Legal
Privacy Policy
Effective: 2026-08-04
WeConsult Rx (“we”, “us”), operated by DRX Consulting Group, LLC, provides a consultant-pharmacy compliance platform at app.weconsultrx.com (the “Platform”) for skilled nursing, assisted-living, and dialysis facilities. This Privacy Policy explains how we collect, use, disclose, and safeguard information in connection with weconsultrx.com and the Platform. By accessing the Platform, you consent to the practices described here.
1. Information we collect
1.1 Information you provide: name, work email, phone, organization, role, demo/contact form submissions, newsletter subscriptions, and (if you opt in) your mobile phone number for SMS notifications.
1.2 Automatically collected: login events, audit log entries, feature usage, IP address, browser user agent, request timestamps, and aggregated performance/error telemetry (no PHI).
1.3 Customer content: customer content, including PHI (resident charts, medication regimens, review outcomes), is processed only under a Business Associate Agreement (BAA). It is owned and controlled by the customer, not by WeConsult Rx. See our BAA.
2. How we use information
- To provide, operate, and improve the Platform.
- To respond to demo / contact requests.
- To send transactional notifications (review reminders, license renewals, bundle status) by email and, if you opt in, SMS.
- To send marketing email, only with your consent.
- To sync calendar events (title/time only, via Google or Microsoft OAuth) when you connect a calendar.
- To meet legal, regulatory, and HIPAA obligations.
- To investigate fraud, abuse, or security incidents.
We do not sell personal information. We do not run third-party advertising trackers. We do not share customer content for AI training.
3. How we share information
We do not sell, rent, or trade your information to third parties for marketing. We share information only with subprocessors bound by data processing agreements, needed to operate the Platform. See the full list, purposes, and BAA status of every subprocessor on our Subprocessors page.
AI data processing: chart-review synthesis uses AI inference on de-identified prompts only. Prompts are stripped to the HIPAA Safe Harbor standard before they leave our environment, and de-identification is verified at the egress boundary — a prompt containing residual identifiers is blocked rather than sent. Our primary inference provider operates under a signed BAA; a secondary provider is used only as failover and never receives PHI.
4. Text messaging (SMS and RCS)
If you opt in, from Account Settings or the opt-in checkbox on our public forms, we collect your mobile phone number and a timestamped consent record (the disclosure text and version you agreed to). We use that phone number solely to send you text reminders (e.g. items due for review) via Twilio, delivered as SMS or RCS (Rich Communication Services) messages. Message content — including any rich media that RCS can carry — is limited to facility-level, non-clinical information: no patient, resident, or diagnosis data is ever included in a text message.
Message frequency varies with your facility’s activity; a typical user receives between 0 and 8 messages per week. Message and data rates may apply. Reply STOP to opt out or HELP for help. Full program details are in our SMS & RCS Terms.
Mobile information and messaging consent are not shared with third parties or affiliates for marketing or promotional purposes.
The phone number and consent record collected during opt-in are used only to deliver the notifications you signed up for. We share the phone number with Twilio (our SMS and RCS delivery provider) solely to send messages, and with our database provider (Supabase) to store the consent record — both bound by data processing agreements. We do not sell, rent, lease, or otherwise transfer your phone number or SMS/RCS opt-in status to any other party for marketing, advertising, or promotional purposes.
5. Data retention
- Account data: for the duration of the account + 90 days.
- AI prompts: not retained — inference is stateless and prompts are discarded after the response is returned.
- Audit log: 7 years (HIPAA §164.530(j)).
- Customer content: per the Master Services Agreement.
- Marketing leads: 18 months unless extended by ongoing dialogue.
- SMS consent records: for as long as you remain opted in, plus a reasonable audit-trail period after opt-out.
To request deletion of your data, email [email protected]. Requests are processed within 30 days, subject to legal retention requirements (e.g. the HIPAA audit-log period above).
6. Data security
- TLS 1.2+ encryption in transit; AES-256 encryption at rest.
- Row-level security (RLS) enforcing per-tenant data isolation at the database layer.
- Short-lived JWT authentication tokens.
- Automated audit logging of access to customer content.
- Role-based access controls, least privilege.
- Regular security review and dependency auditing.
7. Your rights
All users: you may access, correct, delete, or port your personal information, and object to processing for specific purposes. Email [email protected] to exercise any of these rights.
California residents (CCPA/CPRA): we do not sell personal information. See /ccpa for your California-specific rights.
EU/UK residents (GDPR): we process data under legitimate interest and consent. See /gdpr for your EU/UK rights, or contact our Data Protection Officer at [email protected].
8. Cookies
See our Cookie Policy for details on cookies and local storage used by weconsultrx.com and the Platform.
9. Children’s privacy
The Platform is intended for use by licensed healthcare professionals and facility staff and is not directed to individuals under 18. We do not knowingly collect information from children.
10. International transfers
Our infrastructure is primarily hosted in the United States. EU/UK transfers rely on Standard Contractual Clauses incorporated into our Data Processing Agreement.
11. Changes to this policy
We will post material changes here and update the effective date. Material changes require at least 30 days’ notice; for active customers we will additionally notify by email.
12. Contact
Data Protection Officer · [email protected] General support · [email protected]