1. Scope and role
This Business Privacy Notice describes the information practices of Pharma Americas Group LLC (collectively, “Pharma Americas,” “we,” “us,” or “our”) for this website, program-review intake, approved client accounts, order requests, service communications, quality and complaint communications, and related business operations.
The website and client portal are designed for business representatives acting for qualified organizations—not for personal, household, patient-care, or consumer purchasing. This notice is not a HIPAA Notice of Privacy Practices. Do not submit protected health information, patient records, medical records, or direct patient identifiers through a public form, checkout note, or ordinary email. If an engagement could require Pharma Americas to receive protected health information as a business associate, the parties must first complete an appropriate written agreement and approve a secure exchange method.
2. Information we collect
- Business identifiers and contact data, including name, job title, organization, organization website, business email, business phone, country, state or region, and communications preferences.
- Qualification and due-diligence data, including organization type, intended markets, service interests, program objectives, estimated program range, timing, qualifications, professional oversight, referral source, and information used to assess eligibility or transaction risk.
- Account and authentication data, including approved organization, approved email, securely derived password credentials, session records, account status, failed-login activity, lockout status, and last-login information.
- Order and transaction data, including items, quantities, price snapshots, organization and contact snapshots, delivery address, payment preference, notes, order status, and related commercial records. This website does not request or store payment-card numbers or bank-account credentials.
- Quality, complaint, safety, and compliance information, including order and lot identifiers, product or service issue details, photographs, shipment or temperature records, disposition communications, and reporting information provided by a business contact.
- Technical and security information, including request headers, IP-derived security signals where available to our infrastructure, timestamps, logs, browser or device information, and information needed to detect fraud, abuse, or unauthorized access.
- Optional website analytics information collected only after consent, including page paths without query strings, referring channel, general browser or device information, approximate geography supplied by the analytics service, and aggregate success events such as a completed program review, access application, approved-client sign-in, or order request. We do not intentionally send form contents, names, email addresses, phone numbers, passwords, order contents, patient information, health information, or direct identifiers to the analytics service.
- Device-local cart data. The client portal may store the current cart in the browser’s local storage for the approved user’s convenience.
3. Sources of information
We receive information directly from you or your organization, from use of our systems, from approved suppliers and service partners, from payment, logistics, quality, professional, or compliance partners involved in a requested program, and from public or authoritative sources used for business verification, sanctions screening, credential review, fraud prevention, or legal compliance.
4. How we use information
- Evaluate program-review requests, organizational eligibility, intended use, transaction risk, and appropriate next steps.
- Create, administer, secure, suspend, or terminate approved client accounts.
- Prepare quotes, review order requests, confirm availability, coordinate documentation, arrange fulfillment, process payment through approved channels, and provide account support.
- Coordinate quality questions, complaints, shipment issues, safety escalations, evidence requests, recalls, corrections, and required or appropriate reporting.
- Authenticate users; detect, investigate, and prevent fraud, credential misuse, diversion, sanctions or export-control risk, unlawful activity, security incidents, and violations of our policies.
- Maintain business, tax, accounting, contractual, audit, compliance, quality, dispute, and litigation records; enforce agreements; protect legal rights; and comply with lawful process.
- Operate, debug, measure, secure, and improve the website and client experience.
- Send transactional, service, safety, account, or relationship communications and, where permitted, relevant business marketing communications. Recipients may opt out of marketing without affecting necessary transactional or safety messages.
5. How we disclose information
We may disclose information to service providers and infrastructure vendors working for us; suppliers, laboratories, fulfillment partners, carriers, customs or trade professionals, payment providers, advisors, and other parties needed to evaluate or perform a requested program; the organization you represent; professional advisors; regulators, courts, law enforcement, or other authorities where required or appropriate; and transaction counterparties in connection with financing, reorganization, sale, merger, or transfer of all or part of the business.
When a visitor permits optional analytics, Google Analytics acts as an analytics service provider for aggregate website measurement. We configure the integration to avoid advertising personalization and Google signals, omit URL query strings from page-location reporting, and limit our event design to non-identifying business outcomes.
Disclosures are limited to the purpose and context reasonably necessary for the relationship, transaction, security review, legal obligation, or instruction. We may also disclose aggregated or de-identified information that does not reasonably identify an individual.
6. No sale or behavioral-advertising sharing
Based on the website practices described in this notice, Pharma Americas does not sell personal information for money and does not share personal information for cross-context behavioral advertising. We may disclose business information to service providers and transaction partners for the operational purposes described above; those disclosures are not a sale merely because a commercial relationship exists.
7. Cookies, sessions, and local storage
The approved client portal uses a strictly necessary, HttpOnly, Secure, SameSite session cookie to maintain authenticated access. The normal session period is approximately twelve hours, subject to earlier expiration, logout, account suspension, security action, or system changes. The portal may use device-local browser storage to retain a cart for the approved account on that device. Clearing site data may remove the cart and session.
Google Analytics is optional and does not load until the visitor selects “Allow analytics.” If allowed, Google Analytics may set first-party identifiers such as _ga cookies to distinguish aggregate visits. The site stores the visitor’s analytics choice in local browser storage. A visitor may decline initially or reopen “Privacy choices” to withdraw permission; withdrawal stops future analytics collection from that browser and directs the site to remove accessible analytics cookies.
We do not use the analytics integration for advertising personalization, and declining optional analytics does not restrict the public website, program-review form, client sign-in, portal, or ordering workflow. We do not promise that future functionality will use exactly the same technologies. If our use of nonessential cookies or advertising technologies materially changes, this notice and any required preference controls will be updated.
8. Retention
We retain information for the period reasonably necessary to evaluate and administer the relationship, complete transactions, maintain security and audit trails, support quality or safety activities, meet tax, accounting, contractual, regulatory, recordkeeping, insurance, dispute, and legal requirements, enforce our rights, and preserve evidence. Retention periods vary by record type, product, role, jurisdiction, and unresolved obligation.
We may retain de-identified information and records that must be preserved by law, contract, legal hold, safety need, or legitimate defense even after an account is closed or another record is deleted.
9. Security and account responsibility
We use administrative, technical, and organizational measures designed to protect information in light of its nature and the way the service operates. No transmission, storage system, or security control can be guaranteed to be completely secure. Approved users are responsible for safeguarding credentials, limiting account access to authorized personnel, using secure devices, and promptly reporting suspected compromise.
Do not send passwords, payment-card data, bank credentials, protected health information, or sensitive technical records through public forms or ordinary email unless Pharma Americas has expressly approved the method and requested the information.
10. Privacy choices and rights
Depending on applicable law and your relationship with us, you may request access, correction, deletion, restriction, portability, or information about certain disclosures; withdraw a consent where processing depends on consent; appeal a denied privacy request; or use an authorized agent. Rights are subject to identity and authority verification and to legal, security, evidentiary, contractual, and other permitted exceptions.
We will not unlawfully discriminate against a person for exercising an applicable privacy right. Requests should be sent to the contact listed on this policy and should identify the organization, business email, request, jurisdiction, and the authority under which the request is made. We may contact the organization represented by the requester when necessary to verify authority.
11. Children and international processing
The services are not directed to children or persons under eighteen, and Pharma Americas does not knowingly approve minors for client access. Information may be processed in the United States and other locations where our service providers or transaction partners operate, subject to applicable contractual and legal safeguards.
12. Changes and contact
We may update this notice to reflect changes in our services, law, risk profile, or practices. The posted effective date identifies the current version. Material changes will be communicated as required by applicable law. Privacy and security questions may be sent to quality@pharmaamericasgroup.com.
Official federal references
These primary sources inform the published operating baseline. They are not endorsements, licenses, or legal determinations about Pharma Americas or any client, product, supplier, destination, or transaction.
Federal business guidance on data minimization, access control, authentication, security, vendor oversight, and incident response.
Open official source ↗Federal Trade CommissionConsumer Privacy and SecurityFederal privacy, data-security, and truth-in-privacy-practices guidance.
Open official source ↗U.S. Department of Health and Human ServicesCovered Entities and Business AssociatesPrimary explanation of when HIPAA applies and when a written business associate arrangement is required.
Open official source ↗Federal Trade CommissionCAN-SPAM Act: A Compliance Guide for BusinessFederal requirements for commercial email, including business-to-business messages.
Open official source ↗
Client access