Privacy Policy

Effective date: 6th of April, 2026

Compound Direct Pty Ltd. is engaged in the development, operation, and maintenance of the Compound Direct Platform, a proprietary software solution designed to simplify and optimize pharmaceutical compounding processes and enable the secure management of related data.

Pharmacies and healthcare providers use the Compound Direct Platform to manage prescriptions, conduct patient risk assessments, process medication orders, and facilitate the safe preparation and delivery of compounded medicines. The Compound Direct Platform also supports secure communication, workflow coordination, and data management between pharmacies and their patients.

This Privacy Policy ("Policy") applies to all personal information processed through the Compound Direct Platform. It explains how data is collected, used, and safeguarded, the limited circumstances under which Compound Direct may access or process it, and the rights and protections afforded under applicable privacy laws. It also describes your rights and choices as a data subject, including how to exercise them through your pharmacy.

1Defined Terms

For clarity, the following terms have the meanings set out below when used in this Policy:

"Compound Direct," "we," "our," or "us" refers to Compound Direct Pty Ltd, the entity responsible for the operation of the Compound Direct Platform and for the processing of Personal Information as described in this Policy.

When processing Personal Information, Compound Direct acts solely as a Data Processor on behalf of Healthcare Organizations and processes such Personal Information only in accordance with their instructions and authority, and not for its own independent purposes.

This restriction applies only to Personal Information. It does not apply to Aggregated Data or De-identified Data (as defined below), which do not constitute Personal Information and may be processed by Compound Direct for its own legitimate business purposes as described in this Policy.

"CD Platform" means the proprietary software system developed, operated, and maintained by Compound Direct to simplify and optimize pharmaceutical compounding processes and to securely manage related data, including prescriptions, risk assessments, and communications between pharmacies and patients.

"Healthcare Organizations" means pharmacies, healthcare providers, or other licensed organizations that use the CD Platform to provide compounding, dispensing, or related pharmaceutical services. For purposes of this Policy, Healthcare Organizations act as Data Controllers, who collect and determine the purposes and means of processing the Patients' Personal Information.

"Patients" means patients, customers, or other individuals whose Personal Information is processed by Healthcare Organizations through the use of the CD Platform. Patients are the data subjects under applicable privacy laws.

"Personal Information" (also referred to as "Personal Data") means any information or opinion that identifies, relates to, or could reasonably identify an individual, directly or indirectly. This includes, but is not limited to, names, contact details, medical information, prescription data, and payment information.

For the avoidance of doubt, Personal Information does not include De-identified Data or Aggregated Data (as defined below). In addition, data derived from or relating to Patients or Healthcare Organizations that is clinical, medical, or health-related in nature is categorically excluded from any Aggregated Data or De-identified Data.

"Sensitive Information" means a subset of Personal Information that includes health and medical details, such as medical history, allergies, prescriptions, dosage requirements, and compounding specifications. Sensitive Information is processed only where necessary for healthcare provision and in accordance with applicable law. Sensitive Information does not include De-identified Data or Aggregated Data.

"Processing" means any operation or set of operations performed on Personal Information, whether or not by automated means, such as collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, transfer, restriction, erasure, or destruction.

"Data Controller" means the person or entity that determines the purposes and means of processing Personal Information. For the purposes of this Policy:

  • Healthcare Organizations act as Data Controllers with respect to the Patients' Personal Information processed through the CD Platform, as they determine how and why such information is collected and used.
  • Compound Direct acts as a Data Controller only in limited circumstances, such as those described in Section 2 hereof (Our Role in Data Processing).

"Data Processor" means the person or entity that processes Personal Information on behalf of, and in accordance with the instructions of, a Data Controller. For the purposes of this Policy, Compound Direct acts as a Data Processor when processing the Patients' Personal Information on behalf of Healthcare Organizations in connection with their use of the CD Platform.

"Subprocessor" means any third-party service provider engaged by Compound Direct to support the delivery of the CD Platform, such as cloud hosting, payment processing, or analytics providers, each of which is contractually bound to maintain confidentiality and implement appropriate data protection measures.

The full and current list of Subprocessors engaged by Compound Direct is maintained in Appendix "A" - Subprocessor List, which is accessible through the CD Platform. Compound Direct updates this Appendix from time to time to reflect changes in Subprocessors, ensuring continued compliance with its contractual and data-protection obligations.

"Aggregated Data" means data that has been combined across multiple data points, entities, or sources such that it represents collective trends, patterns, or statistics and does not reasonably permit identification of any individual, Patient, Healthcare Organization, or other specific person or entity. Aggregated Data may include summaries, averages, trends, or other high-level insights derived from platform usage or operational activity.

"De-identified Data" means Aggregated Data or any data processed to remove or alter personal identifiers, followed by the application of any additional techniques or controls required to remove, obscure, aggregate, alter, and/or protect data in some way so that it is no longer reasonably identifiable to a specific person or entity, taking into account the nature of the data, available technology, the context of processing, and foreseeable risks of re-identification. As such, De-identified Data does not constitute Personal Information or Sensitive Information under applicable privacy laws.

"Operational Data" means data generated through the use and operation of the CD Platform that relates to workflows, transactions, system usage, performance, inventory movement, ingredients, formulations, compositions, preparation methods, purchasing activity, sales volumes, or similar commercial or operational activity.

2Our Role in Data Processing

For the purposes of applicable privacy laws, Healthcare Organizations are the Data Controllers of any Personal Information processed through the CD Platform. Healthcare Organizations determine the purposes, scope, and lawful bases for which the Patients' Personal Information, including Sensitive Information, is collected, used, or disclosed.

Compound Direct acts as a Data Processor on behalf of Healthcare Organizations. We process Personal Information only as necessary to provide, maintain, and secure the CD Platform and its related services, and strictly in accordance with each of the Healthcare Organizations' instructions. We do not determine or influence the purposes for which the Patients' data is collected, used, or otherwise processed.

Compound Direct may, however, act as a Data Controller in limited circumstances, specifically in relation to data that we collect and process for our own operational, administrative, or commercial purposes. These include:

  1. Account and Contact Information of the Healthcare Organizations and their authorized users or staff, used to manage the Patients' data, provide support, and deliver contractual services;
  2. Technical and Platform Usage Data, such as logs, diagnostics, and analytics, used to maintain, improve, and secure the CD Platform;
  3. Administrative, Financial, and Compliance Records required to operate our business, meet legal obligations, and ensure regulatory compliance;
  4. Operational Data of Healthcare Organizations which may be processed into Aggregated Data or De-identified Data.

In these cases, Compound Direct independently determines the purposes and means of processing to ensure the proper operation, security, and integrity of the CD Platform.

Where Compound Direct acts as a Data Processor, this Policy should be read in conjunction with the privacy policy of the relevant Healthcare Organization, which governs how the Patients' information is collected, used, and shared.

Patients who wish to exercise their privacy rights, such as access, correction, or deletion of their Personal Information, should contact the relevant Healthcare Organization directly.

3Our Commitment

We maintain a comprehensive data protection program designed to comply with applicable data protection and privacy laws, including the EU General Data Protection Regulation ("GDPR"), the Australian Privacy Act 1988 ("APA"), and the Australian Privacy Principles ("APPs"), as applicable to the nature of the data we process and our role in such processing.

To ensure consistent protection for all users worldwide, we also adopt generally recognized privacy principles and regularly review and update our policies, practices, and technical safeguards to reflect evolving legal and industry requirements.

5How We Share Information

Compound Direct shares Personal Information only where it is necessary to operate, maintain, or support the CD Platform, and always under appropriate safeguards.

When acting as a Data Processor, we disclose information solely under the instructions of the Healthcare Organization and for the purposes permitted by applicable privacy laws.

The following table summarizes the categories of recipients with whom Personal Information may be shared, the limited purposes for which such disclosures occur, and the safeguards that govern these transfers.

RecipientPurpose / Safeguard
Healthcare Organizations and Healthcare ProfessionalsTo process prescriptions, perform risk assessments, and facilitate the safe delivery of compounded medicines to the Patients. Healthcare Organizations, as Data Controllers, remain responsible for ensuring compliance with healthcare confidentiality obligations and applicable privacy laws.
Payment ProcessorsTo process payments securely on behalf of Healthcare Organizations. Payment data is encrypted, tokenized, and handled directly by Subprocessors that provide payment processing services as listed in Appendix "A" - Subprocessor List. Compound Direct does not store or access full payment card details.
SubprocessorsTo provide essential infrastructure, cloud hosting, data analytics, email delivery, and security services that support the operation of the CD Platform.
Regulators and AuthoritiesTo comply with applicable laws, regulations, or valid legal processes. Any such disclosure is limited to the information legally required and conducted in coordination with the relevant Healthcare Organization, where applicable.
Corporate TransactionsIf Compound Direct is involved in a merger, acquisition, restructuring, or sale of assets, Personal Information may be transferred as part of that transaction under safeguards ensuring continued protection consistent with this Policy.

Compound Direct does not sell, rent, or trade Personal Information, and does not use the Patients' data for advertising, profiling, or marketing purposes. Patient clinical or health data is never shared, licensed, or commercialized.

Separately, Compound Direct may use, share, license, or commercialize De-identified Data, provided that such data does not constitute Personal Information or Sensitive Information and does not identify, and cannot reasonably be used to identify, any individual, Patient, Healthcare Organization, or specific site. Any sharing, licensing, or commercialization of data by Compound Direct outside the above table shall be limited to De-identified Data.

6Personal Data Retention

Compound Direct retains Personal Information only for as long as necessary to fulfill the purposes for which it was processed or as required by applicable law, regulation, or contractual obligations with Healthcare Organizations.

When acting as a Data Processor, we retain Patient information in accordance with the instructions of the Healthcare Organization, including any applicable healthcare or professional retention requirements. Once our services to the Healthcare Organization end, we may return or delete the data in accordance with the governing agreement and legal obligations.

Retention periods vary depending on the category of information and its purpose:

1. Account and Client Information

  • Scope: Business contact details, account credentials, and related records of Healthcare Organizations and authorized users.
  • Retention: Maintained for the duration of the client relationship and for a limited period thereafter to resolve billing, audit, or compliance matters.

2. Health and Medical Records (Client Data)

  • Scope: Health and medical information processed on behalf of Healthcare Organizations, including prescriptions, risk assessments, and compounding details.
  • Retention: Retained for the period directed by the Healthcare Organization or as required under applicable healthcare and recordkeeping laws (typically up to seven years from the last interaction).
  • Disposition: After the retention period, such records may be securely deleted or anonymized, unless further retention is required by law or the Healthcare Organization's instructions.

3. Payment and Transaction Data

  • Scope: Billing details, transaction confirmations, and related payment records.
  • Retention: Retained only for as long as necessary to complete transactions, process refunds or chargebacks, and comply with financial, taxation, and anti-fraud recordkeeping requirements.
  • Note: Compound Direct does not store or retain full payment card details; cardholder data is managed directly by our authorized payment processors (see Appendix "A").

4. Technical and Usage Data

  • Scope: Log files, diagnostics, and platform analytics.
  • Retention: Retained for a limited period as reasonably necessary to ensure platform performance, monitor security, and support troubleshooting or analytics. Following such use, technical and usage data may be securely deleted or processed into Aggregated Data or De-identified Data.

5. Communications and Support Records

  • Scope: Inquiries, technical support requests, and related correspondence.
  • Retention: Maintained for as long as necessary to address your inquiry, provide support, and maintain service records, subject to applicable legal or regulatory requirements.

6. Deletion and De-identification

  • When data is no longer required for the purposes described above or under the Healthcare Organization's instructions, it may be securely deleted or de-identified so that it can no longer reasonably identify an individual.
  • Where deletion is not immediately possible due to technical or legal constraints, the data will be isolated and protected from further processing until it can be securely removed.

7Data Security

We take the protection of Personal Information seriously and implement a combination of technical, organizational, and administrative safeguards to keep data secure.

These measures are designed to prevent unauthorized access, disclosure, alteration, or destruction of Personal Information and are continuously reviewed to align with evolving industry standards.

Our safeguards include:

  1. Encryption in Transit and at Rest: All data transmitted through or stored within the CD Platform is protected using industry-standard encryption protocols. This means that information is protected both while being sent over the internet ("in transit") and while it is stored on our systems ("at rest").
  2. Payment Data Protection: Payment details are tokenized to ensure that sensitive payment information is never stored in raw form within our systems. We also use 3-D Secure Authentication protocols for online transactions to provide an added layer of fraud prevention and user verification.
  3. Access Controls: Access to Personal Information is strictly limited to authorized employees and contractors who require it to perform their duties. We use role-based permissions, multi-factor authentication, and activity logging to prevent unauthorized access and to maintain an auditable record of data handling activities.
  4. Secure Infrastructure: The CD Platform operates on secure, monitored servers that are protected by firewalls, intrusion detection systems, and redundant backups. These safeguards are designed to ensure platform stability, protect against network-based attacks, and prevent data loss in the event of system failure or disaster.
  5. Testing and Audits: We conduct regular vulnerability scans, penetration tests, and security audits to identify and address potential weaknesses. Continuous monitoring helps us detect suspicious activity early, while third-party audits provide independent assurance that our security practices remain effective and compliant with industry standards.
  6. Employee Training and Awareness: Compound Direct personnel with access to personal or health information receive privacy and security training appropriate to their access level. This training ensures that everyone handling Personal Information understands their responsibilities and adheres to legal, ethical, and procedural safeguards.
  7. Incident Response: We maintain formal procedures to detect, investigate, and respond to security incidents or data breaches. If an incident occurs that may affect the rights or freedoms of individuals, Compound Direct will promptly notify the affected Healthcare Organization, or, where Compound Direct acts as Data Controller, the affected individuals and relevant supervisory authorities, as required by law.

When acting as a Data Processor, Compound Direct assists Healthcare Organizations in meeting their breach-notification obligations under applicable privacy laws.

8Your Rights

The rights available to you depend on your relationship with us and the nature of the data being processed.

Patients

Because Healthcare Organizations act as Data Controllers for Patient information, any requests to access, correct, delete, or otherwise exercise rights over your Personal Information should be directed to the Healthcare Organization.

Compound Direct acts solely as a Data Processor in this context and does not determine the purposes or means of processing Patient Personal Information. Accordingly, Compound Direct does not respond directly to Patient rights requests, except to the extent required to assist the Healthcare Organization in complying with applicable privacy laws.

Privacy rights apply only to Personal Information, and shall not extend to Aggregated or De-identified Data.

Requests relating to data processed by Compound Direct exclusively on behalf of a Healthcare Organization will be referred to that Healthcare Organization, unless Compound Direct is required by law to act directly.

Healthcare Organizations and Authorized Users

If you are a Compound Direct client or authorized user of a client account, you may contact us directly to exercise your privacy rights, including:

  1. Access: Obtain confirmation of whether we hold your Personal Information and request a copy.
  2. Rectification: Request correction or completion of inaccurate or incomplete Personal Information.
  3. Erasure: Request deletion of Personal Information, unless retention is required by law or contract.
  4. Restriction: Request temporary suspension of processing while a dispute regarding accuracy or lawfulness is reviewed.
  5. Data Portability: Request transfer of your Personal Information in a structured, commonly used, and machine-readable format.
  6. Objection: Object to processing based on legitimate interests or for direct marketing.
  7. Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.
  8. Complaint: You may contact our Privacy Officer regarding any concerns about our handling of your Personal Information. If you are unsatisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner ("OAIC") or your local data protection authority.

We will respond to all valid requests within the timeframes required by law. Some rights may be subject to conditions or exceptions under the GDPR, APPs, or other applicable regulations.

9International Data Transfers

Because the CD Platform supports Healthcare Organizations and their Patients in multiple jurisdictions, Personal Information processed through the CD Platform may be transferred to, stored, or accessed from countries outside your own, including those where our Subprocessors or Healthcare Organizations operate.

When such cross-border processing occurs, Compound Direct acts as a Data Processor on behalf of the relevant Healthcare Organization, and implements appropriate safeguards to protect Personal Information in accordance with the Healthcare Organization's instructions and applicable privacy laws.

To ensure that Personal Information remains protected wherever it is processed, we apply the following measures:

  1. Standard Contractual Clauses ("SCCs"): For data originating from the European Union ("EU") or European Economic Area ("EEA"), we rely on SCCs to ensure that transfers to our Subprocessors or hosting providers maintain an equivalent level of data protection.
  2. Australian Privacy Principles: For data originating from Australia, we comply with the APPs, which require that overseas recipients handle Personal Information in a manner consistent with Australian privacy standards.
  3. Due Diligence and Contractual Protections: We engage only trusted Subprocessors (see Appendix "A") and require them to implement technical, organizational, and contractual safeguards to ensure security, confidentiality, and compliance with applicable privacy obligations.
  4. Consistent Global Standards: In jurisdictions without equivalent data protection laws, we apply internationally recognized privacy and security principles to maintain a uniform level of protection across all regions.

Transfers or uses of De-identified Data may occur globally for legitimate business purposes, including analytics, benchmarking, and commercialization, provided such data does not constitute Personal Information and cannot reasonably be used to identify any individual, Patient, Healthcare Organization, or specific site.

Because such data falls outside the scope of Personal Information, these transfers are not subject to cross-border transfer requirements that apply specifically to Personal Information. Nevertheless, Compound Direct applies reasonable technical and organizational safeguards to protect such data and to reduce the risk of re-identification.

These measures help ensure that Personal Information processed through the CD Platform remains protected and handled in a manner consistent with this Policy and applicable legal requirements, regardless of where it is transferred or stored.

11Cookies and Tracking Technologies

When you use the CD Platform, we and our authorized Subprocessors (see Appendix "A") may use cookies and similar technologies (such as pixels, web beacons, and local storage) to support the secure and reliable operation of the platform.

These technologies are used for limited, functional purposes, including to:

  • Maintain session integrity and remember user preferences, so that authorized users remain securely logged in and their settings persist between sessions;
  • Monitor system performance and detect technical issues, helping us ensure platform stability and troubleshoot errors efficiently; and
  • Generate aggregated and anonymized usage analytics, which allow us to improve reliability, optimize performance, and enhance user experience.

Data derived from cookies or tracking technologies may be processed into De-identified Data, which does not constitute Personal Information and may be used for analytics and legitimate business purposes.

Compound Direct does not use cookies or similar technologies to deliver third-party advertising, profile users, or track activity across unrelated websites or applications.

We do not use cookies or tracking technologies to collect or infer Patient clinical, health, or treatment information, nor are such technologies used to create De-identified Data or Aggregated Data derived from Patient health data.

You can manage or disable cookies through your browser settings.

Where cookies are not strictly necessary for the operation of the CD Platform, we or the relevant Healthcare Organization (as the Data Controller) will seek your consent before enabling them.

12Updates to the Policy

We may update this Policy from time to time to reflect legal, technical, or operational changes. The latest version of this Policy will always govern how we process Personal Information through the CD Platform.

When we update this Policy, we will let you know in the following ways:

  • For minor updates such as clarifications or improvements in wording, we will simply publish the revised privacy policy on our website or within the CD Platform.
  • For major updates such as significant changes to how we collect, use, or share personal information, we will take reasonable steps to notify affected Healthcare Organizations, and, where appropriate, their Patients, which may include sending an email or displaying a notice within the CD Platform.

We encourage you to review this Policy regularly to stay informed about how we protect your information. Your continued use of the CD Platform after any updates indicates your acceptance of the revised Privacy Policy.

13Contact Us

Should you have any questions, concerns, or requests regarding this Policy or the way your Personal Information is managed, please do not hesitate to contact us at:

Compound Direct Pty Ltd.Email: support@compound.directPhone: 1300 191 676

If you are a Patient, please direct privacy-related requests, such as access, correction, or deletion, to your pharmacy or healthcare provider, which acts as the Data Controller of your information.