Effective date: July 17, 2026 · Last updated: July 17, 2026
ComplyRx ("ComplyRx," "we," "us," or "our") provides a clinical
operations platform used by healthcare clinics ("Clinics," "Customers") to manage treatment
tracking, controlled-substance inventory, DEA recordkeeping, and REMS (Risk Evaluation and Mitigation Strategy)
program compliance for esketamine/Spravato treatment. This Privacy Policy explains what information we collect,
how we use and protect it, and the choices available to you. It applies to our website, our web application, and
related services (together, the "Services").
1. Who this policy covers
This policy covers two distinct groups of people, and it's important to understand which one applies to you:
Clinic staff and administrators who create an account and use the Services to do their jobs
(clinicians, nurses, pharmacy/inventory staff, clinic administrators). For you, we act largely as an ordinary
software provider — we describe below what account and usage information we collect about you directly.
Patients of a Clinic whose health information is entered into the Services by that Clinic's
staff (for example, treatment charts, medication administration records, prior-authorization documents, or a
completed PHQ-9 screening). ComplyRx does not have a direct relationship with patients and does not collect
patient information from patients themselves except in the narrow, clearly-labeled cases described in
Section 13 (for example, an emailed link to complete a PHQ-9 questionnaire, or a
link to review and electronically sign an enrollment form).
This policy also covers visitors to our marketing website who are not yet Clinic customers (for example, if you
submit a contact or demo-request form).
2. Our role & protected health information
Clinics use the Services to store and process protected health information ("PHI") as defined
by the U.S. Health Insurance Portability and Accountability Act ("HIPAA") — including patient names, dates of
birth, contact information, diagnoses, medications, treatment session data, prior authorization details, and
REMS program submissions.
With respect to that PHI, the Clinic is the HIPAA Covered Entity and ComplyRx acts as its
Business Associate under a Business Associate Agreement ("BAA") executed with each Clinic. We
process PHI only as instructed by the Clinic and only to provide, secure, and support the Services — never for
our own independent marketing or advertising purposes, and never to build product outside the scope the BAA and
the Clinic's instructions permit.
If you are a patient with a question about how your specific health information is used, please contact your
Clinic directly — they control that data and can direct you to their own Notice of Privacy Practices. See
Section 13 for more detail.
3. Information we collect
A. Information Clinics and their staff provide to us
Account & identity data — name, work email address, role (admin/staff), and a hashed
password (accounts are provisioned by a Clinic administrator; we do not offer public self-signup).
Clinic configuration data — clinic name, address, DEA registration number, prescriber
credentials and signature, fax and email destinations for REMS submission, and similar practice-level
settings.
Integration credentials — OAuth tokens for connected services the Clinic authorizes, such as
a fax provider, Google Workspace, or Microsoft 365 mailbox, used solely to send required REMS submissions and
related notifications on the Clinic's behalf.
B. Patient/clinical information entered by a Clinic (processed as a Business Associate)
Patient demographics (name, date of birth, sex, contact details, address).
Treatment records — dosing sessions, vitals, monitoring observations, adverse-event reports, and checkout
details.
Medication-inventory and DEA recordkeeping data — lot/serial numbers, receipt/dispense/disposition records,
and related controlled-substance audit trails.
Enrollment, prior-authorization, PHQ-9 screening, and other uploaded or generated clinical documents.
Communications records related to required regulatory submissions (for example, fax and email transmission
logs to the REMS program).
We do not decide what patient information a Clinic collects or how long the Clinic wants a given record kept —
those decisions belong to the Clinic.
C. Information collected automatically
Usage & device data — pages viewed, actions taken, timestamps, browser/device type, and
IP address, used for security, troubleshooting, and improving the Services.
Audit & activity logs — a record of who did what and when within the Services (for
example, who viewed or edited a record), which we maintain to support the Clinic's own compliance and security
obligations.
Cookies and local/session storage — used to keep you signed in, remember your interface
preferences (such as light/dark theme), and support core functionality. See Section 10.
C-1. The ComplyRx mobile apps (iOS and Android)
The ComplyRx mobile applications provide the same Services described in this policy inside a native app.
In addition to the practices above, the mobile apps use the following device capabilities. Each is optional,
requested through the operating system's standard permission prompt, and can be revoked at any time in your
device settings:
Camera — used only to scan medication box barcodes and labels for inventory intake and
treatment verification. Images and barcode data are processed for that workflow; the camera is never used
for any other purpose.
Face ID / Touch ID / fingerprint — used only to unlock the app after it has been in the
background. Biometric matching is performed entirely by your device's operating system; ComplyRx never
receives, stores, or transmits your biometric data — the app is only told whether the unlock succeeded.
Notifications — used for treatment-timer reminders and operational alerts. Notifications
shown on a lock screen are designed to contain patient initials only, never full names or other
identifying details.
App badge and vibration — used to surface how many patients are currently ready and to
accompany reminders.
The mobile apps contain no advertising, no third-party analytics or tracking SDKs, and do not
access your contacts, photos, or location. All data handling otherwise follows the practices described in the
rest of this policy, including the Business Associate commitments in Section B.
D. Information from website visitors who are not Clinic users
If you fill out a contact form, request a demo, or otherwise reach out to us through our marketing website, we
collect the information you choose to provide (such as your name, email, organization, and message) so we can
respond.
4. How we use information
We use information to:
Provide, operate, secure, and maintain the Services, including patient charting, inventory/DEA
recordkeeping, and REMS submission workflows;
Authenticate users and enforce clinic-level and role-based access controls;
Generate and transmit required regulatory forms and submissions on a Clinic's behalf, at that Clinic's
direction (for example, faxing or emailing a completed monitoring form to a REMS program);
Detect, investigate, and prevent fraud, unauthorized access, and other security incidents;
Provide customer support and respond to Clinic inquiries;
Maintain audit trails required for controlled-substance and regulatory compliance;
Improve and troubleshoot the Services (for example, using de-identified or aggregated usage patterns); and
Comply with our legal obligations, including our obligations under a Clinic's Business Associate Agreement.
We do not sell personal information or PHI, and we do not use PHI to serve targeted
advertising.
5. Why we process information
We process information because it is necessary to perform our contract with the Clinic (our Customer), to
comply with legal and regulatory obligations that apply to healthcare recordkeeping (including HIPAA and DEA
requirements), and — for limited operational purposes like security monitoring and service improvement — based
on our legitimate interest in operating a safe and reliable platform, balanced against your privacy interests.
6. How we share information
We disclose information only as described here — never as a general matter of course:
With the Clinic itself — the Clinic that entered or manages a record can access it, subject
to its own internal role-based permissions.
With service providers acting on our behalf — see Section 7 for
the categories of vendors we use and why. These providers are contractually bound to protect the information
and to use it only to provide services to us.
For required regulatory submissions — a completed monitoring form or related documentation
is transmitted (by fax or email) to the applicable REMS program, exactly as a Clinic's own staff would
otherwise do manually.
To comply with law — if required by valid legal process such as a subpoena, court order, or
similar legal obligation.
To protect rights and safety — where we believe in good faith that disclosure is necessary
to investigate or prevent fraud, security incidents, or harm to any person.
In connection with a corporate transaction — such as a merger, acquisition, financing, or
sale of assets, subject to appropriate confidentiality protections and, where PHI is involved, in a manner
consistent with HIPAA.
We do not disclose PHI to any third party for that third party's own independent marketing purposes.
7. Sub-processors & service providers
To provide the Services we rely on a limited set of vetted infrastructure and communication providers, each
bound by contract (and, where PHI is involved, a Business Associate Agreement) to safeguard information and use
it only to provide services to us:
Category
Purpose
Cloud database & application hosting
Secure storage of application data and hosting of the web application.
Static site / content delivery hosting
Hosting and delivery of the website and application front end.
Fax transmission provider
Sending required regulatory monitoring forms to the REMS program by fax, at a Clinic's direction.
Email service providers (customer-connected)
Sending required regulatory submissions and questionnaire links by email, using a mailbox the Clinic itself authorizes and controls.
AI/document-processing provider
Assisting with document data extraction, form auto-fill, and similar automation features. See Section 8.
We maintain an up-to-date list of sub-processors and will notify Clinics of material changes as required by our
agreements with them.
8. Use of AI in the Services
Certain features use a third-party AI model to help extract information from uploaded documents (for example,
reading a pharmacy label, a prior-authorization letter, or a patient intake form) or to answer natural-language
questions about a Clinic's own aggregated, clinic-scoped data in our analytics tool. These requests are made
through a vetted AI provider under contractual terms that prohibit using the submitted content to train that
provider's general-purpose models. Any suggested extraction is always presented to Clinic staff for review and
confirmation before it is saved — the Services do not make unreviewed clinical decisions.
9. How we protect information
We maintain administrative, technical, and physical safeguards designed to protect information against
unauthorized access, disclosure, alteration, and destruction, including:
Encryption of data in transit (TLS) and at rest;
Role-based access controls and row-level data isolation between Clinics ("multi-tenant" access controls),
so one Clinic cannot see another Clinic's data;
Audit logging of access to and changes made within clinical records;
Least-privilege access for our personnel, granted only as needed to provide support or maintain the
Services;
Ongoing monitoring and periodic review of our security configuration.
No system can be guaranteed 100% secure. If we become aware of a security incident affecting PHI, we will
notify affected Clinics in accordance with HIPAA and our Business Associate Agreement, and Clinics remain
responsible for any patient notifications required under applicable law.
10. Data retention
We retain information for as long as a Clinic's account is active and as needed to provide the Services,
including to meet the recordkeeping periods required for controlled-substance and other regulatory compliance
(which can be several years). When a Clinic's account is closed, we retain or return data as required by our
agreement with that Clinic and applicable law, and otherwise securely delete or de-identify it. Append-only
compliance and audit records (such as DEA transaction logs) are, by design, never altered or deleted during the
required retention period.
11. Cookies, local storage & notifications
We use cookies and browser local/session storage that are strictly necessary to keep you signed in, remember
basic interface preferences (like light/dark mode), and maintain security — we do not use third-party
advertising or cross-site tracking cookies. If you enable push notifications (for example, to be alerted when a
patient is ready for their next treatment step), your browser stores a subscription token used solely to
deliver those notifications; you can disable this at any time in your device or browser settings, or in the
Services' own notification settings.
12. Your choices & rights
If you are Clinic staff: you may access or update your own account profile within the
Services, and a Clinic administrator can update or remove your account access. Depending on your location, you
may also have rights to request access to, correction of, or deletion of your personal account information —
contact us using the details in Section 17, or your Clinic administrator.
If you are a patient of a Clinic: your rights regarding your health information — including
rights to access, amend, or receive an accounting of disclosures of your records — are exercised through your
Clinic, which is the party responsible for that information under HIPAA. See Section 13.
13. Notice for patients of a Clinic
If your healthcare provider uses ComplyRx, some of your health information may be stored in our systems. We do
not control what information a Clinic collects about you, how long it is kept, or who at that Clinic can see
it — those choices, and the obligation to give you a Notice of Privacy Practices, belong to your Clinic.
In a small number of cases, we may contact you directly at your Clinic's request and using contact information
your Clinic provides — for example, to send you a secure link to:
electronically review and sign a REMS enrollment form; or
complete a PHQ-9 depression screening questionnaire.
These links are single-purpose, time-limited, and access-controlled. We do not use the information you submit
through them for any purpose other than delivering it back to your Clinic and, where applicable, transmitting
the required regulatory submission.
For any question about your specific medical records, please contact your Clinic directly.
14. Children's information
The Services are intended for use by healthcare clinic staff and are not directed to children. Patient
information for a minor may be entered into the Services by a Clinic in the ordinary course of that minor's
care, subject to the Clinic's own policies and applicable law — we do not independently collect information
from children.
15. Where information is stored
We store and process information in the United States. If we engage a service provider located outside the
United States, we require appropriate contractual safeguards for any transfer of information.
16. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to the Services or our practices. If we
make material changes, we will update the "Last updated" date above and, where appropriate, provide additional
notice to Clinics. Continued use of the Services after an update constitutes acceptance of the revised policy.