Legal

Privacy & Trust Statement

Version
2.0
Effective
August 24, 2026
Last updated
August 2026

RxScribe™ is a desktop clinical documentation and prescribing-support application for Canadian community pharmacies. This Privacy & Trust Statement describes how OneRx Inc. (“OneRx,” “RxScribe,” “we,” “our”) collects, uses, safeguards, and discloses information in connection with the RxScribe desktop application and related services (the “Services”).

We are committed to protecting information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), provincial health-information legislation — including Alberta’s Health Information Act (HIA), Ontario’s Personal Health Information Protection Act (PHIPA), British Columbia’s Personal Information Protection Act (PIPA-BC), Quebec’s Act Respecting the Protection of Personal Information in the Private Sector, and equivalent statutes in other provinces — and professional standards established by Canadian colleges of pharmacy.

This version reflects a material expansion of the Services: pharmacist prescribing, on-device transcription for Ambient Scribe, reading clinical information from an image or a region of your screen, in-app support reports that may include a screenshot, and workstation registration. Sections 4 through 9 describe those features specifically, and we recommend that pharmacy custodians read them in full.

1Purpose of RxScribe

RxScribe is a sandboxed desktop application that helps pharmacists author clinical documentation faster and more consistently, and — where the pharmacist holds the authority to do so — supports them in prescribing within their scope of practice. After signing in through the OneRx portal, a pharmacist selects a module and completes a structured, module-specific workflow.

1.1 Modules currently supported

  • Follow-Up — review and assessment of therapy already underway.
  • Renewal — continuation of existing therapy with structured days-supply capture.
  • CACP / SMMA — comprehensive annual care-plan documentation.
  • Rx Prescribe — algorithm-guided pharmacist prescribing for a published indication. See section 4.
  • Adaptation — equivalent substitution of dose, form, or brand with documented rationale.
  • Injection consent — injection administration with verbal-consent capture.

1.2 Features that span the modules

  • Ambient Scribe — optional recording of a consultation, transcription, and an automatically drafted note the pharmacist must review. See section 5.
  • Reading from an image or screen region — optional extraction of a medication list, clinical values, or an immunization history from a photograph, a file, or a rectangle you drag on your own screen. See section 6.
  • Patient records — an in-app library of finalized records, and a per-patient chart assembled under a pharmacist-chosen patient code. See section 3.3.
  • Feedback & support — in-app reporting that may include a screenshot of the RxScribe window. See section 7.

RxScribe is not a dispensing system, a pharmacy management system, or a regulatory submission portal. It assists the pharmacist in producing professional, defensible clinical records, which the pharmacy custodian then retains in accordance with its own obligations.

Rx Prescribe supports a clinical decision the pharmacist makes and is professionally responsible for. It does not prescribe, and it is not a substitute for the pharmacist’s own assessment. Section 4 and the Terms of Service set out that boundary in detail.

2Roles & Responsibilities

  • The participating pharmacy and its licensed pharmacists are the custodians (or health information custodians / trustees, depending on jurisdiction) of the personal health information processed through RxScribe.
  • OneRx acts as an information manager, agent, or service provider — processing information only on the documented instructions of the custodian and only as necessary to deliver the Services.
  • Ownership and control of clinical documentation generated through RxScribe remain with the pharmacy custodian at all times.
  • Where a pharmacy professional uses RxScribe as part of their independent practice, that professional is responsible for ensuring their use of RxScribe is consistent with their college’s standards of practice and applicable privacy legislation.
  • Deciding whether to use the optional features — Ambient Scribe, image and screen-region reading, and screenshots attached to support reports — and obtaining any consent they require is the custodian’s decision, not ours.

If you are a patient of a pharmacy that uses RxScribe, please direct privacy questions about your health information to that pharmacy. We assist custodians in responding to access and correction requests as required.

3Information We Collect

3.1 Account, sign-in, and stored credentials

When you sign in, RxScribe collects the minimum information needed to authenticate you and authorize your access to the Services:

  • Your professional name, role, and email address registered with the OneRx portal.
  • The pharmacy site identifier(s) you are entitled to access, and your pharmacy’s profile details — including its address, phone and fax number — used to render document footers.
  • Authentication credentials submitted to the OneRx portal, and the session tokens it issues, which RxScribe uses to call the clinical API on your behalf.
  • The documenting-user name you select in the app, which is attributed to the records you create and is remembered on that workstation until you sign out or select someone else.
  • Your choice of whether to stay signed in on this workstation (“Remember this session”).

Please read this if you share a workstation. When “Remember this session” is enabled, RxScribe stores your email address AND your password in your operating system’s protected credential store so the sign-in form can prefill them. They are held outside the application’s own files, are not readable by the part of the app that draws the screen, and are never transmitted to us except as an ordinary sign-in. They deliberately survive signing out, which means anyone with access to your operating-system account can sign back in as you. They are erased when you sign in with “Remember this session” switched off, and when an administrator revokes the workstation. On a shared workstation we recommend leaving that option off and giving each staff member their own operating-system account.

3.2 Clinical documentation content

As you work through a module, RxScribe assembles documentation on the pharmacy custodian’s behalf. Depending on the module, this may include:

  • Selected medications and drug identification numbers, dose, route, frequency, and days supply.
  • Indication(s), assessment topic, encounter reason, and supplementary clinical context that you enter.
  • Patient context you enter for an assessment — which, in Rx Prescribe, includes age, weight, pregnancy or breastfeeding status, allergy classes, active medications, and vital signs such as blood pressure.
  • Adaptation rationale, and the original and adapted supply.
  • Injection selections, route(s), and the verbal-consent record.
  • Immunization history and clinical observations, including any read from an image under section 6.
  • Draft and finalized documentation text that the pharmacist authors, edits, and approves.

Documentation you have not yet finalized is held as a draft — on your workstation, and for some modules on our clinical API — so that you can resume an interrupted note. Finalized records are stored on the clinical API and retrieved through the in-app patient records library.

3.3 Patient identity

RxScribe identifies patients by a pseudonymous patient code that the pharmacist chooses — not by name, date of birth, health number, or chart number. The code is scoped to your pharmacy, and it is what links a set of records together into a patient chart. A pharmacist may also set an optional private mnemonic to help them find a patient again; that mnemonic can be searched but is never returned by our APIs, never appears in a document, and is never written to an audit log.

Patient identifiers are not required to operate RxScribe — an encounter may be documented with no patient code at all. Free-text fields, dictated speech, and captured images are the three places where identifiable information can nonetheless enter the app; pharmacists should follow their custodian’s policies on what, if anything, is entered there. Choosing a patient code that is itself an identifier (a full name, a health number) turns a pseudonymous key into an identifying one, and we recommend against it.

3.4 Information stored on your workstation

Because RxScribe runs locally, some information is held on the workstation itself, in the protected per-user application storage your operating system provides:

  • Drafts of documentation in progress, so that a crash, a restart, or the end of a shift does not lose your work.
  • Application preferences — window size and position, the last module you used, and interface settings.
  • A short queue of diagnostic events, and any support report that could not be sent because the workstation was offline. Screenshots are never part of that queue (see section 7).
  • Application logs, which record errors and operational events but not clinical content.
  • Session tokens and, if you enabled prefill, your sign-in credentials — held in your operating system’s protected credential store rather than in application files, and not readable by the part of the app that draws the screen.

Consultation audio and transcripts are deliberately absent from that list. Neither is ever written to your workstation’s permanent storage. See section 5.

4Pharmacist Prescribing (Rx Prescribe)

Rx Prescribe supports a pharmacist who is prescribing within their own scope of practice. It is available only where the pharmacist holds that authority under their provincial legislation and college standards, and it does not extend, confer, or verify that authority.

4.1 How the workflow uses information

  • The pharmacist selects a published indication. RxScribe retrieves the corresponding clinical pathway — the questions to ask, the red flags to check, and the therapy options to surface — from our clinical API.
  • The pharmacist enters patient context (such as age, weight, pregnancy or breastfeeding status, allergy classes, active medications, and vital signs), answers red-flag screening questions, and completes a structured assessment.
  • That encounter information is sent to our clinical API, which computes the assessment outcome, resolves which therapy pathway and drug groups to surface, and returns any advisories and referral guidance. The evaluation runs on our servers so the clinical logic is authoritative and versioned, rather than depending on the version installed on a given workstation.
  • The pharmacist — not the software — selects the product, dose, and duration from what is surfaced, or decides not to prescribe.
  • RxScribe then generates a chart note and a physician summary from the encounter. The pharmacist reviews and edits both before finalizing, and finalizing writes the record to the pharmacy’s clinical record store.

4.2 Sharing with the patient’s prescriber

The physician summary exists so a patient’s primary care provider can be told what was prescribed and why. If a pharmacist sends, prints, or faxes it, that is a disclosure of personal health information made by the pharmacy custodian, at the pharmacist’s direction, under the custodian’s own authority and consent practices. RxScribe produces the document; it does not transmit it to a prescriber on your behalf, and it does not determine that the disclosure is permitted.

4.3 What the algorithm is, and is not

The clinical pathways in Rx Prescribe are structured representations of published guidance. They compute scores, apply eligibility rules, and gate on red flags in order to present a defensible starting point and a complete record of the reasoning. They do not examine the patient, do not know anything the pharmacist has not entered, and do not perform interaction, allergy, or duplicate-therapy screening against the patient’s full medication history — that remains the function of the pharmacy’s dispensing system and of the pharmacist’s own judgement.

Red-flag screening is an aid, not a safety net. An outcome that raises no flag is not a clearance to prescribe. The pharmacist remains the prescriber of record, and is solely responsible for the clinical appropriateness of what is prescribed, for referring when referral is warranted, and for the accuracy of the resulting documentation.

5Ambient Scribe (Recording a Consultation)

Ambient Scribe is an optional feature. When a pharmacist chooses to use it, RxScribe records the spoken consultation through the workstation microphone, produces a written transcript, and drafts a clinical note from that transcript. The pharmacist reviews and edits the note before anything is saved. Recording never begins automatically: it starts only when the pharmacist explicitly starts a session, and the application shows a clear on-screen indicator — which can be turned toward the patient — of whether recording is active or paused.

Consent is the pharmacist’s responsibility as custodian. RxScribe presents a disclosure to read aloud, requires the pharmacist to confirm the patient was informed and agreed, and offers a decline path that ends the session and returns to ordinary documentation. Patients may decline without affecting the care they receive, and may ask the pharmacist to pause or stop recording at any point.

5.1 Where transcription happens

On workstations that support it, transcription runs entirely on the workstation: the audio is converted to text on the machine itself, and no audio is transmitted anywhere. This is the default wherever it is available, and it is the single most significant privacy property of the feature.

Where on-device transcription is not available — currently on macOS, and on any installation whose on-device engine is missing — RxScribe falls back to transcribing through our clinical service, which uses a third-party speech-to-text provider that processes audio outside Canada. Section 12 describes that path and its safeguards. The engine is chosen once, when the session opens, and does not change mid-consultation.

5.2 What happens to the recording

  • The audio is held in memory only, for as long as it takes to transcribe it. It is never written to permanent storage on the workstation or on our servers, and no copy is kept once the session ends.
  • Drafting the note from the transcript is not done on the workstation. The transcript is sent to our clinical service, which removes identifiers from it before the drafting step, so the drafting model does not receive patient names, health numbers, contact details, or similar identifiers.
  • Identifier removal fails closed: if that service is unavailable or degraded, Ambient Scribe is disabled and the pharmacist is told before recording rather than after.
  • The transcript exists only for the duration of the session. It is shown to the pharmacist for review and destroyed when the note is saved or the session is discarded. It is not part of the clinical record.
  • Only the reviewed, pharmacist-approved note is retained, under the same terms as any other clinical documentation the pharmacy stores.
  • Any period during which recording was paused is recorded as a gap, so the note cannot imply the conversation was continuous.

Patient identifiers are not required to use Ambient Scribe, and pharmacists are asked not to state them aloud where it can be avoided. Automated identifier removal is a safeguard, not a guarantee: it can miss an identifier, and it can also remove something clinically meaningful. That is one of the reasons the pharmacist’s review of every generated note is mandatory before it can be saved.

Notes drafted by this feature are produced by an automated system and can contain errors or omissions, including statements that were never said. Speech-recognition accuracy varies with accent, background noise, and audio quality. The pharmacist must review and correct each note and remains professionally responsible for its accuracy. RxScribe will not save a generated note until the pharmacist confirms it has been reviewed.

6Reading From an Image or Screen Region

RxScribe can read a medication list, clinical values, or an immunization history from a picture instead of requiring them to be typed. The pharmacist supplies the picture in one of two ways: by choosing an image file, or by dragging a rectangle over a region of their own screen. The selected image is sent to our clinical API, which extracts the structured values and matches them against our catalogues. The pharmacist reviews every extracted row before any of it enters a record.

6.1 What this feature can see

This is the one feature in RxScribe that can capture content belonging to other applications. When you drag a rectangle, RxScribe hides its own window and captures the region you selected — which may be your dispensing system, an electronic health record, or a scanned document. Whatever is inside that rectangle, including any patient identifiers visible in it, is contained in the image sent for extraction.

  • Nothing is ever captured without the pharmacist starting the capture and dragging a selection. There is no timer, no hotkey, and no background capture path.
  • Only the rectangle you selected is transmitted. The full-screen frame it was cropped from exists in memory for the length of one crop, is never written to disk, is never logged, and is never sent anywhere.
  • Images are transmitted over an encrypted connection, are used only to produce the extraction result, and are not retained by us as part of the clinical record.
  • Extracted values are treated as a transcription, not as a clinical finding: they are presented for the pharmacist to confirm, correct, or discard.

The pharmacist decides what falls inside the rectangle. Before capturing, please confirm you are authorized to view and to send the content on screen, and select as tightly as the task allows — a selection that includes a patient banner sends that banner too.

7Feedback & Support Reports

RxScribe includes an in-app way to report a problem or request a change. A report contains what you write, the screen you were on, your application version and operating system, and — only if you add one — a screenshot.

7.1 Screenshots

  • A screenshot is only ever taken when you press the button that takes one. There is no automatic or background capture.
  • It can only ever show the RxScribe window itself. It is read from our own application’s rendering rather than from your screen, so it physically cannot include your dispensing system, an electronic health record, or anything on a second monitor.
  • The screenshot is held in memory and is never written to your workstation’s storage. It is discarded automatically after a short period, when you submit the report, and when you sign out.
  • You are shown a preview before sending — precisely so you can notice a patient’s information in the picture and remove the attachment before it goes.
  • If a report cannot be sent because the workstation is offline, the text is queued for the next launch and the screenshots are discarded; a queued report says so in its own body. Screenshots are never written to disk, not even to retry a send.

A submitted report may contain personal health information if you include it — in your description or in an attached image. Please describe the problem rather than the patient wherever that is possible. Reports are retained for as long as needed to investigate and resolve the issue and to keep a record of the resulting change.

8Diagnostics, Logs & Telemetry

To keep RxScribe reliable and secure we collect a bounded set of operational information. It is designed around one rule: enough to find a fault, never enough to reconstruct a patient encounter.

  • Application version, operating system, release channel, and the workstation identifier described in section 9.
  • Sign-in, session, and security-audit events.
  • A fixed, published set of named operational events — startup, update progress, crashes, and error categories — sent in authenticated batches. Events carry named properties from a defined list; they do not carry free-form clinical text.
  • Crash reports identified by error type and by the code path that failed. RxScribe deliberately discards crash MESSAGE text before it is sent, because an error raised inside a clinical operation can quote the data that caused it.
  • Source IP and request metadata observed by our APIs, for rate-limiting and abuse prevention.

Before anything is transmitted, operating-system user folder names are replaced (a staff member’s name commonly appears inside a file path), and anything shaped like a token, password, key, or authorization header is stripped. Our servers re-apply the same rules on receipt rather than trusting the version of the app that sent them.

Application logs are written on the workstation and stay there unless you choose to send one to support. Logs record operations, sizes, counts, and error categories. Audio, transcript text, and the contents of clinical documents are excluded from logging in every environment, including during development.

This is operational telemetry, not analytics. RxScribe contains no advertising or marketing analytics, no behavioural tracking, no third-party trackers, and no session-replay tooling.

9Workstation Registration & Updates

Each RxScribe installation is bound to the workstation it runs on, so a pharmacy’s access can be granted, counted, and revoked per machine.

  • RxScribe derives a stable workstation identifier from an operating-system machine identifier, transformed so the original value cannot be recovered from it. It identifies the computer, not the person, and does not carry your name, a serial number, or a network address.
  • That identifier is registered against your pharmacy and occupies one of its device slots. An administrator can approve, refuse, or revoke a workstation; a revoked workstation loses access and has its stored credentials cleared.
  • When RxScribe is uninstalled it releases its own slot before removing itself. A workstation can only ever deregister itself.
  • RxScribe checks for updates, downloads them, and verifies their integrity and signature before installing. Update checks and outcomes are reported as operational events (section 8).

10How We Use Information

We use information collected through RxScribe solely to:

  • Authenticate you and authorize access to the Services on behalf of your pharmacy custodian.
  • Operate the modules — search medications, list indications, evaluate a prescribing pathway, extract values from an image, transcribe and draft a note, and assemble draft and final documentation.
  • Persist drafts on your workstation and on our APIs so you can resume an in-progress note.
  • Maintain finalized clinical records and patient charts for retrieval through the in-app library.
  • Monitor system performance, diagnose faults, install updates safely, and prevent abuse.
  • Investigate and resolve the support reports you submit.
  • Meet our contractual obligations to the pharmacy custodian, and our own legal and professional obligations.
  • Communicate with you about Service availability, security advisories, and changes that materially affect how RxScribe works.

We do not sell personal information or personal health information, and we do not use it for behavioural advertising. We do not use your clinical content, consultation audio, transcripts, or captured images to train artificial-intelligence models, and the providers we engage are contractually barred from doing so.

Aggregated and de-identified usage data — counts, timings, and error rates that cannot be attributed to a patient, a pharmacist, or a pharmacy — may be used to improve platform reliability and documentation quality.

11Sharing & Disclosure

We disclose information only in the limited circumstances below, and only the minimum necessary for the purpose:

  • Custodian-directed processing — routing information between the RxScribe application and our clinical API at the direction of the pharmacy custodian.
  • Processing providers — the speech-to-text provider used on the fallback transcription path (section 5.1), and the model providers used to draft a note from a de-identified transcript and to extract values from an image. Each is engaged under written confidentiality and data-protection obligations, is permitted to use the information only to return the result, and is barred from retaining it for training or any other secondary purpose.
  • Infrastructure and support providers — hosting, security, error-monitoring, and customer-support vendors engaged by OneRx under equivalent obligations, on a need-to-know basis.
  • Legal or regulatory disclosures — where compelled by Canadian law, lawful order, or the request of a regulatory authority with proper jurisdiction.
  • Safety or fraud prevention — to protect the rights, property, or safety of OneRx, our customers, or the public, and to investigate misuse of the Services.
  • Business continuity — in connection with a merger, acquisition, financing, or reorganization, with appropriate safeguards and continued application of this Statement.

Documents that a pharmacist sends to a patient’s prescriber, to the patient, or to a payer are disclosures made by the pharmacy custodian, not by OneRx. RxScribe produces the document; the decision to disclose it, and the authority to do so, belong to the custodian.

OneRx does not sell personal information or personal health information, and does not disclose information for third-party marketing.

12Where Your Data Resides

RxScribe is built on a Canada-first data strategy. Our clinical API and the OneRx portal authentication services host and process pharmacy information within Canada wherever reasonably possible. A pharmacy custodian that must document where its records are stored should request written confirmation from us for its own assessment.

Some supporting services — for example email delivery, error monitoring, or customer-support tooling — may operate outside Canada. Where that is the case, OneRx applies layered safeguards: legally binding privacy commitments, tightly scoped access, strong encryption in transit and at rest, and contractual restrictions on secondary use. Pharmacy custodians are informed of cross-border arrangements where their applicable legislation requires it.

12.1 The transcription fallback

Where Ambient Scribe cannot transcribe on the workstation (section 5.1), the consultation audio is sent to a third-party speech-to-text provider that processes it outside Canada, most commonly in the United States. This is the only circumstance in which information that has not yet had identifiers removed leaves Canada, and it is unavoidable on that path: identifier removal operates on text, and transcription is the step that produces the text. The audio is transmitted over an encrypted connection, is processed only to produce the transcript, is not retained by the provider for training or any other secondary purpose, and is never written to disk by OneRx.

Everything after transcription is different. The transcript has identifiers removed before it reaches the service that drafts the note. Pharmacists are not required to state identifiers aloud, and the pause control exists so recording can stop the moment a conversation moves to something the patient does not wish captured.

A pharmacy that requires consultation audio never to leave Canada should confirm that its workstations support on-device transcription, and should treat the fallback path as a decision for the custodian rather than a technical detail. Contact us and we will confirm which path a given installation is using.

While information is located in a foreign jurisdiction it may be subject to the laws of that jurisdiction, including disclosure to its lawful authorities. OneRx contests requests it considers unauthorized to the extent permitted by law.

13Retention

  • Account and authentication records are retained for as long as your pharmacy uses RxScribe and for a reasonable period thereafter to satisfy security and audit obligations.
  • Clinical documentation — drafts, finalized records, patient charts, and related metadata — is retained in accordance with the pharmacy custodian’s policies and applicable provincial records-retention requirements.
  • Consultation audio is retained only in memory for the duration of transcription and is never written to disk. The transcript is retained only for the duration of the session and destroyed when the note is saved or discarded. Neither is part of the clinical record.
  • Images captured or supplied for extraction are retained only as long as the extraction requires, and are not retained as part of the clinical record.
  • Screenshots attached to a support report are held in memory only, expire automatically, and are purged on submission and on sign-out. The report itself is retained for as long as needed to investigate and resolve it.
  • Diagnostic events queued on the workstation are bounded in both count and age, and are discarded once sent or once the bound is reached.
  • Local drafts, preferences, and cached files persist on the workstation until you delete the record, sign out, uninstall RxScribe, or clear the application’s data.
  • Session tokens are removed when you sign out, when your session expires, or when a workstation is revoked. Stored sign-in credentials are removed when you sign in with prefill switched off, or when a workstation is revoked — note that they deliberately survive an ordinary sign-out (section 3.1).
  • Aggregated or de-identified records used for service improvement are retained for as long as they remain useful to that purpose.

When information is no longer required for the purposes for which it was collected, we securely delete or de-identify it.

14Security Safeguards

OneRx applies layered administrative, technical, and physical safeguards proportionate to the sensitivity of the information handled. In the desktop application specifically:

  • The part of the app that draws the screen runs isolated and sandboxed, with no direct access to the file system and no ability to make network requests of its own. Everything it needs is requested over a narrow, typed channel, and every request across that channel is validated and checked to have come from the application’s own trusted window.
  • Session tokens and stored credentials are held in the operating system’s protected credential store rather than in application files or browser storage, and are not readable by the part of the app that draws the screen.
  • Clinical documentation submissions are encrypted on the workstation before transmission — with a strong symmetric cipher whose key is itself wrapped for our servers — in addition to the encrypted transport used for every request. Our servers are the only party able to unwrap them.
  • Outbound connections are restricted to our own configured endpoints, use encrypted transport, enforce timeouts, and are never silently retried where a repeat would duplicate a clinical record.
  • The RxScribe window is excluded from operating-system screen capture and screen sharing, so other applications cannot photograph a patient’s information from it.
  • Developer and remote-debugging tools are disabled in shipped builds — they would otherwise expose clinical content and session tokens directly out of a running app — and the application binary is hardened against being repurposed to run untrusted code.
  • Updates are signed and verified before installation, and a version known to be unsafe can be blocked centrally.
  • Role-based access on our APIs, per-workstation binding and revocation, secure authentication including multi-factor where the pharmacy enables it, audit logging, vulnerability monitoring, and regular risk reviews.
  • Privacy and security training for OneRx personnel, and least-privilege access to production systems.

No system can guarantee perfect security. If you believe a security or privacy incident has occurred, please contact us promptly using the details at the end of this Statement.

15Securing Your Own Workstation

RxScribe runs on a computer in your pharmacy, and some information necessarily lives there. You are responsible for the physical and operating-system security of that device. RxScribe does not sign you out after a period of inactivity — a deliberate decision, because re-authenticating repeatedly during a shift carries its own risks — which makes the measures below more important, not less.

  • Lock your workstation whenever you step away from it.
  • Give each staff member their own operating-system account. RxScribe’s stored credentials and drafts are protected per operating-system user, so a shared login shares them too.
  • Enable full-disk encryption.
  • Leave “Remember this session” off on any shared workstation (see section 3.1).
  • Sign out of RxScribe at the end of a shift on a shared workstation, and ask your administrator to revoke any workstation that leaves the pharmacy.

16Cookies, Tracking & Analytics

RxScribe is a packaged desktop application, not a website. Its interface loads from files that ship with the installer and are served privately by the application itself; it does not load remote pages, and it does not run third-party trackers, advertising pixels, or marketing analytics.

The application keeps a small amount of local state to remember non-sensitive interface preferences — for example, which documenting user you last selected on this workstation. There are no third-party cookies for advertising or cross-site tracking. Operational diagnostics are limited to what section 8 describes.

Our public marketing or support websites, if any, may use essential cookies for authentication and security, and optional analytics cookies subject to applicable consent requirements. Those are managed through your browser settings and are outside the scope of the desktop application.

17Access, Corrections & Inquiries

  • Requests about your RxScribe account — your professional profile, sign-in records, audit information — may be directed to OneRx using the contact details at the end of this Statement.
  • Requests about personal health information processed through RxScribe must be directed to the pharmacy custodian. OneRx assists custodians in responding to access and correction requests as required by our agreements and by applicable legislation.
  • Because patients are identified in RxScribe only by a pharmacist-chosen code, locating a specific patient’s records generally requires the custodian to supply that code. We cannot identify a patient from a name.
  • Subject to applicable law and contractual restrictions, you may withdraw consent for our collection, use, or disclosure of personal information at any time. Withdrawing consent may limit our ability to provide some or all of the Services.

We may ask you to confirm your identity before responding to an access, correction, or deletion request, and we may need to retain certain information to meet legal, audit, or regulatory obligations even after such a request.

18Children & Third-Party Services

RxScribe is intended for professional pharmacy use and is not directed to children. We do not knowingly collect personal information from children through the Services. Personal health information about minor patients is handled in accordance with the pharmacy custodian’s policies and applicable legislation, which generally requires consent from a parent, guardian, or other authorized representative for younger minors.

RxScribe may operate alongside third-party services that pharmacy custodians choose to use — the OneRx portal for account management, or the pharmacy’s own dispensing system. Those services are governed by their own terms and privacy policies. OneRx is not responsible for the privacy practices of services we do not operate, including any system whose content a pharmacist captures under section 6.

19Privacy Impact Assessment & Compliance

OneRx maintains a Privacy Impact Assessment appropriate to RxScribe and supports participating pharmacies with the documentation they may require for their provincial regulator — including the Office of the Information and Privacy Commissioner of Alberta, the Information and Privacy Commissioner of Ontario, and equivalent offices in other provinces.

We work collaboratively with pharmacy custodians on data-processing agreements, information manager arrangements, and the reporting obligations that may apply under provincial health-information legislation. Custodians assessing the optional features in sections 4 through 7 may request the supporting detail they need for their own assessment.

20Policy Updates

We may update this Privacy & Trust Statement to reflect changes to the Services, our practices, or our legal obligations. The effective date and version shown at the top indicate the most current version.

Material updates — in particular any change to what leaves your workstation, or to where it is processed — will be communicated through the application, by email to registered pharmacy administrators, or both. Continued use of RxScribe after the effective date of an updated Statement signifies acceptance of the change.

21Contact Us

For questions, concerns, or requests regarding this Statement or our handling of information, please contact our Privacy Officer:

  • Email: admin@myonerx.ca
  • Product support: support@myonerx.ca
  • OneRx Inc. — RxScribe by OneRx

If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada (1-800-282-1376, www.priv.gc.ca) or the privacy regulator in your province.

Ready to Experience the OneRx Difference?

Book a personalized demo and see how OneRx can help your pharmacy thrive.