§ UK GDPR · DPA 2018 · MHRA aligned § ISO 27001 A.8.3 session control § RLS enforced on 42 database tables § Penetration tested 14 April 2026 § 7-year audit retention § HMAC-signed prescription PDFs § UK GDPR · DPA 2018 · MHRA aligned § ISO 27001 A.8.3 session control § RLS enforced on 42 database tables § Penetration tested 14 April 2026 § 7-year audit retention § HMAC-signed prescription PDFs
§ 1.0 Software · Dispensing · Compliance

Turn your brand
into a
prescription retailer.

Sync-RX is the software-and-dispensing package for UK digital health. Headless clinical operations, integrated UK pharmacy fulfilment, and a white-label patient experience. Launch a prescription category in months, not years.

42tables
RLS enforced
7yr
Audit retention
15min
ISO 27001 A.8.3
Pen-tested
14 · 04 · 2026
Attestation § Compliance
Statement of compliance posture
Ref. SRX/CMP/2026-04 · Issued 28 April 2026
  • UK GDPRIn force
  • Data Protection Act 2018In force
  • MHRA digital health alignmentIn force
  • ISO 27001 A.8.3 session controlIn force
  • Row-Level Security · 42 tablesIn force
  • HMAC-SHA256 prescription signaturesIn force
§ 2.0
The compliance gap

Standard commerce SaaS was never built to hold a patient’s data.

2.1 / United Kingdom

The DPA
and UK GDPR

Health data is a special category under UK GDPR Article 9 and the Data Protection Act 2018. Lawful processing requires explicit consent, minimisation, and architectural safeguards that bolt-on plugins cannot deliver.

Storing PHI in a system not designed for it is a regulatory exposure, not a configuration choice.
2.2 / United States

Shopify is not
HIPAA compliant

Shopify’s own guidance is unambiguous. Only data not bound by HIPAA should be stored or processed by the platform. SOC 2 and PCI DSS Level 1 do not equal Protected Health Information cover.

Quoted from the published HIPAA review: "Shopify does not support HIPAA compliance."
2.3 / EU & Canada

EU DPD,
and PIPEDA

The EU Data Protection Directive and Canada’s PIPEDA impose parallel constraints. Cross-border digital health operators inherit every restriction simultaneously. Each jurisdiction is a hard wall, not a checkbox.

Compliance is the architecture. It cannot be bolted on after launch.

Digital health operators lose deals, lose pharmacy partners, and lose investor conviction the moment compliance becomes a workaround. Sync-RX exists so it is not.

§ 3.0
The platform

One operations layer. Two sides of the journey.

For operators

An admin console that replaces the spreadsheet, the CRM, and the manual order log.

KPIs and action queues. Patient records. Order lifecycle from pending through dispensed. Prescription generation with signed PDFs. AI-assisted questionnaire audit. Visual flow builder. Audit-ready compliance posture.

For patients

A self-service portal that looks and feels like your brand.

Treatment tracking, photo uploads, blood test results, and dynamic questionnaires with branching logic. White-label theming via CSS variables means the patient never sees Sync-RX. They see you.

3.1 / Patients Core

Patient records

Comprehensive clinical data with row-level isolation. Photos, weights, side effects, history, all PHI-safe.

  • RLS-enforced on every read and write
  • Role-scoped admin and clinician access
  • Patient-owned uploads via signed URLs
3.2 / Orders Core

Order lifecycle

From pending through review, prescribed, shipped, and delivered. Real-time sync with the dispensing partner.

  • Pharmacy partner webhook integration
  • Subscription holds until prescription is issued
  • Live status sync via Supabase Realtime
3.3 / Prescriptions Core

Signed prescriptions

Generate, sign, and dispatch prescription PDFs with cryptographic integrity built into the pipeline.

  • HMAC-SHA256 digital signatures
  • Direct dispensary submission
  • Auditable issuance record per script
3.4 / Forms Engine

Dynamic questionnaires

Branching logic, AI flagging, and styling controls. The form is the gate to a clinically valid order.

  • Branch on any answer, any condition
  • AI questionnaire audit on submission
  • DOMPurify-sanitised at every render
3.5 / Automation Engine

Visual flow builder

Trigger follow-ups, wellness check-ins, and partner sync events without writing back-end code.

  • Drag-and-drop workflow canvas
  • Time-based and event-based triggers
  • Repeat-prescription wellness gating
3.6 / Audit Compliance

Audit & incident register

Every authentication event, record change, and patient access is logged and retained for seven years.

  • 7-year retention aligned to MHRA & GDPR
  • Severity-tagged incident register
  • AI-powered compliance scanning
§ 4.0
Compliance posture

A live ledger, not a marketing page.

Most platforms claim compliance. We publish the posture and keep it current.

Every control on the right is implemented in production code, verified by the most recent penetration test, and accountable to an audit log retained for seven years.

Where a control is in progress, we say so. SAR export tooling and the formal Right to Erasure workflow are scheduled for the current quarter.

Last assessed 14 · 04 · 2026 · 0 critical · 0 high open
Ref Control Standard Status
4.1.01 Row-Level Security on all 42 tables UK GDPR · ISO In force
4.1.02 Role-based access via app_role enum DPA 2018 In force
4.1.03 15-minute inactivity session timeout ISO 27001 A.8.3 In force
4.1.04 Auth event & record-change audit log MHRA · GDPR In force
4.1.05 7-year audit log retention MHRA · GDPR In force
4.1.06 HMAC-SHA256 prescription signatures Internal In force
4.1.07 DOMPurify on all dynamic HTML render OWASP In force
4.1.08 Pen-test programme · quarterly cadence PTES In force
4.1.09 GDPR SAR export tooling UK GDPR Q2 2026
4.1.10 Right to Erasure cascade workflow UK GDPR Q2 2026
§ 5.0
Partner stack

Plugged into the infrastructure you already trust.

Pharmacy fulfilment
Pharmacy partner integration

Live prescription submission, order webhooks, and bidirectional status sync. Partner-ready out of the box.

Headless commerce
Shopify

Headless storefront and order sync, with PHI never crossing the Shopify boundary. Cart, catalogue, checkout, and nothing more.

Subscriptions
ReCharge

Recurring billing for repeat prescriptions, with subscription release gated on clinical sign-off rather than payment.

Identity verification
LexisNexis & Verif

Configurable per product line. LexisNexis for standard journeys, Verif for selfie capture on GLP-1 and consultation flows.

GP notification
Docman

Scalable NHS surgery notification with an in-app GP search at the point of treatment selection. Datagraphic supported as fallback.

Clinical AI
AI-assisted tooling

Questionnaire auditing, blood test interpretation, and compliance research, with every AI surface in an audited, role-scoped frame.

§ 6.0
Built for UK digital health

Verticals where compliance and conversion collide.

W

Weight management

GLP-1 supply with mandatory wellness check-ins gating each repeat dispense.

T

Testosterone

Bloods-driven protocols, clinician sign-off, and scheduled review cadences.

E

Erectile dysfunction

Discreet patient journeys with consent capture and identity verification baked in.

M

Men’s wellness

Hair, skin, mental health, and adjacent men’s health categories on the same chassis.

§ 7.0
Commercial model

A platform licence and a per-transaction fee.

7.1 / Platform licence

Annual licence

A predictable subscription that gives you the full Sync-RX platform, your white-labelled patient portal, and the partner integrations you need.

Tiered by patient volume and integration scope. Enterprise terms available.
7.2 / Per-transaction

Per-transaction

A fee on every dispensed order processed through the platform. Aligned to volume, transparent on every invoice, and enforced across every deal.

Non-negotiable. The model that keeps Sync-RX honest about uptime and outcomes.
§ 8.0 / Request access

Become a prescription retailer. Let us show you the build.

We work with a small number of UK digital health operators per quarter. If you are launching a new vertical, replatforming away from Shopify limitations, or scoping a pharmacy partner integration, we should talk.

Operator enquiry · UK only