Key commitments
At a glance
- Primary pharmacy data at rest is hosted in Sydney
- Tenants are isolated with role-based access and database-level controls
- Your data is not used to train public or shared AI models
- The platform is designed to minimise sensitive clinical data
Where your data lives
- Customer pharmacy data at rest is primarily hosted in Sydney-region cloud infrastructure
- Application processing is configured to run in Sydney
- Document AI processing uses Standard Azure OpenAI deployments in Australia East
- Each pharmacy account is isolated using role-based permissions and database-level access controls, including row-level security
- Data is not shared between pharmacies
Authentication
- User authentication is provided through a third-party identity provider
- Optional multi-factor authentication; MFA is available but not currently mandatory for every account
- Compromised-password detection and account lockout after repeated failed attempts
- Secure session management; PharmStack does not store users’ plaintext passwords
Encryption and secrets
- Information is encrypted in transit using provider-managed TLS
- Integration credentials and provider API keys stored by PharmStack are encrypted using AES-256-GCM
- Staff passcodes are stored using password hashing rather than as readable values
- Pharmacy documents are stored privately and are not exposed through permanent public URLs
How AI is used
- AI-assisted answers are generated from your pharmacy's documents and configured workflows, and are designed to support (not replace) pharmacist judgment
- If something isn’t covered, the system responds cautiously and can prompt verification or escalation, not open-web guessing
- Your data is not used to train public or shared AI models
- AI providers process submitted information only to provide, secure and monitor the service, subject to their contractual retention and abuse-monitoring arrangements
- AI outputs are designed to assist pharmacists and should be reviewed before being relied upon
How we handle overseas vendors
Core pharmacy data is hosted in Sydney-region cloud infrastructure, and document AI processing runs in Australia East. Other providers may process information in the United States, European Union, Singapore, the Philippines, and through global edge or support infrastructure. That processing can include storage, support access, analytics, messaging, authentication, or data in transit, depending on the service.
We use available contractual, organisational, regional, and technical safeguards. Customer contracts may impose tighter residency or provider terms. For provider-level detail, see our Privacy Policy.
Data handling approach
- Designed for pharmacy operational workflows
- Avoids unnecessary sensitive data
- Updates to your documents are reflected in future answers generated from your data
Operational security
- Server-side role and pharmacy-membership checks
- Private document storage with signed access links
- Authenticated and signature-verified webhook handling
- Encrypted third-party credentials
- Short-lived authentication tokens for realtime features
- Feature-specific activity and compliance records
Access and isolation
- Secure access per pharmacy account
- Role-based user permissions within each pharmacy
- Database-level controls, including row-level security, help keep pharmacy accounts separated
- We maintain a data-breach response process aligned with the Notifiable Data Breaches scheme
Built for how pharmacies work
PharmStack is built by pharmacists, for pharmacists. It fits into your existing workflow, without introducing new systems or risk.
Questions?
We're happy to walk through how PharmStack handles your data and how it would work in your store or group.
For legal detail, see our Privacy Policy.