Privacy Policy
How Nutrapi Ltd collects, uses and protects personal data, in line with the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
Last updated: 6 October 2026
1. Who we are
Nutrapi Ltd (“Pharmin”, “we”, “us” or “our”) is the data controller responsible for the personal data described in this policy. We provide software development, communications automation and consultancy services to businesses. We do not sell, supply, prescribe or dispense medications, and we do not provide healthcare or medical services directly.
Our data controller and contact details are:
Nutrapi LtdData Controller: Kieran Walkin
Glasshouse GH2, Dun Laoghaire, Co. Dublin, Ireland
Email: kieran@pharmin.io
Phone: +353 86 782 7399
Company Registration Number (CRO): 721111
2. Scope of this policy
This policy explains how we handle personal data when you visit our website, contact us, or engage our services. It covers data for which Pharmin is the controller — primarily our own website and business contacts.
When we deliver projects for clients (for example operating Pharmin, WhatsApp automations or integrations on their behalf), we typically act as a data processor, processing end-customer data only on the documented instructions of our client, who remains the controller. That processing is governed by a separate Data Processing Agreement with the relevant client, and the client’s own privacy notice applies to their customers.
3. The information we collect
Information you give us
When you complete our contact form or email us, we collect the information you provide — typically your name, email address and the contents of your message. Our contact form is processed on our behalf by Web3Forms, which delivers your submission to us by email.
Information collected automatically
Our hosting provider keeps standard server logs that may include your IP address, browser type, the pages you request and the date and time of access. These are used for security and to keep the website running reliably. Our website uses strictly necessary cookies to function, and analytics cookies only where you consent to them through our cookie banner.
Where you consent through our cookie banner, we use one analytics provider. PostHog (PostHog, Inc., with data hosted in the European Union) provides website analytics — the pages you view and how you navigate — and, where enabled, a session replay in which any text you type into forms is masked and not captured. It does not set a cookie or collect any data until you have given analytics consent, and you can withdraw that consent at any time from the cookie banner.
Pharmacies we contact about our service
We contact registered retail pharmacies in Ireland about Pharmin. For this we use the Pharmaceutical Society of Ireland’s public register of retail pharmacies (trading name, address, phone number, registration number and registered owner — for a sole trader, that is a person’s name), together with the business email address and other business details a pharmacy publishes on its own website. We keep a record of our contact with each pharmacy: our calls and notes, follow-ups we have scheduled, the emails we have sent (the address, subject and date, not the message itself) and whether you have asked us not to contact you.
Links in our emails. Our emails contain no tracking images, and we do not record whether an email was opened. A link in one of our emails, or a link to one of our pages that we send you directly, carries a short code that identifies that email or link. If you follow it and accept analytics cookies in our cookie banner, PostHog records the visit with that code, so we can see that someone came from that email and which of our pages they read. What we see is the time of the visit and the pages read — not who the visitor was, or anything typed into a form. If you decline or ignore the banner, the code is removed from the address bar, sent nowhere, and nothing about the visit is linked to the email.
Information processed for clients
In the course of delivering services we may process personal data belonging to our clients’ customers (for example contact details and message content flowing through WhatsApp, SMS, voice or email channels). We process this data only as a processor, under our client’s instructions, and do not use it for our own purposes.
4. How we use your data and our legal bases
We use personal data for the following purposes, relying on the lawful bases set out in Article 6 GDPR:
- To respond to enquiries you send us — on the basis of our legitimate interest in answering and following up with people who contact us, or to take steps at your request before entering a contract.
- To provide and manage our services to clients — on the basis of performance of a contract.
- To operate and secure our website — on the basis of our legitimate interest in maintaining a safe, functional website.
- To understand how our website is used, including whether a visit came from one of our emails — only with your consent, given in our cookie banner, which you can withdraw at any time.
- To contact pharmacies about our service and keep a record of that contact — on the basis of our legitimate interest in offering our service to the businesses it is built for (business-to-business direct marketing). Every email names us and tells you how to opt out. You can object at any time, free of charge, by replying to the email or contacting us; we will stop and record your request so that it is honoured.
- To comply with legal obligations — for example accounting, tax and record-keeping requirements.
5. Who we share data with
We do not sell your personal data. We share it only with trusted service providers who help us run our business, and only as far as necessary:
- Hosting — our website is hosted by Hostinger, which stores the website and server logs.
- Contact form processing — Web3Forms processes contact-form submissions and forwards them to us.
- Email — our pharmin.io mailboxes are hosted by Hostinger, and emails to pharmacies are sent one at a time from those mailboxes.
- Website analytics — PostHog (PostHog, Inc., data hosted in the European Union), only where you consent, as described in section 3.
- Communications platforms — where we operate messaging services, data may pass through platforms such as Meta Platforms Ireland Ltd (WhatsApp Business) and other messaging, telephony or email providers, in line with the relevant client engagement.
- Professional advisers and authorities — where required by law or to establish, exercise or defend legal claims.
Each provider is bound to protect personal data and to use it only for the agreed purposes.
Mobile numbers and SMS. Mobile phone numbers collected for SMS messaging are used only to send service messages about a person's own prescriptions, orders and appointments. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes, and mobile numbers are never sold, rented or published. Text messaging opt-in data is not shared with any third party.
6. International transfers
Some of our service providers may process data outside the European Economic Area (EEA). Where that happens, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision, so that your data continues to receive an equivalent level of protection.
7. How long we keep data
We keep personal data only for as long as necessary for the purposes described above. Enquiry and contact data is kept for as long as needed to deal with your request and for a reasonable period afterwards; client project data is retained for the duration of the engagement and any period required by our contract or by law, after which it is deleted or returned.
Our record of contact with a pharmacy — calls, notes, follow-ups, the emails we sent and any website visits linked to them — is deleted 24 months after it was made. If you ask us not to contact you, we keep that request for as long as it is needed to honour it, so that you are not contacted again.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to our processing of your data;
- data portability; and
- withdraw consent at any time, where we rely on consent.
To exercise any of these rights, or to request deletion of your data, contact us at kieran@pharmin.io. We will respond within one month. If your data is processed by us on behalf of a client, we will direct your request to that client as the controller.
9. Complaints
If you have a concern about how we handle your data, please contact us first so we can try to resolve it. You also have the right to lodge a complaint with the Irish supervisory authority:
Data Protection Commission21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
www.dataprotection.ie
10. Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss or disclosure. No method of transmission or storage is completely secure, but we work to keep our systems and our providers’ systems protected.
11. Children
Our website and services are intended for businesses and are not directed at children. We do not knowingly collect personal data from children.
12. Changes to this policy
We may update this policy from time to time. The current version is always available on this page, with the “last updated” date shown above.
13. Contact us
For any question about this policy or your personal data, contact kieran@pharmin.io or write to us at Glasshouse GH2, Dun Laoghaire, Co. Dublin, Ireland.