Back

Legal

Privacy Policy

Last updated: 13 August 2026

We are a health technology company operating across the European Union and the United Kingdom. This policy explains how we handle personal data collected through this website and our partner enquiry process. It does not describe patient or health data processed on behalf of clinical software platforms and healthcare providers, where we act as a processor under a separate data processing agreement — see section 12.

1. Who we are

Pharmafast Limited ("we", "us", "our"), a company registered in Ireland under company number 793106, operates this website under the trading name CareRequest AI. Our registered address is NUIG Business Innovation Centre, Office 204, Galway, H91 236T, Ireland.

We are the data controller for the personal data described in this policy. For any question about this policy or your data, contact admin@carerequest.io.

2. Scope of this policy

This policy applies to visitors to this website and to people who contact us, request our partner brief, sign up for updates, or apply to join our pilot programme.

It does not apply to personal data we process as a processor for a customer under a separate agreement, nor to third-party websites we link to, which have their own policies.

3. Personal data we collect

Information you give us. When you complete a pilot enquiry, partner brief request or email sign-up we collect your name, work email address, company name, role, country and any message you choose to include.

Attribution and marketing data. UTM parameters, referring URL, landing page, selected language and submission timestamp, used to understand which channels generate relevant enquiries and to detect automated submissions.

Technical data. IP address, browser type, operating system, device type and request logs processed by our hosting and content-delivery providers.

Usage data. Where you have consented to analytics cookies, aggregated information about pages viewed, time on page and form submissions.

Correspondence. Emails, meeting requests and notes from calls arising from your enquiry.

We do not ask for, and you should not submit, patient data, clinical records or any special-category health data through this website.

4. Why we use it and our legal basis

Responding to enquiries and evaluating pilot applications — our legitimate interests in operating and growing our business, or steps taken at your request prior to entering a contract.

Sending you the partner brief and related follow-up — performance of your request, and our legitimate interests in business-to-business communication with the organisation you represent.

Sending partner updates you signed up for — your consent, which you may withdraw at any time.

Site security, spam and abuse prevention — our legitimate interests in protecting the service and preventing misuse of our forms.

Analytics and measurement cookies — your consent, given through our cookie banner and withdrawable at any time.

Complying with legal, accounting and record-keeping obligations — compliance with a legal obligation.

5. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Enquiry forms apply simple automated checks (for example a human-verification challenge and a work-email check) before a person reviews your submission.

6. Who we share data with

We share personal data with service providers acting on our documented instructions: website hosting and content delivery, email delivery, calendar and meeting scheduling, customer relationship management, and — where you have consented — analytics tooling. Each provider is bound by a written data processing agreement.

We may also disclose personal data to our professional advisers, to a purchaser or successor in the event of a corporate transaction, or where required by law, regulation or a lawful request from a public authority.

We do not sell personal data and we do not share it for cross-context behavioural advertising.

7. International transfers

We aim to keep personal data within the European Economic Area. Where a provider processes data outside the EEA or the UK, we rely on an adequacy decision, or on the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum where relevant, supported by additional safeguards where appropriate. You can request details of the safeguards in place by emailing admin@carerequest.io.

8. Retention

Enquiry and pilot application records are kept for up to 24 months after our last meaningful contact with you, unless a commercial relationship begins, in which case they are kept for the duration of that relationship plus the period required by applicable statutory record-keeping rules.

Marketing sign-ups are kept until you unsubscribe. Server logs are kept for a short operational period set by our hosting provider. Analytics data is kept in aggregated form.

9. Your rights

Under the GDPR and UK GDPR you may request access to your data, rectification of inaccurate data, erasure, restriction of processing, and portability, and you may object to processing based on legitimate interests, including direct marketing. Where processing relies on consent, you may withdraw it at any time without affecting processing carried out before withdrawal.

Email admin@carerequest.io to exercise a right. We respond within one month, and will tell you if we need longer because a request is complex. We may ask for information to verify your identity.

You also have the right to complain to a supervisory authority, including the Irish Data Protection Commission for EU matters and the UK Information Commissioner's Office for UK matters, or the authority in your country of residence or place of work.

10. Security

The website is served over HTTPS, form submissions are transmitted over encrypted connections, and access to enquiry data is restricted to staff who need it for their role. We keep our security practices under review. No online service can be guaranteed fully secure; please do not send confidential clinical information through this site.

11. Children

This website is intended for business users. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Health data and our role for clinical partners

We are a health technology company. Where our software is embedded by a clinical software vendor, pharmacy group, GP practice or other healthcare provider, any patient or health data flowing through that integration is processed by us as a processor on the documented instructions of that organisation, which remains the controller. That processing is governed by a written data processing agreement including Article 28 GDPR terms, confidentiality obligations, sub-processor controls, security measures, breach notification timelines and deletion or return of data at the end of the engagement.

This policy does not describe that processing. If you are a patient and wish to exercise rights over your health data, contact the healthcare provider or clinical software platform you dealt with; we will assist them in responding.

No patient or special-category health data is collected through this marketing website. Enquiry forms are for business contacts only, and we ask that clinical detail is never submitted through them. Where health data is processed under an integration, it is held within the European Economic Area or the United Kingdom unless the controller instructs otherwise in writing.

13. EU and UK regulatory framework

We operate across the European Union and the United Kingdom and design our processing to meet both the EU GDPR and the UK GDPR together with the Data Protection Act 2018, as well as the ePrivacy rules implemented in each country. Transfers between the EEA and the UK rely on the UK adequacy decision; other transfers rely on the mechanisms described in section 7.

Our security programme is built around the control areas set out in ISO/IEC 27001 — access control, encryption in transit and at rest, logging and audit trails, change management, supplier assurance and incident response. We do not currently hold ISO/IEC 27001 certification, a SOC 2 report or an NHS Data Security and Protection Toolkit submission, and we do not claim compliance with the NHS Digital Technology Assessment Criteria. We are happy to complete security questionnaires and share our current documentation on request.

Where an integration involves health data, we support the controller's data protection impact assessment, record of processing activities and, where required, its clinical risk management and interoperability obligations.

14. Cookies

We use cookies and similar browser storage as described in our Cookie Policy.

15. Changes to this policy

We may update this policy from time to time. Material changes will be reflected in the "last updated" date above and, where appropriate, notified by email to subscribers. Please review this page periodically.

16. Contact

Pharmafast Limited, NUIG Business Innovation Centre, Office 204, Galway, H91 236T, Ireland. Email admin@carerequest.io.