Privacy Policy
Effective 22 September 2026. This Privacy Policy explains what personal data PharmaOneLink collects when you visit pharmaonelink.com or use the Service, why we collect it, who we share it with, how long we keep it and what choices and rights you have. It forms part of the Terms of Service. Words defined in the Terms have the same meaning here.
1. Scope
This Policy covers personal data of visitors to the public pages, of people who register an account, and of Subscribers. It also explains how we treat business contact details of third parties that appear in the Directory. It does not cover the practices of third-party websites we link to or of companies you contact through the Service.
2. Data we collect
Account data. When you register we collect the name, company, country, email address and password you provide, the time and IP address of registration and verification, and the role and status of the account. Passwords are stored only as a salted one-way hash.
Billing data. Payments are taken by Paddle, our Merchant of Record. Paddle collects your payment method, billing address, tax identifiers and transaction details under its own privacy policy. We receive and keep from Paddle the identifiers, plan, status, amounts, currency, dates and country of your subscription and transactions, and notifications of payments, renewals, failures, refunds, disputes and cancellations. We never see your full card number.
Usage data. While you use the Service we record the pages you request, the searches you run, the filters you apply, the companies and records you view and reveal, the lists you create, the time, duration and volume of your activity, your IP address, device and browser identifiers, user agent, language, referrer, approximate location derived from the IP address, and error and performance information.
Communications. We keep the emails and messages you send us, our replies, support notes, and records of the messages we send you and whether they were delivered or opened.
Cookies and similar technologies. We set one strictly necessary session cookie that keeps you signed in. Paddle sets its own cookies during checkout. The public pages use Cloudflare Web Analytics, which does not use cookies or fingerprinting. Fonts are loaded from Google Fonts and icons from jsDelivr; those providers receive your IP address when the files are fetched. We do not use advertising trackers or sell data to advertisers.
Data from other sources. We may combine account data with information from Paddle, from public business registers, from your organisation's public website and from fraud-prevention and security services, to verify identities, prevent abuse and understand our customers.
3. Why we use your data and on what basis
We use personal data: to create and manage your account and verify your email; to provide the Directory and its features; to process payments, renewals, refunds and disputes through Paddle; to send service messages about your account, security, billing and changes to the Service or its terms; to answer your questions and provide support; to detect, investigate and prevent unauthorised access, scraping, credential sharing, fraud and other breaches of the Terms, including by analysing usage patterns and by tracing copied data; to protect our rights, property and safety and those of others; to comply with legal, tax, accounting and regulatory obligations; to measure, maintain, secure and improve the Service; to understand how the Service is used and to develop new features, products and services; and to contact you about your experience, satisfaction, surveys and research, new products, features, offers and related services that we think may interest you.
Where data-protection law requires a legal basis, we rely on: performance of the contract with you (account, Directory access, billing, support); our legitimate interests (security, fraud and abuse prevention, enforcement of the Terms, service improvement, business communications with professional users, and marketing of our own services to existing customers); compliance with legal obligations (tax, accounting, sanctions, responding to lawful requests); and your consent where the law requires it for a particular use, which you may withdraw at any time without affecting processing carried out before withdrawal.
4. Communications and marketing
By creating an account you agree that we may contact you by email, telephone, messaging services or notices within the Service, at the contact details you provide, about your account and the Service, and also about your experience, surveys and research, new products, features, offers and related services. You may opt out of messages that are not needed to operate your account at any time by using the unsubscribe link in the message or by writing to hello@pharmaonelink.com. Service, security, billing and legal messages continue while your account exists because they are needed to provide the Service.
5. Who we share data with
We share personal data only as follows: with Paddle, which sells and bills the Subscription as Merchant of Record and is an independent controller of the payment data it collects; with our service providers acting as processors under contract, including hosting and content delivery (Cloudflare), transactional email delivery (Resend), and infrastructure, monitoring, analytics and support tools; with professional advisers such as lawyers, accountants and auditors under duties of confidentiality; with courts, regulators, law-enforcement bodies, payment networks and other authorities where the law requires it or where it is necessary to establish, exercise or defend legal claims, including claims arising from breaches of the Terms; with your organisation, where your account was purchased or is administered by it, or where we investigate misuse of an account associated with it; and with a buyer or successor in the event of a merger, acquisition, financing, reorganisation or sale of all or part of our business, subject to this Policy. We do not sell personal data and we do not share it with third parties for their own marketing.
6. International transfers
We are established in Jordan and our providers operate globally. Your data may be stored and processed in Jordan, the European Union, the United Kingdom, the United States and other countries where we or our providers have facilities. Where data is transferred from a country that restricts international transfers, we rely on the safeguards that country recognises, such as standard contractual clauses, adequacy decisions or the provider's certified frameworks, and on the necessity of the transfer to perform our contract with you.
7. Retention
We keep account data for as long as the account exists. When an account is deleted we erase the name, company, country, email address and password and delete sessions and pending tokens; an anonymised stub and the associated subscription and transaction records are kept for up to seven years where needed for tax, accounting, contract, dispute and fraud-prevention purposes, after which they are deleted or irreversibly anonymised. Usage and access logs are kept for up to two years, and longer where they are evidence in an investigation or claim. Communications are kept for up to three years after the last exchange. Security and abuse records, including records of accounts and networks blocked for breaching the Terms, may be kept indefinitely to prevent repeat abuse. Backups are rotated on a schedule and data in them is deleted when the backup expires.
8. Security
We protect personal data with measures appropriate to the risk, including encryption in transit, hashed passwords, access controls, session and rate limits, logging and monitoring, and hosting on providers with independently audited security programmes. No system is completely secure; you are responsible for keeping your credentials confidential and for telling us promptly at hello@pharmaonelink.com if you suspect your account has been compromised. If a breach affecting your personal data occurs we will notify you and any competent authority where the law requires it.
9. Your rights and choices
Depending on where you live you may have the right to: access the personal data we hold about you and receive a copy; have inaccurate data corrected; have data deleted; restrict or object to certain processing, including direct marketing; receive data you provided in a portable format; withdraw consent; and complain to a data-protection authority. You can change your password and delete your account and personal data yourself from the account page (Account, then Delete account and data); to correct your name, company or country write to us. For any other request write to hello@pharmaonelink.com from the email address on your account; we may ask for information to confirm your identity and will respond within the time the law allows, normally within thirty days. Where a request is manifestly unfounded, excessive or would require us to delete records we must keep by law, we may refuse it or charge a reasonable fee and will tell you why.
10. Business contact details in the Directory
The Directory contains names, roles, email addresses, telephone numbers and addresses of companies and, in some cases, of individuals acting for those companies, drawn from public regulatory registers and the companies' own public websites. We process this business contact information in our legitimate interest of operating a professional sourcing directory, and it is shown to Subscribers only for the purpose of making business contact. If you are such a person and want a record corrected or removed, write to hello@pharmaonelink.com with the record concerned and we will act on legitimate requests promptly. Subscribers who use those details are independently responsible for complying with the laws that apply to their communications.
11. Children
The Service is for business users and is not directed at anyone under eighteen. We do not knowingly collect personal data from children; if we learn that we have done so we will delete it.
12. Automated decisions
We use automated rules to detect abuse, such as unusual request volumes, credential sharing or scraping patterns, and those rules may automatically limit, suspend or block access. If you believe a decision was wrong you may ask for human review at hello@pharmaonelink.com.
13. Changes to this Policy
We may update this Policy from time to time. The current version is always available at pharmaonelink.com/privacy with its effective date. Material changes will be announced by email or through the Service before they take effect. Continued use after the effective date is acceptance of the updated Policy.
14. Who we are and how to contact us
The controller of your personal data is Dirwaas Intelligent Solutions LLC, a limited liability company registered in the Hashemite Kingdom of Jordan, trading as PharmaOneLink. Privacy questions, requests and complaints: hello@pharmaonelink.com. If you are in a jurisdiction with a supervisory authority for data protection you may also complain to that authority.