Policy

Last Updated: July 06, 2026

Enhanced Rx by Clinical Flow MD ™ ("Company," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website, make purchases, or otherwise interact with us. By using our website, you consent to the practices described herein.

1. Information We Collect

1.1 Personal Information You Provide

We may collect personally identifiable information that you voluntarily provide, including but not limited to:

  • Name, email address, phone number, and mailing/shipping address

  • Billing and payment information (processed securely via third-party payment processors)

  • Account registration details, including username and password

  • Business or institutional affiliation

  • Communications you send to us, including support requests and feedback

  • Age verification information

1.2 Automatically Collected Information

When you access our website, we may automatically collect:

  • IP address, browser type, operating system, and device identifiers

  • Pages viewed, links clicked, referring URL, and time spent on pages

  • Cookies, pixel tags, web beacons, and similar tracking technologies

  • Geolocation data (at a city/region level)

1.3 Information from Third Parties

We may receive information about you from third-party sources, including payment processors, analytics providers, advertising networks, and social media platforms, to the extent permitted by law.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • To process and fulfill orders, including shipping and payment processing

  • To create, maintain, and secure your account

  • To communicate with you regarding orders, account activity, and customer support

  • To send marketing communications (with your consent, where required by law)

  • To improve our website, products, and services through analytics and research

  • To detect, prevent, and address fraud, abuse, security issues, or technical problems

  • To comply with legal obligations and enforce our terms and policies

  • To personalize your browsing experience and deliver relevant content

3. Legal Bases for Processing (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom (UK), our legal bases for processing your personal data include:

  • Consent: Where you have given clear consent for specific purposes

  • Contract: Where processing is necessary for performance of a contract with you (e.g., order fulfillment)

  • Legal obligation: Where processing is necessary for compliance with a legal obligation

  • Legitimate interests: Where processing is necessary for our legitimate interests, provided these are not overridden by your rights and freedoms

4. Disclosure of Your Information

We may share your information in the following situations:

  • Service providers: Third-party vendors who perform services on our behalf (payment processing, shipping, analytics, email delivery, cloud hosting)

  • Legal requirements: When required by law, regulation, subpoena, court order, or governmental request

  • Business transfers: In connection with a merger, acquisition, reorganization, or sale of assets

  • Protection of rights: To protect Pepi Peptides' rights, property, safety, or the rights, property, and safety of others

  • With your consent: For any purpose disclosed to you at the time of collection

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

5. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, comply with our legal and regulatory obligations (including tax and accounting requirements), resolve disputes, and enforce our agreements. Transaction records are retained for a minimum of seven (7) years as required by applicable law. When personal data is no longer needed, we securely delete or anonymize it.

6. Data Security

We implement industry-standard technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • SSL/TLS encryption for all data in transit

  • Encryption of sensitive data at rest

  • Access controls and authentication requirements for staff

  • Regular security assessments and vulnerability testing

  • PCI DSS-compliant payment processing via third-party processors

However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you

  • Correction: Request correction of inaccurate or incomplete data

  • Deletion: Request deletion of your personal data ("right to be forgotten")

  • Restriction: Request restriction of processing of your personal data

  • Portability: Request transfer of your data in a structured, machine-readable format

  • Objection: Object to processing based on legitimate interests or direct marketing

  • Withdraw consent: Withdraw consent at any time where processing is based on consent

To exercise these rights, contact us at admin@clinicalflowmd.com. We will respond within 30 days (or as required by applicable law).

8. Health Insurance Portability and Accountability Act (HIPAA)

Your information is federally regulated and protected:

  • Clinical Flow Med Design LLC may have access to HIPAA information

  • Clinical Flow Med Design LLC does not collect, store, and/or share any HIPAA information

  • Clinical Flow Med Design LLC is not liable for any information collected and handled by partner companies or providers, this includes OpenLoop Health, Agile Telehealth, and Kiran Therapy & Wellness.

To exercise these rights, contact us at admin@clinicalflowmd.com or call 954-998-3810.

9. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience, analyze usage, and deliver relevant content. Categories of cookies we use include:

  • Essential cookies: Required for basic site functionality (authentication, cart, security)

  • Analytics cookies: Help us understand how visitors interact with our site

  • Marketing cookies: Used to deliver relevant advertisements (with your consent)

You can manage cookie preferences through your browser settings or our cookie consent tool. Disabling certain cookies may affect the functionality of our website.

10. Do Not Track (DNT) Signals

Our website does not currently respond to "Do Not Track" browser signals. However, you may opt out of tracking through cookie settings and other controls described in this policy.

11. Third-Party Links & Services

Our website may contain links to third-party websites or services. We are not responsible for the privacy practices, content, or security of those sites. We encourage you to review the privacy policies of any third-party sites you visit.

12. Children's Privacy

Our services and products are not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we learn that we have collected personal data from a person under 18 without verification of parental consent, we will take steps to delete that information promptly. If you believe we have inadvertently collected information from a minor, please contact us immediately.

13. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or equivalent mechanisms approved by relevant authorities, to protect your data during such transfers.

14. Data Breach Notification

In the event of a data breach that compromises your personal information, we will notify affected individuals and relevant regulatory authorities in accordance with applicable breach notification laws (including GDPR Article 33/34, CCPA, and state-specific requirements). Notification will be provided without undue delay and no later than 72 hours after becoming aware of the breach, where feasible.

15. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects on you. If we implement such processes in the future, we will update this policy and provide appropriate notice and opt-out mechanisms.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date. For significant changes, we may also provide notice via email to registered account holders. Your continued use of our services after such changes constitutes acceptance of the updated policy.

17. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us: