Privacy Policy
Effective Date: February 27, 2026 | Last Updated: February 27, 20261stRX ("1stRX," "we," "us," or "our") operates the website at iw.getenk.com and the associated telehealth platform (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
Please read this policy carefully. By using the Service you agree to the practices described here. If you do not agree, please do not use the Service.
1. Information We Collect
Information you provide directly:
- Contact information (name, email address, phone number, mailing address)
- Health and medical information you submit during intake questionnaires and consultations
- Payment and billing information (processed securely by our payment processor; we do not store full card numbers)
- Communications you send us through the platform, email, or support channels
Information collected automatically:
- Log data (IP address, browser type, pages visited, time and date of visit)
- Cookies and similar tracking technologies (see Section 6 below)
- Device identifiers and general location (country/state level)
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Service
- Connect you with licensed healthcare providers for consultation and treatment
- Process payments and fulfill medication orders
- Communicate with you about your care, account, and appointments
- Send administrative and service-related notices
- Comply with legal obligations, including HIPAA requirements
- Detect and prevent fraud or other harmful activity
We do not sell your personal information or protected health information to third parties for marketing purposes.
3. How We Share Your Information
We may share your information with:
- Licensed healthcare providers — to facilitate your consultation and treatment
- Compounding pharmacies — to fulfill your prescription (only as directed by your provider)
- Service providers — vendors who assist us in operating the Service (payment processing, cloud hosting, email delivery, analytics), bound by confidentiality obligations
- Legal and regulatory authorities — when required by law, subpoena, or court order
- Business transfers — if 1stRX is acquired, merged, or undergoes a similar transaction, your information may be transferred as part of that transaction
4. Protected Health Information (HIPAA)
If you receive clinical services through our platform, your health information may be considered Protected Health Information ("PHI") under the Health Insurance Portability and Accountability Act ("HIPAA"). Our handling of PHI is governed by our HIPAA Notice of Privacy Practices, which is incorporated into this Privacy Policy by reference.
5. Data Retention
We retain your personal information for as long as necessary to provide the Service, comply with legal obligations (including medical record retention laws, which may require retention for 7–10 years), resolve disputes, and enforce our agreements. When data is no longer required, we delete or anonymize it in accordance with our internal retention schedule.
6. Cookies and Tracking
We use cookies and similar technologies to recognize your browser, maintain session state, analyze usage, and improve the Service. You may disable cookies in your browser settings, but some features of the Service may not function properly without them. We do not currently respond to "Do Not Track" signals.
7. Your Rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Request deletion of your personal information (subject to legal and medical record retention requirements)
- Opt out of non-essential communications
- Lodge a complaint with your applicable data protection authority
To exercise any of these rights, please contact us at privacy@1strx.com.
8. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we learn we have collected information from a minor, we will delete it promptly.
9. Security
We implement administrative, technical, and physical safeguards designed to protect your information from unauthorized access, disclosure, or destruction. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a new effective date. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact:
- Email: privacy@1strx.com
- Mailing address: 1stRX, Privacy Officer, [Address on file]