Privacy Policy
Last updated: 2026-10-05 · v2026-10-05
1. Who we are; what this policy covers
SynxRx, Inc. builds a web platform (synxrx.com) that connects licensed physicians,
independent compounding pharmacies, and their patients for the purpose of
compounded-medication prescriptions and fulfillment.
Most of the data in our platform is Protected Health Information (PHI) under the
Health Insurance Portability and Accountability Act (HIPAA), 45 C.F.R. pts. 160,
162, and 164. SynxRx acts as a Business Associate (BA) of the pharmacies we serve:
a "business associate" is a person who, on behalf of a covered entity (like a
pharmacy) and other than as a member of its workforce, creates, receives, maintains,
or transmits PHI. 45 C.F.R. Sec. 160.103. We sign a Business Associate Agreement
(BAA) with each pharmacy before PHI flows (required where a covered entity discloses
PHI to its BA — 45 C.F.R. Sec. 164.502(e)(1) and 164.308(b)). The obligations owed
to individuals are owed by the covered entity under the HIPAA Privacy Rule —
synxrx.com is not itself a covered entity, and we do not dispense, treat, or bill
for care.
This policy covers: (a) platform users (patients, physicians, pharmacy staff of each
pharmacy organization); and (b) public visitors of synxrx.com. Privacy practices for
PHI are additionally governed by the executed BAA with your pharmacy and with the
HIPAA rules themselves where applicable.
2. Information we collect
– Account/contact data: name, email, mobile number, shipping address, organization
(for pharmacy/physician users), role (e.g., pharmacist, technician, physician,
patient).
– Prescription data: medications and directions as entered and signed by the
prescriber, refill requests, related order history, messages between you and your
prescriber or pharmacy.
– Order data: order items, fulfillment status (e.g., compounding, quality check,
shipped), carrier tracking numbers, batch/lot numbers recorded by pharmacy staff.
– Payment data: card presentment and processing occur inside Stripe Embedded
Checkout; SynxRx never receives or stores card numbers or card verification codes.
– Credentials/attempts: email OTP verification state; security events (login rates,
failed OTPs) recorded in a PII-scrubbed form.
– Technical/usage data: IP, device, browser, cookies for session and to understand
aggregate platform usage.
3. How we use information
– To operate the platform: verify accounts (OTP), org-level tenant isolation and access checks,
prescription/order processing, refills, payments via Stripe, notifications.
– To provide required communication: email/SMS status updates tied to your service.
– To secure the platform: audit logs on every PHI read/write, rate limiting,
session timeouts, abuse detection.
– To comply with law, including HIPAA Administrative, Physical, and Technical
Safeguard requirements and accounting-of-disclosures support.
– To improve the Service, using de-identified or aggregate data where feasible;
SynxRx will not attempt to re-identify de-identified data released to it. 45
C.F.R. Sec. 164.514 describes the de-identification standard.
4. Sharing
We do not sell PHI or personal data. We disclose PHI and personal data only as
permitted by the executed BAA and only to these recipients:
– Your dispensing pharmacy (and its pharmacist staff) — to fill
and track your prescription.
– Your prescribing physician (and their authorized staff) — to manage your care.
– Subprocessors that create, receive, maintain, or transmit data on our behalf,
each bound to the same HIPAA restrictions and conditions by executed agreement
(45 C.F.R. Sec. 164.504(e)(2)(ii)(D) and 164.308(b)(2)); and, where the vendor is
not a BA-handling service, by its data processing agreement:
- Convex — database and serverless execution — a Business Associate Agreement is
available and will be executed before PHI flows.
- Resend — transactional email — messages are content-minimized (no medication or
diagnosis details) and do not carry clinical content.
- Vercel — web hosting and delivery (US regions).
- Stripe — payment processing. Stripe is a PCI-DSS service provider; card data is
tokenized at the browser and transmitted to Stripe directly.
– As required by law, and to public health/other permitted recipients only as
allowed under HIPAA and your pharmacy's instructions.
– Business transfer (successor in interest), where PHI will remain protected
consistently with HIPAA.
5. SMS and marketing communications
Transactional SMS (order/Rx status, OTP) is sent with your consent and you may
stop at any time by replying STOP; a single confirmation is then sent, no further
SMS. Reply HELP for help, START to resume. SMS is sent under 47 U.S.C. 227 (TCPA),
and 47 C.F.R. 64.1200, 64.3100. **No mobile information will be shared with third
parties or affiliates for marketing or promotional purposes.** Marketing email, when
any is sent, must comply with the CAN-SPAM Act, 15 U.S.C. 7704: accurate headers,
physical address, working opt-out mechanism (honored within 10 business days), and
no advertising inside transactional messages.
6. Data security
Administrative, physical, and technical safeguards are implemented consistent with
the HIPAA Security Rule, 45 C.F.R. 164.302-318 (general requirements at 164.306;
administrative at 164.308; physical at 164.310; technical at 164.312). Current
implementation posture (claims, factual as of 2026-10-05; verify at deployment):
TLS 1.3 in transit; AES-256 at rest (Convex-managed); email one-time-passcode auth
with HTTP-only session cookies and a 30-minute idle timeout; server-side RBAC on
every query/mutation; organization-level tenant isolation (org-scoped filters on
every scoped query); audit log on every PHI read/write; per-IP rate limiting and an
SMS cap; executed BAAs with each subprocessor that handles PHI, obtained before PHI flows; PCI data flows do not
touch our servers.
We cannot guarantee absolute security of any data transmission or storage. You
should protect your email inbox (used for OTP login).
7. Data retention; your rights
Retention is governed primarily by the covered entities' legal obligations (the
pharmacy and physician) and by our BAA. Practical schedule for platform data:
account/prescription/order records are retained while your organization is active;
afterward PHI is returned or destroyed per the BAA (45 C.F.R.
164.504(e)(2)(ii)(J)). Account deletion by a patient anonymizes the patient record
while keeping prescription/order history for the pharmacy's required retention
period (e.g., 3-year Pharmacy Board compounded-preparation record requirement,
21 N.C.A.C. 46 .2801(h)).
Your rights. You may request access to, amendment of, or an accounting of disclosures
of your PHI from your covered entity (pharmacy or physician), whose contact is in
your prescription/order communications. SynxRx assists covered entities with these
requests under our BAA (45 C.F.R. 164.504(e)(2)(ii)(E)-(G); 164.524, 164.526, and
164.528). Patients may use in-app tools to update their profile, addresses, and
notification preferences, request refills, and delete their account (anonymization,
noted above). Pharmacy/physician users may contact their administrator.
8. Breach notification
If we discover a Breach of Unsecured PHI as defined at 45 C.F.R. 164.402, we will
notify the affected covered entity without unreasonable delay and within the
Breach Notification Rule's 60-calendar-day maximum (45 C.F.R. 164.410); the covered
entity in turn notifies individuals (without unreasonable delay and no later than
60 calendar days after discovery — 45 C.F.R. 164.404). North Carolina's Identity
Theft Protection Act additionally requires businesses that own or license personal
information to notify affected North Carolina residents without unreasonable delay
(N.C.G.S. Sec. 75-65(a)), and to notify the NC Attorney General's Consumer
Protection Division (N.C.G.S. Sec. 75-65(e1)); destruction of records is governed
by N.C.G.S. Sec. 75-64. For any SynxRx data set that falls outside HIPAA
(e.g., prospective-platform marketing list), the FTC's Health Breach Notification
Rule, 16 C.F.R. pt. 318, requires notice to consumers without unreasonable delay
and no later than 60 days, and to the FTC within 10 business days for breaches
affecting 500 or more individuals.
9. Cookies and analytics
We use session cookies for login and aggregate analytics to understand platform
usage. We do not run advertising trackers on platform pages.
10. Children
The platform is not directed to children under 18.
11. International use
SynxRx serves users in the United States; all hosting is in U.S. regions. We do not
market to EU/UK users; if an EU/UK data subject nonetheless interacts with the
platform,.
12. Changes to this policy
Material changes will be posted at /privacy with a version date; continuing to use
the platform after a change constitutes acceptance.
13. Contact
Privacy Officer, SynxRx, Inc. — privacy@synxrx.com
---
Appendix — Citation index (Privacy Policy)
– HIPAA Privacy, Security, and Breach Notification Rules: 45 C.F.R. pts. 160, 162,
164 - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164
– BA definition: 45 C.F.R. 160.103 -
https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
– BA contracts: 45 C.F.R. 164.502(e); 164.504(e) -
https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504
– Security Rule BA assurance: 45 C.F.R. 164.308(b) -
https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
– De-identification: 45 C.F.R. 164.514
– Minimum necessary: 45 C.F.R. 164.502(b)
– Subcontractor flow-down: 45 C.F.R. 164.504(e)(2)(ii)(D); 164.308(b)(2)
– Access/amendment/accounting duties (assistance to CE duties):
45 C.F.R. 164.504(e)(2)(ii)(E)-(G); 164.524; 164.526; 164.528
– PHI return/destruction at termination: 45 C.F.R. 164.504(e)(2)(ii)(J)
– Breach definition: 45 C.F.R. 164.402
– BA breach duty to CE (60 calendar days): 45 C.F.R. 164.410 -
https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.410
– Individual notification (60 days): 45 C.F.R. 164.404 -
https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.404
– Security Rule scope: 45 C.F.R. 164.302-318
– North Carolina Identity Theft Protection Act: N.C.G.S. 75-60 through 75-68;
individual-notice duty and AG notice: N.C.G.S. 75-65(a), (e1); records
destruction: N.C.G.S. 75-64 -
https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/ByArticle/Chapter_75/Article_2A.html
– Government-source PDF for G.S. 75-65:
https://www3.ncleg.gov/EnactedLegislation/Statutes/PDF/BySection/Chapter_75/GS_75-65.pdf
– FTC Health Breach Notification Rule: 16 C.F.R. pt. 318 -
https://www.ftc.gov/legal-library/browse/rules/health-breach-notification-rule
– TCPA / FCC rules: 47 U.S.C. 227 - https://www.law.cornell.edu/uscode/text/47/227 ;
47 C.F.R. 64.1200; 64.3100
– CAN-SPAM Act: 15 U.S.C. 7704 - https://www.law.cornell.edu/uscode/text/15/7704