Privacy

Privacy policy.

What Freemi processes, why, where it is held, and who is responsible for it. Written to be read rather than to be survived.

Last updated 7 August 2026  ·  Ask us about anything on this page
On this page
  1. Who we are
  2. Controller or processor
  3. What we process
  4. Why, and on what basis
  5. Where your data is held
  6. International transfers
  7. Sub-processors
  8. What the AI sees
  9. How long we keep it
  10. Your rights
  11. If you are a patient
  12. Security
  13. If something goes wrong
  14. Children
  15. Changes
  16. Contact

1. Who we are

Freemi is a software company based in Dublin, Ireland. We build two products: Freemi Pharmacy, which runs the work around a pharmacy’s dispensing system, and Freemi Practice, which runs the patient journey for allied health practices.

This policy covers this website and both products. It is written for two audiences: the pharmacy or practice deciding whether to use Freemi, and anyone who wants to understand what happens to information once it is in the system.

2. Controller or processor: the distinction that matters

Most of this policy turns on one point, so it comes first.

For patient information, your pharmacy or practice is the data controller and Freemi is the processor. The patient is your patient. The record is your record. We hold and process it on your written instructions so the software can do its job, and we do not decide what to do with it.

Freemi is the controller for a narrower set of things: the account details of the people who use the software, our billing records, the enquiries sent through this website, and the ordinary analytics described in our cookie policy.

This is not a technicality. It decides who a patient asks when they want a copy of their record, who answers a regulator, and who is accountable if something goes wrong. In every case involving patient information, that is the practice, with our help.

3. What we process

CategoryExamplesWhose data
Account and staffName, work email, role and permissions, sign-in times, actions taken in the systemYour team
Patient operational dataName, contact details, appointments, requests, messages across every connected channel, consent records, forms, recallsYour patients
Clinical recordsTreatment notes and their version history, cases, letters, attachments. Practice only. In Pharmacy, clinical records stay in your dispensing systemYour patients
FinancialInvoices, payments, refunds and outstanding balances. Card details are handled by Stripe and never reach FreemiYour patients and your business
OperationalTasks, SOPs and sign-offs, incidents, rotas, clock-in and timesheets, documentsYour team
AuditEvery important action with an actor, a timestamp and the values before and afterYour team
WebsiteEnquiries you send us, and aggregate page analyticsYou

We do not buy personal data, we do not sell it, and we do not use your patients’ information to advertise anything to anyone.

4. Why we process it, and on what basis

PurposeLawful basis
Running the software you have asked us to runPerformance of a contract with your business. For patient data, we act on your documented instructions as processor
Keeping the system secure, and keeping an audit trailLegitimate interests: protecting your business, your patients and ours
Billing you, and keeping the records tax law requiresContract, and legal obligation
Answering an enquiry you send through this siteLegitimate interests: replying to someone who asked us a question
Aggregate analytics on this websiteConsent, which you can decline without losing anything

Where health information is involved, the condition for processing special-category data rests with your practice as controller, ordinarily the provision of health or social care. Your data processing agreement with us sets out the instructions we act on.

5. Where your data is held

Freemi’s primary database is hosted in the United States. We would rather say that plainly here than let a Dublin address imply otherwise.

The specifics, so you can check them:

  • The database is Google Cloud Firestore in the nam5 multi-region, which spans data centres in Iowa and South Carolina.
  • Application logic runs as Google Cloud Functions in us-central1 (Iowa) for Pharmacy and europe-west1 (Belgium) for the platform and administration layer.
  • The website and application front ends are served from Firebase Hosting’s global edge network.

We are an Irish company and the GDPR applies to what we do regardless of where the servers sit. If your practice needs data held inside the EEA as a condition of using Freemi, tell us before you sign rather than after. It is a fair requirement and we would rather have the conversation early.

6. International transfers

Because of the above, personal data is transferred outside the EEA to the United States. Those transfers rely on the safeguards our infrastructure and service providers put in place, principally the European Commission’s Standard Contractual Clauses, and, where the provider is certified, the EU–US Data Privacy Framework.

We will give you the current transfer documentation for every provider in the table below on request, in writing, as part of a due-diligence pack. We would rather send you the actual documents than a paragraph claiming they exist.

7. Sub-processors

These are the third parties that may process personal data on our behalf. This is the real list as at the date above, not a generic one.

ProviderWhat it doesWhat it can see
Google Cloud / FirebaseHosting, database, authentication, application logic, file storageAll data in the system
TwilioSMS and WhatsApp messagingPhone numbers and the content of messages sent through those channels
SendGrid (Twilio)Transactional and campaign emailEmail addresses and the content of emails sent
StripePayments, invoicing and refundsBilling details and payment records. Card numbers go to Stripe directly and are never stored by Freemi
OpenRouterRouting requests to AI modelsThe content of the specific request sent for drafting or classification. See section 8
ComposioConnecting a practice’s Gmail or Outlook mailboxMail in the connected mailbox, where you have connected one
Meta (WhatsApp Business)The WhatsApp channelPhone numbers and message content on that channel
Apple and Google WalletLoyalty passes, where the feature is onThe pass itself. No clinical information

We will tell you before adding a sub-processor that materially changes this picture, and you may object.

8. What the AI sees, and what it does not

Freemi drafts. Your team sends. That sentence is the whole design, and it has consequences worth spelling out.

  • A model is sent the specific content needed for a specific task: classifying an incoming message, drafting a reply, or summarising a request. It is not given standing access to your database.
  • Anything requiring professional judgement is routed to an authorised person rather than answered automatically. You decide, per workflow, what may run on its own, and your team signs that off before anything reaches a patient.
  • The audit trail records which actions were automatic and which were taken by a person.
  • You refine the rules over time. The system does not quietly change its own behaviour based on your patients.

We do not permit our AI providers to train their models on your data, and we will confirm that contractually in the data processing agreement. If a provider’s terms ever changed on that point, we would move provider rather than accept it.

9. How long we keep it

While you are a customer, your data stays in the system because that is what the system is for. Retention periods for clinical and financial records are set by your own professional and statutory obligations, not by us, and your data processing agreement records what you have instructed.

When you leave: you export your data, and we delete our copy. Backups age out on their ordinary cycle rather than being surgically edited, and we will confirm the cycle in writing. Audit records of administrative actions are kept for their own retention period, because a log you can delete is not a log.

10. Your rights

Under the GDPR you have the right to be told what is held about you, to get a copy, to have mistakes corrected, to have data erased in some circumstances, to restrict or object to processing, to portability, and to complain to a supervisory authority. In Ireland that is the Data Protection Commission, dataprotection.ie.

Where Freemi is the controller, which is your own account details, our billing records and enquiries through this site, ask us and we will handle it.

11. If you are a patient

If you are a patient of a pharmacy or practice that uses Freemi and you want to see, correct or delete your record, please contact them, not us. They hold the relationship and the legal responsibility, and they can act immediately. We are their processor and we will help them respond, but we cannot act on your record without their instruction.

If you have asked your practice and got nowhere, write to us anyway and we will make sure the request reaches the right person there.

12. Security

The detail lives on our security page. In short: roles are enforced on the server rather than by hiding buttons in the interface, so someone without permission is refused and the attempt is logged; every important action carries an actor, a timestamp and the values before and after; and the trail is exportable so you are never dependent on us to account for something.

We do not claim certifications we do not hold. If your due-diligence process needs a specific control evidenced, ask, and you will get a straight answer including where we fall short.

13. If something goes wrong

If a personal data breach affects your business, we will tell you without undue delay and in any case in time for you to meet your own 72-hour obligation as controller. You will get what happened, what was affected, what we have changed, and the audit trail. We would rather make an awkward call early than a worse one late.

14. Children

Freemi is sold to healthcare businesses, not to individuals, and this website is not directed at children. Patient records held by a practice may relate to children; where they do, the practice is the controller and its own safeguarding and consent arrangements apply.

15. Changes to this policy

If we change something that matters, we will change the date at the top and tell existing customers rather than relying on you to re-read the page. Adding a sub-processor, changing where data is held, or changing what the AI is permitted to do all count as mattering.

16. Contact

Email hello@freemi.ai and mark it for the attention of privacy. A person reads it, and you will get a written reply. If you need a signed data processing agreement, a sub-processor list for a due-diligence pack, or answers to a security questionnaire, say so and we will send them.

The rest of it

Terms
The agreement between your business and Freemi.
Cookies
What this site sets, and the long list of what it does not.
Security
Access control, the audit trail, and what happens on a bad day.

Ask a person, not a policy page.

If your practice has a specific question, or your own advisers need something in writing for a due-diligence pack, email us and you will get a written answer from someone who knows the system rather than a link back to this page.

Contact the team