Data Protection

8

Sep

Controller and Contact Information

PharmaWeb (pharmaweb.net) is operated in the United States by Benjamin Aghaki-Allen, who serves as the controller for personal information processed through the site.

Mailing address: 10 W Sunset Way
Issaquah, WA 98027

Email: [email protected]

Scope and Applicability

This notice describes how we collect, use, disclose, and safeguard personal information in connection with your use of PharmaWeb, including our webpages, tools, and communications. This notice is written to align with applicable United States privacy laws while reflecting generally recognized data protection principles.

PharmaWeb provides educational health and medication content and is not a medical provider or a covered entity under HIPAA. Do not submit protected health information. Any information you choose to provide may be processed as described in this notice.

Categories of Personal Information Collected

We may collect the following categories of personal information, depending on your interactions with the site:

  • Identifiers: name, email address, online identifiers (cookies, IP address), device IDs.
  • Internet or network activity: pages viewed, links clicked, time on page, referring/exit pages, error logs, and other diagnostic data.
  • Approximate location: derived from IP address (city/region level).
  • Commercial or service information: subscriptions to updates, inquiries, preferences.
  • User content and communications: messages you send us (e.g., via email or forms).
  • Inferences: preferences or interests derived from site interactions.

Sensitive Personal Information

We do not seek sensitive personal information. If you voluntarily share health-related details (e.g., conditions, medications, side effects) in communications, we treat them as sensitive and use them only to respond to your inquiry or provide requested services. We do not use sensitive personal information to infer characteristics or for cross-context behavioral advertising.

Sources of Personal Information

  • Directly from you: when you contact us or adjust preferences.
  • Automatically: via cookies, pixels, and similar technologies when you browse the site.
  • Service providers and partners: analytics and hosting providers that generate aggregated or pseudonymous metrics.

Purposes of Processing

  • Provide and operate the website, including troubleshooting and support.
  • Deliver educational content, features, and user-requested communications.
  • Measure usage, perform analytics, and improve performance and content relevance.
  • Personalize on-site experience (e.g., remembering preferences).
  • Maintain security, detect fraud, prevent abuse, and ensure integrity of systems.
  • Comply with legal obligations and exercise or defend legal claims.

Disclosures of Personal Information

We disclose personal information to the following categories of recipients for the purposes described above:

  • Service providers/contractors: hosting, cloud infrastructure, analytics, security, communication tools. They are restricted from using personal information for their own purposes.
  • Professional advisors: legal, compliance, or accounting advisors, when necessary.
  • Authorities: when required by law, legal process, or to protect rights, safety, and security.
  • Successors: in connection with a corporate transaction (e.g., merger or transfer) subject to continued protection of personal information.

Sale or Sharing of Personal Information

We do not sell personal information for money. We may engage in processing that could be considered “sharing” or “targeted advertising” under certain U.S. state laws when we use analytics or advertising tools that observe your interactions across sites. You may opt out of sale/sharing or targeted advertising as described under Your Privacy Rights (United States) below.

Retention

We retain personal information for as long as needed to fulfill the purposes described, including to meet legal, accounting, or reporting requirements. Typical retention periods include: essential security logs (up to 24 months), analytics data (12–24 months, often aggregated or pseudonymized), customer communications (up to 36 months), and records needed for legal compliance (up to 7 years). We may retain de-identified or aggregated information for longer.

Cookies and Similar Technologies

We use cookies, pixels, and similar technologies to operate the site and understand usage. Categories include:

  • Essential: required for core functionality and security.
  • Functional: remember choices or settings.
  • Analytics: measure traffic and performance.
  • Advertising/Personalization: support audience measurement or targeted content.

You can manage cookies through your browser settings and, where provided, our on-site consent tools. If your browser or extension sends a recognized opt-out preference signal (such as a Global Privacy Control), we treat it as a request to opt out of sale/sharing for the device and browser used.

Your Privacy Rights (United States)

Depending on your state of residence (for example, California, Colorado, Connecticut, Utah, Virginia), you may have the following rights, subject to applicable law and verification:

  • Access/Know: request the categories and specific pieces of personal information we collected about you.
  • Correction: request that we correct inaccurate personal information.
  • Deletion: request deletion of personal information we collected from you.
  • Portability: receive certain information in a portable format.
  • Opt-out: opt out of sale or sharing of personal information and targeted advertising.
  • Limit use of sensitive personal information (California): request that we limit use to permitted purposes.
  • Appeal: if we deny your request, submit an appeal and receive a written explanation.
  • Non-Discrimination: we will not discriminate against you for exercising your rights.

How to Exercise Your Rights

Submit requests by emailing [email protected] or writing to the postal address above. Please describe your request, the state you reside in, and provide contact details. We will verify your identity using information you provide and information we maintain. We will respond within the timeframe required by law (generally 45 days, with a possible 45-day extension). You may use an authorized agent where permitted; we may require proof of authorization and verification of your identity.

Opt-out of sale/sharing or targeted advertising by contacting us at the email above, adjusting cookie preferences (where offered), or enabling a recognized opt-out preference signal in your browser. To limit use of sensitive personal information (California), contact us using the methods above.

If we deny your request, you may appeal by replying to our decision email or writing to the address above and stating “Privacy Request Appeal” in your communication. We will respond to appeals within the legally required period and provide our reasons.

Additional Disclosures for California Residents

In the past 12 months, we collected the categories listed under “Categories of Personal Information Collected” from the sources and for the purposes described in this notice. We disclosed those categories to service providers and other recipients as outlined under “Disclosures of Personal Information.” We do not sell personal information for monetary consideration. We may “share” identifiers, internet/network activity, and inferences with analytics or advertising partners for cross-context behavioral advertising, subject to your right to opt out. We do not have actual knowledge of selling or sharing the personal information of consumers under 16 years of age.

We do not offer financial incentives in exchange for personal information. Our “notice at collection” is provided by this Data Protection page at or before the point of collection.

Security

We implement reasonable and appropriate administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, disclosure, alteration, or destruction. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Children’s Privacy

PharmaWeb is intended for a general audience and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, please contact us and we will take appropriate steps to delete it.

International Users

PharmaWeb is operated in the United States, and your information may be processed and stored in the U.S. and other countries that may have different data protection laws than your country of residence. If you are located in the EEA, UK, or Switzerland, we will process your personal information consistent with applicable requirements and rely on appropriate safeguards for transfers (such as standard contractual clauses with our service providers). Where applicable, legal bases may include consent, performance of a contract or steps prior to entering into a contract, legitimate interests (such as site operation, security, and improvement), or compliance with legal obligations. You may have rights of access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent. To exercise these rights, contact us at [email protected].

Third-Party Content and Services

Our site may reference third-party content or services. Your interactions with third parties are governed by their own policies and terms, which we do not control. We encourage you to review those policies when applicable.

Changes to This Notice

We may update this Data Protection page from time to time. Material changes will be indicated by updating the effective date below and, where required, additional notice. Your continued use of the site after an update signifies acceptance of the revised notice.

Effective Date

Effective: September 15, 2025