pharcel

Legal

Privacy Policy

Last updated: June 2026

This Privacy Policy is provided as a general template. It describes how pharcel (“pharcel,” “we,” “us”) handles personal information in connection with the pharcel platform at pharcel.ai. Where you are a contracted customer, the signed Master Services Agreement (MSA) and Data Processing Agreement (DPA) govern and control over anything in this document. Please consult those executed agreements for the terms that apply to your organization.

1. Introduction

pharcel provides an AI platform that helps pharmaceutical and life-sciences organizations run commercial, medical affairs, and market-access operations. This policy explains what personal information we collect, why we collect it, how we use and share it, and the rights available to individuals. It applies to our marketing website and to the pharcel platform, except where a customer agreement states otherwise.

In most platform deployments our customer is the controller of the data processed in the service, and pharcel acts as a processor on the customer's behalf and under their documented instructions. For our website and account administration, pharcel acts as a controller.

2. Information We Collect

  • Account and contact data, name, business email, job title, employer, and credentials used to authenticate to the platform.
  • Customer content, data your organization uploads or connects to the service, which may include commercial, targeting, engagement, and, where a customer chooses, clinical or health-related information.
  • Usage and device data, log data, IP address, browser and device identifiers, feature usage, and timestamps generated as you interact with the service.
  • Support and communications, records of your correspondence with our sales, support, and success teams.
  • Cookies and similar technologies , see our Cookie Policy.

3. How We Use Information

  • To provide, operate, secure, and improve the pharcel platform.
  • To authenticate users, administer accounts, and enforce access controls.
  • To provide customer support and respond to requests.
  • To monitor performance, detect and prevent fraud, abuse, and security incidents.
  • To meet legal, regulatory, and contractual obligations, including pharmacovigilance and record-keeping requirements where applicable.
  • To send service and administrative communications, and, with consent where required, relevant product updates.

We do not use customer content to train foundation models for other customers. Where AI features process customer content, that processing occurs to deliver the service to that customer and under their instructions.

4. Legal Bases (GDPR)

Where the EU/UK General Data Protection Regulation applies and pharcel acts as a controller, we rely on one or more of the following legal bases:

  • Contract, to provide the service and administer your account.
  • Legitimate interests, to secure, maintain, and improve the platform, provided your rights do not override those interests.
  • Consent, for non-essential cookies and certain marketing communications, which you may withdraw at any time.
  • Legal obligation, to comply with laws applicable to us.

Where pharcel acts as a processor, the customer is responsible for establishing the legal basis for processing under the DPA.

5. Data Sharing & Sub-processors

We do not sell personal information. We share it only as needed to operate the service and as permitted by the applicable customer agreement:

  • Sub-processors, vetted cloud infrastructure, hosting, model-inference, and analytics providers that process data on our behalf under contractual data-protection terms. A current list is available on request and maintained under the DPA.
  • Professional advisors, auditors, legal, and compliance advisors bound by confidentiality.
  • Legal and safety, where required by law, legal process, or to protect rights, safety, and the integrity of the service.
  • Corporate transactions, in connection with a merger, acquisition, or asset sale, subject to this policy.

6. Data Security

We maintain administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit and at rest, role-based access controls, network isolation, audit logging, least-privilege access, and regular security testing. We maintain an incident-response program and notify affected customers of confirmed security incidents in accordance with the DPA and applicable law. No method of transmission or storage is completely secure.

7. Data Retention

We retain personal information for as long as needed to provide the service and for legitimate business or legal purposes. Customer content is retained per the customer agreement and deleted or returned upon termination as set out in the DPA. Account and log data are retained for the periods required to secure the service and meet our obligations, after which they are deleted or anonymized.

8. International Transfers

pharcel operates globally and may process data in countries other than where you are located. Where we transfer personal information across borders, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary measures where required. Customers may configure regional data residency where the service supports it.

9. Your Rights

Subject to applicable law, you may have the right to access, correct, delete, restrict, or object to the processing of your personal information, to data portability, and to withdraw consent. To exercise these rights, contact us using the details below. Where pharcel processes data as a processor on a customer's behalf, we will refer your request to the relevant customer (controller) and support them in responding.

10. PHI & HIPAA

Where a customer uses the platform to process Protected Health Information (PHI) as defined under the U.S. Health Insurance Portability and Accountability Act (HIPAA), pharcel will act as a Business Associate and enter into a Business Associate Agreement (BAA). PHI is handled only within deployments configured for it and in accordance with the BAA and applicable law. Customers should not upload PHI to environments not covered by an executed BAA.

11. Cookies

We use cookies and similar technologies on our website. Non-essential cookies are opt-in. For details on the categories we use and how to manage them, see our Cookie Policy.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, where changes are material, provide additional notice. Continued use of the service after an update constitutes acceptance of the revised policy.

13. Contact

For privacy questions or to exercise your rights, contact our privacy team at [email protected]. For contractual or legal matters, contact [email protected].