Effective date: July 17, 2026 · Last updated: August 24, 2026
ComplyRx ("ComplyRx," "we," "us," or "our") provides a clinical
operations platform used by healthcare clinics ("Clinics," "Customers") to manage treatment
tracking, controlled-substance inventory, DEA recordkeeping, and REMS (Risk Evaluation and Mitigation Strategy)
program compliance for esketamine/Spravato treatment. This Privacy Policy explains what information we collect,
how we use and protect it, and the choices available to you. It applies to our website, our web application, and
related services (together, the "Services").
1. Who this policy covers
This policy covers two distinct groups of people, and it's important to understand which one applies to you:
Clinic staff and administrators who create an account and use the Services to do their jobs
(clinicians, nurses, pharmacy/inventory staff, clinic administrators). For you, we act largely as an ordinary
software provider — we describe below what account and usage information we collect about you directly.
Patients of a Clinic whose health information is entered into the Services by that Clinic's
staff (for example, treatment charts, medication administration records, prior-authorization documents, or a
completed PHQ-9 screening). ComplyRx does not have a direct relationship with patients and does not collect
patient information from patients themselves except in the narrow, clearly-labeled cases described in
Section 13 (for example, an emailed link to complete a PHQ-9 questionnaire, or a
link to review and electronically sign an enrollment form).
This policy also covers visitors to our marketing website who are not yet Clinic customers (for example, if you
submit a contact or demo-request form).
2. Our role & protected health information
Clinics use the Services to store and process protected health information ("PHI") as defined
by the U.S. Health Insurance Portability and Accountability Act ("HIPAA") — including patient names, dates of
birth, contact information, diagnoses, medications, treatment session data, prior authorization details, and
REMS program submissions.
With respect to that PHI, the Clinic is the HIPAA Covered Entity and ComplyRx acts as its
Business Associate under a Business Associate Agreement ("BAA") executed with each Clinic. We
process PHI only as instructed by the Clinic and only to provide, secure, and support the Services — never for
our own independent marketing or advertising purposes, and never to build product outside the scope the BAA and
the Clinic's instructions permit.
If you are a patient with a question about how your specific health information is used, please contact your
Clinic directly — they control that data and can direct you to their own Notice of Privacy Practices. See
Section 13 for more detail.
3. Information we collect
A. Information Clinics and their staff provide to us
Account & identity data — name, work email address, role (admin/staff), and a hashed
password (accounts are provisioned by a Clinic administrator; we do not offer public self-signup).
Clinic configuration data — clinic name, address, DEA registration number, prescriber
credentials and signature, fax and email destinations for REMS submission, and similar practice-level
settings.
Integration credentials — OAuth tokens for connected services the Clinic authorizes, such as
a fax provider, Google Workspace, or Microsoft 365 mailbox, used solely to send required REMS submissions and
related notifications on the Clinic's behalf.
B. Patient/clinical information entered by a Clinic (processed as a Business Associate)
Patient demographics (name, date of birth, sex, contact details, address).
Treatment records — dosing sessions, vitals, monitoring observations, adverse-event reports, and checkout
details.
Medication-inventory and DEA recordkeeping data — lot/serial numbers, receipt/dispense/disposition records,
and related controlled-substance audit trails.
Enrollment, prior-authorization, PHQ-9 screening, and other uploaded or generated clinical documents.
Communications records related to required regulatory submissions (for example, fax and email transmission
logs to the REMS program).
We do not decide what patient information a Clinic collects or how long the Clinic wants a given record kept —
those decisions belong to the Clinic.
C. Information collected automatically
Usage & device data — pages viewed, actions taken, timestamps, browser/device type, and
IP address, used for security, troubleshooting, and improving the Services.
Audit & activity logs — a record of who did what and when within the Services (for
example, who viewed or edited a record), which we maintain to support the Clinic's own compliance and security
obligations.
Cookies and local/session storage — used to keep you signed in, remember your interface
preferences (such as light/dark theme), and support core functionality. See Section 10.
C-1. The ComplyRx mobile apps (iOS and Android)
The ComplyRx mobile applications provide the same Services described in this policy inside a native app.
In addition to the practices above, the mobile apps use the following device capabilities. Each is optional,
requested through the operating system's standard permission prompt, and can be revoked at any time in your
device settings:
Camera — used only to scan medication box barcodes and labels for inventory intake and
treatment verification. Images and barcode data are processed for that workflow; the camera is never used
for any other purpose.
Face ID / Touch ID / fingerprint — used only to unlock the app after it has been in the
background. Biometric matching is performed entirely by your device's operating system; ComplyRx never
receives, stores, or transmits your biometric data — the app is only told whether the unlock succeeded.
Notifications — used for treatment-timer reminders and operational alerts. Notifications
shown on a lock screen are designed to contain patient initials only, never full names or other
identifying details.
App badge and vibration — used to surface how many patients are currently ready and to
accompany reminders.
The mobile apps contain no advertising, no third-party analytics or tracking SDKs, and do not
access your contacts, photos, or location. All data handling otherwise follows the practices described in the
rest of this policy, including the Business Associate commitments in Section B.
D. Information from website visitors who are not Clinic users
If you fill out a contact form, request a demo, or otherwise reach out to us through our marketing website, we
collect the information you choose to provide (such as your name, email, organization, and message) so we can
respond.
4. How we use information
We use information to:
Provide, operate, secure, and maintain the Services, including patient charting, inventory/DEA
recordkeeping, and REMS submission workflows;
Authenticate users and enforce clinic-level and role-based access controls;
Generate and transmit required regulatory forms and submissions on a Clinic's behalf, at that Clinic's
direction (for example, faxing or emailing a completed monitoring form to a REMS program);
Detect, investigate, and prevent fraud, unauthorized access, and other security incidents;
Provide customer support and respond to Clinic inquiries;
Maintain audit trails required for controlled-substance and regulatory compliance;
Improve and troubleshoot the Services (for example, using de-identified or aggregated usage patterns); and
Comply with our legal obligations, including our obligations under a Clinic's Business Associate Agreement.
We do not sell personal information or PHI, and we do not use PHI to serve targeted
advertising.
5. Why we process information
We process information because it is necessary to perform our contract with the Clinic (our Customer), to
comply with legal and regulatory obligations that apply to healthcare recordkeeping (including HIPAA and DEA
requirements), and — for limited operational purposes like security monitoring and service improvement — based
on our legitimate interest in operating a safe and reliable platform, balanced against your privacy interests.
6. How we share information
We disclose information only as described here — never as a general matter of course:
With the Clinic itself — the Clinic that entered or manages a record can access it, subject
to its own internal role-based permissions.
With service providers acting on our behalf — see Section 7 for
the categories of vendors we use and why. These providers are contractually bound to protect the information
and to use it only to provide services to us.
For required regulatory submissions — a completed monitoring form or related documentation
is transmitted (by fax or email) to the applicable REMS program, exactly as a Clinic's own staff would
otherwise do manually.
To comply with law — if required by valid legal process such as a subpoena, court order, or
similar legal obligation.
To protect rights and safety — where we believe in good faith that disclosure is necessary
to investigate or prevent fraud, security incidents, or harm to any person.
In connection with a corporate transaction — such as a merger, acquisition, financing, or
sale of assets, subject to appropriate confidentiality protections and, where PHI is involved, in a manner
consistent with HIPAA.
We do not disclose PHI to any third party for that third party's own independent marketing purposes.
7. Sub-processors & service providers
To provide the Services we rely on a limited set of vetted infrastructure and communication providers, each
bound by contract (and, where PHI is involved, a Business Associate Agreement) to safeguard information and use
it only to provide services to us:
Category
Purpose
Cloud database & application hosting
Secure storage of application data and hosting of the web application.
Static site / content delivery hosting
Hosting and delivery of the website and application front end.
Fax transmission provider
Sending required regulatory monitoring forms to the REMS program by fax, at a Clinic's direction.
Email service providers (customer-connected)
Sending required regulatory submissions and questionnaire links by email, using a mailbox the Clinic itself authorizes and controls.
AI/document-processing provider
Assisting with document data extraction, form auto-fill, and similar automation features. See Section 8.
Transactional email provider (ComplyRx-operated)
Sending account and service emails we originate — staff invitations, password resets and similar notices. Distinct from the customer-connected mailboxes above, which a Clinic authorizes and controls.
Payment processing
Processing Clinic subscription payments. Receives Clinic billing contact and payment details; receives no patient information.
Identity provider
Authenticating staff sign-in and managing multi-factor authentication.
Cloud compute provider
Running the automated processes that submit required regulatory forms on a Clinic's behalf.
Manufacturer copay & patient-support program
Submitting a patient's enrollment to the medication manufacturer's copay-support program, at a Clinic's direction and where the patient has agreed to enroll. Operated by the program sponsor, not by ComplyRx.
Benefits & prior-authorization clearinghouse
Checking pharmacy benefits and submitting prior-authorization requests to payers on a Clinic's behalf.
SPRAVATO REMS program
Receiving the enrollment and monitoring forms the program requires, at a Clinic's direction. Operated by the program sponsor, not by ComplyRx; a Clinic's obligations to the program are set by the program itself.
We maintain an up-to-date list of sub-processors and will notify Clinics of material changes as required by our
agreements with them.
8. Use of AI in the Services
Certain features use a third-party AI model to help extract information from uploaded documents (for example,
reading a pharmacy label, a prior-authorization letter, or a patient intake form) or to answer natural-language
questions about a Clinic's own aggregated, clinic-scoped data in our analytics tool. These requests are made
through a vetted AI provider under contractual terms that prohibit using the submitted content to train that
provider's general-purpose models. Any suggested extraction is always presented to Clinic staff for review and
confirmation before it is saved — the Services do not make unreviewed clinical decisions.
9. Google API Services & Limited Use
ComplyRx's use of information received from Google APIs adheres to the
Google API Services
User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from
Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
What we access. When a Clinic administrator connects a Google Workspace mailbox, we request
only the gmail.send scope (permission to send email on the connected account's behalf) and the
userinfo.email scope (the connected account's email address, shown in Settings so the Clinic can
see which mailbox is connected). We never read, list, modify, or delete any email in the connected mailbox,
and we do not receive or store any Gmail message content.
How we use it. The send permission is used solely to transmit required regulatory
submissions (for example, SPRAVATO REMS monitoring and enrollment forms) and related questionnaire links from
the Clinic's own verified mailbox, at the Clinic's direction.
Transfer. Google user data is never sold and never transferred to third parties, including
data brokers, advertisers, or any third-party AI/ML service. It is never used for advertising, lending or
credit decisions, or any purpose other than providing the sending feature the Clinic connected it for.
AI/ML. No Google user data is used to develop, improve, or train any AI or machine-learning
model, and no Google user data is transmitted to the AI provider described in Section 8. The AI features of
the Services operate only on documents and data a Clinic uploads directly — never on Gmail data.
Protection, retention & deletion. OAuth tokens are stored encrypted at rest, are
accessible only to the connected Clinic's authorized workflow, and are protected by the safeguards described
in Section 10. Disconnecting the integration in Settings removes the stored tokens from our systems, so
ComplyRx can no longer use them. That does not by itself revoke the underlying authorization at
the provider — to withdraw it there as well, revoke access at
myaccount.google.com/permissions
(Google) or the equivalent Microsoft account page.
10. How we protect information
We maintain administrative, technical, and physical safeguards designed to protect information against
unauthorized access, disclosure, alteration, and destruction, including:
Encryption of data in transit (TLS) and at rest;
Role-based access controls and row-level data isolation between Clinics ("multi-tenant" access controls),
so one Clinic cannot see another Clinic's data;
Audit logging of access to and changes made within clinical records;
Least-privilege access for our personnel, granted only as needed to provide support or maintain the
Services;
Ongoing monitoring and periodic review of our security configuration.
No system can be guaranteed 100% secure. If we become aware of a security incident affecting PHI, we will
notify affected Clinics in accordance with HIPAA and our Business Associate Agreement, and Clinics remain
responsible for any patient notifications required under applicable law.
11. Data retention
We retain information for as long as a Clinic's account is active and as needed to provide the Services,
including to meet the recordkeeping periods required for controlled-substance and other regulatory compliance
(which can be several years). When a Clinic's account is closed, we retain or return data as required by our
agreement with that Clinic and applicable law, and otherwise securely delete or de-identify it. Append-only
compliance and audit records (such as DEA transaction logs) are, by design, never altered or deleted during the
required retention period.
12. Cookies, local storage & notifications
We use cookies and browser local/session storage that are strictly necessary to keep you signed in, remember
basic interface preferences (like light/dark mode), and maintain security — we do not use third-party
advertising or cross-site tracking cookies. If you enable push notifications (for example, to be alerted when a
patient is ready for their next treatment step), your browser stores a subscription token used solely to
deliver those notifications; you can disable this at any time in your device or browser settings, or in the
Services' own notification settings.
13. Your choices & rights
If you are Clinic staff: you may access or update your own account profile within the
Services, and a Clinic administrator can update or remove your account access. Depending on your location, you
may also have rights to request access to, correction of, or deletion of your personal account information —
contact us using the details in Section 17, or your Clinic administrator.
If you are a patient of a Clinic: your rights regarding your health information — including
rights to access, amend, or receive an accounting of disclosures of your records — are exercised through your
Clinic, which is the party responsible for that information under HIPAA. See Section 13.
14. Notice for patients of a Clinic
If your healthcare provider uses ComplyRx, some of your health information may be stored in our systems. We do
not control what information a Clinic collects about you, how long it is kept, or who at that Clinic can see
it — those choices, and the obligation to give you a Notice of Privacy Practices, belong to your Clinic.
In a small number of cases, we may contact you directly at your Clinic's request and using contact information
your Clinic provides — for example, to send you a secure link to:
electronically review and sign a REMS enrollment form; or
complete a PHQ-9 depression screening questionnaire.
These links are single-purpose, time-limited, and access-controlled. We do not use the information you submit
through them for any purpose other than delivering it back to your Clinic and, where applicable, transmitting
the required regulatory submission.
Text messages (SMS)
If you tell your Clinic that you agree to receive text messages, your Clinic may use ComplyRx to send you the
secure links described above by text instead of email. These messages are sent on behalf of your Clinic and are
limited to links to forms and questionnaires your Clinic has asked you to complete — typically no more than
four messages a month, and never marketing.
Consent — texts are sent only after you have told your Clinic you agree to receive them.
Agreeing is never a condition of receiving care.
Opting out — reply STOP to any message to stop receiving texts. Reply
HELP for help. Message and data rates may apply.
Your mobile number — your phone number and text-message consent are used only to deliver
these messages. They are not shared with third parties or affiliates for marketing or promotional
purposes.
Delivery — messages are sent from your Clinic's own phone system, which your Clinic has
connected to ComplyRx, so the number you see is your Clinic's and your replies reach your Clinic. Message
content is kept to the minimum needed to deliver the link and never names a medication or diagnosis.
For any question about your specific medical records, please contact your Clinic directly.
15. Children's information
The Services are intended for use by healthcare clinic staff and are not directed to children. Patient
information for a minor may be entered into the Services by a Clinic in the ordinary course of that minor's
care, subject to the Clinic's own policies and applicable law — we do not independently collect information
from children.
16. Where information is stored
We store and process information in the United States. If we engage a service provider located outside the
United States, we require appropriate contractual safeguards for any transfer of information.
17. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to the Services or our practices. If we
make material changes, we will update the "Last updated" date above and, where appropriate, provide additional
notice to Clinics. Continued use of the Services after an update constitutes acceptance of the revised policy.