Privacy Policy
Last Updated: 4th August 2026
This Privacy Policy explains how Terralis collects, uses, stores, and shares information when you use our websites, mobile apps, and related pharmacy software ("Services"). Terralis is the second brain for modern pharmacies. The Services are built for the Ghanaian pharmacy market and process operational data and, depending on your use, patient health-related data on behalf of the pharmacies that use them.
By using the Services, you agree to the practices described here, except where applicable law requires separate consent for certain processing — see Section 3 on how consent for patient health data works in practice at the pharmacy counter.
1. Data Controller & Data Processor Roles
Under Ghana’s Data Protection Act, 2012 (Act 843), and similar laws in other jurisdictions we operate in, these roles determine who is responsible for what:
- For patient and customer health-related data (allergies, conditions, visit notes, prescriptions, and similar records entered into the Services) — the subscribing pharmacy is the Data Controller. Terralis is the Data Processor, and we process that data only on the pharmacy’s instructions, as described in our Data Processing Agreement with each subscribing organization.
- For account, billing, and platform-usage data (your login, your organization’s subscription details, diagnostic and usage logs) — Terralis is the Data Controller.
In practice: the pharmacy decides what patient information is recorded and why, and is responsible for having a lawful basis and consent for recording it. Terralis is responsible for processing that data securely, only for the purposes the pharmacy configures, and not for our own independent purposes.
2. Information We Collect
We collect information needed to run accounts, pharmacy workflows, security, billing, and product improvement.
2.1. Account & organization information
- Name, email, phone
- Password (stored using strong one-way hashing)
- Company or pharmacy name, address, industry, branding
- Subscription, plan, and payment-related metadata
- Role assignments (owner, admin, staff, branch scope)
2.2. Pharmacy & operational data
- Drug and inventory records, batches, expiry, suppliers, and stock movements
- Sales and transaction records (items, quantities, totals, payment methods, timestamps)
- Safety and workflow events generated in-product (e.g. interaction or prescription prompts, severities, overrides where your configuration allows)
- Branch structure, permissions, and audit log entries
- Analytics you generate inside the product (e.g. dashboards)
2.3. Prescription & patient health-related data
Depending on features a pharmacy enables, the Services may process, on the pharmacy’s behalf:
- Prescription images or files attached to sales or customer records
- Customer profiles, including contact details and purchase history
- Health-related context a pharmacist chooses to record: known allergies and reactions, chronic or ongoing conditions, and visit notes — recorded to support point-of-sale safety checks and continuity of care, not for diagnosis
This is treated as special personal data under Act 843. The subscribing pharmacy is responsible for obtaining valid consent before recording it — see Section 3 for how that consent is captured at the counter, and Section 8 for the data-subject rights that apply to it.
2.4. Usage, device & diagnostic data
- App and web activity, feature usage, and event logs
- IP address, device type, browser, and approximate location
- Push notification tokens
- Error, crash, and performance diagnostics
2.5. Media you upload
Optional profile photos or other files you choose to attach.
3. How Patient Consent Works in Practice
Health-related data is usually entered by a pharmacist during an in-person encounter, not typed directly by the patient. Act 843 requires an explicit, affirmative act of consent before a pharmacy records special personal data. Subscribing pharmacies are expected to obtain that consent through one of the following methods before recording a customer’s allergies, conditions, or visit notes:
- A posted notice at the point of sale explaining, in plain language, that the pharmacy records health information to check that medicines are safe for the customer, with the option to decline; or
- A brief verbal explanation from the pharmacist at the time health information is first recorded, with the customer’s acknowledgment; or, where the customer is a minor or is being assisted by a caregiver, acknowledgment from the person acting on their behalf.
The Services record that consent was given, when, by which method, and which staff member captured it, attached to the customer’s record. This is a one-time record per customer, not repeated at every visit, and can be updated if the customer later objects. Pharmacies remain responsible for actually obtaining consent in line with this Policy and applicable law; Terralis provides the tooling to record and honor it.
4. How We Use Information
We use data to provide and secure the Services, communicate with you, and improve reliability.
4.1. Core pharmacy platform
- Operating dispensing-adjacent workflows you configure
- Evaluating combinations against product safety data and showing alerts or prompts
- Enforcing prescription rules per your policy settings
- Maintaining audit trails for sensitive actions
- Inventory, expiry, reporting, and branch operations
4.2. Communication
- Transactional messages (security, billing, account)
- Operational alerts you configure (e.g. stock, batches)
- Support conversations
4.3. Security & abuse prevention
- Authentication, access control, and fraud monitoring
- Detecting unauthorized access or policy violations
4.4. Improvement, analytics & AI-assisted features
- Debugging, performance tuning, and reliability
- Aggregated or de-identified analytics to understand feature usage
- Where offered, AI or automation that summarizes or surfaces drug and product information in-product. If we introduce AI features that process patient-identifiable health data (for example, summarizing visit notes), we will update this Policy to describe that processing specifically and, where required, seek separate consent before enabling it for a pharmacy.
We do not sell personal or health-related data.
5. How We Share Information
We share information only as described below.
5.1. Within your organization
Users you authorize may see data according to role and branch permissions. Health-related data is scoped to the organization that recorded it — staff at a different, unaffiliated pharmacy cannot see it.
5.2. Service providers
Vendors that help us host, store, deliver, secure, or analyze the Services—for example:
- Cloud infrastructure and databases
- Backups and logging
- Payment processors
- Email and push delivery
- Error monitoring
- AI or machine-learning infrastructure where those features are enabled
Providers may process data only on our instructions, under written confidentiality and security obligations, and — for patient health data — consistent with our Data Processing Agreement with the relevant pharmacy.
5.3. Legal & safety
We may disclose information if we believe in good faith it is necessary to:
- Comply with law, regulation, or legal process
- Protect rights, safety, and security of users or the public
- Investigate fraud or enforce our agreements
We do not rent or sell your information to data brokers.
6. Data Security
We use administrative, technical, and organizational measures appropriate to the sensitivity of pharmacy operations and patient health data, including:
- Encryption in transit (HTTPS/TLS) for all Services traffic
- Encryption at rest for stored data, including health-related records
- Role- and branch-scoped access controls, so staff only see data for organizations and branches they are authorized to access
- Attribution of every health-related record to the staff member who entered it
- Monitoring and logging of access to sensitive data
No online service is perfectly secure. Please protect your credentials and devices, and report suspected unauthorized access immediately.
7. Data Retention
We retain information while your account is active and as needed to provide the Services, comply with law, resolve disputes, and enforce agreements. Pharmacy and transaction records may be retained longer where regulations applicable to you require record retention.
Health-related records (allergies, conditions, visit notes) are retained according to the pharmacy’s instructions and applicable record-keeping law. A pharmacy may mark a record inactive or request deletion at any time, subject to legal exceptions; some data must be kept for audit or regulatory reasons even after a deletion request.
8. Your Rights
8.1. Account & platform rights
If you have a Terralis account (as an organization owner, admin, or staff user), you may request access to, correction of, or deletion of your own account information by contacting us at the email below. We will respond consistent with applicable law.
8.2. Patient & customer data-subject rights
If a pharmacy has recorded your health-related or personal information (as a customer or patient), the pharmacy is the Data Controller for that information under Act 843. To access, correct, restrict, or request deletion of your records, contact the pharmacy directly.
Terralis provides pharmacies with the tools to fulfil these requests in the Services (viewing, correcting, deactivating, or deleting a customer’s record). If a pharmacy is unable to assist you, you may contact us and we will direct your request to the relevant organization or, where we act as Controller for the request, respond directly. You may also lodge a complaint with Ghana’s Data Protection Commission.
9. Children’s Privacy
Terralis accounts are not directed to individuals under 18, and we do not knowingly collect account information from children. This does not restrict pharmacies from recording health-related information about pediatric patients as part of ordinary pharmacy care — that data is entered by a pharmacist or guardian, not by a child using the Services directly, and is subject to the same consent and security practices described in Sections 2.3 and 3.
10. International Data Transfers
The Services are currently hosted on Hetzner cloud/VPS infrastructure, with our database running on the same infrastructure. This means personal and health-related data you submit is currently transferred to and processed outside Ghana. We are evaluating a migration to a managed database provider (such as Neon) as we scale; if we change providers or hosting regions, we will update this section and, where the change is material, provide additional notice as described in Section 12.
Where we transfer data outside Ghana, Act 843 requires that the destination offer an adequate level of protection, or that we rely on another valid safeguard. We do this through a combination of: contractual data protection obligations with our infrastructure providers, encryption in transit and at rest, and — for special personal data — the consent captured as described in Section 3, which covers processing on our infrastructure regardless of its physical location.
11. Ghana Data Protection Act & Regulatory Status
Terralis is built for pharmacies operating in Ghana and is designed to align with the Data Protection Act, 2012 (Act 843) and the oversight of Ghana’s Data Protection Commission (DPC).
Terralis is currently focused exclusively on the Ghanaian pharmacy market. Registration with the Data Protection Commission of Ghana is in progress. We will update this section with our registration details once confirmed, and we do not claim completed registration until that happens.
12. Changes to This Policy
We may update this Policy. We will post the new date and, where changes are material, provide additional notice (e.g. email or in-app).
13. Contact
Privacy questions or data requests — use the contact details below.