1. Who We Are
TTECHNOS LLC (“we”, “us”) develops and operates the TrityMed mobile and web application (“the App”). TrityMed is a healthcare management platform that we license to healthcare organizations — clinics, dialysis centres, and medical practices — so they can manage appointments, clinical records, and communication with the people in their care.
We are a software provider. We are not a healthcare provider, we do not practise medicine, and we do not deliver clinical care. Each healthcare organization using TrityMed remains responsible for the care it provides and for the medical records it creates.
This policy explains what personal and health information the App collects, why, how it is protected, and what rights you have over it.
Contact for privacy questions: tessemat@ttechnos.com
Telephone: +1 (571) 234-3721
Registered address: 9661 Franklin Woods Pl, Lorton, VA 22079-2345, United States.
Data Protection / Privacy Officer: TrityMed Privacy and Security Officer, reachable at the address above. Each healthcare organization using TrityMed also designates its own privacy officer for questions about the records it holds.
2. Data Ownership and Roles
You are the ultimate owner of your health data. This is a foundational principle of the Ethiopian national EHR standard and of this platform.
Your healthcare organization is the custodian and controller of your health record. It decides what is recorded, which of its staff may see it, and how long it is kept.
We are the processor. We host and protect the record and make it available to your organization and to you, acting on that organization's instructions. We do not own your health data, and we do not use it for our own purposes.
For account and technical information — your login credentials, device details, and diagnostic data — we act as controller, because that information is needed to operate the App itself.
3. Information We Collect
3.1 Identity and demographic information
Full name, date of birth, sex, address (region, zone/sub-city, woreda, kebele, house number), phone number, email, marital status, occupation, preferred language, and emergency contact. The exact fields collected depend on what your healthcare organization requires.
3.2 Health information
Medical record number (MRN), diagnoses, treatment history, dialysis session records where your organization provides dialysis, vital signs, laboratory results, medications, vascular access information, allergies, immunization history, clinical notes, referral and consultation records, and incident records.
This information is entered by your healthcare organization, not by us.
3.3 Account and usage information
Organization code used to join your healthcare organization, login credentials stored as a secure hash and never in plain text, one-time password (OTP) verification records, session and device information, and in-app activity logs.
3.4 Billing and insurance information
Insurance policy details, billing and payment records, and claims status, where your organization uses these features.
4. Why We Collect It
Information is processed to:
- Enable your healthcare organization to provide clinical care, including scheduling, treatment documentation, and follow-up.
- Communicate with you about appointments, treatment, and your care team.
- Process billing and insurance claims.
- Meet the legal, regulatory, and reporting obligations of your healthcare organization to the Ministry of Health and other competent authorities.
- Maintain the security, integrity, and audit trail of your medical record.
- Operate, secure, and improve the App itself, using de-identified or aggregate data only, unless you separately consent to identified research use.
We do not sell your personal or health information, we do not share it with data brokers, and we do not use health information for advertising or to train machine learning models.
5. Consent
When you register for TrityMed you are asked to give explicit consent to this policy. We record the date, time, and version of the policy you consented to. You may:
- Withdraw consent for non-essential processing, such as marketing communications, at any time in Settings.
- Request a copy of your data.
- Request correction of inaccurate data.
- Request that your account be deactivated.
Consent for clinical data collection necessary to provide safe care cannot be withdrawn while you remain an active patient of your healthcare organization, as withdrawing it would prevent that organization from treating you safely. You may still request deactivation of your record when you are no longer receiving care.
6. Who Can Access Your Data
Access is restricted by role and by organization. Staff at one healthcare organization can never see another organization's records — each organization's data is isolated at the platform level.
Within your own organization, access follows least-privilege principles and is limited to:
- Your treating physicians, nurses, and dialysis technicians.
- Laboratory, pharmacy, dietitian, and social work staff involved in your care, where applicable.
- Billing and insurance staff, limited to billing-relevant information.
- Administrative staff, limited to non-clinical account and scheduling data.
- System administrators at your organization, for technical operation only and under audit.
Our own personnel may access records only where necessary to operate or support the platform, under contract and audit.
Every access to your record is logged: who accessed it, what they did, when, and from where. These logs cannot be altered or deleted.
We do not share your data with third parties for their own marketing purposes. Data may be shared:
- With other health facilities, at your request or your care team's request, for continuity of care, such as referrals.
- With the Ministry of Health and national health information systems, where required by law or national EHR interoperability requirements.
- With service providers who process data strictly on our behalf under contract, such as cloud-hosting, email delivery, and push notification providers, who are bound by confidentiality obligations and may not use the data for their own purposes.
- Where required by law, court order, or to prevent serious harm.
7. How We Protect Your Data
- All data in transit is encrypted using TLS/HTTPS.
- Data at rest is encrypted.
- Multi-factor authentication is required for account access.
- Role-based access control, organization-level isolation, and least-privilege enforcement are used throughout.
- Comprehensive, tamper-resistant audit logging records all record access.
- Regular security testing and vulnerability management are performed.
- Staff are trained on privacy and security obligations, and access is revoked promptly when no longer needed, including after departure.
No system is 100% secure. If a breach occurs that affects your information, we will notify the affected individuals, the affected healthcare organization, and the competent authority without undue delay, consistent with applicable law.
8. Data Retention
Consistent with the national EHR standard, health records are not permanently deleted, including after account closure, because medical records must remain available for continuity of care, legal, and public health purposes. Instead, inactive or closed records are deactivated and access is restricted, with the deactivation date recorded against the record.
Clinical record retention periods are set by your healthcare organization, following applicable Ethiopian health record retention requirements, Ministry of Health guidance, and that organization's approved record-retention policy. We retain records on their behalf and cannot shorten or override those periods.
Non-clinical data, such as marketing preferences, device tokens, and diagnostic logs, is deleted upon request or after 24 months of inactivity, unless it must be retained for a legitimate legal, security, or operational purpose.
9. Your Rights
You have the right to:
- View your own health information through the patient portal. This is view-only; edits and deletions to the clinical record must go through your care team.
- Request correction of inaccurate demographic or contact information.
- Request a copy of your records.
- Ask who has accessed your record and when.
- Deactivate your TrityMed account, which removes your login credentials and device data from our systems. Your organization's clinical record about you is retained under section 8.
- File a complaint with your healthcare organization, with us, or with the competent Ethiopian authority, about how your data has been handled.
Requests about your medical record should go to your healthcare organization, which controls it. Requests about your account or the App itself can be sent to tessemat@ttechnos.com.
10. Children and Dependents
Where a patient is a minor or is unable to manage their own account, an authorized caregiver or legal representative may register and act on the patient's behalf. The healthcare organization verifies the caregiver's authority before access is granted.
11. International Users and App Store Distribution
TrityMed is operated by TTECHNOS LLC and is licensed to healthcare organizations. It is distributed through international app stores so that patients and staff of those organizations can install it wherever they are.
The App is not usable without an organization code issued by a licensed healthcare organization. Your data is processed under the law applicable to the organization providing your care, together with Ethiopian law and the safeguards described in this policy. Where information is processed in a country other than your own, including where our cloud infrastructure is located, appropriate safeguards such as contractual protections are applied.
12. Changes to This Policy
We may update this policy as our practices, the law, or the national EHR standard evolve. We will notify you of material changes in-app and request renewed consent where required.
13. Contact Us
TTECHNOS LLC
9661 Franklin Woods Pl
Lorton, VA 22079-2345
United States
For questions about your medical records, contact the healthcare