Get Compliance RX

Legal

Data Processing Addendum

Effective September 13, 2026. This Addendum describes how Get Compliance RX protects personal data processed for customers.

Application

This Data Processing Addendum applies when it is incorporated into an agreement between a customer and Get Compliance RX and Get Compliance RX processes personal data on that customer’s behalf. The applicable order form and agreement define the services, processing duration, data categories, and business purposes.

Roles and documented instructions

The customer determines the purposes and means of processing as controller or business, and Get Compliance RX acts as processor or service provider, as those terms apply. Get Compliance RX processes customer personal data only to provide and secure the contracted services, follow documented customer instructions, and comply with applicable law.

Confidentiality

Personnel authorized to process customer personal data are subject to appropriate confidentiality obligations and receive access only as needed for their responsibilities.

Security measures

Get Compliance RX maintains administrative, technical, and organizational measures designed to protect customer personal data against unauthorized access, loss, alteration, or disclosure. Measures are selected according to the nature of processing and reasonably identified risks. No security program can eliminate every risk.

Subprocessors

Get Compliance RX may use subprocessors to support hosting, infrastructure, security, communications, and service operations. Get Compliance RX remains responsible for requiring subprocessors to protect customer personal data consistently with applicable contractual obligations. Customers may request current subprocessor information using the contact below.

Rights requests and compliance assistance

Taking into account the nature of processing and information available, Get Compliance RX will provide reasonable assistance with verified data-subject requests, security assessments, and customer obligations under applicable privacy law. If we receive a request concerning customer-controlled data, we may direct the requester to the customer.

Security incidents

Get Compliance RX will notify the affected customer without undue delay after confirming a security incident involving customer personal data, as required by applicable law or agreement, and will provide reasonably available information and cooperation.

Return and deletion

At the end of the applicable services, Get Compliance RX will delete or return customer personal data in accordance with the customer agreement, documented instructions, retention schedules, and legal obligations. Secure backup copies may remain until overwritten through ordinary retention cycles.

International transfers

Where cross-border transfer requirements apply, the parties will use an appropriate transfer mechanism and supplementary safeguards required by applicable law.

Audits and information

Get Compliance RX will make information reasonably necessary to demonstrate compliance with applicable processing obligations available under the customer agreement. Any audit must protect confidentiality, avoid unreasonable disruption, and account for relevant third-party reports or documentation.

Order of precedence

If this Addendum conflicts with the applicable customer agreement regarding personal-data processing, this Addendum controls. Customer-specific terms, including any required business associate agreement, must be documented in a signed agreement.

DPA contact

Contact hello@getcompliancerx.com to request a customer-specific DPA or discuss contractual requirements. You can also review our Privacy Policy and Security principles.

Newsletter

Pharmacy reimbursement news, in plain English.

New articles, audit and reconciliation updates, and what AI actually changes for independent pharmacies. A few emails a month, no noise.

Why subscribe?

Name is optional. Unsubscribe at any time on our unsubscribe page.