Privacy Policy
Effective 21 September 2026. This policy explains how Property Stack Pty Ltd (ABN 43 612 526 888) (“PharmacyPulse”, “we”, “us”) collects, holds, uses and discloses personal information in providing PharmacyPulse HR (the “Service”) at pharmacypulse.com.au. We are bound by the Australian Privacy Principles in the Privacy Act 1988 (Cth).
1. The two roles we hold
The Service is used by community pharmacies to keep records about their business and their staff. That gives us two roles.
- For a pharmacy's own records — its staff files, contracts, clearances, certificates, policies, registers, incidents, HR feedback, daily checks and the like — the pharmacy is the collector of that information and decides why it is collected. We hold and process it on the pharmacy's behalf and on its instructions. Questions about why a pharmacy holds particular information about a person, or requests to see or correct it, are properly made to the pharmacy first; we assist the pharmacy to answer them.
- For the information we collect ourselves — account details, billing contact, support correspondence, and the technical records of the Service's operation — we are the collector, and this policy applies directly.
2. What we collect
From the pharmacy and its organisation: the pharmacy's name, address, ABN, contact details, services, registrations and insurances, and the names and contact details of its directors, accountable persons and billing contact.
From the people who use the Service: name, work email address, mobile number, role at the pharmacy, sign-in and authenticator details, and the records each person makes or signs while using it.
About staff, where the pharmacy records it: employment details, position, start and end dates, contracts and variations, position descriptions, clearances and checks (such as police and working-with-children checks), qualifications and certificates, training and competency records, emergency contacts, and, where the pharmacy chooses to record them, health information relevant to work and immunisation status. Health information is sensitive information; the pharmacy is responsible for collecting it with the person's consent and only where it is reasonably necessary.
About incidents and HR matters: the accounts, names and outcomes the pharmacy records, including complaints and feedback raised by staff.
Payment information: card and bank account details are entered directly with our payment provider and are never held by us. We hold the provider's reference for the customer and the subscription's status.
Technical information: sign-in times, the pages requested, the browser and device, IP address, and an audit log of who recorded, changed or approved what and when.
3. How we use it
- To provide the Service to the pharmacy: to hold its records, show them to the people entitled to see them, send the notifications and emails the Service is built to send, and produce its reports and the assessor pack.
- To operate accounts: to sign people in, verify a second factor, reset passwords and prevent unauthorised access.
- To bill the organisation and to respond when a payment fails.
- To support the pharmacy when it writes to us.
- To keep the Service secure and reliable, investigate faults and misuse, and meet our legal obligations.
We do not sell personal information, use it for advertising, or use it to train artificial-intelligence models.
4. Who we disclose it to
We disclose personal information only to the people the pharmacy has given access to, and to the providers we rely on to run the Service, each under contract and only for that purpose:
- Our database, authentication and file-storage provider, hosted in Sydney, Australia.
- Our web-hosting provider. Web requests may be handled through its global network.
- Our payment provider, which receives the billing contact's name and email and the card or bank details entered with it, and is itself bound by the Privacy Act and by payment-card standards.
- Our email-delivery provider: email addresses and the content of the emails the Service sends.
- An AI document-reading provider, which receives a certificate or document at the moment it is uploaded, in order to read its details into the record, and the questions typed into Ask Pulse together with the pharmacy's documents they are answered from.
- A forms provider, only where a pharmacy chooses to connect an external form to a register.
The database and file storage are in Sydney, Australia, and this site is served from Sydney. The web-hosting, payment, email-delivery and AI document-reading providers are companies based in the United States of America and process the information described above there, and the web-hosting provider's network is global. Each is engaged under terms that confine its use of the information to providing its service to us, and we take reasonable steps to ensure that every overseas recipient handles personal information consistently with the Australian Privacy Principles.
We may also disclose information where the law requires it, or to protect the rights, property or safety of a person.
5. How we keep it secure
- Records are held in Sydney, in a database that is backed up daily.
- Every record carries its pharmacy, and the database itself refuses a request from anyone outside that pharmacy. A test of that separation runs with every release.
- Every connection is encrypted in transit.
- Every person signs in with a password and an authenticator code. Staff see their own record only; the office, the registers and other people's files are open only to those the pharmacy has given an office.
- Records are superseded and dated rather than erased, and an append-only log records who did what and when.
If a data breach occurs that is likely to result in serious harm, we will notify the affected pharmacies and individuals and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
6. How long we keep it
While a pharmacy subscribes, its records are kept for as long as the pharmacy keeps them; the Service supersedes records rather than deleting them, because a dated history is what an assessment relies on. When a subscription ends, or at any time on request to support@pharmacypulse.com.au, we provide the pharmacy with a complete copy of its records in a readable form. We retain the pharmacy's records for 12 months after the subscription ends, so that a lapsed subscription can be resumed without loss, and then delete them, other than what we must keep to meet legal, accounting or dispute obligations. The pharmacy remains responsible for keeping its own employee records for the seven years the Fair Work Regulations 2009 require, and the copy we provide is made for that purpose. Backups are overwritten on their own cycle.
7. Access and correction
A person may ask to see the personal information held about them and to have it corrected. A staff member sees their own record in the Service at any time; for anything else, or if a record is wrong, ask the pharmacy first, since the record is the pharmacy's. If that does not resolve it, write to us at the address below and we will respond within thirty days.
8. Complaints
A complaint about our handling of personal information may be made to support@pharmacypulse.com.au. We will acknowledge it within seven days and respond within thirty. If the response does not resolve it, a complaint may be made to the Office of the Australian Information Commissioner at oaic.gov.au.
9. Cookies
The Service uses cookies only to keep a person signed in and to enforce the idle time-out. It does not use advertising or third-party analytics cookies.
10. Changes
We may update this policy. Material changes are notified to each organisation's billing contact by email before they take effect, and the current version is always at pharmacypulse.com.au/privacy.
Contact
Property Stack Pty Ltd (ABN 43 612 526 888, ACN 612 526 888), trading as PharmacyPulse HR
PO Box 181, Magill SA 5072
support@pharmacypulse.com.au
