QD by Pharm·ology — Privacy Policy

Last updated: October 3, 2026 · Effective: October 3, 2026

1. Who we are

QD ("QD by Pharm·ology", "the Service") is a Model Context Protocol (MCP) connector operated by Pharm·ology ("Pharm·ology", "we", "us"), ApS, registered in Denmark, company CVR no. 45557898. Contact: contact@pharmology.dk. We are the data controller for the personal data described here.

2. Scope

This policy covers personal data processed when you connect to and use the QD MCP connector through an MCP client (for example, Claude). It does not cover our public websites (pharmology.ai, pharmology.dk) except where they host this policy, nor third-party services you reach independently.

3. What data we collect

We practice data minimization. When you connect and use QD we process:

  • Account / identity (via our authentication provider, Auth0): your email address and your Auth0 subject identifier (sub), plus the OAuth scopes/permissions granted to you. We do not receive or store your password; authentication is handled by Auth0.
  • Usage records (per request): a timestamp, your email/sub, your subscription tier, the command you invoked and its command text (which may contain the drug names, conditions, or trial identifiers you searched for), a success/error/denied status, and the request latency. These are stored to operate the Service, enforce entitlements, meter usage, and debug.
  • Technical data: standard server and transport metadata (e.g. IP address and request headers seen transiently by our hosting provider).

We do not ask for or intentionally process special-category data about you. The clinical and regulatory content QD returns is drawn solely from public sources (see §7) and is not personal health data about you. QD is read-only: it never writes your data into its corpus.

4. How we use your data and legal bases (GDPR)

Provide the Service

(authenticate you, run commands, return results) — performance of a contract (Art. 6(1)(b)).

Enforce entitlements and secure the Service

(verify your subscription, prevent abuse) — legitimate interests (Art. 6(1)(f)).

Meter and bill usage; maintain operational logs

— contract and legitimate interests.

Comply with legal obligations

(e.g. accounting) — Art. 6(1)(c).

We do not use your data for advertising, we do not sell it, and we do not use your queries to train machine-learning models.

5. Sharing and sub-processors

We share personal data only with service providers that process it on our behalf under contract:

We may disclose data if required by law. If we undergo a business transfer, data may be transferred subject to this policy.

6. International transfers

Both of our sub-processors are configured to process your data in the EU/EEA, so primary processing stays within the EEA. Where a residual transfer outside the EEA can occur, it is covered by appropriate safeguards under the relevant provider's Data Processing Addendum:

  • Northflank is a UK company. Processing on UK infrastructure is covered by the European Commission's UK adequacy decision; any Northflank region outside the EEA/UK is covered by the EU Standard Contractual Clauses (with the UK Addendum).
  • Auth0's parent, Okta, Inc., is US-based. Where identity data is routed to US infrastructure, Auth0 relies on the European Commission's modernised Standard Contractual Clauses incorporated in its Data Processing Addendum.

We keep a Data Processing Addendum with each provider on file.

7. Data sources of the content we return

QD's clinical and regulatory content is extracted from public sources and attributed in-product — clinical-trial registries (including ClinicalTrials.gov and EU CTIS), national and regional medicines regulators (including the FDA and EMA), regulatory guidance, and biomedical literature (PubMed). This content is not personal data about you.

8. Retention

Usage records

Retained for 24 months for operations, security, and billing, then deleted or aggregated.

Account/identity

Retained for the life of your subscription and 2 years thereafter, subject to legal retention requirements.

Aggregated/anonymized statistics

May be kept indefinitely.

9. Security

Access is authenticated via OAuth 2.0/OIDC (Auth0) with per-user entitlements; QD permits only read-only (SELECT) queries; entitlement and usage tables are never exposed through user queries; data is transmitted over HTTPS/TLS. No system is perfectly secure, but we apply measures appropriate to the risk.

10. Your rights

Subject to applicable law (including the GDPR), you may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests. To exercise these rights contact contact@pharmology.dk. You may also lodge a complaint with your supervisory authority (in Denmark, Datatilsynet).

11. Children

QD is a professional tool not directed to children and is not intended for anyone under 18.

12. Changes

We may update this policy; material changes will be posted here with a new "Last updated" date.

13. Contact

Pharm·ology ApS — contact@pharmology.dk.