Privacy policy
Last updated: July 7, 2026
This Privacy Policy describes how RoseRx Inc. (Delaware, USA) and Rosemary Health Pty Ltd trading as RoseRx (ABN 72 632 003 377, Australia) (together, "RoseRx," "we," "us," or "our") collect, use, and protect information about you in connection with our website at roserx.ai, our communications with you, and the RoseRx platform and related services (collectively, the "Services").
RoseRx provides a compliance-native platform that converts MLR-approved pharmaceutical content into conversational AI agents for patient, healthcare professional (HCP), and field team engagement (the "Platform"). Our clients are pharmaceutical and life sciences companies.
Please read this Privacy Policy carefully. By using the Services, you agree to this Privacy Policy. If you do not agree, please discontinue use of the Services.
When This Policy Applies, and When It Does Not
RoseRx acts as a data controller for the information described in this policy: information we collect through our website, our marketing and events, and the administration of Platform user accounts.
This Privacy Policy does not apply to information we process on behalf of our clients. RoseRx is a business-to-business platform and does not directly interact with consumers, patients, or the general public on its own behalf. When a patient, caregiver, or HCP interacts with a conversational agent deployed by one of our clients, that client is the data controller (or, under Australian law, the responsible APP entity), and RoseRx acts as a processor or service provider on the client's documented instructions. In such cases our processing is governed by our agreement with that client, and the client's own privacy policy applies. If you are an end user of one of our clients and have questions about how your information is processed, please contact the client who provided your information to us. We cooperate with our clients if they need our assistance in responding to requests from individuals to exercise their privacy rights.
Under the Privacy Act 1988 (Cth), Rosemary Health Pty Ltd is an APP entity and remains accountable for personal information it handles, including information handled on behalf of clients, and meets that accountability through the practices described in this policy and our client agreements.
Information We Collect
The types of information we collect as a controller include:
Contact and account information, such as your name, business email address, company, job title, username, and professional or regulatory identifiers (for example, AHPRA or NPI registration numbers for health professionals).
Communications, such as the content of messages you send us and records of your correspondence.
Event information, when you register for a RoseRx event, webinar, or publication.
Platform account information, including login credentials. Passwords are hashed and are not accessible to RoseRx personnel.
Usage and technical information, such as IP address, browser and device type, pages viewed, referring URLs, and Platform activity logs, collected automatically through cookies and similar technologies.
We do not collect personal information from consumers, patients, or the general public on our own behalf.
How We Use Your Information
We use the information we collect to:
Provide, secure, and improve the Services.
Respond to your inquiries and provide support.
Administer Platform accounts, authenticate users, and maintain audit trails.
Communicate with you, including sending service notices and, with your consent where required, information about our products. You can opt out of marketing communications at any time.
Comply with our legal obligations and enforce our agreements.
How We Disclose Your Information
We share information only as described below. We do not sell personal information, and we have not done so in the preceding 12 months. We do not share personal information for cross-context behavioral advertising.
Related entities. RoseRx Inc. and Rosemary Health Pty Ltd share information between them to operate the business, subject to this policy.
Service providers. We employ trusted vendors to perform functions on our behalf, such as hosting, cloud infrastructure, communications, analytics, and security. These providers have access to information only as needed to perform their functions and may not use it for other purposes.
Legal and safety. We may disclose information to comply with any law, regulation, legal process, or governmental request, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of RoseRx, our clients, our users, or the public.
Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction and remains subject to the commitments in the policy in effect at the time of collection.
We do not disclose personal information to third parties for their own marketing purposes.
Cookies and Tracking
We use cookies and similar technologies for essential site functions and analytics. You can manage cookies through your browser settings and, where displayed, our cookie banner. We honor the Global Privacy Control (GPC) signal as a valid opt-out where required by law.
How We Protect Your Information
We maintain an information security program with administrative, technical, and physical safeguards designed to protect information, including encryption in transit and at rest, multi-factor authentication, and role-based, least-privilege access controls. RoseRx maintains a SOC 2 Type 2 attestation. Where a client deployment involves protected health information (PHI), RoseRx enters into a Business Associate Agreement and handles PHI in accordance with the Health Insurance Portability and Accountability Act (HIPAA), including operating such deployments under subprocessor terms that provide for zero retention of that data. Our certifications, security policies, subprocessor list, and related documentation are available through our Trust Center. No method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
Security Incidents and Breach Notification
If we experience a security incident affecting personal information we control, we will investigate, contain, and remediate it, and we will notify affected individuals and regulators where required by law and within the applicable timeframes. Where an incident affects information we process on behalf of a client, we will notify the client without undue delay so the client can meet its own obligations, as set out in our agreement and any Business Associate Agreement.
In Australia, we comply with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth). We will notify the Office of the Australian Information Commissioner and affected individuals of an eligible data breach as required.
Artificial Intelligence
The Platform delivers content that our clients have approved through their medical, legal, and regulatory (MLR) review processes, within guardrails defined by the client. Individuals interacting with a RoseRx-powered agent are informed that they are interacting with an AI system, and agents do not provide medical advice, diagnosis, or treatment.
We do not sell end-user conversation data, and we do not use it to train foundation models or other general-purpose AI. We do not use one client's data to develop or improve another client's deployment. We may use conversation data to operate, secure, and improve the deployment it belongs to, on the client's instructions and under our agreement and any Business Associate Agreement, using de-identified or aggregated data where the purpose is improvement.
Automated decisions. RoseRx does not use automated processing to make, or to substantially assist in making, decisions that produce legal or similarly significant effects about individuals, such as decisions about eligibility, benefits, or access to a service or treatment. Our agents deliver client-approved information; they do not make these decisions. Where a client configures any decisioning within its own deployment, that client is the controller, or under Australian law the responsible APP entity, for those decisions. Where automated processing uses personal information, the information involved is limited to the conversation content and the account and usage information described in this policy.
International Transfers
RoseRx operates in the United States and Australia. Information may be transferred to, stored in, and processed in either country, and in other countries where our service providers operate. Where we transfer personal information out of Australia, we take steps required under Australian Privacy Principle 8 to ensure the overseas recipient handles the information consistently with the Australian Privacy Principles, or we obtain your consent to the transfer.
How Long We Keep Your Information
We retain information for as long as necessary to fulfill the purposes described in this policy, or as required by law, after which it is deleted or de-identified.
Website inquiries: retained for up to 36 months after our last interaction.
Platform user accounts: deleted within 30 days of termination. Minimal identifiers may persist in audit logs for the log-retention period below.
End-user conversation data: retained for a maximum of 24 months during the contract term unless the client agreement specifies otherwise, and returned or deleted within 90 days of termination. Records connected to adverse events or other safety information are retained for the longer period required by applicable pharmacovigilance regulations (10 or more years).
Security and audit logs: retained for a minimum of 12 months and a standard period of 24 months.
Your Rights and Choices
All individuals. You may contact us at privacy@roserx.ai to request access to, correction of, or deletion of your personal information, to opt out of marketing, or to raise a concern. We may need to verify your identity before acting on a request, and we aim to respond within 30 days of a verified request, or the period required by applicable law. In some cases we may need to retain certain information to meet legal, regulatory, or contractual obligations, and we will tell you where this applies. We will not discriminate against you for exercising your rights. If your request relates to information we process through a client's deployment of the Platform, we will refer your request to that client and assist them in responding.
Australia. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You may request access to and correction of your personal information. If you are dissatisfied with our response to a privacy complaint, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.
United States. Residents of states with comprehensive privacy laws may have the right to know, access, correct, delete, and port their personal information; to opt out of the sale of personal information, sharing or processing for targeted advertising, and certain profiling (practices we do not engage in); and to appeal a refused request. These laws include those of California, Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Texas, Oregon, Florida, Delaware, New Jersey, New Hampshire, Nebraska, Kentucky, Rhode Island, Minnesota, and Maryland, among others as they take effect.
Some states, including Washington (under the My Health My Data Act), Nevada, and Connecticut, regulate consumer health data. We do not collect consumer health data as a controller. Where we process information that may include health data on behalf of a client, we do so as that client's processor or service provider, on the client's documented instructions and under our agreement and any Business Associate Agreement.
You may exercise your rights by emailing privacy@roserx.ai. We may need to verify your identity before responding, and we will respond within the timeframe required by your state's law, generally 45 days.
Children
The Services are business services and are not directed to children. We do not knowingly collect personal information from children under 13, or a higher age where applicable law requires. If we learn we have collected such information without required parental consent, we will delete it.
Changes to This Policy
This Privacy Policy may change from time to time. We will post any changes on this page and update the "Last updated" date above. Where we make material changes, we will notify clients by email or in-platform notice. Your continued use of the Services after we post changes constitutes acceptance of those changes.
Contact Us
Privacy inquiries and rights requests: privacy@roserx.ai. General inquiries: contact@roserx.ai.
United States RoseRx Inc.
Australia Rosemary Health Pty Ltd t/a RoseRx (ABN 72 632 003 377)
Australian residents may also contact our Privacy Officer at privacy@roserx.ai.