Privacy Policy

Effective June 1, 2026

Teliyadu ("we", "us", "our") operates DosePoint, a cloud-based pharmacy management platform. This Privacy Policy explains what personal data we collect across all features of DosePoint, why we collect it, how we use and protect it, and the rights available to you. Please read it carefully.

1. Who This Policy Covers

This policy applies to all individuals whose data is processed through DosePoint:

  • Pharmacy account holders. the organisation or individual who signs up for an DosePoint subscription, including multi-branch and enterprise accounts.
  • Pharmacy staff. administrators, pharmacists, pharmacy technicians, cashiers, and other personnel granted role-based access to the dashboard.
  • Patients. individuals whose patient, prescription, dispensing, billing, or communication records are managed within DosePoint, including users of the patient web portal.
  • Patient family members. guardians and family members linked to a patient record where the pharmacy enables dependent management.
  • Corporate account holders. employers or insurers who fund pharmacy care for employees and whose billing or coverage data is processed within DosePoint.
  • Configured integration users. authorised people and systems that use an integration explicitly implemented and enabled for a pharmacy.
  • Website visitors. anyone who browses dosepoint.co without creating an account.

2. Data We Collect

2.1 Pharmacy & organisation account data

Pharmacy name, branch locations (for multi-branch accounts), subdomain, billing address, tax identification number, contact name, email, and phone. Subscription plan, billing cycle, and payment method metadata (processed by Stripe or Chapa . we never store raw card or bank account numbers).

2.2 Staff account data

Full name, email address, phone number, role, assigned branch(es), profile photo (optional), hashed password, session tokens, login history, IP addresses, and device information. Staff scheduling data including working hours, leave records, and shift assignments. Payroll-relevant data where payroll integration is enabled (salary grade, bank details) . this data is encrypted at rest and access is restricted to Admin role users.

2.3 Patient demographic & contact data

Full name, date of birth, gender, nationality, phone number(s), email address, residential address, emergency contact details, patient photograph (optional), patient ID or national ID number (where required by local regulation), preferred language, and communication preferences (SMS, email, WhatsApp, push notification).

2.4 Patient health and medication data

This is the most sensitive category of data we process. It includes: medical and medication history, known allergies, current medications and recorded conditions; prescription records (including the prescriber named on an external order); dispensing records covering what was verified, what was handed over, and the batch and expiry drawn from; controlled-substance register entries; insurance policy and claim details; and documents uploaded against a patient record, such as prescriptions and lab results.

2.5 Document data

Uploaded prescriptions, identification documents, insurance records, supplier documents, and other files that staff attach to supported records. Files are stored on AWS S3 with server-side encryption and tenant-scoped access.

2.6 Guardian and dependent data

Where dependent records are enabled, we may store a guardian's name, relationship, contact information, and authority alongside the patient record.

2.7 Prescription and dispensing data

Medication-order source and status, attributable prescriber identity, verification evidence, dispensing events, reversals, refill projection, and the batch and expiry used for handover.

2.8 Financial & insurance data

Invoices, medication or service line items, payment records, partial-payment allocations, outstanding balances, patient credits, daily cash closing, insurance claims, and corporate-account billing data.

2.9 Communication data

Configured SMS messages and replies, email communications, push-notification delivery records, and available delivery status. The channels and providers used depend on the pharmacy's configuration and market.

2.11 Remote-care data

DosePoint does not provide synchronous remote-care sessions and does not collect media-session recordings or metadata.

2.12 Inventory & procurement data

Pharmacy supply items, stock levels, usage logs, low-stock alert history, purchase orders, supplier names and contact details, and delivery records where the procurement module is used.

2.13 Survey & feedback data

Patient feedback and free-text responses submitted through enabled feedback workflows. Access is limited according to role and tenant.

2.14 API & integration data

Integration endpoint configuration, event logs, and minimum-necessary payload metadata for implemented integrations. Secrets are stored hashed or in a secrets manager and raw health payloads are not retained for general analytics.

2.15 Usage & analytics data

Server access logs, application error reports (via Sentry), infrastructure telemetry (via Better Stack), feature interaction events (page views, button clicks, report generation), and performance metrics. This data does not include the content of clinical records but may include metadata such as user access records, which are also recorded as audit log entries.

2.16 Website visitor data

Server logs including IP address, referrer, browser, and pages visited on dosepoint.co. Demo request form submissions (name, email, pharmacy details). Microsoft Clarity captures marketing-site usage data such as page interactions, heatmaps, and session replay to improve the website. We do not use advertising networks or retargeting pixels.

3. Lawful Basis for Processing

We process personal data on the following legal bases:

  • Contract performance. processing necessary to deliver the DosePoint service to pharmacy account holders and their staff.
  • Legitimate interests. security monitoring, fraud prevention, product improvement, and aggregated analytics, where these do not override individual rights.
  • Legal obligation. compliance with applicable law, including health data regulations, tax requirements, and court orders.
  • Consent. optional marketing communications to website visitors and other non-essential communication channels where opt-in is required.
  • Vital interests. in exceptional circumstances where health data must be disclosed to protect a patient's life.

For special category health data (clinical records, medical history, imaging), processing is based on Article 9(2)(h) GDPR (healthcare provision) and equivalent provisions under applicable national law. The pharmacy, as data controller, is responsible for establishing and documenting the patient's consent for the creation of health records.

4. How We Use Your Data

  • To create and manage pharmacy accounts, staff profiles, and patient records.
  • To authenticate users, maintain sessions, and enforce role-based access controls across all branches.
  • To support formulary, prescription intake, pharmacist verification, dispensing, recalls, and medication counselling.
  • To send refill reminders, collection notices, recall notices, and two-way messages through the pharmacy's configured channels.
  • To run patient marketing campaigns and loyalty programmes on behalf of the pharmacy, where the pharmacy has obtained patient consent.
  • To generate pharmacy reports including daily cash closing, outstanding balances, dispensing volume, controlled registers, inventory, expiry exposure, and procurement.
  • To process subscription payments (Stripe) and pharmacy-to-patient payments (Chapa).
  • To facilitate insurance billing, pre-authorisation, and claim tracking.
  • To support secure messages between pharmacy staff and patients where enabled.
  • To serve the patient web portal with the patient's own records, balances, documents, education, and messages where enabled.
  • To process API requests from authorised third-party integrations on behalf of the pharmacy.
  • To diagnose errors, monitor uptime, and improve platform performance.
  • To respond to support requests.
  • To comply with applicable law and respond to lawful legal requests.

We do not sell your data. We do not use patient health data to train models operated by Teliyadu or any third party, and DosePoint does not send patient data to generative-model providers.

5. Tenant Isolation & Multi-Branch Data Separation

Each pharmacy organisation's data is stored in a dedicated PostgreSQL schema, entirely separate from every other pharmacy on the platform. This is enforced at the database level . there is no shared table with a pharmacy identifier column that could be bypassed by an application bug. Middleware on every API request verifies the pharmacy's subdomain and activates the correct schema before any query runs.

For multi-branch organisations, all branches share a single tenant schema owned by the organisation. Branch-level data segregation within the schema is enforced by the application's RBAC layer . staff assigned to Branch A cannot view Branch B's patient records or financials unless granted explicit cross-branch permissions by the organisation's Admin.

Teliyadu platform staff access tenant data only for authorised support operations, require internal approval for each access event, and every access is immutably audit-logged with the reason and the approving manager.

6. Data Retention

We retain different categories of data for different periods:

  • Active clinical records . retained for the life of the subscription. Pharmacies control record-level deletion within their account.
  • Closed pharmacy accounts . data is held for 30 days after account closure to allow export, then permanently and irreversibly deleted, including all backups that fall within the deletion window.
  • Audit logs . retained for 7 years to meet healthcare regulatory requirements in the jurisdictions we operate in.
  • Financial records . invoices, payment records, and tax-relevant data are retained for 7 years from the transaction date.
  • Communication logs . SMS, email, and push notification delivery records retained for 2 years.
  • Temporary processing artifacts . retained only for the operational period required by the implemented workflow and then deleted according to documented retention rules.
  • Message and notification delivery metadata . retained according to the pharmacy agreement and applicable operational requirements.
  • Implemented integration event metadata . retained for 90 days unless the applicable agreement specifies otherwise.
  • Server & access logs . retained for 90 days.
  • Database backups . automated daily snapshots retained for 30 days, then purged.
  • Anonymised aggregated analytics . may be retained indefinitely; they contain no personal identifiers.

7. Third-Party Sub-Processors

We engage the following sub-processors. Each is bound by a data processing agreement and processes data only as instructed by Teliyadu.

  • Amazon Web Services (AWS) . cloud infrastructure (eu-central-1, Frankfurt): ECS (compute), RDS PostgreSQL (database), ElastiCache Redis (caching/queuing), S3 (file storage), SNS (SMS), SES (email), CloudFront (CDN), CloudWatch (infrastructure monitoring), Secrets Manager (credential storage).
  • Stripe . SaaS subscription billing and payment card processing. Stripe is PCI-DSS Level 1 certified. We receive tokenised payment references only.
  • Chapa · pharmacy-to-patient payment processing where that integration is configured and commercially available.
  • Firebase (Google) . push-notification delivery where the configured web channel uses Firebase.
  • Sentry . real-time application error monitoring. Error payloads are scrubbed to remove patient identifiers before transmission.
  • Better Stack . uptime monitoring, log aggregation, and on-call alerting. Infrastructure-level logs only; no patient record content.
  • Twilio / AWS SNS . configured SMS delivery for refill, collection, recall, and patient communication.

We publish an up-to-date sub-processor list at dosepoint.co/security. We will provide 30 days' notice before adding a new sub-processor that processes health data.

8. International Data Transfers

All primary data storage and processing occurs in Frankfurt, Germany (AWS eu-central-1), within the European Economic Area. Some sub-processors (Stripe, Sentry, Firebase, AI inference) may process data in the United States or other countries. Where data is transferred outside the EEA, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Adequacy decisions where applicable.
  • Binding Corporate Rules where the sub-processor has published them.

Pharmacies operating under Ethiopian law: DosePoint is designed to comply with Ethiopia's Computer Crime Proclamation (No. 958/2016) and the relevant provisions of the Ethiopian Health Sector Transformation Plan regarding patient data confidentiality. We continue to monitor the development of a dedicated health data protection framework in Ethiopia and will update our practices as legislation evolves.

10. Patient Communication & Marketing

DosePoint can communicate with patients for refill, collection, recall, counselling, account, and opted-in marketing purposes. The pharmacy is responsible for:

  • Obtaining and recording patient opt-in consent before sending marketing communications.
  • Honouring opt-out requests promptly . DosePoint provides a one-click unsubscribe mechanism for email campaigns and automatic opt-out handling for SMS STOP replies.
  • Ensuring marketing content complies with applicable laws (including Ethiopia's commercial communications regulations and GDPR where applicable).

Teliyadu does not send marketing communications to patients on its own behalf. All patient-facing messages are sent by the pharmacy through DosePoint, with the pharmacy's name and contact information visible to the recipient.

11. Your Rights

Depending on your jurisdiction, you may have the following rights over your personal data:

  • Access. obtain a copy of the personal data we hold about you.
  • Rectification. correct inaccurate or incomplete data.
  • Erasure. request deletion of your data where we have no overriding legal basis to retain it.
  • Restriction. ask us to limit how we use your data while a dispute is resolved.
  • Portability. receive your data in a structured, machine-readable format (JSON or CSV).
  • Objection. object to processing based on legitimate interests.
  • Withdraw consent. where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
  • Lodge a complaint. you have the right to complain to your local data protection authority.

Patients should direct data rights requests to their pharmacy first . the pharmacy is the data controller for clinical records. If the pharmacy cannot fulfil the request, patients may contact us at support@dosepoint.co.

Pharmacy staff and account holders may exercise rights over their own account data by emailing support@dosepoint.co. We will respond within 30 days.

12. Cookies & Tracking

DosePoint dashboard: A single session cookie is set on login for authentication. No third-party cookies are set by the dashboard application.

Patient web portal: uses a tenant-bound authenticated session and does not include advertising SDKs.

Marketing site (dosepoint.co): We use essential cookies for locale preference and CSRF protection, and Microsoft Clarity analytics cookies to understand aggregate site usage, heatmaps, and session replay. We do not use advertising networks or retargeting pixels.

Tenant-bound intake links: supported intake pages may use a session cookie to protect the submission flow. They do not set advertising cookies on the referring site.

13. Children's Data

DosePoint is not directed at children as end users. Minors appear as patients in clinical records under the authority of their treating pharmacy and the consent of their legal guardian. Paediatric patient records are flagged in the system and access is restricted to clinical staff. Guardians may request access to or deletion of their child's records by contacting the pharmacy.

Patient web-portal accounts follow the age, guardian-authority, and consent requirements configured by the responsible pharmacy and applicable law.

14. Corporate & Insurance Account Data

Where a corporate employer or insurance provider is linked to a pharmacy's account, we process the corporate entity's name, contact details, and the list of covered individuals (name, employee/policy ID, coverage tier). This data is visible only to the pharmacy's Admin role and to the corporate account holder's designated contact. Individual employees' health records remain confidential to the treating pharmacy and are not shared with the employer. Minimum-necessary medication and billing data may be shared with the insurer as part of the claims process, consistent with the patient's consent and applicable law.

15. Changes to This Policy

We will notify pharmacy account holders by email at least 14 days before any material changes to this policy take effect. Minor clarifications (grammar, formatting, new examples that do not change meaning) may be made without notice. The current version of this policy is always available at dosepoint.co/privacy with the effective date shown at the top.

16. Contact & Data Protection Enquiries

For questions about this policy, data rights requests, or security concerns:

Email: support@dosepoint.co

Subject line: "Privacy" or "Data Rights Request"

We aim to acknowledge all privacy enquiries within 48 hours and resolve them within 30 days.

Last updated: Effective June 1, 2026