PRIVACY POLICY
How ScriptWise handles personal data
Effective 15 August 2026 · Version 1.0
1. Who we are
ScriptWise ("the Registry", "we", "us") is a prescription-fill registry operated on behalf of the Cayman Islands healthcare sector and made available to licensed pharmacies, prescribing doctors and the Ministry of Health. For the purposes of the Data Protection Act (2021 Revision) ("the DPA"), the operator of ScriptWise is the data controller for the Registry. Participating pharmacies and practices remain controllers of the records they hold in their own systems.
Contact for data protection matters: privacy@scriptwise.ky.
2. What personal data we hold
2.1 Patient data
Recorded by the pharmacy or prescriber when a patient is first registered or a script is filled:
- Identity — name, date of birth, gender, national identification number where captured;
- Contact — phone number, email address and address where captured;
- Health data — the medications dispensed to you (name, strength, quantity, days' supply, prescriber, dispensing pharmacy and dates), scripts written for you and images of scripts you present, and any allergies or primary physician you disclose;
- Registration facts — which pharmacy registered you and when.
2.2 Professional user data
For pharmacists, prescribers, administrators and Ministry users: name, work email, phone number, professional role, the pharmacy or practice you work at, sign-in activity, and two-factor authentication enrolment.
2.3 Operational data
Audit trails of who accessed or changed what and when; billing records per pharmacy (which never contain patient identifiers); and technical logs required to run the service securely.
3. Why we process it and on what basis
- Preventing duplicate and unsafe dispensing. When a pharmacist looks a patient up, the Registry shows what has already been dispensed across participating pharmacies and flags overlapping supply. This is processing necessary for the provision of health care and in the substantial public interest of medicines safety.
- Prescriber workflow. Doctors may register a patient and issue a script through the Registry so it can be filled at any participating pharmacy.
- Public-health oversight. The Ministry of Health sees aggregate, patient-anonymous statistics only — dispensing volumes, trends, duplicate-attempt counts and import-versus-dispensing comparisons. Ministry views never contain patient identifiers.
- Security, audit and legal obligation. Access logging, fraud prevention and compliance with the DPA and healthcare regulation.
- Running the service. Authenticating users, sending account emails, and billing participating pharmacies for their use of the Registry.
4. How we protect it
- Encryption at rest. Patient-identifying fields are encrypted with authenticated encryption before storage. Fields that must remain searchable (for example a surname) are additionally protected with keyed blind indexes rather than stored in the clear.
- Encryption in transit. All connections use TLS.
- No public exposure. The registries that hold patient data are internal-only services, reachable solely by the ScriptWise application tier with per-service credentials — never directly from the internet.
- Least privilege. Every screen is role-restricted; pharmacy staff see only what dispensing requires, prescribers see their prescribing tools, and Ministry users see aggregates only.
- Accountability. Every access to a patient record is logged against the professional user's registration. Users are told at sign-in that access is audited.
- Strong authentication. Confirmed email accounts, account lockout, and two-factor authentication.
5. Who we share it with
We do not sell personal data and do not share it for marketing. Personal data is disclosed only:
- to participating pharmacies and prescribers, strictly in the course of dispensing to or prescribing for you;
- to the Ministry of Health, in patient-anonymous aggregate form only;
- to service providers who host or support the Registry under contract and confidentiality (for example email delivery), who may process data only on our instructions;
- where required by law, a court order or a regulator with lawful authority.
6. How long we keep it
Dispensing records are retained for as long as needed to serve the Registry's medicines-safety purpose and to meet healthcare record-keeping obligations, after which they are deleted or irreversibly anonymised. Audit logs are retained for the period required for security and accountability. Billing records, which contain no patient identifiers, are retained per financial record-keeping requirements. Where you exercise your right to erasure (section 7), your registry data is removed as described there.
7. Your rights
Under the DPA you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erasure — ScriptWise provides a "Remove My Data" process through which your registry records (patient record, dispensing history and uploaded scripts) are deleted across all internal registries. Erasure requests are actioned by a system administrator and are themselves logged. Billing records are retained because they contain no patient identifiers;
- Restrict or object to processing in certain circumstances;
- Complain to the Office of the Ombudsman of the Cayman Islands if you believe your data has been mishandled.
To exercise any right, contact your pharmacy or write to privacy@scriptwise.ky. To request erasure directly, use our data erasure request form. We may need to verify your identity before acting.
8. Cookies
ScriptWise uses only strictly-necessary cookies: an authentication cookie that keeps you signed in, an anti-forgery cookie that protects forms, a short-lived status cookie for account messages, and a theme preference. We do not use advertising or third-party analytics cookies.
9. International transfers
The Registry is hosted for the Cayman Islands. Where a service provider processes data outside the Islands, we ensure appropriate safeguards are in place as required by the DPA.
10. Changes to this policy
We may update this policy as the Registry evolves. The effective date at the top of this page shows the current version; material changes will be notified to professional users at sign-in.
See also our Terms & Conditions.