Legal

Privacy Policy

How we collect, use, and protect your information.

Last updated · 25 August 2026

This Privacy Policy explains how Replionix Solutions (“Replionix”, “we”, “us”) collects, uses, protects, and processes information when hospitals and healthcare organizations use our platform. We are committed to protecting your information and maintaining transparency regarding data processing, in line with Saudi Arabia’s Personal Data Protection Law (PDPL) and, where applicable, the EU General Data Protection Regulation (GDPR).

1. Information We Collect

Replionix primarily processes business and operational inventory information provided by hospitals and healthcare organizations. We collect the following categories of information:

Inventory and Operational Data

When customers upload CSV exports from ERP/HIS systems, we process inventory-related data including:

  • SKU catalogs, product names, and item categories
  • Stock quantities, physical inventory balances, and warehouse locations
  • Batch numbers and expiration dates
  • Cost prices and inventory valuations
  • Delivery lead times and pending purchase requests
  • Average daily consumption rates
  • Alternative item references

This data belongs to you. We process it solely to provide the Service.

Account Information

We collect:

  • Organization name
  • User names and email addresses
  • Account credentials

Contact and Demo Requests

When you submit our contact or demo request form, we collect your name, job title, organization, email address, phone number, area of interest, and any message you provide.

Technical Data

Standard server logs necessary to operate and secure the platform, including IP address, browser type, device information, pages visited, usage logs, and security event logs.

2. Information We Do Not Intentionally Collect

Replionix is not designed to collect or process:

  • Patient health records or medical histories
  • Clinical or diagnostic information
  • Patient identifiers or demographics
  • Protected Health Information (PHI) as defined by HIPAA or equivalent regulations

Customers should not upload such information into the platform. If we become aware that such data has been uploaded, we will work with the customer to delete it promptly.

3. How We Use Information

We use the information we collect to:

  • Provide inventory analytics through our four intelligence engines (Inventory Control, Expiry Control, Stockout Control, and PR Prioritization)
  • Generate deterministic inventory calculations, recommendations, and executive summaries
  • Calculate dynamic reorder points, expiry risk clusters, and stockout predictions
  • Score and validate purchase requests
  • Produce reports, dashboards, and PDF/CSV exports
  • Respond to your enquiries and schedule demos or pilots
  • Maintain, secure, and improve the platform
  • Send service-related communications you have requested
  • Develop new features and improve forecasting models

4. Legal Basis for Processing

We process personal data on the following legal bases:

  • Consent: when you voluntarily submit a contact form, demo request, or pilot application
  • Contract performance: when processing is necessary to provide the Service to registered customers
  • Legitimate interest: for operating, securing, and improving our platform

5. Automated Decision Processing

The current Replionix calculation path uses documented arithmetic and business rules, not a machine-learning or generative-AI model. Automated processing includes:

  • Days-of-stock and consumption-rate calculations
  • Expiry exposure grouping and batch-level valuation
  • Reorder-point and suggested-quantity calculations
  • Lead-time-cover risk classification
  • Purchase recommendation priority rules
  • Rules-based executive summary assembly from approved datasets

Outputs depend on the completeness and accuracy of the uploaded dataset and configured assumptions. They are decision-support tools, not directives. Customers remain solely responsible for all business decisions.

6. Demo Data Processing

When prospective users upload CSV files through our public interactive demo, the data is processed in memory only and is not stored on our servers after the session ends. No demo data is persisted, shared, or used for any purpose beyond generating the instant analysis results displayed to the user during that session.

7. Data Sharing

Replionix does not sell customer information.

We may share information only with:

  • Infrastructure and service providers: cloud hosting, database, and security providers necessary to operate the platform, who are contractually required to maintain appropriate confidentiality and security standards
  • Legal authorities: when required by law, regulation, or valid legal process

See our Security page for details on our infrastructure partners and security practices.

8. Data Security

We implement reasonable safeguards including:

  • TLS encryption for all data in transit
  • Encryption at rest for stored data in managed cloud databases
  • Access controls and authentication mechanisms
  • Rate limiting and abuse prevention
  • Security monitoring and logging

Despite these measures, no internet-based service is completely secure. We continuously work to improve our security posture and are transparent about our current status on our Security page.

9. Data Retention

We retain customer information only as long as necessary to:

  • Provide the Service and fulfill contractual obligations
  • Maintain security and audit records
  • Comply with legal and regulatory requirements

Customers may request deletion of their data at any time, subject to contractual and legal obligations.

10. International Data Transfers

Because Replionix may serve organizations in the GCC, Asia, Africa, and other regions, information may be processed in countries other than the customer’s location. We take reasonable steps to ensure appropriate protection of transferred information in accordance with applicable data protection laws.

11. Your Rights

Depending on applicable laws (including the Saudi PDPL and GDPR), you may have the following rights:

  • Access your personal data and request a copy
  • Correct inaccurate or incomplete information
  • Request deletion of your personal data
  • Restrict or object to certain processing activities
  • Withdraw consent at any time (where processing is based on consent)
  • Request information about how your data is handled

To exercise any of these rights, email info@replionix.com.

12. Cookies and Analytics

Replionix may use cookies and analytics technologies to maintain platform functionality, understand usage patterns, improve user experience, and monitor security. We do not use third-party advertising or tracking cookies.

Users may control cookie preferences through their browser settings. For more details, see our Cookie Policy.

13. Children’s Privacy

Replionix is a business-to-business platform designed for use by hospitals and healthcare organizations. It is not intended for use by children. We do not knowingly collect information from individuals under applicable child privacy age requirements.

14. Changes to This Policy

We may update this Privacy Policy periodically. Updated versions will be published on this page with a revised effective date. For material changes, we will make reasonable efforts to notify active customers in advance.

15. Contact Us

For privacy-related questions or data rights requests, contact us at info@replionix.com or visit our Contact page.

For security concerns, contact security@replionix.com.

Replionix Solutions
Jeddah, Saudi Arabia
www.replionix.com