Back to site →

Legal

Privacy Policy

Effective Date: August 31, 2026 Last Updated: August 31, 2026

On this page

01Scope and Our Role 02Information We Collect 03How We Use Information 04AI and Automated Processing 05How We Disclose Information 06Protected Health Information 07Cookies and Similar Technologies 08Data Retention 09Security 10Your Choices and Privacy Rights 11Consumer Health Data Outside HIPAA 12Children’s Privacy 13International Data Transfers 14Third-Party Services and Links 15Changes to This Privacy Policy 16Contact Us

Telos is a decision-intelligence service for outpatient practices operated by Telos AI Health LLC (“Telos,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, disclose, retain, and protect Personal Information in connection with telosoms.com, app.telosoms.com, our software, integrations, application programming interfaces, support, sales, marketing, and related services (collectively, the “Services”).

Privacy at a Glance

  • Telos is a business service, not a patient portal. Our Services are intended for outpatient practices and their authorized workforce members.
  • Telos does not currently accept or process Protected Health Information. Customers must not submit PHI or patient-identifying information to the Services.
  • Our customers control their practice data. When we process data for a customer, the customer generally determines why the data is used, and Telos acts as a processor or service provider, as applicable.
  • We do not sell Customer Data or use it for targeted advertising.
  • We do not use Customer Data to train publicly available or cross-customer general-purpose AI models.
  • Telos supports human decisions. Recommendations, forecasts, scores, and suggested actions are intended to assist authorized users, not replace their judgment.

Public website forms are not intended for patient information or Protected Health Information. Please do not submit patient information through a sales, demo, newsletter, or general-contact form.

01Scope and Our Role

This Privacy Policy applies when Telos determines the purposes and means of processing Personal Information, including information about website visitors, prospective customers, customer administrators and users, vendors, and other business contacts.

Customer Data

A practice or other organization may submit, connect, or otherwise make non-PHI information available to Telos for processing through the Services (“Customer Data”). Customer Data may include Personal Information about the customer’s employees, contractors, owners, referral sources, and other business contacts.

For Customer Data, the customer generally acts as the controller or business, and Telos acts as its processor or service provider. We process Customer Data according to the customer’s instructions, our agreement with the customer, any applicable data processing addendum, and applicable law.

If you are a patient, employee, or other individual whose information was provided to Telos by one of our customers, please direct privacy requests to that customer. We will assist the customer as required by contract and law, but we may not be able to respond directly unless the customer authorizes us to do so.

Protected Health Information

“Protected Health Information” or “PHI” has the meaning given under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”). Telos does not currently offer PHI-enabled Services and has not entered into Business Associate Agreements with customers. Customers must not submit, connect, upload, transmit, or otherwise make PHI available to Telos. This Privacy Policy is not a health-care provider’s Notice of Privacy Practices and does not replace any notice provided by your health-care provider.

Personal Information

“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household. It does not include information that has been lawfully deidentified or aggregated so that it cannot reasonably be linked to an individual.

02Information We Collect

The information we collect depends on how you interact with Telos, the features a customer uses, the systems a customer connects, and the choices made by the customer and its authorized users.

A. Information You Provide Directly

We may collect:

  • Contact and professional information, such as name, work email address, telephone number, job title, professional role, practice or organization name, business address, and professional discipline.
  • Account and authentication information, such as username, account identifier, authentication records, role, permissions, and account settings.
  • Sales and onboarding information, such as practice type, practice size, locations, number of providers or visits, business goals, operational challenges, requested features, and implementation requirements.
  • Communications and support information, such as messages, support requests, feedback, survey responses, and information provided during calls, meetings, or demonstrations. Where calls or meetings are recorded, we provide notice or obtain consent as required by law.
  • User content, such as prompts, questions, instructions, notes, assumptions, uploaded files, corrections, approvals, and other content submitted through the Services.
  • Billing information, such as billing contacts, subscription details, invoices, payment status, and transaction records. When an online payment provider processes a payment, it may collect payment-card or bank information directly under its own privacy policy, while Telos receives limited billing and transaction information.
  • Marketing preferences, such as whether you wish to receive product news, educational content, event invitations, or other communications.

B. Information From Customers and Connected Systems

At a customer’s direction, the Services may collect or receive non-PHI data from accounting, banking, scheduling, practice-management, billing, payroll, workforce, customer-relationship, communications, or other systems. Depending on the implementation, this may include:

  • Financial and revenue-cycle data, such as cash and account balances, revenue, expenses, budgets, accounts receivable totals, collections, payments, aggregate claims information, payer mix, reimbursement information, payroll estimates, compensation-related information, and financial projections.
  • Practice operations data, such as locations, provider availability, aggregate schedules, open capacity, deidentified waitlist counts, cancellation and no-show rates, attendance trends, patient-flow totals, billable hours, referral totals, intake activity, and operational workflows.
  • Workforce data, such as employee or contractor names or identifiers, roles, schedules, utilization, productivity, performance metrics, compensation-related data, staffing levels, and hiring assumptions.
  • Business goals and decision inputs, such as targets, budgets, staffing plans, growth assumptions, historical trends, preferred thresholds, and scenarios an authorized user asks Telos to evaluate.
  • Integration and synchronization information, such as source-system identifiers, authorization tokens, connection status, data freshness, import history, field mappings, reconciliation results, errors, and audit records.

Customers are responsible for ensuring that they have the rights and permissions needed to provide Customer Data to Telos, configuring the Services consistently with applicable law and their own notices, policies, and agreements, and excluding PHI and patient-identifying information from all connected data and uploads.

C. Information Collected Automatically

When you use the Services, we and our service providers may automatically collect:

  • Internet Protocol address;
  • browser type, device type, operating system, language, and device identifiers;
  • pages or features viewed, links clicked, referring pages, and dates and times of activity;
  • session, authentication, error, diagnostic, security, and audit logs;
  • cookie identifiers and similar technology data; and
  • general location derived from an Internet Protocol address, such as city, state, or country.

D. Information From Other Sources

We may receive information from customer administrators and authorized users, connected-system and integration providers, identity and authentication providers, payment processors, referral partners, consultants, vendors, publicly available business sources, and other parties that you or a customer directs us to use.

03How We Use Information

We may use Personal Information to:

  • provide, operate, maintain, configure, and improve the Services;
  • connect, import, reconcile, standardize, analyze, and present customer-authorized data;
  • generate business-health indicators, forecasts, scenarios, recommendations, explanations, suggested priorities, and other decision-support outputs;
  • show the sources, periods, assumptions, calculations, missing inputs, stale inputs, or conflicting inputs behind an output;
  • authenticate users, manage permissions, secure accounts, and maintain audit trails;
  • personalize the Services for a customer’s practice, goals, data, workflows, and authorized users;
  • provide onboarding, training, customer success, support, and troubleshooting;
  • process subscriptions, invoices, payments, and other commercial transactions;
  • communicate about the Services, including administrative, security, support, and product messages;
  • send marketing communications where permitted by law and consistent with your choices;
  • monitor performance, detect and prevent fraud or misuse, investigate incidents, debug errors, and protect the rights, safety, and security of Telos, our customers, users, and others;
  • conduct internal analytics, quality assurance, research, testing, and product development;
  • comply with law, enforce agreements, establish or defend legal claims, and respond to lawful requests; and
  • create deidentified or aggregated information as permitted by law and contract.

AI Model Use and Product Improvement

Telos does not use Customer Data to train publicly available or cross-customer general-purpose AI models. We may use Customer Data to provide, configure, test, secure, or improve the Services for the customer that supplied the data, as permitted by our agreement with that customer. We may also use deidentified or aggregated information to improve the Services, evaluate performance, develop benchmarks, and conduct analytics, provided that we maintain that information in deidentified or aggregated form and do not attempt to reidentify it except as permitted by law to test or validate the deidentification process.

When an AI, cloud, or infrastructure provider processes Customer Data for Telos, we require it to process the data only to provide contracted services to Telos, subject to appropriate confidentiality, security, and use restrictions.

04AI and Automated Processing

Telos uses automated systems, which may include artificial intelligence and statistical methods, to analyze customer-authorized information and produce forecasts, business-health indicators, recommendations, explanations, rankings, alerts, or suggested actions.

These outputs are intended to support authorized users’ business and operational judgment. Telos does not independently make final decisions about patient diagnosis or treatment, employment, credit, insurance, housing, or other legally significant matters. Customers and their authorized users control whether and how they use Telos outputs and are responsible for reviewing the underlying data, assumptions, limitations, and context before acting.

Where applicable law provides rights concerning profiling or automated decision-making, you may exercise those rights as described in Section 10. For Customer Data, requests should ordinarily be directed to the relevant customer.

05How We Disclose Information

We may disclose Personal Information in the following circumstances:

A. Customers and Authorized Users

We disclose information within the customer account to the customer and users the customer authorizes, according to configured permissions. Customer administrators may be able to access, manage, export, correct, or delete information associated with their account and users.

B. Service Providers and Subprocessors

We may disclose information to vendors that provide cloud hosting, data storage, database, security, identity, authentication, communications, analytics, customer support, billing, payment, integration, AI or model infrastructure, implementation, professional, or other services. These providers are permitted to use Personal Information only for the services they provide to Telos or as otherwise allowed by law and contract.

C. Connected Services and Customer-Directed Recipients

At a customer’s or authorized user’s direction, we may exchange information with connected systems, integration partners, consultants, advisers, or other recipients selected by the customer. Those third parties’ own privacy terms may apply to their independent processing.

D. Professional Advisers

We may disclose information to lawyers, auditors, insurers, accountants, financial advisers, and other professional advisers where reasonably necessary to obtain advice, protect our interests, or comply with obligations.

E. Legal, Safety, and Compliance Reasons

We may disclose information when we reasonably believe disclosure is necessary to comply with law or legal process; respond to lawful requests; enforce agreements; investigate fraud, abuse, or security incidents; protect rights, property, safety, or security; or establish, exercise, or defend legal claims.

F. Business Transactions

We may disclose or transfer information in connection with an actual or proposed merger, financing, acquisition, reorganization, bankruptcy, receivership, sale of assets, or similar transaction, subject to appropriate confidentiality protections and applicable law.

G. With Consent or at Direction

We may disclose information with your consent or at the direction of you or the relevant customer.

H. Deidentified or Aggregated Information

We may disclose information that has been deidentified or aggregated so it cannot reasonably be linked to an individual, subject to applicable law and customer agreements.

No Sale or Targeted-Advertising Sharing

Telos does not sell Personal Information or Customer Data for monetary or other valuable consideration. Telos does not share Personal Information for cross-context behavioral advertising and does not use Customer Data for targeted advertising. Telos has not sold or shared Personal Information for those purposes during the preceding 12 months.

06Protected Health Information

Telos does not currently accept or process PHI and is not offering the Services under a Business Associate Agreement. Customers must not submit PHI or patient-identifying information through an account, integration, upload, prompt, support request, email, public website form, or any other channel.

If Telos offers PHI-enabled Services in the future, it will first complete the required contractual, technical, and operational safeguards, execute an applicable Business Associate Agreement with the customer, and update this Privacy Policy as appropriate. Signing up for or using the current Services does not create a Business Associate Agreement or authorize the submission of PHI.

If you believe PHI was submitted to Telos inadvertently, stop further submission and contact privacy@telosoms.com promptly. Patients should contact their health-care provider or practice regarding medical records or privacy rights.

07Cookies and Similar Technologies

We and our service providers may use cookies, pixels, local storage, software development kits, and similar technologies to:

  • keep users signed in and provide essential functionality;
  • remember preferences and settings;
  • protect accounts and detect malicious activity;
  • understand use of the Services and improve performance; and
  • measure the effectiveness of our communications and website.

You may be able to manage nonessential cookies through a cookie-settings tool made available on our website or through your browser settings. Blocking cookies may affect certain features. Where required by law, we obtain consent before using nonessential cookies.

Some browsers or extensions transmit Global Privacy Control or other opt-out preference signals. We process legally recognized signals where required and applicable. Because there is not a uniform industry standard for other “Do Not Track” signals, the Services may not respond to them.

08Data Retention

We retain Personal Information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, comply with customer instructions and contractual commitments, maintain security and continuity, resolve disputes, enforce agreements, satisfy tax, accounting, audit, insurance, and legal obligations, and establish or defend claims.

Retention depends on the type of information and context:

  • Website, sales, and marketing information is retained while we have an active relationship or legitimate business need and for a reasonable period afterward, subject to opt-out rights and legal requirements.
  • Account, administrative, billing, and transaction information is retained during the customer relationship and afterward as needed for account administration, audit, tax, contract, fraud-prevention, and legal purposes.
  • Customer Data is retained according to the customer agreement, customer instructions, product configuration, and applicable law. Following termination, we return or delete Customer Data as required by the applicable agreement and law, except where retention is legally required or deletion is not technically feasible. Residual copies may remain in protected backups until overwritten through the ordinary backup cycle.
  • Security, diagnostic, and audit records are retained for periods appropriate to detecting, investigating, and documenting security, reliability, and compliance events.

We may retain deidentified or aggregated information for longer periods where permitted by law and contract, provided it remains deidentified or aggregated.

09Security

We maintain administrative, technical, and physical safeguards designed to protect Personal Information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access. Safeguards are selected based on the nature and sensitivity of the information, the risks presented by processing, and the Services involved, and may include access controls, authentication, encryption, logging, monitoring, vendor-management, backup, vulnerability-management, workforce-training, and incident-response measures.

No method of transmission or storage is completely secure. You and each customer are responsible for maintaining appropriate account permissions, protecting credentials, promptly removing access for former personnel, and notifying us of suspected unauthorized activity.

10Your Choices and Privacy Rights

Communications

You may unsubscribe from marketing emails by using the unsubscribe link in the message or contacting us. Even after opting out of marketing, you may continue to receive transactional, security, support, or other nonpromotional communications.

Account Information

Authorized users may be able to review or update certain account information through the Services. Customer administrators control many account and permission settings.

U.S. State Privacy Rights

Depending on where you live and the context in which we process your Personal Information, you may have the right to:

  • confirm whether we process your Personal Information and access it;
  • obtain a portable copy of certain Personal Information;
  • correct inaccurate Personal Information;
  • request deletion of Personal Information;
  • opt out of a sale, targeted advertising, or certain profiling or automated processing;
  • limit certain uses or disclosures of Sensitive Personal Information;
  • withdraw consent where processing is based on consent; and
  • appeal a decision concerning a privacy request.

These rights are subject to legal exceptions and may not apply in every circumstance. We do not discriminate against individuals for exercising applicable privacy rights.

To submit a request or appeal, email privacy@telosoms.com with the subject line “Privacy Request” or use any privacy-request form we make available. Describe your request and the state or country where you reside. We may need to verify your identity and authority before completing the request. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and direct identity verification.

For Customer Data, please submit the request to the practice or organization that controls the data. If you submit the request to Telos, we may refer it to that customer and support its response.

California Privacy Disclosures

The following table summarizes categories of Personal Information Telos may have collected during the preceding 12 months. Whether a category is collected in a particular case depends on the individual’s interaction with Telos and the customer’s configuration.

CategoryExamplesTypical SourcesBusiness or Commercial PurposesCategories of Recipients
IdentifiersName, email, phone, IP address, account ID, practice name, online identifiersYou; customers; integrations; automatically from useProvide and secure Services; account administration; support; communications; analytics; complianceCustomers and authorized users; service providers; connected services; advisers; legal recipients
Customer-record and contact informationBusiness address, billing contact, professional information, transaction-related informationYou; customers; payment or integration providersOnboarding; billing; customer success; support; administration; complianceService providers; advisers; legal recipients; customer-directed recipients
Commercial informationSubscription, invoices, service history, feature use, customer relationship dataYou; customers; our systems; payment providersProvide and improve Services; billing; analytics; customer successService providers; advisers; customer-directed recipients
Internet or electronic-network activityBrowser, device, pages viewed, clicks, session and log dataAutomatically from use; security and analytics providersEssential functionality; security; debugging; performance; analyticsHosting, security, analytics, and support providers
Approximate geolocationGeneral location inferred from IP addressAutomatically from useSecurity; localization; analyticsHosting, security, and analytics providers
Professional or employment-related informationRole, employer, discipline, permissions, schedules, utilization, productivity, compensation-related or workforce informationYou; customers; workforce, payroll, or practice systemsProvide customer-requested analytics and decision support; account administrationCustomer and authorized users; service providers; connected services
Sensitive Personal InformationAccount credentials; financial information; contents of certain communications; precise data a customer elects to provideYou; customers; integrationsProvide, secure, and support the Services; comply with law; customer-directed processingCustomer and authorized users; service providers and subprocessors; connected services; legal recipients
Audio, electronic, or visual informationCall or meeting recordings, support screenshots, uploaded materialsYou; customers; communications or support providersSales, onboarding, training, support, quality assurance, with notice or consent where requiredCommunications, support, hosting, and professional-service providers
InferencesForecasts, business-health indicators, rankings, recommendations, alerts, or suggested priorities derived from customer-authorized dataGenerated by Telos from information described aboveProvide decision intelligence, explanations, scenarios, and product functionalityCustomer and authorized users; service providers supporting the functionality

Telos does not sell or share these categories for cross-context behavioral advertising. We do not use or disclose Sensitive Personal Information for purposes that would require a right to limit under California law, except as necessary to provide the Services, prevent and investigate security incidents, resist malicious or illegal activity, ensure safety, verify and maintain service quality, or as otherwise permitted by law. We do not offer financial incentives in exchange for Personal Information.

EEA, United Kingdom, and Switzerland

If European Economic Area, United Kingdom, or Swiss data-protection law applies to our processing in a controller role, our legal bases may include performance of a contract, steps requested before entering a contract, our legitimate interests in operating and securing the Services and conducting business, consent, and compliance with legal obligations. Where we process Customer Data as a processor, the customer is responsible for identifying the lawful basis for that processing.

Subject to applicable law, you may have rights to access, correct, erase, restrict, or port Personal Data; object to certain processing; withdraw consent; and lodge a complaint with a supervisory authority. You may exercise rights by contacting us as described above.

11Consumer Health Data Outside HIPAA

Certain U.S. state laws regulate “consumer health data” that is not PHI or otherwise exempt from those laws. Telos is designed as a business service for outpatient practices, not as a direct-to-consumer health application, and the current Services are not intended to receive individual-level consumer health data.

Customers must not submit information that identifies an individual and reveals or can reasonably be used to infer that individual’s past, present, or future physical or mental health status or health-care services. If such information is submitted inadvertently, Telos may return, isolate, or delete it as reasonably necessary to protect individuals and comply with law. Telos does not sell consumer health data.

Where applicable, individuals may request access, deletion, or information about disclosures by contacting us as described in Section 10. For data controlled by a customer, requests should be directed to that customer.

12Children’s Privacy

The Services are intended for organizations and authorized adult workforce members and are not directed to children. We do not knowingly collect Personal Information directly from children through the public website for our own purposes.

Customers must not submit information about identified or identifiable pediatric patients to the current Services. A parent, guardian, or patient seeking to exercise rights concerning information held by a practice should contact that practice directly.

13International Data Transfers

Telos and its service providers may process information in the United States and other countries where we or they operate. Those countries may have data-protection laws that differ from the laws where you live. Where required, we use lawful transfer mechanisms and safeguards, which may include adequacy decisions, approved contractual clauses, or other legally recognized mechanisms.

14Third-Party Services and Links

The Services may connect to or contain links to third-party systems, applications, websites, or services. A customer’s decision to connect a third-party service may permit data to flow between Telos and that service. Third parties may process information under their own privacy policies and terms when acting independently. This Privacy Policy does not govern third parties’ independent practices.

15Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version and revise the “Last Updated” date. If a change materially affects how we use Personal Information, we will provide additional notice where required, such as through the Services or by email. We will obtain consent where required by law before applying a materially different use to information already collected.

16Contact Us

Questions, privacy requests, or security concerns may be sent to:

Telos Privacy

Telos AI Health LLC

410 10th Avenue West, Palmetto, Florida 34221

Email: privacy@telosoms.com

Decision intelligence for outpatient leaders.

Product

Platform How it works Trust Scenario planning

Practices

Pediatric therapy Physical therapy Chiropractic Audiology

Company

Contact sales Sign in

Legal

Privacy Terms
© 2026 Telos.