Legal
Privacy Policy
Last updated 21 July 2026
Sample terms prepared for the PharmaLink Global platform. Review by qualified counsel is required before commercial launch.
This policy explains what personal data PharmaLink Global handles when you use the Platform, why we handle it, and the choices you have. It covers the business contacts who register, negotiate and manage organizations on the Platform.
1. What we collect
Account details you give us (name, work email, contact number, job role, organization and country); authentication data, including the email, name and provider identifier returned when you sign in through Google or your company SSO; the trading activity you generate (requests, quotes, messages, orders, samples); the documents your organization uploads for verification; and technical records such as sign-in times, IP address and device or browser information.
2. What we do not collect
We do not ask for patient data, health records or consumer information, and the Platform must not be used to transmit them. When you sign in through a provider we receive only your basic profile — never your password.
3. Why we handle it
To create and secure your account, to operate matching, negotiation and fulfilment, to verify organizations and keep an audit trail, to provide support, to bill your plan, to detect fraud, sanctions and abuse, and to meet legal obligations. Where we rely on legitimate interests, those are the security and integrity of a regulated trading venue.
4. Who can see it
Your name, organization and the commercial terms you send are visible to the counterparties you choose to deal with, and to colleagues in your own organization according to their role. We use service providers for hosting, email and analytics under contract, and we disclose data to regulators or law enforcement only where legally required.
5. International transfers
The Platform serves organizations across multiple regions, so data may be processed outside your country. Where that happens we use recognised safeguards for the transfer.
6. How long we keep it
Account and trading records are kept for the life of the account and afterwards for the period that tax, audit, sanctions-screening and product-traceability obligations require. Verification documents are retained with their integrity hashes so an audit can confirm what was relied on and when.
7. Security
Passwords are stored only as salted hashes, access is scoped by role and organization, and document access is short-lived and permission-checked. No system is perfectly secure; tell us immediately if you suspect an account has been compromised.
8. Your rights
Subject to your local law, you may request access to your personal data, correction, deletion, restriction, portability, or object to certain processing. Much of this is self-service in account settings. Requests that would break a record we are legally required to keep may be refused in part, and we will explain why.
9. Marketing
Market updates and price insights are optional and consent-based. You can withdraw consent at any time in your notification settings or from the link in any such message; service and transactional messages will continue.
10. Cookies
We use cookies that are necessary to keep you signed in, to remember your language, and to measure aggregate usage so we can improve the Platform. Necessary cookies cannot be switched off without breaking sign-in.
11. Contact
Privacy questions or rights requests: privacy@pharmalink.example.