OneRx Privacy & Trust Statement
Table of Contents
- 1. Overview
- 2. Products & Services covered
- 3. Legislation and standards
- 4. Information we collect
- 5. How we use information
- 5A. Consent
- 5B. Automated processing
- 6. Product-specific handling
- 7. Who we share information with
- 8. Where information is held
- 9. Retention
- 10. Security
- 11. Your rights
- 11A. Children
- 12. Third-party services
- 13. Contact us
- 14. Changes to this Statement
1. Overview
OneRx builds software for Canadian community pharmacies. OneRx Inc. (“OneRx,” “we,” “our,” “us”) provides Rx Scribe, Rx Manager (including its Rx Assist and Rx Connect modules), Rx Intelligence, Rx Incident, and the myonerx.ca site (collectively, the “Services”). Our customers are pharmacies; the pharmacists, technicians, and administrative staff who use the Services do so on behalf of a pharmacy account.
Each province and territory has its own privacy and health-information laws. Under the law that applies where a pharmacy operates, the pharmacy is responsible for the health information it handles, as its custodian or, in Saskatchewan and Manitoba, its trustee. OneRx acts on the pharmacy’s behalf as its service provider, a role some of those laws call an information manager and others an agent. We process health information only on the pharmacy’s documented instructions, and only as far as delivering the Services requires.
For the personal information we handle in our own right (for example, information about a pharmacist’s OneRx account), we are an accountable organization under the federal Personal Information Protection and Electronic Documents Act (PIPEDA) or, where it applies instead, a substantially similar provincial law. Section 3 names the laws, privacy oversight offices, and pharmacy regulators for every province and territory.
This Statement explains what information the Services collect, why, who we share it with, and the rights available to individuals.
2. Products & Services covered
This Statement covers the OneRx suite as a whole. The clauses that follow apply to all Services unless a specific product is called out. Product-specific handling is described in Section 6.
- Rx Scribe. A desktop application that helps pharmacists produce clinical documentation from a consultation, including an ambient-scribe workflow that captures consultation audio and produces a draft note.
- Rx Manager. The desktop pharmacy-operations platform used by pharmacy staff. Rx Manager includes several integrated modules delivered as part of the same product:
- Rx Assist. Prescription intake and extraction from images and faxes.
- Rx Connect. Pharmacy telephony, fax, and phone-number management.
- Additional modules for scheduling and appointments, incident logging, call and fax logging, and a patient-facing booking surface.
- Rx Intelligence. An analytics platform that surfaces operational and business metrics (sales, cost, inventory, formulary coverage, purchase-order optimization) to pharmacy owners and managers.
- Rx Incident. A Continuous Quality Improvement platform for incident reporting, root-cause analysis, and pharmacy practice self-assessment, aligned with the continuous quality improvement expectations of provincial and territorial pharmacy regulatory authorities and with the National Incident Data Repository (NIDR).
- OneRx portal (myonerx.ca). The public marketing site, including its contact form.
3. Legislation and standards we work to
Across Canada, the federal Personal Information Protection and Electronic Documents Act (PIPEDA) applies to personal information collected, used, or disclosed in the course of commercial activity. Alberta, British Columbia, and Quebec have private-sector privacy laws that apply instead of PIPEDA within those provinces. Ontario, New Brunswick, Nova Scotia, and Newfoundland and Labrador have health-information laws that apply instead of PIPEDA to health information custodians.
Each province and territory also has its own health-information legislation, privacy oversight office, and pharmacy regulator, listed below. A pharmacy remains the custodian of its own records under the laws where it operates, and OneRx supports that role through its agreement with the pharmacy. We also work to the model standards of the National Association of Pharmacy Regulatory Authorities (NAPRA).
- Alberta
- Privacy law: Health Information Act (HIA) and Personal Information Protection Act (PIPA).
- Privacy oversight: Office of the Information and Privacy Commissioner of Alberta.
- Pharmacy regulator: Alberta College of Pharmacy.
- British Columbia
- Privacy law: Personal Information Protection Act, which applies to private-sector pharmacies, and the E-Health (Personal Health Information Access and Protection of Privacy) Act for health information banks.
- Privacy oversight: Information and Privacy Commissioner for British Columbia.
- Pharmacy regulator: College of Pharmacists of British Columbia.
- Saskatchewan
- Privacy law: The Health Information Protection Act (HIPA).
- Privacy oversight: Information and Privacy Commissioner of Saskatchewan.
- Pharmacy regulator: Saskatchewan College of Pharmacy Professionals.
- Manitoba
- Privacy law: The Personal Health Information Act (PHIA).
- Privacy oversight: Manitoba Ombudsman.
- Pharmacy regulator: College of Pharmacists of Manitoba.
- Ontario
- Privacy law: Personal Health Information Protection Act, 2004 (PHIPA).
- Privacy oversight: Information and Privacy Commissioner of Ontario.
- Pharmacy regulator: Ontario College of Pharmacists.
- Quebec
- Privacy law: Act respecting the protection of personal information in the private sector, and the Act respecting health and social services information where it applies.
- Privacy oversight: Commission d’accès à l’information du Québec.
- Pharmacy regulator: Ordre des pharmaciens du Québec.
- New Brunswick
- Privacy law: Personal Health Information Privacy and Access Act (PHIPAA).
- Privacy oversight: Office of the Ombud for New Brunswick.
- Pharmacy regulator: New Brunswick College of Pharmacists.
- Nova Scotia
- Privacy law: Personal Health Information Act (PHIA).
- Privacy oversight: Information and Privacy Commissioner of Nova Scotia.
- Pharmacy regulator: Nova Scotia Pharmacy Regulator.
- Prince Edward Island
- Privacy law: Health Information Act.
- Privacy oversight: Information and Privacy Commissioner of Prince Edward Island.
- Pharmacy regulator: Prince Edward Island College of Pharmacy.
- Newfoundland and Labrador
- Privacy law: Personal Health Information Act (PHIA).
- Privacy oversight: Office of the Information and Privacy Commissioner for Newfoundland and Labrador.
- Pharmacy regulator: College of Pharmacy of Newfoundland and Labrador.
- Yukon
- Privacy law: Health Information Privacy and Management Act (HIPMA).
- Privacy oversight: Yukon Information and Privacy Commissioner.
- Pharmacy regulator: Professional Licensing and Regulatory Affairs, Community Services, Government of Yukon.
- Northwest Territories
- Privacy law: Health Information Act.
- Privacy oversight: Information and Privacy Commissioner of the Northwest Territories.
- Pharmacy regulator: Professional Licensing Office, Department of Health and Social Services, Government of the Northwest Territories.
- Nunavut
- Privacy law: No territorial health-information law applies to private pharmacies; PIPEDA applies.
- Privacy oversight: Information and Privacy Commissioner of Nunavut, for territorial public bodies. Matters under PIPEDA go to the Office of the Privacy Commissioner of Canada (Section 13).
- Pharmacy regulator: Professional Practice Unit, Department of Health, Government of Nunavut.
4. Information we collect
4.1 Account and professional identity
- The pharmacist, technician, or administrator’s name, professional role, and email address registered with the OneRx portal.
- The pharmacy site(s) the individual is entitled to access, and the pharmacy’s own profile details, meaning its address, phone and fax numbers and licence identifiers, which are used to render document footers, populate telephony records, and route work to the correct site.
- Regulator identifiers (for example a College licence number) where a Service requires them.
4.2 Authentication
- Credentials submitted to the OneRx portal, and the session tokens the portal issues, which the Services use to call OneRx APIs on the individual’s behalf. Passwords are stored as one-way hashes.
- Where a desktop application offers a “remember this session” option, the individual’s email address and, in some configurations, an encrypted credential are held in the operating system’s protected credential store so the sign-in form can prefill them. These are held outside the application’s own files and are only used to sign the individual in.
4.3 Pharmacy operational data (Rx Manager and its modules)
- Prescription intake. Images and PDFs of prescriptions received by the pharmacy, and the structured fields extracted from them (patient name, drug, DIN, dose, directions).
- Telephony. Inbound and outbound call metadata, voicemail, SMS content where SMS is used, call recordings where a pharmacy has enabled recording, and fax content sent and received on the pharmacy’s numbers.
- Fax and print capture. Content sent through the pharmacy’s virtual printer for delivery as a fax.
- Number-management records. Port-in and porting-out status, number-allocation history, and forwarding configuration.
- Scheduling. Staff calendars, patient appointment bookings made through the patient-facing booking surface, and the personal information a patient provides in that booking.
- Business and workflow records. Incident and CQI records handled through Rx Manager’s operational features (Rx Incident is a separate product; see 4.5).
4.4 Consultation audio and clinical documentation (Rx Scribe)
- Consultation audio recorded during an ambient-scribe session, the transcript produced from it, and the clinical note or prescribing document drafted from that transcript.
- The pharmacist’s dictations, edits, and the state of their in-progress workflows.
- Metadata about the workstation and the session used to produce a document.
4.5 Incident and CQI records (Rx Incident)
- Incident narratives, medication details (including DINs), patient stage of care, and other structured fields required to report an incident in the NIDR-aligned format.
- Root-cause analyses, follow-up actions, CQI meeting records, and pharmacy practice self-assessment (PPSA) responses.
- Sensitive incident narrative fields are held with field-level AES-256 encryption in our database. Before submission, narratives are scanned by a PII-detection service configured with recognizers for Canadian identifiers, including Alberta health numbers, Social Insurance Numbers, and postal codes, so that identifiers a reporter did not intend to include can be flagged and removed.
4.6 Analytics data (Rx Intelligence)
- Aggregated and de-identified operational data drawn from the pharmacy’s dispensing and business systems: sales volumes, drug mix, cost and margin, patient counts, formulary and prior-authorization patterns, and inventory forecasts.
- Rx Intelligence is designed to work with aggregated and de-identified data. Where a report requires patient-level information, the pharmacy remains the custodian of that data and controls access to it.
4.7 Website information (myonerx.ca)
- Information an individual provides through the contact form.
- Standard server-side request logs (IP address, user agent, request path, timestamp) held for a short period for security and diagnostics.
- Minimal cookies necessary to operate the site. The contact form is protected by Cloudflare Turnstile, which may set a cookie of its own to tell a person from an automated script. The site uses no analytics or marketing cookies.
4.8 Diagnostic and usage information
- Application telemetry, meaning feature usage counts, error reports and performance measurements, used to diagnose problems and improve the Services. Telemetry schemas are checked at build time to keep patient identifiers out of telemetry.
- Support correspondence you send us.
5. How we use information
We use the information collected for the following purposes:
- To provide, secure, and support the Services.
- To authenticate users and enforce the entitlements set by the pharmacy custodian.
- To produce the outputs the pharmacist has asked the Service to produce: a clinical note, an extracted prescription, a fax, a call record, an incident report, or an analytics view.
- To detect, prevent, and respond to security incidents and misuse of the Services.
- To meet our legal and regulatory obligations, and to enable pharmacy custodians to meet theirs.
- To communicate with users about the Services, through service notices, security advisories, and support responses.
We do not use customer data, patient health information, consultation audio, prescription images, fax content, or incident narratives to train artificial-intelligence models, ours or a third party’s.
Where a component of a Service invokes a third-party model to process information at inference time, we contract for enterprise terms that prohibit the provider from retaining or training on the content submitted, and we prefer enterprise endpoints (for example Google Vertex AI over a consumer-tier Gemini endpoint, and OpenAI’s enterprise API tier with training disabled) over free-tier endpoints for that reason.
5A. Consent
OneRx’s handling of information rests on the following bases:
- Pharmacy account information and business records. The pharmacy custodian consents to OneRx’s handling of information necessary to deliver the Services through the Commercial Agreement between the pharmacy and OneRx, and through this Statement. Individual pharmacists, technicians, and administrators consent to the handling of their professional identity and account information by using the Services in accordance with the Commercial Agreement.
- Personal health information. Personal health information is handled on the documented instructions of the pharmacy custodian, in the pharmacy’s capacity as custodian under the health-information legislation of the province or territory where it operates (see Section 3). Patient consent for the custodian’s collection, use, and disclosure of that information sits with the pharmacy.
- Sensitive processing. Where OneRx introduces a new use of information that goes beyond delivering the Services as described here, such as using aggregated de-identified information to publish a benchmark, that use is opt-in per pharmacy custodian, and this Statement is updated to describe it.
An individual may withdraw consent to OneRx’s handling of their own personal information at any time by contacting the Privacy Officer (Section 13), subject to legal or contractual obligations that require continued processing. Withdrawal of consent may mean that the individual can no longer use the Services.
5B. Automated processing and machine-generated outputs
Several Services produce outputs generated automatically from information the pharmacy provides. Rx Scribe drafts a clinical note from a consultation transcript, Rx Assist extracts prescription fields from an image, Rx Incident may surface AI-assisted pattern signals, and Rx Intelligence generates purchase-order and inventory recommendations.
- Every machine-generated output is a draft for a pharmacy professional to review. OneRx does not make clinical, dispensing, prescribing, or business decisions on the pharmacy’s behalf.
- Where an output is generated with the assistance of a third-party model, that inference request runs under a “no retention, no training” contract as described in Section 5.
- An individual affected by a machine-generated output may request an explanation of the categories of information used to produce it, and may direct that request to the pharmacy custodian (for outputs about a patient) or to OneRx (for outputs about the individual’s own account).
6. Product-specific handling
6.1 Rx Scribe: consultation audio
Where the workstation can transcribe on-device, consultation audio is transcribed locally and the audio file is not transmitted to OneRx. Where the workstation cannot transcribe on-device, the audio is streamed over an encrypted connection to a speech-to-text provider that produces the transcript. That provider is engaged under contractual terms that prohibit retention of the audio and its use for training or any other secondary purpose, the audio is processed only to produce the transcript, and it is not written to disk by OneRx. Identifier removal operates on the transcript text before the drafting step, so the drafting model does not receive patient names, health numbers, or contact details.
6.2 Rx Manager: telephony and fax (Rx Connect)
Rx Connect uses a third-party telephony provider (Telnyx) to deliver voice, SMS, and fax on the pharmacy’s numbers. Telnyx is a United States company, and telephony traffic delivered through Telnyx traverses United States infrastructure. This is disclosed here because a pharmacy custodian may need to record it in its own privacy impact assessment.
Call recordings, where the pharmacy has enabled recording, may contain health information. The pharmacy is responsible for obtaining any consent required and for setting its retention policy for those recordings; OneRx supports the pharmacy in configuring an audible recording notice or announcement in line with CRTC and Office of the Privacy Commissioner of Canada guidance.
Rx Connect also includes a virtual printer that a pharmacy may install on a workstation to route print jobs into the pharmacy’s fax workflow. The virtual printer captures only the jobs the pharmacy explicitly prints to it; it is not a general-purpose keystroke or screen capture, and it does not intercept print jobs sent to other printers on the workstation.
6.3 Rx Manager: prescription intake (Rx Assist)
Prescription images and PDFs uploaded to Rx Assist are processed by an on-service optical-character-recognition engine. Non-standard prescriptions may be escalated to a third-party model for structured extraction; that escalation runs under the same “no retention, no training” terms described in Section 5. Extracted images and generated artifacts are stored with an authenticated-delivery cloud storage provider and are accessible only to the pharmacy that uploaded them.
6.4 Rx Manager: patient-facing booking
The patient-facing booking surface collects the personal information the patient provides to book an appointment (name, contact details, appointment reason). That information is delivered to the pharmacy and is held by OneRx on the pharmacy’s behalf as its information manager.
6.5 Rx Incident
Incident reports are held with field-level encryption for sensitive narrative content. Where a pharmacy has enabled AI-assisted pattern detection, de-identified aggregate signals may be processed by a third-party model under the same “no retention, no training” terms. Where the PII-detection service is temporarily unavailable, a masking fallback is applied so that reports cannot be submitted with unredacted identifiers.
6.6 Rx Intelligence
Rx Intelligence is designed to work with aggregated and de-identified operational data. Some workflows require patient-level information at ingestion or at query time. Prior-authorization tracking is one, and so is a report that drills into a specific patient’s dispensing history. That information is processed as personal health information under the pharmacy’s custodianship, with the same handling as elsewhere in this Statement. Reports and dashboards that OneRx displays across the pharmacy operator’s account use aggregated data by default; patient-level views are gated by the pharmacy’s own access controls.
6.7 OneRx portal
The marketing site collects only the information described in 4.7. It is not used to store patient health information.
8. Where information is held
The Services are built on a Canada-first data strategy. Our clinical and operational APIs, and the OneRx portal’s authentication services, host and process pharmacy information within Canada wherever reasonably possible.
Some supporting services necessarily operate outside Canada. Telephony delivered through Telnyx traverses United States infrastructure. Certain error-monitoring, email-delivery, and inference services may operate outside Canada. Where that is the case, OneRx applies layered safeguards: legally binding privacy commitments, tightly scoped access, strong encryption in transit and at rest, and contractual restrictions on secondary use.
While information is located in a foreign jurisdiction it may be subject to the laws of that jurisdiction, including disclosure to its lawful authorities.
9. Retention
OneRx retains records held on behalf of a pharmacy for the life of the pharmacy’s account with us, so that the pharmacy has continuous access to the records it needs to operate. On written request from the pharmacy custodian, we delete records subject to any legal, audit, or regulatory obligation that requires us to hold them for a longer period, and subject to a reasonable operational window to complete the deletion across backups.
OneRx does not today operate an automatic deletion schedule for pharmacy records. Where a pharmacy requires a specific retention or deletion schedule, that is arranged in the pharmacy’s agreement with OneRx.
Server-side request logs and diagnostic telemetry are held for a short period appropriate to their purpose.
10. Security
OneRx applies administrative, technical, and physical safeguards proportionate to the sensitivity of the information handled. Current safeguards include:
- Encryption in transit for all Service traffic (TLS), and encryption at rest for stored records held in OneRx databases and object storage.
- Field-level AES-256 encryption for sensitive incident-narrative fields in Rx Incident.
- Session-based and token-based authentication with least-privilege authorisation.
- PII-detection with Canadian recognizers for identifiers that a reporter did not intend to include.
- Build-time contract checks that keep patient identifiers out of telemetry.
- Signed and idempotent webhook processing for telephony events.
- Privacy and security training for OneRx personnel, and least-privilege access to production systems.
- Detection, logging, and incident-response processes for security events.
No system can guarantee perfect security. If an individual believes a security or privacy incident has occurred, they should contact us promptly using the details in Section 13.
Where OneRx becomes aware of a breach of security safeguards involving personal information or personal health information, we notify the affected pharmacy custodian promptly. Where the breach creates a real risk of significant harm to an affected individual, which is the standard under PIPEDA’s Breach of Security Safeguards Regulations and is also used by several provincial laws, we support the pharmacy custodian’s notification to affected individuals and to the applicable regulator. Provincial and territorial health-information laws set their own notification duties for custodians, and we support pharmacies in meeting them. Where OneRx itself is the accountable organization for the information involved, we notify the Office of the Privacy Commissioner of Canada or the applicable provincial or territorial privacy oversight office as required. OneRx keeps records of every breach of security safeguards for at least the periods required by law.
11. Your rights
An individual has the right to ask about the personal information OneRx holds about them, to correct information that is wrong, and, subject to legal and regulatory obligations, to ask that it be deleted.
- Requests about a user’s OneRx account, covering the professional profile, sign-in records and audit information, may be directed to OneRx using the details in Section 13.
- Requests about personal health information processed through the Services must be directed to the pharmacy custodian. OneRx assists custodians in responding to access and correction requests as required by our agreements and by applicable legislation.
We may ask an individual to confirm their identity before responding to a request, and we may need to retain certain information to meet legal, audit, or regulatory obligations even after such a request.
11A. Children
The Services are designed for use by pharmacy professionals and staff acting in a professional capacity. They are not directed at, and are not intended for use by, individuals under 18 years of age in their personal capacity. A pharmacy may of course hold information about patients of any age as part of its custodianship; that information is handled as personal health information under this Statement.
12. Third-party services
The Services operate alongside third-party services that a pharmacy chooses to use, such as the pharmacy’s dispensing system, its email provider, or systems whose content a pharmacist captures through Rx Manager’s intake features. Those services are governed by their own terms and privacy policies. OneRx is not responsible for the privacy practices of services we do not operate.
13. Contact us
For questions, concerns, or requests regarding this Statement or our handling of information:
OneRx Privacy Officer
Privacy Officer: admin@myonerx.ca
Support and general inquiries: support@myonerx.ca
If an individual is not satisfied with our response, they may contact:
- The privacy oversight office for their province or territory, listed in Section 3, for matters under provincial or territorial privacy and health-information laws.
- The Office of the Privacy Commissioner of Canada (1-800-282-1376, priv.gc.ca), for matters under PIPEDA.
14. Changes to this Statement
We may update this Statement from time to time. The effective date at the top of the Statement is updated when we do. Material changes will be brought to pharmacy custodians’ attention through the OneRx portal or by email.
