Privacy Policy

Last updated: 10.1.2023

1. INTRODUCTION

TelyRx, Inc., including its subsidiaries and affiliates (collectively, “TelyRx,” “we,” “us,” or “our”), is committed to protecting your privacy and safeguarding your personal information. This Privacy Policy explains how we collect, use, disclose, and protect your information when you access or use:

  • Our website at www.TelyRx.com
  • Our mobile applications
  • Our telehealth, pharmacy, and healthcare-related services

By accessing or using the TelyRx services (collectively, the “Service”), you agree to the terms and conditions described in this Privacy Policy. If you do not agree, please discontinue the use of our Service immediately.

2. SCOPE OF THIS PRIVACY POLICY

This Privacy Policy applies to all personal data collected through our websites, applications, telehealth platforms, pharmacy services, and any services utilized by and through TelyRx. It governs our compliance with federal and state laws, including but not limited to:

  • Health Insurance Portability and Accountability Act (HIPAA)
  • California Consumer Privacy Act (CCPA) & California Privacy Rights Act (CPRA)
  • Virginia Consumer Data Protection Act (VCDPA)
  • Colorado Privacy Act (CPA)
  • Connecticut Data Privacy Act (CTDPA)
  • Utah Consumer Privacy Act (UCPA)
  • Texas Data Privacy and Security Act (TDPSA)
  • Nevada Revised Statutes (NRS 603A) on Consumer Privacy

TelyRx is required by law to protect your personal and health information and is dedicated to ensuring your data remains secure.

3. INFORMATION WE COLLECT

TelyRx collects personal, health-related, financial, and technical information from various sources to facilitate pharmacy services, telehealth interactions, compliance with legal obligations, and operational improvements. We ensure that all collected data is handled securely and transparently in compliance with applicable privacy laws.

A. Information You Provide Directly to Us

We collect the following personal and health-related information when you:

  • Create an account, register for our services, or interact with our platform
  • Complete medical intake forms, submit prescriptions, or communicate with our providers
  • Engage with customer support, provide feedback, or submit inquiries
  • Make purchases, process payments, or sign up for delivery services

1. Personally Identifiable Information (PII)

  • Full legal name
  • Date of birth
  • Gender, pronouns, and marital status
  • Home, mailing, and shipping addresses
  • Email address and phone number
  • Social Security Number (SSN) (where legally required)
  • Driver’s license, passport, or other government-issued ID (for identity verification)

2. Protected Health Information (PHI)

  • Medical history, current conditions, and past treatments
  • Prescriptions, medication adherence data, and dosage details
  • Physician name, healthcare provider details, and pharmacy information
  • Insurance details, including policy numbers and coverage, or related information
  • Lab test results, diagnostic records, and imaging reports
  • Allergies, lifestyle factors, and self-reported health information
  • Communication between you and healthcare professionals

3. Financial & Payment Information

  • Billing address and credit card details (processed securely through third-party payment processors)
  • Health Savings Account (HSA) or Flexible Spending Account (FSA) details
  • Payment transaction history and invoicing records

4. User-Generated Content

  • Emails, chat transcripts, and customer service interactions
  • Product reviews, testimonials, or surveys submitted through our platform
  • Comments, messages, or responses on our social media platforms

5. Sensitive Information (As Defined by Law)

  • Racial or ethnic background (only if disclosed voluntarily for regulatory purposes)
  • Biometric data (if used for authentication or regulatory requirements)
  • Sexual and reproductive health information (when required for services such as birth control prescriptions)

B. Information We Collect Automatically

When you visit our website, use our mobile applications, or engage with our services, we automatically collect technical and behavioral data using cookies, analytics tools, and tracking technologies.

1. Device & Technical Information

  • IP address
  • Device type, operating system, browser type, and version
  • Unique device identifiers (such as MAC address)
  • Internet service provider (ISP) information

2. Website & App Activity

  • Pages viewed, time spent on each page, and navigation patterns
  • Clickstream data (buttons clicked, searches performed, interactions with content)
  • Error logs and system performance data
  • Heatmaps and scrolling behavior (for improving user experience)

3. Location Data

  • Approximate geolocation based on IP address
  • Precise geolocation (only when explicitly allowed by the user)

4. Cookies, Web Beacons & Tracking Technologies

  • Session cookies for login authentication
  • Persistent cookies for storing preferences and improving user experience
  • Pixel tags and web beacons to measure engagement with emails or advertisements
  • Third-party tracking technologies used for analytics, advertising, and fraud detection

C. Information We Receive from Third Parties

We collect additional personal and health-related data from third-party sources to ensure continuity of care, verify user identity, and comply with healthcare regulations.

1. Healthcare Providers & Pharmacies

  • Prescription data and refill history
  • Care coordination records and referral notes

2. Marketing, Advertising & Analytics Partners

  • Data from advertising platforms (Google Ads, Facebook, etc.) to optimize campaigns
  • Demographic and interest-based data collected from third-party surveys
  • Customer segmentation data for personalized recommendations

3. Government Agencies & Regulatory Authorities

  • Licensing and certification verification (where required)
  • Compliance reporting data related to HIPAA, Medicare, Medicaid, and pharmacy regulations
  • Fraud prevention alerts and watchlist screenings

4. Social Media & Public Databases

  • User interactions on social media platforms (likes, shares, comments)
  • Publicly available information from professional networks, such as LinkedIn
  • Online reviews and ratings related to our services

4. HOW WE USE YOUR INFORMATION

At TelyRx we collect and use your personal, financial, technical, and health-related information to provide safe, legal, and efficient healthcare and pharmacy services. Our use of your information complies with applicable federal and state privacy laws, including but not limited to:

  • Health Portability and Accountability Act (HIPAA)
  • Health Information Technology for Economic and Clinical Health Act (HITECH Act)
  • California Consumer Privacy Act (CCPA) & California Privacy Rights Act (CPRA)
  • Virginia Consumer Data Protection Act (VCDPA)
  • Colorado Privacy Act (CPA)
  • Connecticut Data Privacy Act (CTDPA)
  • Utah Consumer Privacy Act (UCPA)
  • Texas Data Privacy and Security Act (TDPSA)
  • Nevada Revised Statutes (NRS 603A) on Consumer Privacy
  • General Data Protection Regulation (GDPR) (for EU-based individuals, if applicable)
  • Federal Trade Commission Act (FTC Act) governing consumer privacy protection

We process personal information only for legitimate business purposes, in accordance with these legal frameworks.

A. Provision of Healthcare and Pharmacy Services

We use your Protected Health Information (PHI) and Personally Identifiable Information (PII) to:

  1. Process and Fulfill Prescriptions:
    • Verify prescriptions from licensed healthcare providers.
    • Ensure proper dosage, medication instructions, and patient safety.
    • Contact healthcare providers for prescription clarification, refills, or substitutions.
  2. Facilitate Telehealth & Remote Consultations:
    • Connect you with licensed medical professionals.
    • Provide connection with medical professionals for virtual medical assessments, diagnoses, and treatment plans.
    • Allow medical professionals to conduct follow-ups and medication adherence monitoring.
  3. Medication Safety & Regulatory Compliance:
    • Check for potential drug interactions, contraindications, and allergies based off the information you have attested and confirmed to.
    • Conduct compliance checks under HIPAA, FDA, and state pharmacy boards.
  4. Prescription Delivery & Logistics:
    • Coordinate shipping of medications through authorized carriers.
    • Track shipments and update users on order status.
    • Ensure temperature-sensitive medications meet proper handling requirements.

B. Customer Service & Support

We use your data to:

  1. Provide Account & Technical Support:
    • Assist with login issues, password resets, and account verification.
    • Respond to inquiries regarding prescription status, billing, or shipping.
    • Troubleshoot technical issues related to our website or mobile app.
  2. Communicate Important Updates:
    • Notify users of prescription refills, expired prescriptions, or missed doses.
    • Send alerts about service changes, new policies, or regulatory updates.
    • Provide safety warnings, drug recall notifications, or FDA advisory updates.
  3. Resolve Disputes & Process Refunds:
    • Investigate and resolve billing discrepancies.
    • Process refunds or adjustments for incorrect orders.
  4. Enhance Customer Experience:
    • Collect and analyze user feedback via surveys and reviews.
    • Customize recommendations for pharmacy services and telehealth options.

C. Fraud Prevention & Security Compliance

We process certain personal data to:

  1. Verify Identity & Prevent Unauthorized Access:
    • Use multi-factor authentication (MFA) for secure account access.
    • Require identity verification for high-risk transactions.
    • Flag suspicious login attempts, account takeovers, or fraudulent claims.
  2. Detect and Prevent Fraudulent Activities:
    • Monitor for fraud, prescription forgery, or fake medical records.
    • Block transactions flagged by fraud detection algorithms.
    • Report fraudulent activity to law enforcement or regulatory bodies.
  3. Ensure Regulatory & Legal Compliance:
    • Conduct regular audits to comply with HIPAA and state privacy laws.
    • Maintain security logs to track data access and prevent breaches.
    • Respond to legal requests, subpoenas, or law enforcement investigations.
  4. Enforce Terms of Use & Other Policies:
    • Restrict access to users violating our policies.
    • Take action against unauthorized reselling of prescription drugs.
    • Protect intellectual property rights, trademarks, and proprietary content.

D. Marketing, Personalization & Business Optimization

We use certain non-PHI data for:

  1. Marketing & Promotional Communications (Opt-In Only):
    • Provide email, SMS, or in-app promotions for new products/services.
    • Offer personalized discounts, refill reminders, or subscription incentives.
    • Send loyalty program updates or special pharmacy member offers.
  2. Advertising & Audience Targeting (Where Legally Permitted):
    • Use cookies and tracking pixels to tailor ads for relevant services.
    • Retarget website visitors with customized promotions.
    • Analyze marketing effectiveness through A/B testing and user engagement metrics.
  3. Product & Service Personalization:
    • Recommend medications or health products based on prescription history.
    • Offer tailored health content, wellness tips, or drug interaction alerts.
  4. User Experience Optimization:
    • Improve website navigation, reduce page load times, and enhance accessibility.
    • Conduct heatmap analysis to refine user interfaces.
    • Streamline order placement and checkout experiences.

E. Legal Compliance & Corporate Transactions

TelyRx may process your data to:

  1. Comply with Legal & Regulatory Obligations:
    • Adhere to federal/state pharmacy laws and controlled substance tracking.
    • Maintain HIPAA-compliant privacy and security measures.
    • Report data breaches as required under HITECH Act & state data breach laws.
  2. Respond to Law Enforcement & Government Requests:
    • Cooperate with legal investigations related to fraud, cybercrime, or drug misuse.
    • Disclose data per court orders, subpoenas, or regulatory enforcement actions.
    • Provide necessary reports to DEA, FDA, or health agencies.
  3. Support Mergers, Acquisitions & Business Transfers:
    • In the event of a sale, merger, or corporate restructuring, we may transfer user data.
    • Ensure contractual protections for data security in asset transfers.

F. Data Analytics & AI-Powered Insights

We leverage artificial intelligence (AI) and machine learning (ML) to:

  1. Analyze Prescription & Health Trends:
    • Identify common treatment patterns across patient populations.
    • Improve predictive analytics for medication adherence.
  2. Enhance Safety & Compliance Monitoring:
    • Detect medication errors, potential drug abuse, or opioid dependency risks.
    • Flag non-compliance in health data reporting.
  3. Optimize Business Operations:
    • Forecast inventory needs based on prescription trends.
    • Improve delivery logistics and minimize medication waste.

G. Additional Uses for Data Processing

Other use cases for processing your information include:

  1. Data Retention & Archiving
    • Maintain transaction history for regulatory retention periods.
    • Allow users access to past prescriptions for medical recordkeeping.
  2. Emergency Situations
    • Use PHI to provide urgent medical assistance in life-threatening cases.
    • Notify designated emergency contacts in critical health situations.
  3. Research & Development (De-Identified Data)
    • Conduct statistical analysis for improving patient outcomes.
    • Share anonymized health insights with research institutions for clinical advancements.

H. Your Privacy Rights & Control Over Your Data

You may exercise rights under HIPAA, CCPA, CPRA, GDPR, and state-specific laws regarding:

  • Access & Portability – Request copies of your data.
  • Correction Requests – Update inaccurate information.
  • Opt-Out of Marketing – Restrict promotional communications.
  • Deletion Requests – Ask to erase non-regulatory data.
  • Restrict Processing – Limit certain types of data usage.
  • Appeal Decisions – Challenge automated processing decisions.

5. DISCLOSURE OF INFORMATION

We may disclose your personal information under the following circumstances:

A. Healthcare Providers & Business Associates

We share Protected Health Information (PHI) only as required for treatment, payment, and healthcare operations under HIPAA.

B. Service Providers & Vendors

We share personal data with third-party vendors that provide payment processing, IT security, marketing, and customer support.

C. Legal Compliance & Government Authorities

We may disclose personal information when required to comply with court orders, subpoenas, regulatory requests, or law enforcement investigations.

D. Business Transactions

If TelyRx undergoes a merger, acquisition, or sale of assets, your personal data may be transferred as part of the business transaction.

6. STATE-SPECIFIC PRIVACY RIGHTS

Certain U.S. state laws grant additional rights regarding your personal information. Below is a breakdown of these rights for each applicable state law:

A. California Consumer Privacy Act (CCPA) & California Privacy Rights Act (CPRA)

California residents have the following rights:

  1. Right to Access – You can request access to the personal information we have collected about you in the last 12 months, including:
    • Categories of personal data collected.
    • Sources from which the data was collected.
    • Purpose of collecting or selling the data.
    • Third parties with whom we share or sell data.
  2. Right to Correction – You have the right to request that we correct inaccurate personal information.
  3. Right to Deletion – You may request the deletion of personal information we collected from you, subject to exceptions for legal obligations, security purposes, and business needs.
  4. Right to Opt-Out of Sale or Sharing – You can opt out of the sale or sharing of your personal data for targeted advertising purposes.
  5. Right to Limit the Use of Sensitive Personal Information – You can restrict how we use your sensitive personal data (e.g., financial, biometric, or health-related information) to only those purposes necessary for providing services.
  6. Right Against Discrimination – You will not be penalized, denied services, or charged different rates for exercising your privacy rights.
  7. Authorized Agent Representation – You may designate an authorized agent to submit privacy requests on your behalf.

How to Exercise Your Rights:
California residents may submit a request by emailing [email protected] or calling (800) 878-1660

B. Virginia Consumer Data Protection Act (VCDPA)

Virginia residents have the following rights:

  1. Right to Confirm Processing – You can confirm whether we process your personal data and access a copy of your personal data.
  2. Right to Correction – You may request that we correct inaccuracies in your personal information.
  3. Right to Deletion – You can request deletion of your personal data, subject to legal and business exceptions.
  4. Right to Data Portability – You can request a copy of your data in a portable and accessible format.
  5. Right to Opt-Out – Virginia residents may opt out of:
    • Targeted advertising.
    • The sale of their personal data.
    • Profiling-based decision-making that has significant legal or similar effects.
  6. Right to Appeal – If we deny your request, you may appeal our decision, and we must respond within 60 days.

How to Exercise Your Rights:
Virginia residents can submit requests at [email protected] or (800) 878-1660.

C. Colorado Privacy Act (CPA)

Colorado residents have the following rights:

  1. Right to Access – You can request access to the personal data we have collected about you.
  2. Right to Correction – You can request that we correct inaccurate personal data.
  3. Right to Deletion – You have the right to request deletion of your personal data.
  4. Right to Data Portability – You can request a copy of your data in a commonly used format.
  5. Right to Opt-Out – You can opt out of:
    • Targeted advertising.
    • The sale of personal data.
    • Automated decision-making that significantly affects you.
  6. Right to Appeal – If we deny your request, you have the right to appeal the decision.

How to Exercise Your Rights:
Colorado residents can submit requests via [email protected] or (800) 878-1660.

D. Connecticut Data Privacy Act (CTDPA)

Connecticut residents have the following rights:

  1. Right to Access – You can request access to the personal information we have collected about you.
  2. Right to Correction – You may request that we correct inaccurate personal information.
  3. Right to Deletion – You can request that we delete personal data we have collected from you.
  4. Right to Data Portability – You may request a copy of your personal data in a portable format.
  5. Right to Opt-Out – You may opt out of:
    • Targeted advertising.
    • The sale of personal data.
    • Automated profiling that significantly affects you.
  6. Right to Appeal – If your request is denied, you can appeal, and we must respond within 60 days.

How to Exercise Your Rights:
Connecticut residents can submit requests via [email protected] or (800) 878-1660.

E. Utah Consumer Privacy Act (UCPA)

Utah residents have the following rights:

  1. Right to Access – You may request access to the personal data we have collected about you.
  2. Right to Deletion – You can request deletion of the personal data you provided to us.
  3. Right to Data Portability – You may request a copy of your data in a portable format.
  4. Right to Opt-Out – You may opt out of:
    • Targeted advertising.
    • The sale of personal data.

How to Exercise Your Rights:
Utah residents can submit requests via [email protected] or (800) 878-1660.

F. Texas Data Privacy and Security Act (TDPSA)

Texas residents have the following rights:

  1. Right to Access – You may request access to the personal data we collect about you.
  2. Right to Correction – You may request that we correct inaccurate personal data.
  3. Right to Deletion – You can request deletion of personal data.
  4. Right to Opt-Out – You can opt out of:
    • Targeted advertising.
    • The sale of personal data.
  5. Additional Protections for Sensitive Data – Texas law provides extra protections for biometric data, health information, and geolocation data.

How to Exercise Your Rights:
Texas residents can submit requests via [email protected] or (800) 878-1660.

G. Nevada Revised Statutes (NRS 603A) – Consumer Privacy Rights

Nevada residents have the following rights:

  1. Right to Access – You can request access to your personal information.
  2. Right to Opt-Out of Sale – Nevada law gives consumers the right to opt out of the sale of personal data to third parties.

How to Exercise Your Rights:
Nevada residents can submit requests via [email protected] or (800) 878-1660.

H. General Information on Exercising Your Rights

For all states listed above, you can exercise your rights by:

  • Emailing: [email protected]
  • Mailing Address: 24761 US Hwy 19N, Clearwater, FL 33763
  • Calling: (800) 878-1660

We will process your request in accordance with applicable state laws. If your request is denied, you may have the right to appeal, and we will provide information on how to do so.

7. DATA SECURITY MEASURES

At TelyRx, we prioritize the security and privacy of your data, implementing industry-standard protections to safeguard Protected Health Information (PHI) and personal data. Our security framework complies with HIPAA, HITECH, CCPA, TDPSA, and other applicable laws.

1. Data Encryption & Protection

  • End-to-End Encryption: All data in transit is secured via TLS 1.2+, and data at rest is protected with AES-256 encryption.
  • Secure Storage: PHI, financial details, and sensitive records are stored in encrypted databases with controlled access.
  • Secure Backups: Daily encrypted backups are stored in geographically redundant locations for disaster recovery.

2. Access Control & Authentication

  • Role-Based Access Control (RBAC): Employees receive only the minimum necessary access.
  • Multi-Factor Authentication (MFA): Required for all logins, ensuring secure access.
  • Session Timeouts & IP Restrictions: Automatic session expirations and restricted access prevent unauthorized logins.

3. Continuous Security Monitoring & Threat Detection

  • 24/7 Monitoring: Security teams track and prevent unauthorized access, cyber threats, and data breaches.
  • Intrusion Detection Systems (IDS): AI-driven tools detect and block potential security risks.
  • Audit Logs: All data access and modifications are logged and reviewed for anomalies.

4. HIPAA & Regulatory Compliance

  • Annual Risk Assessments: Regular audits ensure compliance with HIPAA, HITECH, and PCI-DSS.
  • Strict Third-Party Security Standards: Business partners handling PHI sign Business Associate Agreements (BAAs).
  • Breach Notification Policy: In the event of a breach, affected individuals and regulators are notified per legal requirements.

5. Employee Training & Security Awareness

  • Mandatory HIPAA Training: All employees undergo annual compliance training.
  • Phishing Prevention & Cybersecurity Training: Regular security awareness sessions.
  • Confidentiality Agreements: Employees and contractors sign strict NDAs and data protection policies.

8. DATA RETENTION POLICY

We retain personal data for as long as necessary to:

  • Provide services and maintain user accounts
  • Comply with legal and regulatory obligations
  • Resolve disputes and enforce agreements

9. HIPAA COMPLIANCE & PROTECTED HEALTH INFORMATION (PHI)

As a licensed pharmacy and healthcare services provider, TelyRx is committed to full compliance with the Health Insurance Portability and Accountability Act (HIPAA) and other applicable federal and state healthcare privacy laws. We recognize the sensitive nature of Protected Health Information (PHI) and have implemented stringent policies, safeguards, and procedures to ensure the confidentiality, security, and lawful use of patient information.

HIPAA Compliance Measures

  • Encryption of data at rest and in transit.
  • Secure authentication measures for system access.
  • HIPAA-compliant cloud storage and data transfer protocols.
  • Access controls to ensure only authorized personnel have access to PHI.
  • Regular audits and risk assessments to identify vulnerabilities.
  • Employee training programs on HIPAA compliance and patient confidentiality.

Your HIPAA Rights

As a patient or customer of TelyRx, you are entitled to specific rights under HIPAA, including:

  1. The Right to Access Your PHI
    • You have the right to request and obtain copies of your medical records and health information.
    • Requests for access must be submitted in writing to [email protected].
    • We will provide requested records within 30 days unless an extension is needed.
  2. The Right to Request an Accounting of PHI Disclosures
    • You may request a list of instances where TelyRx has shared your PHI with third parties, excluding disclosures made for treatment, payment, or healthcare operations.
    • This list will cover disclosures made within the past six years from the date of your request.
  3. The Right to Restrict Certain Uses and Disclosures of PHI
    • You may request limitations on how your PHI is used or disclosed for treatment, payment, or healthcare operations.
    • While TelyRx will consider all requests, we are not obligated to agree unless the disclosure is to a health plan for payment or healthcare operations, and the information pertains solely to services for which you have paid out-of-pocket in full.
  4. The Right to Amend Your PHI
    • If you believe that any information in your medical record is inaccurate or incomplete, you can request a correction.
    • We will review your request and amend records where appropriate.
  5. The Right to Confidential Communications
    • You can request that we communicate with you via alternative methods (e.g., phone, email, or mail) or at specific locations to ensure privacy.
  6. The Right to File a Complaint
    • If you believe your privacy rights have been violated, you have the right to file a complaint with:
      • TelyRx’s Privacy Office at [email protected] or (800) 878-1660.
      • The U.S. Department of Health & Human Services (HHS) via https://www.hhs.gov/hipaa.
  7. The Right to Obtain a Copy of Our HIPAA Notice of Privacy Practices
    • You may request a physical or electronic copy of TelyRx’s HIPAA Notice of Privacy Practices at any time.

HIPAA & Third-Party Disclosures

TelyRx will not disclose your PHI without your explicit authorization except in the following circumstances:

  • For Treatment – To healthcare providers involved in your care.
  • For Payment – To billing companies, and payment processors.
  • For Healthcare Operations – To improve service quality and conduct internal audits.
  • When Required by Law – To comply with federal or state regulations, court orders, or public health authorities.

If you wish to authorize a third party to access your PHI, you must submit a signed authorization form specifying the scope of access granted.

10. CHILDREN'S PRIVACY

Age Restrictions & Compliance with COPPA

TelyRx services are strictly intended for use by individuals aged 18 and older. We do not knowingly collect, use, or disclose personal information from individuals under the age of 18, in compliance with the Children’s Online Privacy Protection Act (COPPA) and other applicable laws.

Actions Taken If Minor Data is Collected

  1. We will immediately delete the information from our records.
  2. We will notify the parent or legal guardian (if identifiable) about the data collection.
  3. We will take corrective measures to prevent future occurrences, including updating our data monitoring systems.

Parental Controls & Reporting

  • If you are a parent or guardian and believe that your child’s data has been collected through TelyRx, please contact us immediately at [email protected] or (800) 878-1660.
  • Parents may request deletion of minor data and restrict further data collection through a formal request.

Teen Privacy & Healthcare Exceptions

In certain states, minors may have the legal right to seek confidential healthcare services (e.g., reproductive health, mental health, substance abuse treatment) without parental consent. In such cases, state laws will determine whether PHI can be disclosed to parents or guardians.

11. CHANGES TO THIS PRIVACY POLICY

TelyRx reserves the right to update this Privacy Policy. Updates will be posted with an updated effective date.

12. CONTACT INFORMATION

For privacy-related inquiries, please contact:

TelyRx, Inc.
24761 US Hwy 19N
Clearwater, FL 33763
Attn: Privacy Officer
Email: [email protected]