endear.ai

Privacy Policy

Endear, Inc. · Endear Compliance Cloud and related services

Last updated: August 13, 2026

Endear, Inc. ("Endear," "we," "us," or "our") provides Endear Compliance Cloud, a DSCSA/CSA regulatory compliance product delivered as a Microsoft SharePoint web part and supporting backend services (the "Service"). This policy explains what information we collect, how we use it, and the choices available to you.

1. Information we collect

Account and business information, provided at trial signup or account setup: legal business name, EIN, NPI (dispensing practices) or GLN (distributors), contact name/email/phone, and business address.

Compliance/transaction data, generated through your use of the Service: serialized drug-product identifiers (GTIN, serial number, lot, expiry), EPCIS track-and-trace transaction records, and, for accounts with controlled-substance (CSA) tracking enabled, Schedule II-V order records including purchaser/supplier DEA numbers. This is supply-chain and transaction data, not clinical or patient health records -- see Section 6.

Billing information: for self-service paid accounts, payment is processed by Stripe, Inc.; we do not receive or store your full payment card number. For contract-billed distributor accounts, we retain billing/invoice records (amounts, dates, invoice status) but not payment card data.

Technical/usage information: standard web request logs (IP address, timestamps, error logs) generated by using the Service, retained for security and troubleshooting.

2. How we use this information

To provide the Service: provisioning your SharePoint site, enforcing trial/subscription limits, and enabling compliance recordkeeping and trading-partner document exchange.

To meet regulatory recordkeeping obligations DSCSA itself imposes on this category of data (a multi-year audit-trail retention requirement -- see Section 4).

To bill you (or, for distributors, your own downstream customers) for the Service.

To provide customer support when you contact us, and to send service-related notices -- not marketing, unless you separately opt in.

We do not sell your information, and we do not use your compliance/transaction data to train any product or model outside of operating the Service itself.

3. Where your data lives

Most of your day-to-day operational compliance records are created and stored on your own SharePoint site, inside your own Microsoft 365 tenant -- you retain ownership and administrative control of that data at all times, independent of your relationship with Endear.

A defined subset of data is also processed and retained on Endear’s own backend infrastructure (hosted on Microsoft Azure): account/billing records, consent and provisioning status, the compliance audit trail described in Section 4, and, for distributor accounts, trading-partner exchange records needed to route documents between your organization and your trading partners, who are structurally on a different Microsoft 365 tenant than yours.

4. Data retention

Compliance/transaction data (Section 1) is retained for a minimum of six years to meet DSCSA’s own regulatory recordkeeping requirement, independent of whether you remain an active customer.

Account and billing records are retained for the duration of your account and a reasonable period afterward for legal and accounting purposes; contact us to request deletion of data that is not subject to a regulatory retention requirement.

5. Sub-processors and third parties

We share information with service providers necessary to operate the Service, under contractual confidentiality and security terms: Microsoft Azure (hosting, Key Vault-managed secrets), Microsoft 365/SharePoint (your own tenant, which you control independently of us), and Stripe, Inc. (payment processing for self-service subscriptions). We may disclose information if required by law.

We do not share your information with third parties for their own independent marketing purposes.

6. Health information (HIPAA) note

Endear Compliance Cloud’s data model is built around supply-chain and controlled-substance-order data, not clinical treatment records. Depending on your specific integration (for example, an OpenEMR-connected deployment supplying an internal order/encounter reference), some fields may be linkable to an individual patient’s dispensing event. If this applies to your organization and you require a Business Associate Agreement, contact us at support@endear.ai to discuss.

7. Your choices and rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or export personal data we hold about you. Contact support@endear.ai to make a request; we will confirm the applicable process and timeline for your jurisdiction when you reach out.

8. Contact us

Questions about this policy, or requests regarding your data: support@endear.ai.

9. Changes to this policy

We will post material changes here with an updated "Last updated" date.