, phone number, date of birth, address, gender, and insurance information.
- Insurance Provider
- A third-party health insurer or scheme (e.g. RSSB, MMI, or a private insurer) configured within a Pharmacy Account for co-payment calculation purposes.
- Batch
- A tracked quantity of a specific product received on a specific date, with its own cost, expiry date, and remaining quantity.
- Reconciliation
- The process of comparing recorded stock and cash figures against physical counts or till totals to identify discrepancies.
- Audit Log
- A system-generated record of actions taken within a Pharmacy Account, including the acting Staff User, the action performed, timestamp, and technical details such as IP address and browser/device information.
- Personal Data
- Any information relating to an identified or identifiable natural person, as defined under Rwandan data protection law.
3.Eligibility & Pharmacy Accounts
- A Pharmacy Account may only be registered by a person with legal authority to bind the pharmacy business — typically its owner, licensed pharmacist-in-charge, or authorized representative.
- Pharmacy Accounts require a valid business name and Tax Identification Number (TIN). Providing false registration details is a breach of these Terms and may result in suspension.
- The Pharmacy Account — not any individual Staff User — is the contracting party under these Terms. The Admin is responsible for ensuring every Staff User they create agrees to, and complies with, these Terms.
- You must keep login credentials secure and must not share individual staff logins between multiple people. Actions performed under a Staff User's login are treated as authorized by that person and by the Pharmacy Account.
- Notify us immediately at info@griincompanyltd.com if you suspect unauthorized access to any account under your Pharmacy Account.
4.Staff Users, Roles & Permissions
The Service uses role-based access control so that Staff Users only see what's relevant to their job — for example, a cashier processing sales does not need the same access as an Admin reviewing financial reports.
- The Admin is responsible for assigning appropriate roles and permissions to each Staff User, and for promptly removing access when a staff member leaves or changes role.
- We are not responsible for losses arising from a Pharmacy Account granting excessive access to a Staff User, or failing to revoke access after that person's employment ends.
- Certain support and platform-maintenance functions may be performed by Griin Company Ltd personnel holding elevated system-level access — see Section 13.
5.Permitted Use
You may use the Service only for lawful, legitimate pharmacy business operations — including inventory management, sales and billing, client record-keeping, supplier and purchase order management, expense tracking, and reporting — consistent with these Terms and any documentation we publish.
6.Prohibited Conduct
Without limiting Section 5, you must not:
- Engage in illegal activity, fraud, phishing, harassment, or impersonation.
- Share login credentials, or otherwise allow access by anyone other than the individual to whom a Staff User account was issued.
- Upload malware, attempt to bypass access controls, scrape data, reverse-engineer the Service, or disrupt its normal operation.
- Falsify or knowingly enter inaccurate stock levels, batch expiry dates, prices, sales figures, or reconciliation records with intent to mislead a regulator, auditor, insurer, or business partner.
- Use the Client records feature to store sensitive personal data beyond what is reasonably necessary for pharmacy operations, or without a lawful basis for doing so.
- Use the Service to dispense, record, or bill for products in a manner that violates Rwanda FDA regulations, Rwanda Pharmacy Council standards, or any other applicable pharmaceutical law.
7.Your Content & Business Records
Your Pharmacy Account retains ownership of all Content it submits — your stock records, sales history, client records, and reports remain yours. By submitting Content, you grant Griin Company Ltd a limited, non-exclusive license to store, process, transmit, and display that Content solely to provide, maintain, and improve the Service, and to comply with our legal obligations.
We do not sell Content to third parties, and we do not use one Pharmacy Account's Content to benefit another Pharmacy Account.
8.Accuracy of Business Records — Your Responsibility
The Service calculates and displays figures — stock value, selling prices, VAT, insurer co-payments, reconciliation totals, and reports — based entirely on data your Staff Users enter. We provide the calculation engine; you provide, and are responsible for, the underlying data.
| Area | Your responsibility | Our responsibility |
|---|---|---|
| Stock & batches | Entering correct quantities, cost prices, and expiry dates when receiving stock | Tracking, alerting on low stock/expiry, and calculating stock value from the data provided |
| Pricing & markup | Configuring accurate cost prices, markup percentages, and confirming VAT settings are correct | Applying your configured markup and VAT consistently across stock and sales screens |
| Sales & billing | Verifying the amount charged to a client matches what is displayed before completing a sale | Calculating the sale total from current pricing and VAT configuration |
| Insurer co-payments | Configuring correct insurer rates and confirming eligibility with the insurer directly | Splitting client/insurer amounts based on the rates you configured |
| Reconciliation | Performing physical stock counts and cash counts and investigating discrepancies flagged by the system | Surfacing discrepancies between recorded and reported figures |
| Expenses | Categorizing and entering expense records accurately | Aggregating and displaying expense totals and trends |
9.Pricing, VAT & Insurance Calculations
- Where enabled, the Service calculates Value Added Tax (VAT) based on the rate and product VAT-category settings you configure, consistent with the general framework of Rwanda's VAT law (see Section 27). You are responsible for confirming the correct VAT treatment of your products with the Rwanda Revenue Authority (RRA) and for filing your own VAT returns.
- Insurer co-payment splits are calculated using the rates and rules you configure for each Insurance Provider. GRIINWARE has no relationship with, and does not guarantee reimbursement from, any Insurance Provider — that relationship and any resulting dispute is between your pharmacy and the insurer.
- Selling prices shown in Stock and Sales are calculated consistently from cost price, markup, and VAT settings. If you believe a displayed price is incorrect, verify your pricing configuration before completing a transaction — do not rely on the Service to catch pricing-configuration errors on your behalf.
10.Patient/Client Data & Confidentiality
Client records may include health-adjacent information such as insurance status, prescribing doctor details, and purchase history. This is sensitive information deserving the same professional confidentiality your pharmacy already owes its clients under pharmacy practice standards.
- Only give Staff Users access to Client records they need for their role.
- Where the Service allows marking a transaction as private or restricted, use that feature for sensitive purchases and ensure only authorized staff can view such records.
- You must have a lawful basis (such as the client's consent or a legitimate pharmacy-operations purpose) before entering a client's Personal Data into the Service.
- Do not use Client records for marketing, research, or any purpose beyond direct pharmacy operations without the client's separate, informed consent.
11.Privacy & Data Protection
We process Personal Data in accordance with our Privacy Policy and Rwanda's Law No. 058/2021 of 13/10/2021 relating to the protection of personal data and privacy, supervised by the National Cyber Security Authority (NCSA).
Key obligations this creates for both parties:
- We implement technical and organizational measures appropriate to the risk, and maintain records of processing activities as a data processor for your Pharmacy Account's Content.
- Your Pharmacy Account acts as the data controller for the Client and Personal Data you enter — meaning you decide what data to collect and why, and you are responsible for having a lawful basis to do so.
- We recommend every Pharmacy Account designate an internal contact person responsible for data protection matters (a Data Protection Officer, or "DPO"), particularly if you process data at scale.
- High-risk processing (e.g. large-scale sensitive health data) may require a Data Protection Impact Assessment under the law — this is a shared responsibility between the Pharmacy Account (as controller) and us (as processor providing the underlying tooling).
12.Security, Sessions & Audit Logging
- The Service records an Audit Log entry for significant actions — logins, sales, stock adjustments, price changes, user management changes — including the acting Staff User, timestamp, IP address, and browser/device information.
- This logging exists to protect your Pharmacy Account: it lets an Admin trace who did what, and helps us investigate security incidents. It also means actions taken under a given login are attributable to that Staff User and cannot later be disclaimed as "not really me."
- We use session-based authentication; sessions may expire after a period of inactivity for your protection. Log out on shared or public devices.
- In the event of a security incident affecting Personal Data we control, we will notify affected Pharmacy Accounts and the National Cyber Security Authority as required by law. You must notify us promptly of any suspected breach involving your account.
13.Our Support Staff's Access to Your Data
A limited number of authorized Griin Company Ltd personnel hold system-level access that can span multiple Pharmacy Accounts, used only for:
- Diagnosing and fixing technical issues you report;
- Routine platform maintenance, security monitoring, and abuse prevention;
- Complying with a legal obligation or valid legal process.
Such access is logged, restricted to what is necessary for the purpose, and subject to the same confidentiality obligations described in Section 11. We do not access your Content to view, use, or share client information out of curiosity or for any commercial purpose unrelated to operating the Service.
14.Data Export, Backup & Portability
- Where the Service offers export functionality (for example, exporting reports or expense records to CSV/Excel), you may use it at any time to obtain a copy of your Content.
- We recommend exporting and independently backing up critical records periodically, and definitely before closing a Pharmacy Account or downgrading your usage.
- We are not liable for Content that becomes unavailable after account termination if you did not export it beforehand, subject to any longer retention required by applicable law.
15.Health & Pharmacy Regulation
If you operate a licensed pharmacy in Rwanda, you remain independently responsible for complying with:
- Law N° 003/2018 of 09/02/2018 establishing the Rwanda Food and Drugs Authority (Rwanda FDA), which regulates pharmaceutical products, their storage, sale, and distribution;
- Rwanda Pharmacy Council registration, licensing, and Good Pharmacy Practice standards for pharmacy professionals;
- Any narcotics, psychotropic substance, and controlled-drug regulations applicable to your dispensing activity.
The Service is a business-management tool, not a clinical decision-support system, and is not a substitute for a licensed pharmacist's professional judgment, patient counseling obligations, or regulatory reporting duties.
16.Payments, Billing & Refunds
If the Service or any part of it is offered for a fee, the applicable subscription terms, billing cycle, accepted payment methods, taxes, and refund/cancellation procedure will be presented to you at signup or upgrade and form part of these Terms. Prepaid fees are generally non-refundable except where required by Rwandan consumer protection law (see Section 27).
17.Third-Party Services & Integrations
The Service may integrate with third-party providers such as payment processors, SMS/email gateways, or cloud hosting infrastructure. Those providers operate under their own terms and privacy practices. Griin Company Ltd is not responsible for third-party service outages, errors, or policy changes.
18.Intellectual Property
All intellectual property rights in the Service itself — including its software, user interface, branding, and documentation — belong to Griin Company Ltd or its licensors. You may not copy, adapt, decompile, or create derivative works of the Service without our prior written permission. This does not affect your ownership of your own Content.
19.Limitation of Liability
To the maximum extent permitted by Rwandan law, Griin Company Ltd will not be liable for indirect, incidental, special, punitive, or consequential damages, including loss of profit, business interruption, or reputational harm, arising from your use of the Service. Where the law permits a cap, our aggregate liability for any claim is limited to the fees you paid us in the twelve (12) months preceding the claim, or [fixed sum in RWF] if no fees were paid.
This limitation does not apply to losses caused by our gross negligence, willful misconduct, or fraud, or to any liability that cannot be limited under mandatory Rwandan law.
20.Indemnification
You agree to indemnify and hold harmless Griin Company Ltd, its officers, and employees from claims, liabilities, losses, and expenses arising from your misuse of the Service, breach of these Terms, violation of applicable law, or inaccurate Content entered by your Staff Users.
21.Suspension & Termination
We may suspend or terminate access to the Service for violations of these Terms, security risks, prolonged inactivity, or discontinuation of the Service. On termination, Content may be deleted according to our retention policy and applicable law. You are responsible for exporting your Content beforehand, per Section 14.
22.Force Majeure
Neither party is liable for delays or failures caused by events beyond its reasonable control, including power or internet outages, natural disasters, government action, or widespread infrastructure failure.
23.Governing Law & Dispute Resolution
These Terms are governed by the laws of the Republic of Rwanda. Disputes arising from these Terms or the Service will be submitted to the competent courts of Rwanda, unless the parties agree in writing to arbitration or mediation instead.
24.Changes to These Terms
We may update these Terms from time to time. Material changes will be communicated by email or a prominent notice within the Service at least fourteen (14) days before they take effect. Continued use of the Service after that date constitutes acceptance of the updated Terms.
25.Severability & Entire Agreement
If any provision of these Terms is found invalid or unenforceable, the remaining provisions continue in full force. These Terms, together with our Privacy Policy, constitute the entire agreement between you and Griin Company Ltd regarding the Service.
26.Contact & Notices
For support requests, legal notices, or data protection inquiries, contact us at:
Griin Company LtdEmail: info@griincompanyltd.com
[Address Line 1]
[City], Rwanda
27.Legal Sources & References
The following Rwandan legal instruments were reviewed and are referenced in these Terms. This section is provided for transparency and is not itself legal advice.
- Law No. 058/2021 of 13/10/2021 relating to the protection of personal data and privacy Gazetted 15/10/2021. Supervisory authority: National Cyber Security Authority (NCSA). See RISA overview.
- Law N° 18/2010 of 12/05/2010 relating to electronic messages, electronic signatures and electronic transactions Governs the validity of electronic agreements and transactions, including account creation and acceptance of these Terms.
- Law N° 011/2026 of 26/02/2026 relating to competition and consumer protection Replaces the former Law n° 36/2012. Regulator: Rwanda Inspectorate, Competition and Consumer Protection Authority (RICA). This is recent legislation — have counsel confirm its current provisions before publishing.
- Law N° 049/2023 of 05/09/2023 establishing the value-added tax Replaces Law No 37/2012. Sets the standard VAT rate and administration by the Rwanda Revenue Authority (RRA).
- Law N° 003/2018 of 09/02/2018 establishing Rwanda Food and Drugs Authority Regulates pharmaceutical products, storage, sale, and distribution. See Rwanda FDA overview.
- Rwanda Pharmacy Council — laws, policies & guidelines Governs professional licensing, registration, and Good Pharmacy Practice standards. See pharmacycouncil.rw.
Other statutes — including companies law, employment law, and sector-specific regulations — may impose additional obligations depending on how your pharmacy is structured. This page is not legal advice. Have these Terms reviewed by a qualified Rwandan lawyer before publishing, and re-verify the 2026 consumer protection citation given how recently it was enacted.