Privacy Policy
Last updated 28 July 2026
This Privacy Policy applies only to information collected through our website and from clinic personnel, prospective customers, business contacts, and authorized users of the trellOS platform.
It does not govern Protected Health Information (“PHI”)that trellOS creates, receives, maintains, or transmits on behalf of healthcare providers. PHI is governed by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), including the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule, the Health Information Technology for Economic and Clinical Health Act (“HITECH Act”), applicable Business Associate Agreements, and each healthcare provider’s Notice of Privacy Practices — see Patient health information below and our HIPAA page.
Who we are
trellOS is operated by BrainBox Holdings, LLC. For questions regarding this Privacy Policy or our privacy practices, please contact privacy@trellos.org.
Information we collect
Depending on how you interact with trellOS, we may collect the following categories of information.
Information you provide. This may include:
- Name
- Clinic or organization name
- Professional title or role
- Business email address
- Mobile telephone number
- State or practice location
- Prescribing volume or practice information
- Information submitted through forms, surveys, waitlists, or support requests
- Communications you send to us
Account information. If you use the trellOS platform, we collect information necessary to establish, administer, authenticate, secure, and maintain your account, including user identifiers, authentication information, account activity, permissions, and audit records.
Technical information. When you visit our website or submit information, we may automatically collect certain technical information, including IP address, browser type, operating system, device information, user-agent string, referring webpage, date and time of access, website request metadata, authentication logs, security logs, error logs, and form submission records. Where applicable, technical information may also be retained as evidence of SMS consent or other legally required records.
Cookies and similar technologies
Our website may use cookies or similar technologies necessary to provide website functionality, authentication, security, fraud prevention, and user experience. We do not use advertising trackers or technologies for cross-context behavioral advertising. See our Cookies page for detail.
How we use information
We use the information we collect for legitimate business, operational, security, and regulatory purposes, including to:
- Respond to inquiries.
- Notify you when onboarding or services become available in your state.
- Create, administer, and secure user accounts.
- Authenticate users.
- Operate, maintain, improve, and support the trellOS platform.
- Deliver communications you request by email or SMS.
- Detect, investigate, and prevent fraud, abuse, unauthorized access, and security incidents.
- Maintain audit logs and business records.
- Comply with applicable legal, regulatory, contractual, accounting, tax, and compliance obligations.
- Investigate incidents and protect our legal rights.
- Support quality assurance, business continuity, disaster recovery, and platform maintenance.
We do not sell personal information or use your personal information for third-party marketing.
Mobile information and SMS communications
No mobile information will be shared with third parties or affiliates for their own marketing or promotional purposes. We may disclose mobile information only to trusted service providers that facilitate SMS delivery, or where required by law, legal process, regulatory authority, protection of our legal rights, or in connection with a merger, acquisition, financing, or other corporate transaction. SMS opt-in information and consent records are never sold.
If you voluntarily opt in to receive SMS communications, we collect and maintain records necessary to demonstrate your consent. Our records may include mobile telephone number, date and time of consent, IP address, source of consent, exact consent language presented, and confirmation of opt-in.
These records are retained while you remain subscribed and for at least two (2) years following your opt-out, or longer where required by applicable law, carrier requirements, or legitimate business needs.
SMS communications are administered in accordance with applicable federal law, carrier requirements, and industry standards governing text messaging communications. You may opt out at any time by replying STOP. Reply HELP for assistance. Additional information is available in our SMS Terms.
How we share information
We disclose information only where reasonably necessary to operate our business or where required or permitted by applicable law. Recipients may include:
- Cloud hosting providers
- Authentication providers
- Database providers
- Email delivery providers
- SMS delivery providers
- Payment processors
- Customer support providers
- Cybersecurity and security service providers
- Professional advisors, including legal counsel, accountants, and auditors
- Government agencies or regulators where legally required
- Courts, law enforcement, or other governmental authorities pursuant to lawful process
- Successor organizations in connection with mergers, acquisitions, financing transactions, restructuring, bankruptcy, or sale of assets
All service providers are contractually required to protect personal information and may use it only for the services they perform on our behalf. We do not sell or rent personal information. We do not disclose personal information for another organization’s independent marketing purposes. The current list of subprocessors is at /subprocessors.
Patient health information
trellOS provides technology services to healthcare organizations. Where trellOS creates, receives, maintains, or transmits Protected Health Information (“PHI”) on behalf of a Covered Entity, trellOS functions as a Business Associate as those terms are defined under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended by the Health Information Technology for Economic and Clinical Health Act (“HITECH Act”), including the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule (45 C.F.R. Parts 160 and 164). trellOS performs such services solely pursuant to applicable Business Associate Agreements (“BAAs”) and creates, receives, maintains, uses, and discloses PHI only as permitted or required by such agreements and applicable law.
As a Business Associate, trellOS complies with applicable obligations imposed by HIPAA and the HITECH Act. Healthcare providers remain responsible for determining the purposes and means of using Protected Health Information, responding to patient requests, maintaining their Notice of Privacy Practices, and fulfilling obligations owed directly to patients under HIPAA.
If you are a patient seeking information regarding your medical record, please contact your healthcare provider directly. See also our HIPAA page.
Data retention
We retain information only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, comply with applicable law, resolve disputes, enforce agreements, protect our legal interests, and satisfy regulatory obligations.
Typical retention periods include:
- Waitlist and inquiry records: while communications remain active and for up to three (3) years thereafter.
- SMS consent records: while subscribed and for at least two (2) years following opt-out.
- User account information: for the duration of the account and thereafter in accordance with applicable legal, regulatory, contractual, audit, security, and business record retention requirements.
- Security and audit logs: in accordance with our internal retention schedule and applicable law.
Retention periods may be extended where necessary to comply with litigation holds, investigations, contractual obligations, or regulatory requirements.
Your privacy rights
Subject to applicable law, you may have the right to:
- Request access to personal information we maintain about you.
- Request correction of inaccurate information.
- Request deletion of certain personal information.
- Request information regarding categories of personal information collected and disclosed.
- Withdraw consent where processing is based upon consent.
- Opt out of SMS communications by replying STOP.
- Unsubscribe from marketing emails using the unsubscribe mechanism included within those communications.
Depending on your jurisdiction, you may possess additional rights under applicable privacy laws, including the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and other applicable U.S. state privacy laws.
To exercise applicable privacy rights, please contact privacy@trellos.org. We will respond to verified requests in accordance with applicable law.
Information security
trellOS maintains administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction, consistent with applicable legal requirements, recognized security practices, and industry standards. Our safeguards may include, as appropriate:
- Encryption of data in transit
- Encryption of data at rest where appropriate
- Role-based access controls
- Authentication controls
- Security logging and monitoring
- Audit logging for sensitive activities
- Vendor security oversight
- Periodic security assessments
- Incident response procedures
No method of electronic transmission, storage, or information security is completely secure. Accordingly, while we continually work to protect information entrusted to us, we cannot guarantee absolute security.
Business transfers
If trellOS undergoes a merger, acquisition, financing transaction, corporate restructuring, bankruptcy, or sale of all or substantially all of its assets, information governed by this Privacy Policy may be transferred as part of that transaction, subject to applicable law.
Third-party websites
Our website may contain links to third-party websites or services. This Privacy Policy does not apply to third-party websites, products, or services, and trellOS is not responsible for their privacy, security, or content.
Children's privacy
trellOS is intended solely for healthcare professionals, healthcare organizations, and authorized business users. Our website and platform are not directed to children under the age of thirteen (13), and we do not knowingly collect personal information directly from children.
United States operations
trellOS is intended for users located within the United States. If you access our services from outside the United States, you acknowledge that your information may be transferred to, processed, and stored in the United States, where privacy and data protection laws may differ from those in your jurisdiction.
Changes to this Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our business practices, technology, legal obligations, or regulatory requirements. When material changes are made, we will revise the “Last Updated” date appearing at the top of this Privacy Policy and, where required by applicable law or where the changes materially affect your rights, provide additional notice through appropriate means.
Your continued use of the website or platform after the effective date of an updated Privacy Policy constitutes acknowledgment of the revised Privacy Policy.
Questions about anything on this page? compliance@trellos.org
