Privacy policy
This policy covers two distinct processing activities: the apotheca.ma marketing site, and the Apotheca application used by pharmacies. The roles and responsibilities differ between them, so they are addressed separately.
Data controller
The controller for data collected on https://apotheca.ma is:
- BuildOdyscy SARL
- 332, BD Brahim Roudani, étage 5, appt 21, Résidence Rayhane, quartier Maârif, Casablanca, Maroc
- ICE 003993346000008 - RC Casablanca 738383
- [email protected]
No data protection officer has been appointed to date. Requests concerning personal data are handled by the publisher at the address above.
Part A - The apotheca.ma website
This part describes what happens when you browse the marketing site, complete the contact form or request a demonstration. BuildOdyscy SARL acts here as the data controller.
Data collected
The site is fully static and carries no analytics tool, no advertising tracker and no social media widget. The only data you send us is what you type yourself:
- Contact form: full name, pharmacy name, email address, phone number, the content of your message.
- Demo request: the same fields, plus your city and the number of pharmacies you run.
- Technical context of the submission: the site language and the page the form was sent from, so we can reply in the right language and with the right context.
To this is added the technical data inherent to browsing any website: your IP address and the characteristics of your request appear in the server logs and in those of our content delivery provider. Your IP address is also held briefly in a technical cache to limit the number of form submissions per hour and block automated abuse.
The forms are also protected by Cloudflare Turnstile, an anti-robot check. On submission it passes Cloudflare your IP address and technical signals from your browser, in order to tell a person apart from an automated client. The check does not try to identify you and does not follow you from one site to another; what it does about cookies is described on the Cookies page.
Purposes and legal bases
- Answering your enquiry, arranging a demonstration, preparing a quote - on the basis of your own approach to us and our legitimate interest in responding to a commercial enquiry.
- Keeping the site secure and available (logging, rate limiting, bot filtering) - legitimate interest.
- Meeting our legal and accounting obligations - legal obligation.
We do not use this data for unsolicited marketing, we do not sell it and we do not rent it.
Recipients
Your message is recorded in our internal enquiry tracker and notified by email to the Apotheca team. The only third parties involved are Cloudflare, for network delivery, security and the anti-robot check, and ZeptoMail (Zoho Corporation), which carries that email. The detail is on the Subprocessors page.
Retention
Enquiries received through the forms are kept for twenty-four (24) months from our last exchange with you and then deleted, unless a contractual relationship has begun - in which case they follow the retention period applicable to that contract. Technical logs are kept for at most twelve (12) months. The anti-abuse counters holding your IP address expire after one hour.
Cookies
Browsing https://apotheca.ma sets no cookies; only the forms' anti-robot check may set two, and only when it has to show a verification. The detail, including for the application, is on the Cookies page.
Part B - The Apotheca application
Who is responsible for what
The Apotheca application is a management tool made available to pharmacies. The data a pharmacy enters into it - its staff, its customers, its sales, its purchases - remains its own: the client pharmacy is the data controller, and BuildOdyscy SARL acts as a processor, on its instructions and within the limits of the agreement signed with it.
One practical consequence follows: if you are the customer of a pharmacy and wish to exercise your rights over data concerning you, the request must go to that pharmacy, which is responsible for it. We assist them; we cannot stand in their place.
BuildOdyscy SARL is, on the other hand, the controller for the data strictly necessary to provide the service: user accounts, login and activity logs, subscription billing and support.
Categories of data processed
- Pharmacy staff accounts: first and last name, username, email address, phone number, date of birth, profile picture, role and permissions, password hash, PIN hash, two-factor authentication settings.
- Pharmacy identity: business name, address, ICE, business licence (patente) number.
- The pharmacy's customers: first and last name, email, phone, address, city, country, customer type, affiliated organisation, deferred account balance and loyalty points.
- Commercial history: sales, returns and refunds, compounded preparations, payments and due dates, linked where applicable to a named customer.
- Colleagues and suppliers: contact details of partner pharmacies, delegates and sales representatives recorded by the pharmacy.
- Connection and audit data: IP address, user agent, device type, browser, operating system, city and country derived from the IP address, whether the attempt succeeded or failed, and an activity log of sensitive actions.
- Staff attendance where the pharmacy enables time tracking.
- Forum contributions: posts, comments, likes, attached images and online presence status.
- Subscription: plan, amount, status, dates and transfer confirmation. No card data is collected: payment is made by bank transfer, outside the application.
Health-related data
The application is not a patient record and holds no scanned prescriptions, medical documents or identity papers: the only uploadable files are images, in three restricted areas (marketplace offers, announcements, forum).
Even so, linking a named customer to the medicines dispensed to them is by its nature data touching on health. Law no. 09-08 subjects such processing to prior authorisation from the CNDP, and the pharmacy, as controller, must complete the formalities incumbent on it for its own records. BuildOdyscy SARL completes those that fall to it as processor and host. None of these formalities is complete as at the date of this page; the receipt numbers will be added here once obtained.
Security measures
The measures actually in place are described without embellishment on the Security page, which also states what is not in place. In short: encrypted transport, bcrypt hashes for passwords and PIN codes, two-factor authentication, session token expiry and revocation, lockout after repeated failures, per-module permissions, a tamper-resistant activity log and request rate limiting.
We do not, as things stand, encrypt individual database columns. We would rather write that down than let it be assumed.
Retention and deletion
A pharmacy's data is kept for the duration of its subscription. On termination it is returned to the pharmacy on request in a usable format, then deleted within the period set out in the agreement.
The application does not currently offer self-service account deletion: deactivating a user revokes their access immediately, and any request for permanent deletion is handled manually on receipt of a message to [email protected]. The activity log, designed to be tamper-resistant, is the exception: its entries can be neither modified nor erased, which is precisely what gives it evidential value.
Sharing between pharmacies
The inter-pharmacy network rests on information a pharmacy chooses to publish: product exchanges, surplus stock, orders placed against marketplace offers. A pharmacy's customer records, its sales and its financial data are never published to the network. Forum contributions and online presence status are, by design, visible to other users.
Transfers outside Morocco
Site and application data is hosted in Germany, within the European Union, with Hetzner Online GmbH. Other providers operate from the United States: Cloudflare for network delivery and security, ZeptoMail (Zoho Corporation) for service emails, and Google for approximate login geolocation. The data concerned, its destination and its purpose are detailed on the Subprocessors page.
Articles 43 and 44 of law no. 09-08 make any transfer of personal data to a foreign country subject to CNDP authorisation. That authorisation has not yet been obtained as at the date of this page; it will be recorded here when it is. Our providers are in any case contractually bound to confidentiality and to security safeguards.
Your rights
Under law no. 09-08 on the protection of individuals with regard to the processing of personal data, you have a right of access, rectification and objection, and the right to withdraw your consent where processing rests on it.
To exercise them, write to [email protected] or [email protected]. We respond within thirty (30) days at most. Proof of identity may be requested where there is reasonable doubt as to who is asking.
If you are the customer of a pharmacy that uses Apotheca, address your request to that pharmacy: its records are its responsibility.
You may at any time lodge a complaint with the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP), www.cndp.ma.
Minors
The site and the application are intended for healthcare professionals and their teams. We do not knowingly collect data concerning minors through them.
Changes to this policy
This policy may change along with our practices, our providers or the regulatory framework. The version in force is the one published on this page, dated at the top. Client pharmacies are notified of substantial changes by email.