Who we are and what this covers
Krepko Pty Ltd (ACN 693 126 171, ABN 20 693 126 171) operates the Krepko marketing site, the KShop pharmacy patient portal and the Krepko pharmacy operational platform. In this policy, Krepko means that company. Its registered office is at 17 Ullapool St, Heathwood QLD 4110, Australia, and its contact address is team@krepko.com.au.
This policy explains how Krepko collects, holds, uses and discloses personal information. Krepko handles personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where a participating pharmacy handles the same information under its own obligations, this policy does not describe or limit what that pharmacy does.
This is the current version of the Krepko privacy policy and it replaces the separate KShop privacy document issued previously.
The three Krepko surfaces
In plain English
Krepko does three different things, and they collect very different information. This site takes an email address if you ask to hear from us. KShop is a pharmacy service for patients and handles prescriptions. The platform is the software a pharmacy runs its own operations on. Each section below says which one it is talking about.
A summary for orientation. The wording below is what applies.
The marketing site is public, has no accounts and collects contact details only where a person submits the waitlist or Pioneers form. KShop is an authenticated pharmacy patient portal and ordering service in which Krepko processes information on behalf of, and alongside, a participating pharmacy. The platform is the operational software used by pharmacy staff, in which the pharmacy is the party that determines what is collected and why. Nothing in the marketing-site sections applies to patient or pharmacy operational data, and nothing in the KShop or platform sections applies to a person who has only visited this website.
Waitlist and Pioneers
The waitlist collects an email address. A Pioneers application collects name, work email address, organisation and optional module interests. The service normalises the email address so a person is not recorded twice; that normalised address remains personal information. Krepko records consent evidence and operational timestamps alongside the entry. Neither form asks for patient data or clinical free text, and neither should be used to send any.
The waitlist purpose is to contact a person about Krepko product and pilot updates. The Pioneers purpose is to contact an applicant about their application or participation, and about product and pilot updates. Email sending is disabled, so no welcome or marketing message is currently sent from these forms; an entry is a record of interest and consent, not a subscription that is being acted on.
Abuse prevention and logs
In plain English
To stop the forms being abused, Krepko counts requests against one-way digests of the network address and email address rather than storing either directly. Those counters last no more than 30 days. Application logs record what happened, not who: no email, name, organisation or form content. Consent evidence is kept alongside the entry under the same 24-month policy.
A summary for orientation. The wording below is what applies.
Rate controls create abuse-event rows containing network and email HMAC digests. The 24 hours is the rate-counting and purge-eligibility window, not the maximum stored retention. Older abuse-event rows are removed by bounded traffic-triggered cleanup or explicit maintenance, and are retained for no longer than 30 days in any case. A raw network address is processed transiently to derive the network digest and is not stored by the lead service.
Separately, consent evidence retains its abuseKey network-keyed identifier, normalised email subject key, purpose, request mode, server-fixed source, consent version and timestamp with the entry under the 24-month policy. Application logs are redacted categorical logs and exclude email, name, organisation, interests, module selections, form fields, raw request body, raw network address, provider response bodies, database response bodies, authorisation values, secrets and consent payload. Vercel generates its own platform and access logs as the hosting provider; their exact fields and retention are set by Vercel rather than by Krepko.
Cookies, storage and analytics
In plain English
Krepko sets no lasting browser storage of its own on this site. Vercel Web Analytics and Speed Insights do run, and they see which page was viewed, where you came from, a coarse location and your device context, with query strings stripped before sending. Krepko’s own events record which link or form was used, never what you typed. No cookie is set and no identifier follows you between sites, so there is no consent banner. This is not a claim to be free of all tracking.
A summary for orientation. The wording below is what applies.
Krepko does not use first-party persistent browser storage on these flows. Vercel Web Analytics and Speed Insights are active on the ten indexed marketing pages. Web Analytics data may include a page or event timestamp, pathname URL, referrer, filtered query information, coarse location, device, browser and operating-system context and script version. Speed Insights processes performance measurements and related technical context. Query and hash are removed from the URL passed through each beforeSend hook before it leaves the browser.
Krepko custom events are limited to a fixed navigation destination and placement, a call-to-action action and placement, or a form name and success or error outcome. They exclude form values and stable identifiers. Vercel is the analytics and performance provider and processes this data under its own terms. This policy makes no absolute anonymity or tracking-free representation.
Third-party choices
The booking page offers a direct Calendly link and may create its scheduler after proximity or click. The embed uses fixed parameters, no prefill and a configured strict-origin-when-cross-origin referrer policy. Calendly may collect information the visitor chooses to supply plus ordinary request, network and device data; the exact configured fields and retention remain subject to live and provider verification. The founders page offers intent-based click-to-load YouTube playback and direct navigation to YouTube. Calendly and YouTube may process their own cookies, storage, request and device data under their own terms. These optional services are not described as tracking-free, and neither loads unless a visitor chooses it.
KShop: patients and pharmacies
KShop is an authenticated pharmacy patient portal and ordering service. Krepko operates the technology platform and the payment integration; the participating pharmacy identified in an account or transaction is responsible for professional and clinical decisions about prescribing information, dispensing, supply and pharmacy care, and may hold the same information independently under its own obligations.
KShop may collect account and identity information such as full name, contact email address, telephone number, account and identity-platform identifiers, account status, the pharmacies an identity is associated with, and whether an identity is operating in customer or staff mode. Krepko’s application databases do not hold passwords, multi-factor secrets or recovery material as ordinary account fields; those are handled by Google Identity Platform. KShop may also process patient identifiers, prescription and repeat information made available by the pharmacy, dispensing and medication information, information about regulated or monitored medicines, and information required for pharmacist review, prescription validation, identity or age verification and regulatory checks. Some structures use a cryptographic hash derived from date-of-birth information rather than storing a plaintext date of birth.
Order and transaction records may include the customer identifier and pharmacy, products and quantities, fulfilment references, order and dispensing-request status, prices and totals, delivery or collection method and address snapshots, payment and refund status, tracking and cancellation information, and the audit and workflow records needed to operate the service reliably. Communications systems may hold message content and delivery records, including rendered templates, provider message identifiers, delivery attempts and evidence of communication preferences. Payments are processed through a Tyro Payments Limited merchant facility; Krepko may receive transaction identifiers, amounts, status, timestamps, payment method type and limited payment details, and does not use payment information for advertising or profiling.
Health and sensitive information
A person’s prescription, medicine and dispensing information can reveal health information. Krepko collects, uses and discloses health information and other sensitive information only where permitted by law, including where it is reasonably necessary to provide the pharmacy service requested, where a consent has been given, or where the handling is otherwise authorised or required by law.
Krepko does not make prescribing or dispensing decisions. Those remain with the prescriber, pharmacist or participating pharmacy. The marketing site collects no health information, and its forms should not be used to send any.
Pharmacy operational data
The Krepko platform is the operational software a participating pharmacy uses to run its own work across the modules it has subscribed to. In that setting the pharmacy determines what is collected and for what purpose, and Krepko processes it to provide, secure and support the service and the workflows the pharmacy has asked for. The specific data, roles, access, environments, retention and deletion arrangements for a given pharmacy are set out in that pharmacy’s own agreement rather than by this policy.
Each participating pharmacy is provisioned with a separate database. Pharmacy records are not held in one shared table keyed by a pharmacy column, and a request must resolve identity, pharmacy membership, operating mode and module entitlement before any pharmacy database is opened.
Where information is processed
In plain English
Personal information you send Krepko is processed and stored in Sydney. The forms on this site are handled by functions running in Sydney and written to a database in Sydney; pharmacy and KShop data sits in Google Cloud in Sydney. The pages of this site are cached on servers around the world, but they carry no personal information. Vercel, which hosts the site, keeps its own logs and analytics in the United States.
A summary for orientation. The wording below is what applies.
Marketing lead records are held in a Neon database in the ap-southeast-2 region, Sydney. The functions that receive a waitlist or Pioneers submission run in Vercel’s Sydney region. The marketing site is a static build, so its pages and assets are served from a global content delivery network and carry no personal information. KShop and pharmacy platform workloads run on Google Cloud in the australia-southeast1 region, Sydney, which the deployment configuration records as the only accepted production region.
Some providers operate outside Australia and some personal information may therefore be transmitted to or processed outside Australia. In particular, Vercel states that its primary processing facilities are in the United States and that data may also be processed where Vercel or its subprocessors maintain operations, which covers its platform logs and its analytics. Resend states that information from users outside the United States may be transferred to and processed in the United States. Twilio and its subprocessors operate internationally. Where the Australian Privacy Principles apply to an overseas disclosure, Krepko takes the steps required of it under applicable law. Provider locations and subprocessors may change.
Who else is involved
Krepko may disclose personal information, or make it accessible, where reasonably necessary for the purposes described in this policy, to: the participating pharmacy associated with an account, prescription request or order; authorised pharmacy personnel and pharmacy systems; Tyro Payments Limited and payment-network participants; Google Cloud for backend services, databases, queues, secrets and related infrastructure; Google Identity Platform for authentication and account security; Neon for the marketing lead database; Vercel for web application hosting, delivery and analytics; Resend for email delivery; Twilio for SMS delivery; Tailscale for secure network connectivity between authorised systems; delivery, courier and logistics providers; professional advisers, auditors, insurers, security providers and service contractors; and government agencies, regulators, courts, law enforcement bodies or other recipients where disclosure is required or authorised by law.
Calendly and YouTube are not recipients of information Krepko discloses to them. They receive whatever a visitor chooses to give them directly, as described above. Krepko does not sell personal information.
Security
Krepko uses technical and organisational measures designed to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Depending on the system these include verified account authentication and multi-factor authentication, access controls and least-privilege permissions, separate databases for each participating pharmacy, encryption in transit and encryption at rest provided by the underlying cloud services, managed secrets storage, secure private network connectivity to participating pharmacy systems, audit and operational logging, security monitoring and incident response processes, and restricted production access.
No internet-connected service can guarantee absolute security. Protect your account credentials and contact Krepko promptly if you believe an account or information has been compromised.
Retention and deletion
Marketing lead and consent personal information is retained for 24 months from the latest consent or approved Pioneers interaction. Abuse-event rows are retained for no longer than 30 days. After a verified deletion request, lead and consent personal information is removed within 30 days.
Krepko must retain a non-personal deletion audit recording request and completion timestamps, affected record classes and outcome; that deletion audit contains no personal information and is retained for seven years, consistent with the period Krepko applies to its other business records.
KShop and platform records are different. Accounts, order histories and pharmacy transaction records are designed to be held on a long-term basis so that customers and pharmacies can retrieve historical information, administer transactions, resolve disputes and satisfy pharmacy, medicines, payment, taxation and audit obligations. That is not treated as permission to keep everything indefinitely: information is retained only for as long as it is reasonably required for a purpose for which it may lawfully be used or disclosed, or for as long as retention is required or authorised by Australian law, and is then destroyed or de-identified. Some prescription, dispensing, medicine, transaction, audit or regulatory records may need to be kept after an account is closed or a deletion request is made.
Access and correction
You may ask for access to the personal information Krepko holds about you, or ask Krepko to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. Email team@krepko.com.au. Krepko may need to complete identity verification before responding, and will respond within 30 days of the request. In the circumstances permitted by law Krepko may refuse access or correction, and will explain the reason where it is permitted to do so.
Where the information is held by a participating pharmacy under its own obligations rather than by Krepko, Krepko will say so and point you to the pharmacy.
Deletion and withdrawal
You may ask Krepko to delete personal information it holds about you, and you may withdraw a consent you have given. Email team@krepko.com.au. Krepko may need to complete identity verification before acting. A verified deletion request covering marketing lead and consent records is actioned within 30 days.
Withdrawing consent stops the use that depended on it. It does not require deletion of information Krepko is required or reasonably needs to retain, including prescription and dispensing records, pharmacy or medicines obligations, taxation and financial records, fraud prevention, chargebacks, audit trails, security investigations or legal claims. A deletion request to Krepko does not require a participating pharmacy to delete information the pharmacy independently holds or is legally required to retain.
Complaints
If you have a privacy question or complaint, email team@krepko.com.au. Krepko will investigate and respond within 30 days. If you are not satisfied with the response, you may complain to the Office of the Australian Information Commissioner (OAIC), which can be contacted at oaic.gov.au.
Children
The marketing site, the waitlist and the Pioneers application are intended for pharmacy professionals and are not directed to people under 18. Krepko does not knowingly collect personal information from a child through them. If you believe a child has submitted information through one of these forms, contact team@krepko.com.au and it will be deleted.
KShop is different, because a pharmacy lawfully dispenses to patients of any age. A KShop account holder must have legal capacity to enter into transactions. A parent, guardian or other authorised representative may act for a patient where the law permits, and the participating pharmacy verifies identity and age where a product or supply requires it.
Data breaches
If Krepko becomes aware of a data breach involving personal information it will investigate and take appropriate steps. Where the Notifiable Data Breaches scheme or another applicable law requires notification, Krepko will notify affected individuals and the relevant regulator as required.
Changes and effective date
Krepko may update this policy to reflect changes to its services, its providers or applicable law. The current version is published at this address with its last-updated date, and takes effect on publication. Where a change materially affects how Krepko handles personal information already collected, Krepko will take reasonable steps to make the change apparent rather than relying on silent republication.
Contact and controller
Krepko Pty Ltd is the entity responsible as controller for the handling described in this policy, except where a participating pharmacy handles information under its own obligations. Its verified contact address for privacy matters is team@krepko.com.au, and it can also be reached on 0434 955 303 or by post at 17 Ullapool St, Heathwood QLD 4110, Australia.
Unresolved decisions
Solicitor decision required: confirm this policy before publication, including the description of Krepko’s role relative to participating pharmacies, the overseas disclosure wording, the retention periods stated above and the relationship between this policy and the terms in a pharmacy’s own agreement.
Owner decision required: confirm the production Calendly account and complete the direct-link test, so the third-party section can be verified rather than described as pending.