What Freemi processes, why, where it is held, and who is responsible for it. Written to be read rather than to be survived.
Freemi is a software company based in Dublin, Ireland. We build two products: Freemi Pharmacy, which runs the work around a pharmacy’s dispensing system, and Freemi Practice, which runs the patient journey for allied health practices.
This policy covers this website and both products. It is written for two audiences: the pharmacy or practice deciding whether to use Freemi, and anyone who wants to understand what happens to information once it is in the system.
Most of this policy turns on one point, so it comes first.
For patient information, your pharmacy or practice is the data controller and Freemi is the processor. The patient is your patient. The record is your record. We hold and process it on your written instructions so the software can do its job, and we do not decide what to do with it.
Freemi is the controller for a narrower set of things: the account details of the people who use the software, our billing records, the enquiries sent through this website, and the ordinary analytics described in our cookie policy.
This is not a technicality. It decides who a patient asks when they want a copy of their record, who answers a regulator, and who is accountable if something goes wrong. In every case involving patient information, that is the practice, with our help.
| Category | Examples | Whose data |
|---|---|---|
| Account and staff | Name, work email, role and permissions, sign-in times, actions taken in the system | Your team |
| Patient operational data | Name, contact details, appointments, requests, messages across every connected channel, consent records, forms, recalls | Your patients |
| Clinical records | Treatment notes and their version history, cases, letters, attachments. Practice only. In Pharmacy, clinical records stay in your dispensing system | Your patients |
| Financial | Invoices, payments, refunds and outstanding balances. Card details are handled by Stripe and never reach Freemi | Your patients and your business |
| Operational | Tasks, SOPs and sign-offs, incidents, rotas, clock-in and timesheets, documents | Your team |
| Audit | Every important action with an actor, a timestamp and the values before and after | Your team |
| Website | Enquiries you send us, and aggregate page analytics | You |
We do not buy personal data, we do not sell it, and we do not use your patients’ information to advertise anything to anyone.
| Purpose | Lawful basis |
|---|---|
| Running the software you have asked us to run | Performance of a contract with your business. For patient data, we act on your documented instructions as processor |
| Keeping the system secure, and keeping an audit trail | Legitimate interests: protecting your business, your patients and ours |
| Billing you, and keeping the records tax law requires | Contract, and legal obligation |
| Answering an enquiry you send through this site | Legitimate interests: replying to someone who asked us a question |
| Aggregate analytics on this website | Consent, which you can decline without losing anything |
Where health information is involved, the condition for processing special-category data rests with your practice as controller, ordinarily the provision of health or social care. Your data processing agreement with us sets out the instructions we act on.
Freemi’s primary database is hosted in the United States. We would rather say that plainly here than let a Dublin address imply otherwise.
The specifics, so you can check them:
We are an Irish company and the GDPR applies to what we do regardless of where the servers sit. If your practice needs data held inside the EEA as a condition of using Freemi, tell us before you sign rather than after. It is a fair requirement and we would rather have the conversation early.
Because of the above, personal data is transferred outside the EEA to the United States. Those transfers rely on the safeguards our infrastructure and service providers put in place, principally the European Commission’s Standard Contractual Clauses, and, where the provider is certified, the EU–US Data Privacy Framework.
We will give you the current transfer documentation for every provider in the table below on request, in writing, as part of a due-diligence pack. We would rather send you the actual documents than a paragraph claiming they exist.
These are the third parties that may process personal data on our behalf. This is the real list as at the date above, not a generic one.
| Provider | What it does | What it can see |
|---|---|---|
| Google Cloud / Firebase | Hosting, database, authentication, application logic, file storage | All data in the system |
| Twilio | SMS and WhatsApp messaging | Phone numbers and the content of messages sent through those channels |
| SendGrid (Twilio) | Transactional and campaign email | Email addresses and the content of emails sent |
| Stripe | Payments, invoicing and refunds | Billing details and payment records. Card numbers go to Stripe directly and are never stored by Freemi |
| OpenRouter | Routing requests to AI models | The content of the specific request sent for drafting or classification. See section 8 |
| Composio | Connecting a practice’s Gmail or Outlook mailbox | Mail in the connected mailbox, where you have connected one |
| Meta (WhatsApp Business) | The WhatsApp channel | Phone numbers and message content on that channel |
| Apple and Google Wallet | Loyalty passes, where the feature is on | The pass itself. No clinical information |
We will tell you before adding a sub-processor that materially changes this picture, and you may object.
Freemi drafts. Your team sends. That sentence is the whole design, and it has consequences worth spelling out.
We do not permit our AI providers to train their models on your data, and we will confirm that contractually in the data processing agreement. If a provider’s terms ever changed on that point, we would move provider rather than accept it.
While you are a customer, your data stays in the system because that is what the system is for. Retention periods for clinical and financial records are set by your own professional and statutory obligations, not by us, and your data processing agreement records what you have instructed.
When you leave: you export your data, and we delete our copy. Backups age out on their ordinary cycle rather than being surgically edited, and we will confirm the cycle in writing. Audit records of administrative actions are kept for their own retention period, because a log you can delete is not a log.
Under the GDPR you have the right to be told what is held about you, to get a copy, to have mistakes corrected, to have data erased in some circumstances, to restrict or object to processing, to portability, and to complain to a supervisory authority. In Ireland that is the Data Protection Commission, dataprotection.ie.
Where Freemi is the controller, which is your own account details, our billing records and enquiries through this site, ask us and we will handle it.
If you are a patient of a pharmacy or practice that uses Freemi and you want to see, correct or delete your record, please contact them, not us. They hold the relationship and the legal responsibility, and they can act immediately. We are their processor and we will help them respond, but we cannot act on your record without their instruction.
If you have asked your practice and got nowhere, write to us anyway and we will make sure the request reaches the right person there.
The detail lives on our security page. In short: roles are enforced on the server rather than by hiding buttons in the interface, so someone without permission is refused and the attempt is logged; every important action carries an actor, a timestamp and the values before and after; and the trail is exportable so you are never dependent on us to account for something.
We do not claim certifications we do not hold. If your due-diligence process needs a specific control evidenced, ask, and you will get a straight answer including where we fall short.
If a personal data breach affects your business, we will tell you without undue delay and in any case in time for you to meet your own 72-hour obligation as controller. You will get what happened, what was affected, what we have changed, and the audit trail. We would rather make an awkward call early than a worse one late.
Freemi is sold to healthcare businesses, not to individuals, and this website is not directed at children. Patient records held by a practice may relate to children; where they do, the practice is the controller and its own safeguarding and consent arrangements apply.
If we change something that matters, we will change the date at the top and tell existing customers rather than relying on you to re-read the page. Adding a sub-processor, changing where data is held, or changing what the AI is permitted to do all count as mattering.
Email hello@freemi.ai and mark it for the attention of privacy. A person reads it, and you will get a written reply. If you need a signed data processing agreement, a sub-processor list for a due-diligence pack, or answers to a security questionnaire, say so and we will send them.
If your practice has a specific question, or your own advisers need something in writing for a due-diligence pack, email us and you will get a written answer from someone who knows the system rather than a link back to this page.
Contact the team