Privacy policy
Effective Date: February 26, 2026
Last Updated: February 26, 2026
TRTL.Health ("TRTL", "we", "us", or "our") develops and operates enterprise white-label patient portal technology, integration middleware, and diagnostic delivery platforms for healthcare providers, clinical laboratories, and hospital systems ("Healthcare Clients").
This Privacy Policy describes how TRTL collects, uses, and safeguards information across our corporate website (trtl.health), our business-to-business (B2B) commercial operations, and our white-labeled patient portal web and mobile applications.
1. Scope & Governance Roles Under Data Protection Laws
Under data protection regulations including the EU/UK General Data Protection Regulation (GDPR) and applicable regional data protection laws:
-
TRTL as a Data Processor: When operating white-labeled portal instances, we process patient demographics, medical laboratory results (FHIR R4 DiagnosticReports/Observations), and delivery metadata strictly on behalf of and under the documented instructions of our Healthcare Clients (the Data Controllers).
-
TRTL as a Data Controller: TRTL serves as a Data Controller for:
-
Business contacts, customer representatives, and corporate website visitors.
-
Direct user consent choices regarding optional product analytics, technical telemetry, and usability logs collected within our portal applications.
-
2. Information We Collect
A. Healthcare Client Diagnostic Data (Processed on Behalf of Controllers)
-
Patient Demographics: Full name, date of birth, MRN (Medical Record Number), mobile phone number, WhatsApp identifier, and email address as transmitted by the client's Laboratory Information System (LIS) or Hospital Information System (HIS).
-
Clinical Diagnostic Results: Diagnostic test panels, observation values, LOINC / SNOMED CT coded elements, provider notes, and lab report PDFs.
B. In-App Portal Telemetry & Cookies
-
Essential Session Data (Strictly Necessary): Authentication tokens, session state, and security flags required to keep users authenticated securely and prevent cross-site request forgery.
-
Optional Product Analytics (Consent-Based): Aggregated or pseudonymized navigation journeys, click patterns, load times, device/browser types, and system error events. We never parse medical record contents, diagnoses, clinical observations, or payment credentials for product analytics.
C. Corporate Website Visitors & B2B Commercial Contacts
-
Professional contact details (name, business email, organization, job title, phone number) submitted via demo requests, commercial inquiries, or support tickets.
-
Standard web server logs (IP address, operating system, browser type, referral URL).
3. Legal Bases for Processing (GDPR Articles 6 & 9)
-
Contractual Necessity (Art. 6(1)(b)): Providing portal infrastructure under B2B commercial agreements; processing and rendering patient lab results under our Data Processing Agreements (DPAs) with healthcare providers.
-
Explicit Consent (Art. 6(1)(a)): Operating optional analytics cookies and product improvement tracking in the patient portal. Users choose to opt in on first login and can toggle this off at any time in portal settings.
-
Legitimate Interests (Art. 6(1)(f)): Maintaining network availability, threat monitoring, bot prevention, and securing patient portal infrastructure.
-
Legal Obligation (Art. 6(1)(c)): Retaining financial, tax, corporate, and statutory audit records.
-
Special Category Data (Art. 9(2)(h)): Handled strictly pursuant to the Healthcare Client’s medical care and healthcare management mandates governed by executed DPAs.
4. Technical Safeguards & Regional Data Residency
TRTL maintains an Information Security Management System (ISMS) aligned with ISO 27001 standards and health data protection frameworks:
-
Encryption Standards: TLS 1.3 enforced for all data in transit across public endpoints; AES-256 envelope encryption via AWS Key Management Service (KMS) applied to all data at rest (RDS PostgreSQL and S3 report storage).
-
Data Residency: Deployed on Amazon Web Services (AWS) cloud infrastructure within regional availability zones, including Middle East / GCC data centers where designated by tenant contractual requirements to satisfy regional residency mandates.
-
Network & Endpoint Isolation: Application services and databases run within private VPC subnets with zero direct internet access. Mobile and browser caching safeguards prevent local caching of sensitive health results on shared client devices.
-
Monitoring: Automated intrusion detection via AWS GuardDuty, continuous vulnerability scanning, and immutable access logging via AWS CloudTrail.
5. Third-Party Sub-Processors & Data Sharing
We do not sell personal data, license medical information, or utilize external behavioral advertising networks. Data is shared strictly with vetted infrastructure partners under binding DPAs:
-
Cloud Hosting & Databases: Amazon Web Services (AWS).
-
Delivery & Telecommunication Gateways: Enterprise messaging partners (such as Twilio and WhatsApp Business API) utilized solely to route authenticated notification tokens and portal access links as directed by the Healthcare Client.
-
Compliance & Security Tooling: Infrastructure used for continuous compliance verification, audit logging, and uptime diagnostics.
6. Retention and Deletion Lifecycle
-
Healthcare Client Patient Data: Maintained for the active term of the agreement with the Healthcare Client. Upon contract termination, TRTL provides a standard 30-day grace period allowing the Healthcare Client to complete data extraction, after which tenant data is deleted or permanently de-identified from production databases. Backups rotate and expire on automated schedules.
-
In-App Analytics & Preference Records: Analytics preference tokens remain for up to 1 year unless cleared by the user. Aggregated, pseudonymized performance metrics are retained for platform optimization.
-
Security & Ingestion Audit Logs: Retained for 12 months for compliance traceability before automated rotation.
-
B2B Commercial Records: Retained for the contract duration plus statutory tax and accounting retention limits (typically 5 to 7 years).
7. Exercise of Data Subject Rights
-
Patients Accessing Lab Results: Because TRTL acts as a Data Processor on behalf of your healthcare facility, any requests to inspect, rectify, download, restrict, or delete your diagnostic health records must be directed to your healthcare provider or laboratory (the Data Controller). If TRTL receives an inquiry directly from a patient regarding medical records, we forward the request to the designated Healthcare Client.
-
In-App Analytics Opt-Out: You may withdraw consent for optional portal analytics at any time directly within the application by navigating to Settings → Privacy → Analytics Consent and toggling the preference to Off.
-
B2B Contacts & Inquiries: Business representatives and website visitors seeking to exercise access, rectification, or erasure rights regarding corporate contact information may contact our compliance team directly.
8. Contact Information
For inquiries regarding this Privacy Policy, our Data Processing Agreements, or technical security architecture:
Email: privacy@trtl.health