Legal
Data Processing Addendum
Effective September 13, 2026. This Addendum describes how Get Compliance RX protects personal data processed for customers.
Application
This Data Processing Addendum applies when it is incorporated into an agreement between a customer and Get Compliance RX and Get Compliance RX processes personal data on that customer’s behalf. The applicable order form and agreement define the services, processing duration, data categories, and business purposes.
Roles and documented instructions
The customer determines the purposes and means of processing as controller or business, and Get Compliance RX acts as processor or service provider, as those terms apply. Get Compliance RX processes customer personal data only to provide and secure the contracted services, follow documented customer instructions, and comply with applicable law.
Confidentiality
Personnel authorized to process customer personal data are subject to appropriate confidentiality obligations and receive access only as needed for their responsibilities.
Security measures
Get Compliance RX maintains administrative, technical, and organizational measures designed to protect customer personal data against unauthorized access, loss, alteration, or disclosure. Measures are selected according to the nature of processing and reasonably identified risks. No security program can eliminate every risk.
Subprocessors
Get Compliance RX may use subprocessors to support hosting, infrastructure, security, communications, and service operations. Get Compliance RX remains responsible for requiring subprocessors to protect customer personal data consistently with applicable contractual obligations. Customers may request current subprocessor information using the contact below.
Rights requests and compliance assistance
Taking into account the nature of processing and information available, Get Compliance RX will provide reasonable assistance with verified data-subject requests, security assessments, and customer obligations under applicable privacy law. If we receive a request concerning customer-controlled data, we may direct the requester to the customer.
Security incidents
Get Compliance RX will notify the affected customer without undue delay after confirming a security incident involving customer personal data, as required by applicable law or agreement, and will provide reasonably available information and cooperation.
Return and deletion
At the end of the applicable services, Get Compliance RX will delete or return customer personal data in accordance with the customer agreement, documented instructions, retention schedules, and legal obligations. Secure backup copies may remain until overwritten through ordinary retention cycles.
International transfers
Where cross-border transfer requirements apply, the parties will use an appropriate transfer mechanism and supplementary safeguards required by applicable law.
Audits and information
Get Compliance RX will make information reasonably necessary to demonstrate compliance with applicable processing obligations available under the customer agreement. Any audit must protect confidentiality, avoid unreasonable disruption, and account for relevant third-party reports or documentation.
Order of precedence
If this Addendum conflicts with the applicable customer agreement regarding personal-data processing, this Addendum controls. Customer-specific terms, including any required business associate agreement, must be documented in a signed agreement.
DPA contact
Contact hello@getcompliancerx.com to request a customer-specific DPA or discuss contractual requirements. You can also review our Privacy Policy and Security principles.
