Security and privacy
Built for the most sensitive data there is.
What we do to protect pharmacy data, and what we have not done yet.
Where data lives
We intend to host PRAESI Pharmacy OS in the European Union. The storage and error-reporting services it can use accept EU regions only and are switched off by default. The hosting provider for real pharmacy data has not yet been finally approved.
No health data in analytics
The product has no advertising or third-party analytics. Error reports, when switched on, go to an EU-hosted service and are rebuilt from an allow-list, so they carry no names, medicines, prescription details or IP addresses.
GDPR: who is responsible
- The pharmacy is the controller of its customers' and patients' data.
- PRAESI TECHNOLOGIES LTD acts as processor, under a written data processing agreement.
- No real patient data is processed until the pharmacy has signed a data-protection impact assessment and a processing agreement, and an independent security review is complete.
Safeguards built in
- Each pharmacy's data is kept separate, and every request is checked on the server.
- Short sign-in sessions, and a lost device can be signed out.
- Work saved on a phone while offline is encrypted.
- Backups are encrypted before they leave the system.
- An append-only audit trail records who did what, and why.
- Customer and prescription identifiers are shortened or masked on screen by default.
The pharmacist stays in charge
PRAESI does not make clinical decisions. It never uses automated or AI suggestions for clinical advice, dosing, substitution or dispensing, and it never bypasses a permission.
What we do not claim
- We hold no security or quality certification today, such as ISO 27001, and claim none.
- An independent security review and a penetration test are planned before any real data is used.
- GESY and KOEF connections: not yet approved; our requests are being submitted.
Report a security issue
Write to mstefanou@praesi.ai. Please do not include any patient information.