Legal
How information is handled across the Aether pharmacy network.
Your privacy across Aether
This policy explains what information may be processed, why it is used, how it is protected, and the choices available to you.
Last updated: September 5, 2026
Aether Pharmacy Network operates the Aether multi-tenant pharmacy platform. Each listed pharmacy controls the pharmacy-specific records it creates or receives through its storefront and staff workspace, while Aether operates the shared platform, security, account, infrastructure and support services. Questions can be sent to support@gtss.software or +254790670542.
Information is used to provide pharmacy services; authenticate accounts; process prescriptions, refills, orders, bookings and payments; support medication adherence and caregiver features; provide customer/pharmacist communication; detect abuse and security incidents; maintain audit records; improve reliability; and comply with applicable legal, professional and regulatory obligations.
Prescription, adherence, screening, vaccination, symptom and related records may be sensitive health information. Access is restricted by account, pharmacy and role permissions. Optional symptom images are stored in private object storage and are served through short-lived application-authorised access. Do not use the website or AI assistant as an emergency service. In Kenya call 999 or 112 when urgent emergency help is required.
Some features use an external AI model provider to generate educational or support responses. The platform is designed to minimise the information sent. Detailed caregiver clinical context is disabled by default unless the deployment has explicitly enabled that processing. AI does not replace a pharmacist or doctor and must not be used to make emergency, diagnostic or prescribing decisions.
Different records have different operational, clinical, financial, security and legal retention needs. We retain information only for the applicable purpose and required period, then delete or anonymise it where appropriate. Some records may need to be preserved for legal, professional, accounting, fraud or audit requirements even after an account is closed.
Controls include tenant isolation, role-based access, database row-level security, protected sessions, encrypted integration credentials, private health-media storage, rate limiting and audit logging. Security reduces risk but no internet service can guarantee absolute security.
Subject to applicable law and record-retention obligations, you may request access, correction, deletion or other available controls over personal information. You can also manage communication preferences in the product. Requests may require identity verification before information is disclosed or changed.
Privacy questions or rights requests can be sent directly to our privacy contact.
support@gtss.software