Privacy Policy

Last updated: September 11, 2026

1. Notice and Policy Updates

This Privacy Policy establishes the standards for how we handle data within our systems. Notice is available to users at or before the point of data collection through the following methods:

For new Clients, the current Privacy Policy is provided during onboarding.

· For others, the current Privacy Policy can be viewed on our web portals that are technically capable.

· We reserve the right to change this Privacy Policy as laws, regulations, industry standards, and our business practices evolve.

· For changes that affect your rights or the nature of our data processing, we will provide notification via web portal, the email address on file, or other means.

2. Collection of Personal Information

We limit the collection of information to the data categories necessary to deliver services. These categories include:

· Professional and billing identifiers such as provider names, National Provider Identifiers (NPI), Tax IDs, and service location addresses.

· Patient demographics including names, gender, and dates of birth.

· Claim metadata and clinical coding including claim numbers, dates of service, and standardized medical codes such as procedure, diagnosis, and revenue codes.

· Financial processing attributes including billed charges, fee schedules, allowed amounts, and calculated savings.

· Inquiries from website visitors, Clients, and prospective Clients.

3. Intended Uses

Personal information is processed only for the purposes described in this Privacy Policy and in accordance with applicable contractual, legal, regulatory, and privacy requirements.

· Data including PII and PHI is used primarily to calculate allowed amounts and savings and to return repricing results to the requesting party.

· For Client organizations that submit information through system-to-system integrations, data is processed pursuant to the applicable Client agreement, Business Associate Agreement (BAA), and other contractual requirements.

· Data that has been de-identified or anonymized in accordance with applicable requirements may be retained long-term for system trend analysis and benchmarking.

4. Data Retention, Disposal, and Residency

· Files and associated PII and PHI received from Clients as part of claims processing is typically retained only for as long as necessary to fulfill relevant business obligations. This may be extended as part of complying with laws, regulations, and legal requirements.

· Certain documentation and records required under the HIPAA Security Rule, Privacy Rule, and Breach Notification Rule are retained for six years or longer, as applicable.

· Other data is retained in accordance with the Company's data classification plan and applicable business, legal, and contractual requirements.

· When data is no longer required, the Company uses data cleanout, anonymization, or other appropriate secure deletion and sanitization methods.

· Data processing and storage take place in the United States.

5. Disclosure to Third Parties

Personal information is disclosed or made accessible only to the following categories of third parties, as necessary to provide services and subject to appropriate contractual confidentiality, privacy, and security requirements:

· Cloud infrastructure providers utilized for secure hosting and data storage.

· Managed service providers and technical consultants responsible for system administration, security, compliance, and maintenance.

· Software development firms engaged for system optimization and support.

6. Rights of Access and Correction

As a Business Associate and service provider, we process data on behalf of our Clients. Data requests received directly from data subjects will be referred to the relevant Client for fulfillment and response, as appropriate. · Authorized users may contact privacy@trpndirectpay.com to determine whether we maintain personal information about them, obtain access to that information, or request that we update or correct it.

· We strive to ensure the accuracy and completeness of all information used for repricing purposes.

7. Challenging a Denial

If a request for data access or correction is denied due to legal restrictions, regulatory requirements, or other reasons, we will provide a written explanation for the denial. Individuals may challenge a denial by emailing us at privacy@trpndirectpay.com.

8. Breach Notification and Reporting

For any breach involving unsecured PHI, the Company will notify affected Clients without unreasonable delay and in no case later than 60 calendar days after discovering the breach. For other types of breaches, notifications will occur as soon as possible after the investigation concludes. If you identify a potential security vulnerability or suspect an unauthorized disclosure has occurred, please report it immediately to security@trpndirectpay.com.

9. Security Statement

We implement administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of your data. However, no system can be guaranteed to be 100% secure.

· Users are responsible for maintaining the security of their own account credentials and for ensuring that data is uploaded via secure, authorized channels.

· We are not responsible for unauthorized access resulting from a compromise of user-managed credentials or unsecured local environments.

10. Choices

If you disagree with this Privacy Policy, you may choose not to proceed with using the platform. If you would like to limit the collection, use, and disclosure of your information, please email us at privacy@trpndirectpay.com. If you choose to do so, this may limit our ability to provide services going forward.

11. Contact

If you have questions about this Privacy Policy or our data handling practices, please contact us at privacy@trpndirectpay.com.

12. User Acknowledgement

By logging into, accessing, or using the platform, you acknowledge that you have read and understood this Privacy Policy and the Company's data processing practices described herein.