PhIX Privacy Policy
Privacy Policy
Effective date: November 1, 2025
This Privacy Policy explains how PharmaSafe – PhIX (“PharmaSafe“, “PhIX“, “we“, “us“, or “our“) collects, uses, discloses, and protects information when you visit our website and when you use the PhIX platform and related services (the “Services“).
We are committed to protecting privacy and safeguarding information in compliance with Alberta’s Health Information Act (HIA) and other applicable privacy laws and standards. This Policy is meant to be clear and practical for pharmacy teams, licensees, and users.
Quick Summary (TL;DR)
We collect account, business, usage, and support information to operate the website and the PhIX platform.
Health‑related information in PhIX is handled on behalf of custodians (pharmacies/licensees) and is de‑identified for safety learning and required reporting where possible.
We may share de‑identified incident data with ISMP Canada/NIDR and relevant regulators as required or permitted by law and standards (e.g., ACP).
Data is stored in Canada where feasible and protected with administrative, technical, and physical safeguards.
You can access or correct your account information and can contact us about privacy at phix@pharmasafe.ca or 1‑888‑581‑9008.
Who We Are & Roles
PharmaSafe provides software and services that support quality improvement and incident learning in pharmacies. For website visitors and PhIX account users, we act as a service provider for participating pharmacies. For health information entered into PhIX (e.g., details about medication incidents or close calls), the pharmacy/licensee is the “custodian” under the HIA and PharmaSafe acts as a “affiliate/service provider” processing that information on the custodian’s documented instructions.
Where this Policy says “you”, it refers to website visitors, PhIX users, and pharmacy personnel who interact with the Services.
Scope
This Policy covers:
Our public website pages and forms.
The PhIX web application and related support channels.
Communications and materials you send us (e.g., help tickets, emails).
This Policy does not override any service agreements, data processing terms, or custodian policies that may apply to a participating pharmacy. If there is a conflict, written agreements with the custodian take precedence for health information handling.
Information We Collect
1) Website & Account Information
Identity & contact: name, role, work email, phone, employer/pharmacy.
Account credentials: login identifiers, role/permissions, authentication logs.
Business details: pharmacy license number, address, ACP/NIDR configuration.
Communication: inquiries, feedback, and support correspondence.
2) Platform/Operational Data
Usage & device: IP address, browser type/version, OS, pages/features used, timestamps, diagnostic logs.
Cookies & similar tech: strictly necessary cookies; with your consent, optional analytics cookies. (See Cookies & Analytics below.)
3) Health‑Related Information (PhIX)
Incident/CQI+ records input by pharmacy teams (e.g., incident type, contributing factors, corrective actions, location/time context, product details).
Free‑text narratives and attachments provided by users.
Reporter/team metadata (e.g., role, site) for quality and accountability.
Minimization & De‑identification: PhIX is designed to
(a) avoid direct identifiers of patients and staff
(b) support de‑identification and the capture of safely shareable fields for learning and reporting.
We ask users not to include unnecessary direct identifiers in free‑text fields.
How We Use Information
We use information to:
Provide and secure the Services (authentication, role‑based access, logging, uptime, troubleshooting, fraud/security monitoring).
Support CQI++ workflows in participating pharmacies (incident capture, review, learning, and corrective action tracking) in accordance with custodian instructions and applicable standards.
Generate analytics & insights using de‑identified or aggregated data to improve safety and platform performance.
Meet obligations related to reporting and oversight (e.g., NIDR submissions where required by ACP; responding to lawful requests).
Communicate with users (service messages, updates, training, and support).
We rely on consent, contracts with custodians, and legal permissions under the HIA and other applicable laws as the appropriate legal bases for these purposes.
Sharing & Disclosure
We may disclose information as follows:
On behalf of custodians to fulfill CQI+ and regulatory requirements, including de‑identified submissions to ISMP Canada’s National Incident Data Repository (NIDR) and other required recipients.
Service providers/sub‑processors that support hosting, security, email delivery, and analytics—bound by confidentiality and data protection obligations.
Regulatory or legal disclosures when required or permitted by law, including cooperating with oversight authorities and responding to lawful requests.
Business transfers (e.g., merger, acquisition) where safeguards and notice are provided as required by law.
We do not sell personal information.
Data Location & Transfers
We seek to store and process data in Canada wherever feasible. If limited functions require processing outside Canada (e.g., certain email or incident response tools), we will use safeguards such as contractual protections and access controls, and we will inform custodians as appropriate.
Retention
Account & operational data: kept while your organization uses the Services and for a reasonable period thereafter (typically up to 24 months) to maintain records, resolve disputes, and meet legal requirements.
Incident/CQI+ records: retention is primarily determined by the custodian and applicable ACP/legislative requirements. We retain copies only as necessary to provide the Services, for audit/security, or as required by law or contract.
We apply data minimization, and when information is no longer needed, we take steps to securely delete or de‑identify it.
Security
We implement layered administrative, technical, and physical safeguards, such as:
Role‑based access controls (RBAC) and authentication protections (e.g., MFA availability).
Encryption in transit and at rest for sensitive data where applicable.
Network security, logging, and intrusion detection.
Secure development lifecycle and vulnerability management.
Workforce privacy and security training.
No system is perfectly secure; we continually improve controls and monitor for threats.
Cookies & Analytics
Necessary cookies enable core features (e.g., login sessions, security). You cannot opt out of these and still use the platform.
Analytics cookies (website): used to understand visits and improve usability. Where required, we seek your consent and provide controls to opt out.
Do Not Track: our response may vary based on browser and technology support.
You can adjust cookie settings in your browser and via any in‑product controls we provide.
Individual Rights
Depending on your role and applicable law, you may have rights to access, correct, or request deletion of certain information. For health information in PhIX, please contact the pharmacy/licensee (custodian) first. For website or account data we control, contact us directly (see Contact Us below).
We will assist custodians in responding to privacy requests concerning health information processed on their behalf.
Children’s Privacy
Our Services are intended for professional use by pharmacy teams and are not directed to children.
Third‑Party Links
Our website may link to third‑party sites or resources we do not control. Their privacy practices are governed by their own policies.
Privacy Impact Assessment (PIA)
PharmaSafe prepares and maintains a Privacy Impact Assessment appropriate to the Services and assists participating custodians with information needed for their obligations under Alberta’s OIPC processes. Summary information may be available upon request.
Changes to This Policy
We may update this Policy from time to time. The “Effective date” at the top indicates when the latest changes took effect. Material changes will be communicated through the website or in‑product notices.
Contact Us
PharmaSafe – PhIX
Email: phix@pharmasafe.ca
Phone: 1‑888‑581‑9008
If you have questions, concerns, or feedback about privacy or security, please contact us. We will respond promptly and work with custodians and regulators as appropriate.
