TERMS OF SERVICE
Last Updated / Effective Date: September 15, 2026
Welcome to CHARMAIL (the “Service,” “Platform,” or “System”), owned and operated by ROJO BPO, a New York corporation (“Company,” “we,” “us,” or “our”).
PLEASE READ THESE TERMS OF SERVICE (“TERMS”) CAREFULLY BEFORE ACCESSING OR USING THE SERVICE. BY ACCESSING, REGISTERING FOR, LOGGING INTO, OR USING THE SERVICE, OR BY OPTING IN TO RECEIVE SMS OR EMAIL NOTIFICATIONS FROM OR THROUGH THE SERVICE, YOU (“USER,” “YOU”) AGREE TO BE BOUND BY THESE TERMS. IF YOU DO NOT AGREE TO THESE TERMS, DO NOT ACCESS OR USE THE SERVICE.
1. Description of the Service & Core Architecture
The Service is a specialized communication portal facilitating confidential, authenticated information exchange among patients, healthcare providers, clinics, business associates, and authorized call centers.
- Two-Step Secure Notification Model: The Service functions as a two-tier communication system:
- Notification Tier (Unsecured Transmission Channel): When a message, update, or record is available, the System transmits an alert via standard electronic mail (Email) or Short Message Service (SMS)/text message. Notifications are designed to contain zero (0) Protected Health Information (PHI) or personally identifiable health details. Notifications strictly serve as generic transactional prompts (e.g., “You have a new secure message from your care team. Log in to [Portal URL] to view.”).
- Secure Portal Tier (Encrypted Vault): To read, reply to, or transmit PHI, clinical data, or confidential medical records, the recipient must navigate to the designated portal link, authenticate their identity via authorized credentials and/or multi-factor authentication (MFA), and view the information within an encrypted session.
2. Not for Medical Emergencies
DO NOT USE THIS SERVICE FOR MEDICAL EMERGENCIES.
If you are experiencing a life-threatening medical event, psychiatric crisis, or urgent clinical condition, immediately call 911 (or your local emergency response number) or proceed to the nearest hospital emergency department. The Service is not monitored on an uninterrupted real-time basis and neither Company, providers, nor call centers guarantee immediate responses.
3. Role of Company & HIPAA Business Associate Status
- Technology Conduit: Company provides software infrastructure. Company is not a healthcare provider, does not practice medicine, nursing, or any other licensed profession, and does not provide clinical, diagnostic, or treatment advice. Clinical decisions, message content, and medical records are solely the responsibility of the participating healthcare providers and users.
- Business Associate Agreement (BAA): To the extent Company handles, stores, or processes PHI on behalf of Covered Entities (e.g., healthcare providers, health plans) or Business Associates (e.g., call centers), Company’s handling of such information is governed by the applicable Business Associate Agreement (“BAA”) executed between Company and the respective Covered Entity or Business Associate, pursuant to the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”) and the Health Information Technology for Economic and Clinical Health Act (“HITECH”). In the event of a direct conflict between these Terms and an executed BAA regarding PHI, the BAA controls.
4. User Eligibility, Identity Verification, and Account Security
- Eligibility: You must be at least 18 years old (or the legal age of majority in your jurisdiction) or an emancipated minor to register an account. If you access the service on behalf of a minor dependent or an adult for whom you are a legally recognized personal representative/guardian, you represent and warrant that you hold full legal authority to do so under applicable law.
- Authentication Credentials: Users must maintain the absolute confidentiality of their usernames, passwords, biometrics, one-time passcodes (OTPs), and any other authentication mechanisms.
- Prohibition on Credential Sharing: Sharing login credentials, access tokens, or multi-factor authentication codes is strictly prohibited. You agree to notify Company immediately of any suspected or actual unauthorized use of your credentials or any security breach.
- Accuracy of Contact Information: You are strictly responsible for maintaining accurate, current, and verified mobile telephone numbers and email addresses. Company bears zero liability for notifications misdirected due to obsolete, incorrect, or re-assigned phone numbers or email addresses provided by you or your provider.
5. Mandatory User Best Practices and Acceptable Use
All users—including patients, medical providers, and call center personnel—agree to comply with the following mandatory security and operating standards:
- Endpoint Security: Users must access the portal solely from secure, password- or biometric-protected devices with updated operating systems, supported browsers, and active anti-malware safeguards.
- Public/Shared Devices: Users must never save passwords, store session tokens, or leave active portal sessions unattended on public, unencrypted, or shared workstations (e.g., library computers, shared call center desks). Users must explicitly log out at the conclusion of each session.
- Call Center & Provider Specific Standards:
- Authorized personnel must verify the identity and legal authorization of callers and recipients prior to dispatching notifications or transmitting PHI.
- Staff must strictly abide by the “Minimum Necessary” standard under HIPAA.
- Under no circumstances shall providers or call center staff override platform safeguards or input PHI into the subject lines, notification fields, or SMS body text intended for the unsecured notification channel.
- Prohibited Conduct: You shall not:
- Reverse engineer, decompile, crawl, scrape, or exploit the platform or its APIs.
- Upload malicious scripts, trojans, viruses, or corrupted clinical payloads.
- Use the Service to harass, threaten, defame, impersonate, or violate the intellectual property or privacy rights of any party.
6. SMS/Text Messaging and Email Communication Terms (TCPA & Regulatory Compliance)
By enrolling in the Service, providing your mobile number or email address to Company or your healthcare organization/call center, or replying to an opt-in prompt, you expressly agree to the following terms pursuant to the Telephone Consumer Protection Act (TCPA) and applicable regulations:
- Consent to Electronic Notifications: You expressly consent to receive recurring automated and non-automated transactional SMS/text messages and emails from or on behalf of Company, your healthcare provider, and associated call centers regarding account alerts, appointment updates, secure message arrival alerts, billing notifications, and security verification codes (e.g., MFA/OTP).
- Zero-PHI Transmission Acknowledgment: You acknowledge that SMS and unencrypted email networks are inherently non-secure public communication channels. You understand and agree that notifications transmitted over these channels will only inform you of the existence of a message or request an action, and you must log in to the portal to review the actual protected health data.
- Message Frequency & Rates: Message frequency varies based on your care schedule, provider interactions, and account activity. Standard message and data rates may apply as dictated by your wireless carrier. Company is not responsible for carrier charges incurred.
- Opt-Out Instructions (SMS): You may cancel and opt out of SMS notifications at any time. To stop receiving text messages, reply STOP to any SMS received from the Service. Upon texting STOP, you will receive one single confirmation text verifying your de-enrollment. Following this, you will receive no further SMS messages from that designated number unless you re-enroll.
- Opt-Out Instructions (Email): To opt out of non-critical transactional or operational emails, click the “Unsubscribe” or “Notification Preferences” link at the footer of the email, or adjust your communication preferences inside the secure portal settings.
- Impact of Opting Out: You acknowledge that opting out of SMS and/or email notifications may impair your ability to receive timely notifications regarding pending communications from your healthcare provider or call center. Critical security notifications (such as password resets or emergency account access verification initiated directly by you) may still be sent where legally permitted.
- Customer Support: For SMS assistance, reply HELP to any message received, or contact contact@rojobpo.com or call 1-855-632-6112.
- Carrier Disclaimer: Supported carriers are not liable for delayed, undelivered, or misdirected messages. Delivery of SMS alerts is subject to effective transmission from your mobile network operator.
7. Intellectual Property
The Service, its underlying architecture, proprietary software, design, user interfaces, documentation, databases, and trademarks are the exclusive property of Company and its licensors. Except for the limited, non-exclusive, revocable, non-transferable right to access the Service in accordance with these Terms, no right, title, or interest in Company Intellectual Property is granted to you.
8. Disclaimers of Warranties
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW:
- THE SERVICE, INCLUDING ALL SOFTWARE, NOTIFICATIONS, PORTALS, AND INFRASTRUCTURE, IS PROVIDED STRICTLY ON AN “AS IS” AND “AS AVAILABLE” BASIS.
- COMPANY EXPRESSLY DISCLAIMS ALL WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING WITHOUT LIMITATION THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, QUIET ENJOYMENT, AND NON-INFRINGEMENT.
- COMPANY DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, TIMELY, ERROR-FREE, SECURE, FREE OF VIRUSES OR HARMFUL COMPONENTS, OR THAT TRANSMISSIONS OVER PUBLIC TELECOMMUNICATIONS NETWORKS (INCLUDING SMS AND EMAIL) WILL BE DELIVERED WITHOUT DELAY OR PACKET LOSS.
- COMPANY ASSUMES NO RESPONSIBILITY FOR ANY MEDICAL, CLINICAL, LEGAL, OR ADMINISTRATIVE ERRORS, DELAYS, OMISSIONS, OR MISDIRECTIONS ARISING FROM CONTENT SUBMITTED BY PATIENTS, PROVIDERS, OR CALL CENTERS.
9. Limitation of Liability
TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW:
- EXCLUSION OF CONSEQUENTIAL DAMAGES: IN NO EVENT SHALL COMPANY, ITS AFFILIATES, OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, SUPPLIERS, OR LICENSORS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, PUNITIVE, COVER, OR CONSEQUENTIAL DAMAGES (INCLUDING, WITHOUT LIMITATION, DAMAGES FOR LOSS OF PROFITS, REVENUE, GOODWILL, USE, CLINICAL OUTCOMES, MEDICAL MALPRACTICE, INTERRUPTION OF CARE, DATA CORRUPTION, OR LOSS OF DATA), HOWEVER CAUSED, UNDER ANY THEORY OF LIABILITY (WHETHER IN CONTRACT, TORT, STRICT LIABILITY, NEGLIGENCE, INDEMNITY, OR OTHERWISE), EVEN IF COMPANY HAS BEEN ADVISED AS TO THE POSSIBILITY OF SUCH DAMAGES.
- AGGREGATE LIABILITY CAP: THE TOTAL AGGREGATE LIABILITY OF COMPANY AND ITS AFFILIATES ARISING OUT OF OR RELATING TO THE SERVICE OR THESE TERMS SHALL NOT EXCEED THE GREATER OF:
- (A) THE TOTAL FEES ACTUALLY PAID BY YOU TO COMPANY FOR THE USE OF THE SPECIFIC SERVICE IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM; OR
- (B) ONE HUNDRED UNITED STATES DOLLARS ($100.00 USD).
- ALLOCATION OF RISK: THE PARTIES ACKNOWLEDGE THAT THE LIMITATIONS OF LIABILITY AND DISCLAIMERS HEREIN REFLECT AN INFORMED, REASONABLE ALLOCATION OF RISK AND FORM AN ESSENTIAL BASIS OF THE BARGAIN BETWEEN THE PARTIES.
10. Indemnification
You agree to defend, indemnify, and hold harmless Company, its parent, subsidiaries, affiliates, officers, directors, employees, agents, and licensors from and against any third-party claims, liabilities, damages, judgments, awards, losses, costs, expenses, or fees (including reasonable attorneys’ fees and expert witness costs) arising out of or relating to:
- Your violation of these Terms or applicable local, state, federal, or international laws (including HIPAA, TCPA, CAN-SPAM, and state consumer protection statutes);
- Your misuse of the Service, endpoints, or credentials;
- Any clinical, operational, or administrative data, messages, or files you transmit, dispatch, or fail to transmit through the Service;
- Transmission of incorrect phone numbers or email addresses, or failure to update contact information, causing notifications to be routed to third parties;
- For Providers and Call Centers: Any claim that clinical instructions, triage determinations, or message content violated professional standards of care or applicable medical board rules.
11. Suspension and Termination
Company reserves the right, in its sole and absolute discretion, without prior notice or liability, to suspend, disable, throttle, or terminate your access to the Service (or any portion thereof) if:
- You breach any provision of these Terms or related agreements;
- Company suspects unauthorized access, credential stuffing, scraping, or an active security compromise;
- Required by law enforcement, regulatory mandates, or judicial process;
- Continued provision of the Service exposes Company, healthcare providers, or call centers to security, operational, or legal liability.
Upon termination, your right to access the portal immediately ceases. Relevant medical records stored within Covered Entity systems remain subject to state medical record retention laws and the Covered Entity’s policies, independent of portal access.
12. Dispute Resolution, Mandatory Binding Arbitration, and Class Action Waiver
- Informal Resolution: Prior to filing any legal proceeding, you and Company agree to attempt to resolve any dispute, claim, or controversy arising out of or relating to these Terms or the Service informally by sending written notice to ROJO BPO, 5 West 37th Street, Suite 603, New York, NY, 10018. The parties shall negotiate in good faith for at least thirty (30) days.
- Mandatory Arbitration: Any unresolved dispute, controversy, or claim shall be settled by binding individual arbitration administered by the American Arbitration Association (“AAA”) under its Commercial Arbitration Rules or Consumer Arbitration Rules (as applicable), before a single neutral arbitrator in New York City, NY. Judgment on the award may be entered in any court having jurisdiction.
- CLASS ACTION WAIVER: YOU AND COMPANY AGREE THAT EACH PARTY MAY BRING CLAIMS AGAINST THE OTHER ONLY IN AN INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS, COLLECTIVE, REPRESENTATIVE, OR PRIVATE ATTORNEY GENERAL PROCEEDING. THE ARBITRATOR HAS NO AUTHORITY TO CONSOLIDATE CLAIMS OR PRESIDE OVER ANY CLASS PROCEEDING.
13. Governing Law and Jurisdiction
These Terms and any dispute arising hereunder shall be governed by and construed in accordance with the laws of the State of New York, without giving effect to any choice or conflict of law provision or rule. To the extent court proceedings are permitted, the parties submit to the exclusive personal jurisdiction of the state and federal courts located within New York County.
14. Severability, Entire Agreement, and Modifications
If any provision of these Terms is held invalid, illegal, or unenforceable by an arbitrator or court of competent jurisdiction, such provision shall be enforced to the maximum extent permissible, and the remaining provisions shall remain in full force and effect. Company reserves the right to modify these Terms at any time by posting revised terms on the platform and updating the “Effective Date.” Continued use of the Service following such revisions constitutes your affirmative acceptance of the amended Terms.