Privacy Policy

Last updated 2nd September 2026

How Terralis collects, uses, stores, protects, and shares account, operational, medication, and health-related information.

On this page
  1. 1. Controller and Processor Roles
  2. 2. Information We Collect
  3. 3. How We Use Information
  4. 4. AI and Automated Processing
  5. 5. How We Share Information
  6. 6. Data Security
  7. 7. Data Retention
  8. 8. Data Subject Rights
  9. 9. Children’s Privacy
  10. 10. International Data Transfers
  11. 11. Ghana Data Protection
  12. 12. Your Responsibilities
  13. 13. Changes to This Policy
  14. 14. Contact

Privacy Policy

This Privacy Policy explains how Terralis (“Terralis”, “we”, “us”, or “our”) collects, uses, stores, protects, and shares information when you use our websites, mobile applications, APIs, and related services (collectively, the “Services”).

Terralis provides software for medication-related decision support and pharmacy and healthcare workflows.

Where an organization uses the Services to process patient or customer information, Terralis may process that information on the organization’s behalf as a Data Processor. This Policy should be read together with any applicable Data Processing Agreement.

1. Controller and Processor Roles

The role Terralis plays depends on the type of information and how it is used.

1.1. Patient and customer information

Where a pharmacy, hospital, clinic, or other healthcare organization uses Terralis to store or process patient or customer health-related information, the organization generally determines why and how that information is processed.

In those circumstances:

  • The organization generally acts as the Data Controller.
  • Terralis generally acts as the Data Processor.
  • Terralis processes the information according to the organization’s instructions and the applicable Data Processing Agreement.

The organization remains responsible for establishing an appropriate lawful basis for processing, obtaining any required consent, providing required notices, and complying with applicable healthcare and privacy requirements.

1.2. Terralis account and platform information

For information Terralis determines the purposes and means of processing itself — such as account administration, billing, platform security, service diagnostics, and certain product analytics — Terralis acts as the Data Controller.

2. Information We Collect

We collect information necessary to operate accounts, provide healthcare and pharmacy workflows, maintain security, process billing, provide support, and improve the Services.

2.1. Account and organization information

This may include:

  • Name
  • Email address
  • Phone number
  • Login credentials and authentication information
  • Organization or pharmacy name
  • Business address and contact information
  • Organization type and configuration
  • Subscription and billing information
  • User roles, permissions, and branch assignments

Passwords are not stored as plain text and are handled using appropriate security practices.

2.2. Pharmacy and operational data

Depending on the Services used, this may include:

  • Medication and product records
  • Inventory records
  • Batches and expiry information
  • Supplier information
  • Stock movements
  • Sales and transaction records
  • Prescription records
  • Branch information
  • Staff and role information
  • Audit records
  • Workflow events and safety prompts
  • Reports and analytics generated within the Services

Depending on the features enabled by an organization, Terralis may process information such as:

  • Patient or customer name and contact information
  • Prescription images or files
  • Medication lists and medication history
  • Purchase or dispensing history
  • Known allergies and reactions
  • Medical conditions
  • Visit or medication-review notes
  • Patient-specific medication context
  • Clinical findings, flags, or workflow records generated through the Services

Health-related information is treated as sensitive information under applicable privacy law.

Organizations using the Services are responsible for ensuring that they have an appropriate lawful basis, required consent, and appropriate notices before collecting or processing this information.

2.4. Usage, device, and diagnostic information

We may collect:

  • IP address
  • Device type
  • Browser and operating-system information
  • App activity and feature usage
  • Error and crash reports
  • Performance diagnostics
  • Security and authentication logs
  • Push notification tokens
  • Approximate location information where necessary for service functionality or security

2.5. Files and media

We may process files, images, documents, or other media that users choose to upload to the Services.

3. How We Use Information

We use information for the purposes described below, subject to applicable law and the role Terralis has for the relevant information.

3.1. Providing the Services

We use information to:

  • Operate accounts and organizations
  • Provide pharmacy and healthcare workflows
  • Process transactions and prescriptions
  • Maintain medication and patient records
  • Perform configured medication and safety checks
  • Provide reporting and analytics
  • Maintain branch and staff permissions
  • Provide customer support

Where enabled, the Services may use medication information and patient context to support workflows such as:

  • Reviewing medication information
  • Identifying potential drug interactions
  • Surfacing contraindication or safety signals
  • Providing dosing information
  • Supporting counselling workflows
  • Connecting medication information with patient context
  • Organizing clinical information for professional review

These features are intended to assist qualified professionals and do not independently diagnose, prescribe, or treat patients.

3.3. Security and abuse prevention

We use information to:

  • Authenticate users
  • Enforce access controls
  • Detect unauthorized access
  • Investigate security incidents
  • Prevent fraud and abuse
  • Maintain audit and security logs
  • Protect the Services and users

3.4. Product improvement and analytics

We may use aggregated or appropriately de-identified information to:

  • Understand product usage
  • Improve reliability and performance
  • Identify errors and usability problems
  • Develop and improve features
  • Measure service performance

We do not sell personal or health-related data.

4. AI and Automated Processing

Some Terralis features may use artificial intelligence, machine learning, or automated processing to summarize, organize, explain, rank, or surface information.

4.1. Clinical information

Where AI is used with medication or clinical information, the purpose is to help users navigate and understand available information.

AI-generated output may be inaccurate, incomplete, or misleading and must be reviewed by an appropriately qualified professional before being relied upon for patient-related decisions.

4.2. Patient-identifiable information

Where a feature processes patient-identifiable health information using AI or other automated systems, Terralis will provide appropriate product disclosures and implement applicable contractual, technical, and legal safeguards.

Where required, we will obtain or support the collection of additional consent or other lawful authorization before enabling such processing.

4.3. AI providers

Where third-party AI infrastructure is used, the relevant provider may process information only as necessary to provide the enabled functionality and subject to applicable contractual, confidentiality, security, and data-protection obligations.

We will not use patient-identifiable health information to train public or third-party foundation models unless this is expressly authorized by the relevant organization and permitted by applicable law.

5. How We Share Information

We share information only as necessary to operate, secure, support, and improve the Services, or where required or permitted by law.

5.1. Within an organization

Authorized users may access information according to their assigned roles, permissions, and branch scope.

Patient and customer information is intended to remain within the organization that controls it, subject to authorized integrations and applicable law.

5.2. Service providers

We may use third-party providers for services such as:

  • Cloud infrastructure and databases
  • Backups and storage
  • Monitoring and logging
  • Authentication and security
  • Payment processing
  • Email and notifications
  • Customer support
  • Error monitoring
  • AI or machine-learning infrastructure where applicable

Service providers receive only the access reasonably necessary to provide their services and are subject to appropriate contractual, confidentiality, and security obligations.

Where Terralis processes patient health information as a Data Processor, such providers are engaged in accordance with the applicable Data Processing Agreement and applicable law.

We may disclose information where reasonably necessary to:

  • Comply with applicable law or legal process
  • Respond to lawful requests from authorities
  • Protect the rights, safety, and security of users, organizations, or the public
  • Detect, prevent, or investigate fraud, abuse, or security incidents
  • Enforce our agreements

We do not rent or sell personal information to data brokers.

6. Data Security

We use administrative, technical, and organizational measures appropriate to the sensitivity of the information processed through the Services.

These may include:

  • Encryption in transit using HTTPS/TLS
  • Encryption at rest where supported by the relevant infrastructure
  • Role- and organization-scoped access controls
  • Branch-level permissions where applicable
  • Authentication and access controls
  • Audit and security logging
  • Monitoring for unauthorized access and abuse
  • Backup and recovery procedures

No online service can be guaranteed to be completely secure.

Users and organizations are responsible for protecting their credentials, devices, and access to the Services and should report suspected unauthorized access promptly.

7. Data Retention

We retain information for as long as reasonably necessary to:

  • Provide the Services
  • Maintain accounts and business records
  • Meet contractual obligations
  • Comply with applicable legal or regulatory requirements
  • Resolve disputes
  • Prevent fraud and abuse
  • Maintain appropriate audit and security records

For patient and customer health-related information processed on behalf of an organization, retention is generally determined by the organization in accordance with its instructions, the applicable Data Processing Agreement, and applicable record-retention requirements.

Some information may need to be retained after an account is closed where required by law, for legitimate security purposes, or to establish, exercise, or defend legal claims.

8. Data Subject Rights

Your rights depend on the type of information involved and the applicable law.

8.1. Terralis account information

Where Terralis is the Data Controller, you may have rights to request access to, correction of, or deletion of your personal information, subject to applicable legal exceptions.

8.2. Patient and customer information

Where an organization is the Data Controller for your patient or customer information, requests concerning that information should generally be directed to the relevant organization.

Terralis may assist the organization in responding to valid requests where required under the applicable Data Processing Agreement.

Depending on applicable law, data subjects may have rights relating to access, correction, objection, restriction, portability, or deletion.

9. Children’s Privacy

Terralis accounts are not directed to children under 18, and we do not knowingly create accounts for children.

This does not prevent healthcare organizations from processing information about pediatric patients where permitted and required for legitimate healthcare or pharmacy purposes. Such information is handled according to the applicable organization’s responsibilities, this Policy, the applicable Data Processing Agreement, and applicable law.

10. International Data Transfers

Terralis may use cloud and service providers located outside Ghana. As a result, information may be stored or processed outside the country where it was collected.

Where information is transferred internationally, Terralis will use appropriate contractual, technical, organizational, or other safeguards required by applicable law.

The infrastructure providers and processing locations used by Terralis may change as the Services evolve. Where required, we will provide appropriate notice and update this Policy.

11. Ghana Data Protection

Terralis is being developed for use in Ghana and is designed with the requirements of Ghana’s Data Protection Act, 2012 (Act 843), and the role of the Data Protection Commission, in mind.

Where applicable, organizations using Terralis remain responsible for their obligations as Data Controllers, including determining the lawful basis for processing personal data, providing appropriate notices, obtaining required consent, and responding to data-subject requests.

Terralis will maintain appropriate processor arrangements and safeguards for personal information processed on behalf of customer organizations.

Any regulatory registration, certification, or authorization held by Terralis will be stated separately and accurately. We do not claim completed regulatory registration until it has been confirmed.

12. Your Responsibilities

If you use Terralis on behalf of an organization, you are responsible for:

  • Ensuring you are authorized to access the organization’s information.
  • Following your organization’s privacy and security policies.
  • Entering information accurately.
  • Using patient and customer information only for authorized purposes.
  • Protecting your credentials and devices.
  • Reporting suspected privacy or security incidents promptly.

13. Changes to This Policy

We may update this Privacy Policy as the Services, laws, infrastructure, or data-processing practices change.

We will update the “updated” date at the beginning of this Policy. Where changes are material and applicable law requires additional notice, we will provide that notice through appropriate channels.

14. Contact

Privacy questions, data requests, or concerns should be directed to:

Terralis
Email: support@terralis.tech