Privacy Policy
Last updated: July 30, 2026
Section 1: Overview and Dual Role Delineation
This Privacy Policy outlines how RootRx LLC collects, utilizes, secures, and discloses data through its digital platform and integrated healthcare technology services. Because RootRx LLC sits at the intersection of B2B software and healthcare data, we operate under two distinct and legally delineated roles:
- Service Provider / Business Associate: When processing patient information, medical records, or scheduling data inputted by healthcare clinics, RootRx LLC acts strictly as a "Service Provider," "Data Processor," and "Business Associate." In this capacity, all data processing is strictly governed by the Health Insurance Portability and Accountability Act (HIPAA) and the California Confidentiality of Medical Information Act (CMIA).
- Data Controller: When collecting and processing a clinic owner's commercial billing, account registration, or standard B2B marketing data, RootRx LLC acts as a "Data Controller." This commercial data infrastructure is entirely separate, independent, and isolated from protected clinical health records.
Patient Interactions: Patients interact with RootRx exclusively through the clinic's portal. Patient-facing privacy matters are governed by the clinic-authored privacy policies. This document governs RootRx's B2B relationship with the clinic as a vendor.
Section 2: Information Collected by the Company
RootRx LLC limits data collection to information that is adequate, relevant, and reasonably necessary to provide our software services, process commercial transactions, and optimize the clinic owner's experience. The platform collects the following specific categories of data:
- Identity & Contact Data (B2B): First names, last names, clinic names, and email addresses provided voluntarily by clinic owners or administrators when creating a commercial account or submitting inquiries.
- Payment Processing & Data Minimization (Stripe): RootRx does not process, store, or transmit raw credit card numbers from its own servers; patients enter their card data directly into Stripe's secure, hosted checkout page. To initiate the session, RootRx passes only non-clinical metadata (e.g., an opaque internal patient ID, generic visit/order labels, clinic name, and transaction amounts) to the payment gateway.
- Technical Tracking Data: Internet protocol addresses, browser types, and device identifiers are collected automatically via essential/session cookies and security logging to monitor general consumer behavior and platform stability.
- Patient Portal Data: Login credentials required for patients to access secure clinic services.
- AI & Feature Usage: Formula queries, voice dictation, and interaction patterns with clinical assistance features.
Section 3: Purpose and Utilization of Collected Data
RootRx LLC processes personal data strictly for the following commercial and operational purposes:
- Fulfilling and processing B2B commercial software subscriptions and platform access for clinics.
- Delivering administrative updates, operational announcements, and security notifications.
- Providing the secure, encrypted technical infrastructure required for clinics to lawfully manage their patient schedules and medical records.
- Hosting and displaying clinic-authored patient policies;
- Sending transactional notifications via SMS/Email;
- Enabling optional AI-assisted clinical reference features.
Section 4: Data Security Safeguards and Third-Party Tracker Prohibition
RootRx LLC implements and maintains reasonable technical, physical, and administrative security practices designed to protect the confidentiality and integrity of all data. These safeguards include role-based access controls, strict TLS encryption for data in transit, AES-256 encryption for database storage at rest, and immutable audit logging.
- Strict Third-Party Tracker Prohibition: To unequivocally protect patient privacy, RootRx LLC strictly prohibits the use of third-party marketing pixels, analytics trackers, or advertising tags within any authenticated interface handling patient records, PHI, or scheduling. Absolutely no commercial tracking technology is permitted to operate behind the platform's secure login firewall.
While the company takes proactive measures to secure information, no digital transmission or electronic storage method can be guaranteed to be absolutely secure against unauthorized third-party intrusion.
Section 5: California Consumer Rights (CCPA & CMIA)
In accordance with the California Consumer Privacy Act (CCPA), California residents (specifically clinic owners and administrators acting in a commercial capacity) possess specific rights regarding their commercial personal data. These rights include:
- The Right to Know: Users may request formal confirmation regarding the specific pieces of commercial personal data we have collected about them.
- The Right to Delete: Users may request the complete deletion of personal data collected through our commercial platform, subject to standard legal or financial retention mandates for business accounting.
- The Right to Correct: Users may require the company to rectify inaccurate or incomplete commercial record details.
- The Right to Opt-Out: Users retain the absolute right to opt out of the sale or sharing of their personal data (Note: RootRx LLC does not sell your personal data to third-party data brokers).
- Statutory Exemption for Health-Regulated Data: Please be advised that the CCPA rights outlined above apply exclusively to B2B commercial data. There is a strict statutory exemption for health-regulated data sets. Any Protected Health Information (PHI) or medical information inputted into the platform by clinics is governed instead by HIPAA and the California Confidentiality of Medical Information Act (CMIA), and is entirely exempt from CCPA consumer requests. Patients seeking to exercise rights over their medical records and portal login data must contact their healthcare provider (the clinic) directly. Clinic owners may submit B2B CCPA requests by emailing support@rootrx.org.
Section 6: Disclosures to Third Parties
RootRx LLC does not sell, lease, or trade user data to third-party data brokers or external marketers. Commercial personal data is shared exclusively with authorized third-party service providers acting as data processors under binding corporate contracts (and Business Associate Agreements where applicable). These processors include Amazon Web Services (AWS) for secure website hosting and Stripe for payment gateways. All such processors are contractually restricted from using user data for any purpose outside the explicit service boundaries defined by the company. RootRx will provide notice prior to adding new subprocessors.
Section 7: Corporate Modifications
The corporate owner reserves the right to amend this Privacy Policy at any time to align with legislative changes, shifting regulatory guidance, or expansions of the software platform. Any updates will be published immediately on this page with a revised effective date. For material changes, the clinic's authorized representative must formally re-accept the updated Policy via an in-app workflow.
Section 8: Additional Clauses
Data Retention
We retain commercial B2B data for as long as the clinic maintains an active account, or as required by law for financial auditing and tax purposes.
Children's Privacy
This is a B2B platform. We do not knowingly collect personal information from individuals under the age of 13 in our capacity as a Data Controller.
International Transfers
All data processed by RootRx is hosted and maintained on secure servers located within the United States.
Company
RootRx LLC
By Mail: 6341 Tarragon Rd, Rancho Palos Verdes, CA 90275
By e-mail: support@rootrx.org