Legal · Privacy Policy
Privacy Policy
Last updated: April 2026
1. Who we are
Distrolens is a pharma distributor intelligence platform operated by ORFEO. We help pharmaceutical and medtech manufacturers find verified distributors in emerging markets. Our registered address and contact details are available on request at privacy@distrolens.com.
2. What data we collect
We collect the following categories of personal data:
- Account data: name, email address, company name, role — provided when you register.
- Usage data: pages visited, searches performed, reports generated — collected automatically via server logs.
- Billing data: payment method details are processed directly by Stripe and never stored on our servers.
- Business contact data: names, titles, and professional email addresses of pharma distributor personnel sourced from public regulatory registries, company websites, and professional directories.
3. How we use your data
- To provide, operate, and improve the Distrolens platform.
- To process payments and manage subscriptions via Stripe.
- To send transactional emails (password reset, billing receipts).
- To compile and maintain our distributor database from public sources.
- To comply with legal obligations.
We do not sell your personal data to third parties.
4. Legal basis (GDPR)
For users in the European Economic Area, our legal bases are:
- Contract performance — to deliver the service you subscribed to.
- Legitimate interests — to improve the platform and prevent fraud.
- Legal obligation — to comply with applicable law.
- Consent — where we ask for it explicitly (e.g. marketing emails).
5. Data retention
Account data is retained for the duration of your subscription plus 12 months after cancellation, unless a longer period is required by law. Usage logs are retained for 90 days. You may request deletion at any time.
6. Data sharing
We share data only with:
- Stripe — payment processing.
- Resend / Amazon SES — transactional email delivery.
- Vercel / Neon — hosting and database infrastructure.
- Sentry — error monitoring (anonymized stack traces only).
7. Your rights
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion ("right to be forgotten").
- Object to or restrict processing.
- Data portability (receive your data in a machine-readable format).
- Lodge a complaint with your local data protection authority.
8. Cookies
We use only strictly necessary session cookies for authentication. We do not use tracking or advertising cookies.
9. Security
Data is encrypted in transit (TLS 1.3) and at rest. Access is restricted to authorised personnel. We conduct regular security reviews.
10. Changes to this policy
Material changes will be communicated by email to active subscribers at least 14 days before taking effect. The date at the top of this page reflects the most recent revision.
11. Contact
Questions about this policy: privacy@distrolens.com