Privacy Policy
Last Updated: July 1, 2026
TeleTrace is operated by Annovaire Inc (“TeleTrace,” “we,” “us,” or “our”). We respect your privacy and are committed to protecting the information entrusted to us.
This Privacy Policy explains how TeleTrace collects, uses, maintains, discloses, and protects information when individuals visit our website, access the TeleTrace platform, complete visit-verification activities, communicate with us, or otherwise use our services.
For purposes of this Privacy Policy, the TeleTrace website, administrative portal, provider-facing platform, applications, integrations, and related services are collectively referred to as the “Services.”
1. About TeleTrace
TeleTrace is a visit-verification and service-compliance platform used by community-based service agencies and their authorized providers.
Community-based providers use TeleTrace to record and verify the delivery of services, including the date, time, and location at which a service begins and ends. Visit-verification information is transmitted to the administrative portal associated with the authorized agency responsible for the service.
Authorized agency personnel may review this information for purposes such as:
Confirming that a service occurred;
Reviewing recorded service times and locations;
Identifying possible discrepancies;
Supporting documentation and billing validation;
Performing quality-assurance and compliance reviews;
Investigating service-verification concerns; and
Maintaining appropriate service and audit records.
TeleTrace does not independently distribute provider visit-verification information to unrelated employers, advertisers, data brokers, or other unauthorized third parties.
An agency using TeleTrace may also be a provider’s employer, contracting organization, or affiliated healthcare organization. In that circumstance, the agency receives access because it is the authorized TeleTrace customer responsible for the applicable service, not because TeleTrace separately distributes information to employers.
2. Scope of This Privacy Policy
This Privacy Policy applies to information collected through:
The public TeleTrace website;
The TeleTrace provider-facing platform;
The TeleTrace administrative portal;
TeleTrace mobile or web-based applications;
Customer-support communications;
Demonstration, contact, or inquiry forms;
TeleTrace integrations with authorized agency systems; and
Other services that link to this Privacy Policy.
This Privacy Policy applies to community-based providers, agency administrators, supervisors, compliance personnel, authorized customer representatives, website visitors, and other individuals who interact with TeleTrace.
This Privacy Policy does not replace:
An agency’s Notice of Privacy Practices;
An agency’s workforce privacy notice;
An agency’s employment or contractor policies;
Client or patient consent documents;
A Business Associate Agreement;
A customer services agreement; or
Other notices required by applicable law.
Third-party websites and services linked from TeleTrace are governed by their own privacy policies.
3. Our Relationship With Agencies
Agencies determine which individuals are authorized to use TeleTrace and which agency personnel may review visit-verification information.
When TeleTrace processes information on behalf of an agency, the agency generally determines:
Why the information is collected;
Which providers may use the platform;
Which services are subject to visit verification;
Which agency users may access the information;
How the agency uses the information;
How long agency records must be maintained; and
How requests concerning underlying service or client records are handled.
TeleTrace processes agency information to provide the Services, fulfill customer instructions, maintain platform security, meet contractual obligations, and comply with applicable law.
Questions about an agency’s use of visit-verification information should be directed to that agency.
4. Information We Collect
The information collected depends on how an individual interacts with TeleTrace, the features enabled by the agency, and the information the agency directs TeleTrace to process.
A. Provider Account Information
We may collect:
First and last name;
Email address;
Telephone number;
Username and authentication credentials;
Provider, employee, or contractor identification number;
Professional title or provider type;
Credentials or qualifications;
Assigned agency, office, department, or program;
Supervisor or administrative assignment;
Account status;
User role and system permissions; and
Other information required to establish or administer an account.
B. Agency Administrator Information
For agency administrators, supervisors, compliance personnel, and other authorized users, we may collect:
Name;
Business email address;
Business telephone number;
Job title;
Agency affiliation;
Department or program;
Account credentials;
Administrative permissions; and
Records of administrative actions performed within TeleTrace.
C. Client or Service-Recipient Information
Depending on the agency’s configuration, TeleTrace may process limited information concerning the individual receiving the community-based service, such as:
Name;
Client, patient, member, or agency identifier;
Date of birth;
Program assignment;
Service authorization information;
Scheduled service information;
Approved or documented service location;
Assigned provider;
Relevant agency record identifiers; and
Other information necessary to verify or review the service.
Agencies should provide TeleTrace only with information that is reasonably necessary for authorized visit-verification and compliance purposes.
D. Visit-Verification Information
When a community-based provider records a service through TeleTrace, we may collect:
Service date;
Service type;
Service code;
Scheduled service time;
Recorded start time;
Recorded end time;
Service duration;
Recorded service location;
Device location at the beginning of the service;
Device location at the end of the service;
Date and time of each verification event;
Identity of the provider completing the service;
Client or service-recipient identifier;
Provider attestations or confirmations;
Exception or discrepancy information;
Reason codes, comments, or explanations;
Supporting documentation submitted through the platform; and
Audit information associated with the visit.
E. Device and Technical Information
When an individual accesses TeleTrace, we may automatically collect:
Internet Protocol address;
Browser type;
Device type;
Operating system;
Device identifiers;
Application version;
Login date and time;
Session duration;
Pages, screens, or features accessed;
Actions performed within the platform;
Error and diagnostic information;
Network and connection information;
Security events; and
Audit-log activity.
F. Communications and Support Information
When an individual contacts TeleTrace, we may collect:
Name and contact information;
Agency affiliation;
The content of the communication;
Support-ticket information;
Screenshots or files submitted;
Technical details related to the issue; and
Our response and resolution history.
G. Website Information
When an individual visits the public TeleTrace website, we may collect:
IP address;
Browser and device information;
Pages visited;
Referring website;
Date and time of the visit;
Contact or demonstration-request information; and
Cookie or website analytics information.
5. Location Information
Location information is central to TeleTrace’s visit-verification function.
When location access is enabled, TeleTrace may collect the geographic location of a provider’s device when the provider:
Starts a community-based service; and
Ends a community-based service.
TeleTrace does not continuously monitor the provider’s location throughout the service.
TeleTrace does not ordinarily collect the provider’s location:
Before the provider initiates the service-start function;
Continuously between the service start and service end;
After the provider completes the service-end function; or
For advertising or unrelated behavioral tracking.
The location information collected may include:
Latitude and longitude;
Precise or approximate device location;
Location accuracy or confidence information;
The date and time the location was recorded;
IP-derived location information;
Device or browser information; and
The visit-verification event associated with the location.
The accuracy of location information may vary based on the provider’s device, browser, operating system, network connection, environmental conditions, and location-permission settings.
6. How We Use Location and Visit Information
TeleTrace may use location and visit-verification information to:
Confirm the location at which a service began or ended;
Confirm the recorded date and time of a service;
Compare the provider’s device location with the documented service location;
Compare TeleTrace information with authorized agency records;
Identify possible time, location, duration, or documentation discrepancies;
Create an auditable record of the visit-verification event;
Display visit information in the authorized agency portal;
Support agency compliance and quality-assurance activities;
Support documentation and billing validation;
Investigate disputed or unusual service events;
Prevent or detect misuse, fraud, or unauthorized activity;
Troubleshoot technical issues; and
Fulfill contractual or legal requirements.
TeleTrace does not sell provider or client location information.
TeleTrace does not use provider or client location information for targeted advertising.
7. Location Permissions
A provider’s device or browser may request permission before allowing TeleTrace to access location information.
Providers may control location permissions through their browser, application, or device settings. However, declining or disabling location access may prevent the provider from:
Starting a service;
Ending a service;
Completing visit verification; or
Satisfying the agency’s service-verification requirements.
Disabling location permissions does not automatically delete location information that was previously collected.
Questions about whether location verification is required for a particular service should be directed to the agency responsible for that service.
8. Other Ways We Use Information
In addition to visit verification, TeleTrace may use information to:
Create and manage user accounts;
Authenticate users;
Assign roles and permissions;
Provide and operate the Services;
Display information to authorized agency users;
Generate agency reports;
Provide customer and technical support;
Communicate about account, service, or security matters;
Troubleshoot errors;
Maintain and improve platform performance;
Monitor platform availability and reliability;
Protect against unauthorized access;
Detect and investigate fraud, abuse, or security incidents;
Enforce our agreements and policies;
Meet contractual obligations;
Maintain business and audit records;
Protect the rights and safety of TeleTrace, its customers, and users; and
Comply with applicable legal and regulatory obligations.
TeleTrace will not use agency information for a materially different purpose unless the use is permitted by applicable law and applicable agreements.
9. How Information Is Disclosed
TeleTrace may disclose information in the following circumstances.
A. To the Authorized Agency
Visit-verification information is transmitted to the TeleTrace administrative portal associated with the agency responsible for the service.
Depending on permissions established by the agency, information may be available to authorized:
Agency administrators;
Supervisors;
Program managers;
Clinical leaders;
Compliance personnel;
Quality-assurance personnel;
Billing-review personnel;
Internal auditors;
Investigators; and
Other authorized agency representatives.
TeleTrace does not determine what employment, contracting, disciplinary, billing, clinical, or administrative decisions an agency may make based on the information available through its portal.
B. To Service Providers
We may disclose information to service providers that assist us with functions such as:
Cloud hosting;
Data storage;
Database management;
Cybersecurity;
Authentication;
Email and communications;
Customer support;
Software maintenance;
Error monitoring;
Data backup;
Analytics; and
Professional consulting.
Service providers are permitted to access information only as necessary to perform authorized services and are expected to protect the information in accordance with applicable contractual and legal requirements.
Where required, service providers that handle protected health information must enter into appropriate agreements.
C. For Legal or Regulatory Purposes
We may disclose information when we reasonably believe disclosure is necessary to:
Comply with applicable law;
Respond to a court order, subpoena, warrant, or lawful government request;
Cooperate with a regulatory review, audit, or investigation;
Enforce our contracts, terms, or policies;
Detect, prevent, or investigate fraud or illegal activity;
Respond to a security incident;
Protect the rights, property, safety, or security of TeleTrace, our customers, users, or others; or
Establish, exercise, or defend legal claims.
D. Business Transactions
Information may be disclosed as part of a proposed or completed merger, acquisition, financing, restructuring, sale of assets, bankruptcy, or similar business transaction.
Any successor organization will be expected to handle personal information in accordance with applicable law and the commitments applicable to that information.
E. At the Direction of the Agency or Individual
We may disclose information when directed or authorized by the agency controlling the information or by the individual to whom the information relates, where legally permitted.
F. Aggregated or De-Identified Information
We may use or disclose aggregated or de-identified information that does not reasonably identify an individual, subject to applicable law and contractual restrictions.
10. Information We Do Not Sell or Use for Advertising
TeleTrace does not:
Sell personal information for monetary compensation;
Sell precise location information;
Sell protected health information;
Use authenticated platform information for targeted advertising;
Use visit-verification information to create advertising profiles; or
Disclose provider or client information to data brokers for advertising purposes.
If these practices materially change, we will revise this Privacy Policy and provide any notice or choice required by applicable law.
11. HIPAA and Protected Health Information
TeleTrace provides technology services to healthcare and community-based service organizations.
Information processed through TeleTrace may constitute protected health information under the Health Insurance Portability and Accountability Act and its implementing regulations, commonly known as HIPAA.
When TeleTrace acts as a business associate of a covered entity or another business associate, TeleTrace’s use and disclosure of protected health information is also governed by the applicable Business Associate Agreement.
When applicable, TeleTrace will use and disclose protected health information only as:
Permitted or required by the Business Associate Agreement;
Necessary to provide the contracted Services;
Directed by the applicable agency;
Required by law; or
Otherwise permitted under HIPAA.
The agency remains responsible for providing any legally required Notice of Privacy Practices to its clients or patients.
Individuals seeking access to, correction of, or other action concerning protected health information maintained for an agency should generally contact that agency directly. TeleTrace will assist the agency as required by the applicable agreement and law.
This Privacy Policy is not intended to replace an agency’s HIPAA Notice of Privacy Practices.
12. Cookies and Similar Technologies
TeleTrace may use cookies, local storage, session technologies, and similar tools to:
Authenticate users;
Keep users securely signed in;
Maintain platform functionality;
Remember preferences;
Protect accounts;
Prevent unauthorized activity;
Understand public website performance; and
Diagnose technical problems.
Some cookies are essential for the Services to function.
Users may be able to control cookies through browser settings. Blocking essential cookies may prevent parts of TeleTrace from functioning correctly.
TeleTrace should not place advertising trackers on authenticated pages containing visit-verification, provider, client, or protected health information.
13. Data Retention
TeleTrace retains information only for as long as reasonably necessary to:
Provide the Services;
Fulfill the purposes described in this Privacy Policy;
Follow agency instructions;
Comply with customer agreements;
Meet healthcare, service-documentation, billing, audit, or regulatory requirements;
Maintain security and business records;
Resolve disputes;
Enforce agreements; and
Comply with applicable law.
Retention periods may vary depending on:
The type of information;
The agency’s instructions;
The status of the customer relationship;
Contractual obligations;
Applicable healthcare and service-record requirements;
Pending audits, investigations, disputes, or legal matters; and
Security and backup requirements.
When information is no longer required, TeleTrace may delete, destroy, return, or de-identify it in accordance with applicable agreements, policies, and laws.
Information may remain in secured system backups until deleted through established backup-rotation procedures.
14. Data Security
TeleTrace uses administrative, technical, and physical safeguards designed to protect information against unauthorized access, use, alteration, loss, or disclosure.
Depending on the system and information involved, safeguards may include:
Encryption during transmission;
Encryption of stored information;
Role-based access controls;
Unique user accounts;
Authentication controls;
Audit logging;
Access monitoring;
Security testing;
Secure software-development practices;
Backup and recovery procedures;
Incident-response procedures;
Vendor reviews; and
Workforce privacy and security requirements.
No electronic system, network, transmission, or storage environment can be guaranteed to be completely secure.
Users are responsible for maintaining the confidentiality of their credentials, protecting devices used to access TeleTrace, and promptly reporting suspected unauthorized access.
15. User Responsibilities
Individuals who use TeleTrace must:
Use only their assigned account;
Keep login credentials confidential;
Avoid allowing another individual to use their account;
Access information only for authorized purposes;
Submit accurate service information;
Protect the devices used to access TeleTrace;
Comply with applicable agency policies;
Avoid attempting to bypass visit-verification or security controls; and
Promptly report suspected unauthorized activity.
TeleTrace may record user actions and administrative activity to maintain security, accountability, and an appropriate audit trail.
16. Individual Privacy Rights
Depending on the individual’s state of residence and applicable law, the individual may have the right to request:
Confirmation that personal information is being processed;
Access to certain personal information;
Correction of inaccurate personal information;
Deletion of certain personal information;
A copy of certain personal information;
Information about categories of information collected or disclosed;
Restriction of certain uses;
Withdrawal of consent where processing depends on consent;
An appeal of a denied privacy request; or
Other rights provided by applicable law.
These rights are not absolute. A request may be limited or denied when information must be retained for:
Healthcare or service documentation;
Billing or payment review;
Audit or compliance obligations;
Security purposes;
Contractual obligations;
Legal claims;
Agency recordkeeping; or
Other purposes permitted or required by law.
Agency-Controlled Information
When TeleTrace processes information for an agency, the agency generally controls the underlying service record.
TeleTrace may direct an individual’s request to the applicable agency or coordinate with that agency before responding.
Providers and service recipients should contact the applicable agency concerning:
The accuracy of an underlying service record;
Agency decisions based on visit information;
Employment or contracting matters;
Client or patient records;
Billing records;
Documentation requirements; and
Agency retention practices.
Submitting a Privacy Request
Privacy requests may be submitted to:
Email: athompson@annovaire.com
The requester should provide enough information for TeleTrace to identify the relevant account, agency, and information.
TeleTrace may verify the requester’s identity and authority before processing a request.
TeleTrace will not unlawfully discriminate against an individual for exercising an applicable privacy right.
17. Children’s Privacy
TeleTrace is a business and healthcare-operations platform. It is not intended for children under 13 to create or operate independent provider or administrative accounts.
An agency may process information concerning a minor who receives community-based services. In that circumstance, TeleTrace processes the information on behalf of the authorized agency and does not collect it directly from the minor for consumer advertising or marketing purposes.
A parent, guardian, or authorized representative with questions about a minor’s service information should contact the agency responsible for the minor’s services.
18. Third-Party Services and Integrations
TeleTrace may integrate with or link to third-party systems, including:
Electronic health records;
Scheduling systems;
Billing systems;
Agency information systems;
Authentication services;
Mapping or location services; and
Communication platforms.
Third-party services are governed by their own privacy policies, contracts, and security practices.
TeleTrace is not responsible for the privacy practices of third-party services that are not controlled by TeleTrace.
19. Data Processing in the United States
TeleTrace is operated in the United States. Information may be stored and processed in the United States.
The Services are intended primarily for organizations and users located in the United States unless TeleTrace expressly agrees otherwise.
20. Changes to This Privacy Policy
We may update this Privacy Policy to reflect:
Changes to the Services;
New features;
Changes in our information practices;
Changes in legal or regulatory requirements;
Changes in our customer relationships; or
Security and operational improvements.
When we update the Privacy Policy, we will revise the Last Updated date.
When required by law, contract, or the nature of the change, we may provide additional notice through the website, platform, email, or agency communication.
Continued use of TeleTrace after an updated Privacy Policy becomes effective constitutes acknowledgment of the revised policy to the extent permitted by law.
21. Contact Us
Questions, concerns, complaints, or privacy requests concerning TeleTrace may be directed to:
TeleTrace Privacy Team
TeleTrace
Bowie, Maryland
[City, State ZIP Code]
Email: athompson@annovaire.com
Questions about a particular community-based service, visit record, provider requirement, or agency decision should be directed to the agency responsible for that service.