INFORMATION WE COLLECT
We collect information when you use the Services, create or administer an account, or otherwise interact with enavvi. Categories include:
- Account and profile information: name, email, username, role, organization, and related account details.
- Provider and professional information: credentials, NPI, DEA registration, specialty, practice location, and prescribing authority.
- Patient and clinical information: patient identifiers, demographic data, medication history, prescription information, and other health-related data submitted by customers, providers, or integrated systems.
- Prescription and transaction information: prescription details, dosage, pharmacy routing, transaction timestamps, and related records.
- Identity verification and onboarding information: information submitted during registration, credentialing, or identity proofing, including from third-party verification providers.
- Communications and support information: messages, support tickets, feedback, and related communications.
- Device, log, and usage information: IP address, browser type, pages viewed, session data, and diagnostic information.
- Integration and third-party source information: information received from EHR systems, pharmacy networks, and other integrated services.
- Billing and business contact information: payment records, subscription details, and customer contact information.
We may also collect aggregated or de-identified information that does not identify individuals.
HOW WE USE INFORMATION
We use collected information to:
- Provide, operate, and support the Services, including account access, prescribing workflows, and integrations.
- Authenticate users, manage access controls, and maintain security and service integrity.
- Process transactions and route prescriptions to pharmacies and other recipients.
- Respond to support requests, troubleshoot issues, and communicate about service matters.
- Comply with legal, regulatory, audit, and recordkeeping obligations.
- Analyze performance and improve the Services. We may use aggregated or de-identified information for analytics and product development.
- Manage customer accounts, billing, and contracting.
DATA RETENTION AND SECURITY
We retain personal information for as long as necessary to provide the Services, comply with legal and regulatory obligations, resolve disputes, and conduct legitimate business operations. EPCS audit logs are retained for a minimum of two years from the date of the logged event, consistent with 21 CFR § 1311.305. For other information, retention periods vary based on the type of information and applicable requirements.
Our security safeguards are described in Section 3 of the applicable Service Subscription Agreement between eNavvi and Customer. No electronic system is completely secure, and security also depends on appropriate customer and user practices.
YOUR CHOICES AND RIGHTS
Depending on your relationship with enavvi and applicable law, you may have rights to access, update, correct, or request deletion of certain personal information. If you access the Services through a healthcare provider or employer, that organization may control certain information and be responsible for handling privacy requests. You may opt out of marketing communications using the unsubscribe mechanism in those communications.
We may decline or limit requests where permitted by law, where we cannot verify identity or authority, or where retention is required for legal, regulatory, audit, or dispute-resolution purposes.
SMS / TEXT MESSAGING
If you provide a mobile phone number and consent to receive text messages from enavvi, we collect your mobile number, your consent record (date, time, and how consent was given), and message delivery information, and we use them solely to send the messages you opted into: account-security one-time passcodes (login verification, EPCS two-factor authentication, and password reset) and prescription and patient-wallet notifications for your practice. Message frequency varies based on your account and prescribing activity. Message and data rates may apply.
You can opt out of text messages at any time by replying STOP to any message, and you can get help by replying HELP or by contacting help@enavvi.com. Providing a mobile number is optional and is not a condition of creating or using an account.
Mobile opt-in data and SMS consent will not be shared, rented, transferred, or sold to third parties, affiliates, or lead generators for marketing or promotional purposes.
CHILDREN'S PRIVACY
The Services are intended for healthcare providers, prescribers, and authorized users in professional contexts. Information about minors may be processed when submitted by customers or providers in clinical workflows; in those cases, the applicable customer or provider is responsible for obtaining required permissions and complying with applicable law.
POLICY UPDATES AND CONTACT
We may update this Policy to reflect changes in our Services, practices, or legal obligations. Material changes will be communicated via the Services, email, or other reasonable means. Continued use after the updated Policy takes effect constitutes acceptance, subject to rights that cannot be waived by law.
Questions or privacy requests:
ENAVVI, INC.
Attn: eNavvi Security and Compliance Team
21 Esfahan Dr
San Jose, CA 95111
Email: teja@enavvi.com