Privacy Policy
Effective date: July 1, 2026 · Last updated: July 1, 2026
1. Introduction
PharmAlliance Group, LLC, doing business as PharmAlliance AI Solutions (“PharmAiVA,” “we,” “our,” or “us”), respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you visit our website at pharmaiva.app, hold a PharmAiVA account, interact with us, or use the PharmAiVA service (the “Service”).
Two important scope notes. First, when you use the Service on behalf of your employer or another organization, that organization is the controller of the personal data processed through the Service. We process such data as a processor on the organization’s behalf, governed by our Data Processing Addendum (DPA) with that organization. This Privacy Policy does not describe that processing; please consult your organization’s privacy notice. Second, when you visit our website, contact us, hold an account, or apply for a position with us, we act as a controller of your personal data, and this Privacy Policy describes how we handle it.
2. Personal data we collect
Data you provide directly. Account information such as your name, business email address, job title, organization affiliation, and password (stored only as a cryptographic hash) — accounts are provisioned by invitation, so we may receive your business contact details from the organization that invites you. Billing information such as billing contact name, address, and tax identifiers, collected from your organization for invoicing; if card payments are offered in the future, card details would be collected and processed by a payment processor (such as Stripe, Inc.) and would not be stored on PharmAiVA systems. Content you submit to the Service, such as brand names, queries, documents, notes, and settings (where you act on behalf of a customer organization, this content is governed by our agreement with that organization rather than this Privacy Policy). Support correspondence, demo requests and marketing sign-ups, and job application data.
Data collected automatically. Usage data (pages viewed, features used, actions taken, timestamps, referrer URLs); device and connection data (IP address, browser type and version, operating system, language settings, time zone); cookies as described in Section 6; and server and application logs, including error reports, security events, and audit records.
Data from third parties. Publicly available information from regulatory authorities (FDA, Health Canada, MHRA, EMA) and pharmaceutical-industry sources, used to populate the Service’s analytical features. This data generally does not include personal data.
3. How we use personal data
We use personal data to:
- provide and operate the Service, including account provisioning, authentication, and support;
- bill and collect fees, including issuing invoices and processing payments;
- communicate with you about your account, product updates, security alerts, and administrative matters;
- respond to demo requests and market our products, subject to your choices and applicable law;
- analyze and improve the Service, including aggregate usage analytics, debugging, and performance optimization;
- keep the Service secure, detect and prevent fraud and abuse, and enforce our terms;
- comply with legal and regulatory obligations; and
- recruit and evaluate job applicants.
4. Legal bases for processing (GDPR / UK GDPR)
Where the EU GDPR or UK GDPR applies, we rely on: performance of a contract (Art. 6(1)(b)) for providing the Service and billing; legitimate interests (Art. 6(1)(f)) for support, product analytics, security, fraud prevention, strictly necessary cookies, and direct marketing to business contacts (subject to opt-out, and consent where required); legal obligation (Art. 6(1)(c)) for compliance; and pre-contractual measures or legitimate interests for recruitment. You have the right to object to processing based on legitimate interests — see Section 8.
5. How we share personal data
We do not sell personal data. We share personal data only as described below.
Service providers. We share personal data with third parties that help us operate the Service, including Microsoft Corporation (Azure — cloud hosting and database infrastructure in the United States), Resend, Inc. (transactional email delivery), and, if and when card payments are offered, a payment processor such as Stripe, Inc. A current list of sub-processors is available on request from privacy@pharmaiva.app.
Third-party AI platforms. The core function of the Service is to send analytical queries to third-party generative AI platforms and evaluate their responses. Queries generated from customer-configured brand and market settings are transmitted to the AI platforms enabled for the analysis, which may include OpenAI, Anthropic, Google, Microsoft, xAI, Meta Llama (served via Groq, Inc.), Perplexity, DeepSeek, and Serper.dev (for Google AI Overviews / AI search results). These queries are designed to contain brand, product, and market information rather than personal data. These platforms operate under their own terms and privacy policies. DeepSeek processes data in the People’s Republic of China; a customer organization that considers this a concern may disable the DeepSeek platform for its analyses.
Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred to the successor entity subject to this Privacy Policy or an equally protective notice.
Legal requirements. We may disclose personal data to comply with a lawful court order, subpoena, or other legal obligation; to enforce our terms; to protect our rights, property, or safety, or those of our customers or the public; or to cooperate with law enforcement. Where legally permitted, we will notify affected individuals or customers before making such disclosures.
With your consent. We may share personal data for other purposes with your consent.
6. Cookies
The Service and website use only strictly necessary cookies — those required for authentication, session management, and security (for example, sign-in session cookies and cross-site request forgery protection). We do not use advertising cookies, and we do not run third-party analytics or tracking scripts on the website or in the Service. If that changes, we will update this policy and, where required, obtain consent before setting non-essential cookies. You can manage or delete cookies through your browser settings; disabling strictly necessary cookies will prevent you from signing in.
7. International data transfers
PharmAiVA is headquartered in the United States and hosts the Service on infrastructure located in the United States. If you access the Service from outside the United States, your personal data will be transferred to and processed in the United States. Where the GDPR, UK GDPR, or Swiss FADP applies to a transfer, we rely on appropriate safeguards, including the EU Commission Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and supplementary measures described in our DPA. Copies of the relevant transfer safeguards are available on request from privacy@pharmaiva.app.
8. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or port personal data we hold about you as a controller; to object to processing based on legitimate interests, including direct marketing; to withdraw consent where processing is based on consent; and to lodge a complaint with your local supervisory authority.
Residents of California, Colorado, Connecticut, Utah, Virginia, and other US states with comprehensive privacy laws may have additional rights, including the right to opt out of “sales” or “sharing” of personal data. PharmAiVA does not sell or share personal data within the meaning of those laws. To exercise any rights, contact privacy@pharmaiva.app. We will respond within the time required by applicable law. We may need to verify your identity before responding to a rights request. California residents may use an authorized agent to submit requests; we may require written authorization and verification of the agent’s identity.
9. Data retention
We retain personal data only as long as necessary to fulfill the purposes described in this Privacy Policy, to comply with legal obligations, to resolve disputes, and to enforce our agreements. Account data is retained for the duration of the account relationship plus a reasonable period to handle post-termination needs; billing and tax records for seven (7) years or as required by applicable tax law; Service audit logs per the customer organization’s subscription terms unless a longer retention is required by law; marketing data until you opt out or request deletion; and job applicant data for up to twelve (12) months after the position is filled or the application is rejected, unless you consent to longer retention.
10. Data security
We implement administrative, technical, and physical safeguards designed to protect personal data, including encryption in transit (TLS 1.2+), encryption at rest, AES-256-GCM encryption of stored third-party API credentials, role-based access controls, audit logging, rate limiting, and an incident-response process. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
11. Children's privacy
The Service is not directed to children under sixteen (16) years of age. We do not knowingly collect personal data from children. If we learn we have collected personal data from a child, we will delete it.
12. Automated decision-making
We do not use personal data for automated decision-making that produces legal or similarly significant effects on individuals within the meaning of Article 22 of the GDPR.
13. California “Shine the Light” and Do Not Track
California residents may request information about certain sharing of personal data with third parties for their direct marketing purposes. PharmAiVA does not share personal data with third parties for their own direct marketing. We do not respond to Do-Not-Track signals because there is currently no uniform industry standard.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to account holders or by in-app notification at least thirty (30) days before taking effect. The “Last updated” date at the top of this policy indicates when it was last revised.
15. Contact us
For privacy questions, rights requests, or complaints, contact PharmAlliance Group, LLC (dba PharmAlliance AI Solutions) at privacy@pharmaiva.app. If you are unsatisfied with our response to a privacy request, you have the right to lodge a complaint with your local supervisory authority. A list of EU supervisory authorities is available at edpb.europa.eu. UK residents may contact the Information Commissioner’s Office at ico.org.uk.