PRIVACY POLICY

Last Updated / Effective Date: September 15, 2026

ROJO BPO (“Company,” “we,” “us,” or “our”) respects your privacy and is committed to protecting your personal information. This Privacy Policy describes how we collect, use, process, maintain, and safeguard personal information and Protected Health Information (“PHI”) when you access or use CHARMAIL (the “Service”), participate in secure communications, or receive SMS and email notifications from the Service.

1. Dual Regulatory Framework: HIPAA vs. General Privacy Laws

The Service operates under a strict, dual-framework model:

  • Protected Health Information (PHI) & HIPAA/HITECH:
  • When the Service stores, processes, or facilitates access to clinical records, diagnoses, prescriptions, treatment summaries, or provider-patient messages, Company operates as a Business Associate to Covered Entities (healthcare providers, health systems) or fellow Business Associates (medical call centers).
  • In this capacity, our handling of PHI is governed by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), the HITECH Act, and specific Business Associate Agreements (BAAs) executed with your healthcare organization.
  • Your Healthcare Provider’s Notice of Privacy Practices (NPP): The use and disclosure of your core medical records and health conditions are governed by your individual healthcare provider’s Notice of Privacy Practices, not this Privacy Policy.
  • Non-PHI / Operational / Account Information:
  • This Privacy Policy directly governs our collection and processing of operational, diagnostic, and account identity information (such as registration data, portal analytics, device data, and notification preferences) that does not constitute PHI under federal law.

2. The Two-Tier Architecture & Data Minimization Principle

To protect sensitive patient information across unencrypted public networks, the Service enforces an intentional technical separation between Alerts and Clinical Content:

  • Unsecured Notification Layer (SMS & Email):
  • Transmitted across standard cellular telecommunication networks and public internet mail exchanges.
  • Zero-PHI Guarantee: The System enforces data hygiene standards prohibiting the inclusion of PHI, diagnostic codes, prescription names, or sensitive identifiers in SMS or email alert bodies. Notifications contain only general administrative alerts (e.g., “A new secure message is waiting in your portal”) and a uniform authentication link.
  • Secure Vault / Portal Layer:
  • Hosted in hardened, HIPAA-compliant, encrypted cloud infrastructure (TLS 1.2+ in transit; AES-256 at rest).
  • Accessible only following identity verification and multi-factor authentication (MFA). All PHI access, display, and composition occur exclusively within this layer.

3. Categories of Information We Collect

Depending on your role (patient, healthcare provider, or call center agent), we collect:

  • Account and Identity Information: Name, organizational affiliation, professional credentials (NPI, licensing data for providers), role/title, email address, mobile telephone number, and authentication data (hashed passwords, security questions, MFA audit tokens).
  • Metadata & Notification Logs: Date, time, carrier routing status, delivery receipts, click/navigation timestamps, and transactional history related to SMS alerts and emails dispatched.
  • Device & Telemetry Data: IP addresses, operating system types and versions, browser types, unique device identifiers, user-agent headers, and platform security flags (e.g., detection of jailbroken/rooted devices).
  • Audit and Compliance Trails: Full, immutable audit logs documenting every portal login, credential modification, message creation, message access, download, attachment access, and logout, as mandated by HIPAA Security Rule regulations (45 C.F.R. § 164.312(b)).

4. How We Use Your Information

We process your information strictly for legitimate operational, clinical communication, and compliance purposes, including:

  • Provisioning, operating, maintaining, and supporting the portal infrastructure;
  • Dispatching non-PHI SMS and email alerts notifying recipients of messages or pending clinical actions;
  • Authenticating identity and enforcing multi-factor security barriers;
  • Maintaining complete, time-stamped audit trails to support provider HIPAA compliance and detect unauthorized access;
  • Complying with statutory, regulatory, and legal obligations, court orders, subpoenas, and governmental oversight requests;
  • Investigating and mitigating security incidents, data breaches, fraudulent activities, or violations of our Terms of Service.

5. SMS/Text Messaging and TCPA Privacy Compliance

We strictly uphold the privacy and security of mobile telephone numbers:

  • Explicit Consent & Opt-In: Mobile telephone numbers collected directly through portal self-registration, electronic consent forms, or provided by Covered Entities/call centers are utilized exclusively for operational and transactional notifications.
  • No Sharing for Marketing: Mobile numbers, SMS consent records, and opt-in data will NOT be sold, rented, leased, shared, or disclosed to third parties, data aggregators, or affiliates for marketing, advertising, or promotional purposes.
  • Service Providers: Mobile numbers are shared solely with authorized telecommunications conduits, SMS gateway aggregators, and cellular carriers strictly to deliver the transactional SMS alerts requested by your healthcare team.
  • Opt-Out Mechanism: You can revoke consent to receive SMS notifications at any time by texting STOP to any SMS alert. To re-enable alerts, text UNSTOP or START, or adjust your preferences in the portal.

6. Sharing and Disclosure of Information

We disclose collected information only under the following limited circumstances:

  • With Covered Entities and Call Centers: We provide authorized providers, medical practices, and call centers with access to audit logs, transmission records, message status indicators, and account interactions associated with their patients and personnel.
  • With Subcontractors and Service Providers: We engage vetted third-party vendors (e.g., SOC-2 / HIPAA-compliant cloud hosting facilities, security monitoring firms, SMS aggregators, transactional email dispatchers). These subcontractors are bound by written agreements and, where applicable, Business Associate Agreements requiring them to maintain equivalent administrative, physical, and technical safeguards.
  • For Legal & Regulatory Compliance: When required by applicable federal, state, or international laws, subpoenas, warrants, regulatory audits, or civil investigations, or when necessary to protect the life, safety, or fundamental rights of any individual.
  • Business Transfers: If Company undergoes a merger, acquisition, corporate reorganization, or sale of assets, data held by Company may be transferred to the acquiring entity, subject to the terms of this Privacy Policy and applicable HIPAA Business Associate commitments.

7. Technical, Administrative, and Physical Safeguards

Company implements a comprehensive information security program designed in alignment with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C), NIST standards, and industry best practices:

  • Encryption: All data in transit across the secure portal is encrypted using Transport Layer Security (TLS 1.2 or higher). All stored portal data, messages, attachments, and backups are encrypted at rest using AES-256 or equivalent cryptographic standards.
  • Access Controls & Multi-Factor Authentication: Access to system administration and clinical records requires unique user identification, role-based access controls (RBAC), automatic session timeouts, and multi-factor authentication (MFA).
  • Network & Infrastructure Security: Hardened cloud environments protected by web application firewalls (WAF), intrusion detection/prevention systems (IDS/IPS), segmented virtual private clouds (VPCs), and continuous vulnerability monitoring.
  • Immutable Audit Logging: System activity, message access events, and administrative actions are written to secure, tamper-resistant logging services monitored for suspicious behaviors.
  • Workforce Security: Mandatory workforce HIPAA compliance training, identity vetting, and strict non-disclosure obligations.

8. Data Retention and Deletion

  • Operational and System Data: We retain non-PHI account records, telemetry, and system logs for as long as necessary to fulfill the purposes outlined in this policy, satisfy legal or audit requirements, and enforce our agreements.
  • PHI and Medical Records: Company retains PHI in accordance with instructions from the applicable Covered Entity, specific provisions in executed Business Associate Agreements, and statutory medical record retention schedules (typically ranging from 5 to 10 years depending on state law). When instructed by a Covered Entity or upon termination of service without ongoing retention duties, Company securely purges, de-identifies, or destroys PHI in compliance with NIST SP 800-88 standards.

9. Patient Privacy Rights (HIPAA & State Laws)

  • HIPAA Rights: Under HIPAA, patients possess specific rights regarding their Protected Health Information, including the right to inspect and receive a copy of health records, request amendments, request restrictions on disclosures, and obtain an accounting of disclosures. Because Company is a Business Associate, all such requests must be directed to your treating healthcare provider (the Covered Entity). Company will assist your healthcare provider in fulfilling verified requests in accordance with our BAA.
  • State Consumer Rights (e.g., CCPA/CPRA, where applicable): To the extent non-PHI personal information is collected from state residents whose laws afford specific rights (e.g., California, Virginia, Colorado):
  • You may have the right to request access to, deletion of, or correction of non-PHI personal information held directly by Company.
  • Note: Medical information governed by HIPAA, the California Confidentiality of Medical Information Act (CMIA), and clinical trials data are expressly exempt from consumer privacy statutes such as the CCPA/CPRA.
  • We do not “sell” or “share” (for targeted behavioral advertising) any personal information.

10. Children’s Privacy

The Service is not directed to children under the age of 13 for independent registration. Minors may only use the Service with the involvement, consent, and supervision of a parent or legal guardian, or pursuant to applicable state laws permitting adolescent confidential healthcare services (e.g., reproductive health, mental health, or substance use treatment). We do not knowingly collect personal information directly from children under 13 without verified parental or legal authorization.

11. Changes to This Privacy Policy

Company reserves the right to modify this Privacy Policy periodically to reflect technological advancements, regulatory changes, or operational updates. Material updates will be indicated by revising the “Last Updated / Effective Date” at the top of this document. Continued engagement with the Service or maintenance of an active notification subscription following the posting of an updated Privacy Policy constitutes your acceptance of the terms.

12. Contact Information, Security Officer, & Regulatory Inquiries

For questions, concerns, or requests regarding this Privacy Policy, your account data, or our security protocols, contact our designated privacy and security team:

  • Attn: Privacy Officer & Information Security Officer
  • Company Legal Name: ROJO BPO
  • Mailing Address: 5 West 37th Street, Suite 603, New York, NY, 10018
  • Email: legal@rojobpo.com
  • Telephone: 1-855-632-6112