EDGESTONE TECH PRIVACY POLICY

Website Visitors • Enterprise Clients • Healthcare & Pharmaceutical Solutions

Effective Date: July 16, 2026 | Last Reviewed: July 16, 2026

Edgestone Tech, Inc. | Headquarters: Louisville, Kentucky, USA | Global Delivery Center: Hyderabad, India

https://www.edgestonetech.com


Introduction and Purpose

Edgestone Tech, Inc. (“Edgestone Tech,” “the Company,” “we,” “us,” or “our”) is a global information technology solutions provider headquartered in Louisville, Kentucky, USA, with a global delivery center in Hyderabad, India. We design, build, deploy, and maintain custom software, enterprise cloud infrastructure, and artificial intelligence and data analytics platforms for clients operating in highly regulated sectors, with a primary concentration in healthcare and pharmaceuticals.

This Privacy Policy (“Policy”) is intended to give both casual website visitors and enterprise healthcare procurement and compliance teams a clear, complete, and legally precise understanding of how Edgestone Tech collects, uses, discloses, and safeguards information. Because Edgestone Tech serves two fundamentally different populations — individuals browsing our public website and enterprise clients whose regulated data flows through the systems we build and operate — this Policy is deliberately organized into two distinct governance tracks, described in Section 1 below.

Nothing in this Policy is intended to, and nothing in this Policy shall, limit, modify, or override the terms of any executed contract, Master Services Agreement (MSA), Data Processing Agreement (DPA), or Business Associate Agreement (BAA) between Edgestone Tech and an enterprise client. Where any conflict exists between this Policy and an executed BAA or DPA, the terms of that executed agreement control.

1. Scope of This Policy: Website Visitors vs. Enterprise Clients

Edgestone Tech interacts with information in two operationally and legally distinct capacities. Compliance officers and procurement teams evaluating Edgestone Tech should note this distinction carefully, as different legal frameworks, safeguards, and obligations attach to each.

1.1 Website Visitors

This category covers any individual who visits www.edgestonetech.com, browses our public marketing pages, downloads whitepapers or case studies, or submits information through our “Get in Touch,” sales inquiry, careers, or newsletter subscription forms. In this capacity, Edgestone Tech acts as a data controller (or “business” under applicable state law) with respect to the ordinary business contact information voluntarily submitted, and processes that information under standard commercial privacy principles described in Sections 2, 6, and 7 of this Policy.

1.2 Enterprise Clients (Healthcare & Pharmaceutical Organizations)

This category covers healthcare systems, hospitals, payors, pharmaceutical and life sciences companies, digital health vendors, and other regulated organizations that engage Edgestone Tech to design, build, host, migrate, or maintain custom software, enterprise cloud infrastructure, or AI/data analytics platforms that create, receive, maintain, or transmit Protected Health Information (“PHI”) or other regulated data on the client's behalf. In this capacity, Edgestone Tech does not act as a general data controller. Instead, Edgestone Tech acts strictly as a Business Associate (or subprocessor/data processor, as applicable) operating under the express written instructions of the client, governed by a signed Business Associate Agreement and/or Data Processing Agreement, as detailed fully in Section 2 below.

Governing Document Hierarchy
  1. Executed Business Associate Agreement (BAA) or Data Processing Agreement (DPA) with the enterprise client — controls all handling of PHI and regulated data.
  2. Master Services Agreement (MSA) and applicable Statement of Work (SOW) — controls commercial and technical delivery terms.
  3. This Privacy Policy — applies to website interactions and serves as general disclosure of Edgestone Tech's compliance posture; it does not supersede items 1 or 2.

2. HIPAA and Business Associate Status

2.1 Business Associate, Not Covered Entity

When Edgestone Tech provides healthcare software development, cloud hosting, data migration, AI/analytics, or related technical services that involve access to PHI, Edgestone Tech operates strictly as a “Business Associate” as that term is defined under the Health Insurance Portability and Accountability Act of 1996, as amended, and its implementing regulations, including the Privacy Rule, Security Rule, and Breach Notification Rule (collectively, “HIPAA”). Edgestone Tech is not a healthcare provider, health plan, or healthcare clearinghouse, and does not independently qualify as a “Covered Entity” under HIPAA.

2.2 Client Ownership and Control of PHI

All PHI processed, stored, transmitted, or otherwise handled within systems that Edgestone Tech builds, deploys, hosts, or maintains for a client is, and at all times remains, the sole property of the applicable client (the “Covered Entity” or, where applicable, the upstream Business Associate). Edgestone Tech claims no ownership interest in client PHI, does not use client PHI for any purpose outside the scope of the engagement, and accesses PHI solely to the extent necessary to perform the contracted development, hosting, maintenance, support, or analytics services.

2.3 Precedence of the Business Associate Agreement

Prior to any engagement involving PHI, Edgestone Tech executes a Business Associate Agreement with the client that satisfies the requirements of 45 C.F.R. § 164.502(e) and § 164.504(e). The executed BAA — not this general website Privacy Policy — is the controlling legal instrument governing permitted uses and disclosures of PHI, minimum necessary standards, breach notification timelines and procedures, subcontractor flow-down obligations, audit rights, and termination/data-return or destruction obligations. In the event of any inconsistency between this Policy and an executed BAA, the BAA governs without exception.

2.4 Scope of BA Obligations
  • Edgestone Tech will not use or disclose PHI other than as permitted or required by the BAA or as required by law.
  • Edgestone Tech will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI, as detailed in Section 3.
  • Edgestone Tech will report any security incident or breach of unsecured PHI to the applicable client without unreasonable delay and in accordance with the timelines specified in the BAA.
  • Edgestone Tech will ensure that any downstream subcontractor or agent that creates, receives, maintains, or transmits PHI on Edgestone Tech's behalf agrees, through a written agreement, to substantially similar restrictions and conditions, as detailed in Section 5.
  • Upon termination of an engagement, Edgestone Tech will return or destroy all PHI, or, where return or destruction is infeasible, extend BAA protections for as long as the PHI is retained, consistent with the terms negotiated in the applicable BAA.

3. Data Protection and Technical Safeguards

Edgestone Tech's engineering, security, and compliance programs are architected around the HIPAA Security Rule's requirement for reasonable and appropriate administrative, physical, and technical safeguards, and are further aligned to recognized frameworks including NIST SP 800-66, NIST SP 800-53, and SOC 2 Trust Services Criteria. The following controls apply, at a minimum, across every system Edgestone Tech builds or manages that processes regulated healthcare data.

3.1 Technical Safeguards
  • Encryption in transit: all data transmitted between clients, end users, and Edgestone Tech-managed systems is encrypted using TLS 1.3 (or the then-current, industry-recognized successor protocol).
  • Encryption at rest: all PHI and other regulated data stored within databases, object storage, backups, and archival media is encrypted using AES-256 or an equivalent NIST-validated cryptographic standard.
  • Multi-Factor Authentication (MFA): strict, mandatory MFA is enforced for all administrative, engineering, and end-user access to systems containing PHI, with no exceptions for privileged accounts.
  • Role-Based Identity and Access Management (IAM): access to PHI is governed by role-based access controls built on the principle of least privilege, with segregation of duties between development, operations, and data-analytics personnel, and periodic access recertification.
  • Comprehensive audit logging: all authentication events, data access events, configuration changes, and administrative actions within systems handling PHI are logged, tamper-evidenced, and retained in accordance with client BAA requirements and applicable regulation.
  • Local-first / private cloud processing for sensitive workloads: sensitive data-analysis architectures — including optical character recognition (OCR) pipelines, medical record parsing, and document-intelligence workloads — are designed to execute within the client's private cloud, virtual private cloud (VPC), or on-premises/local-first environment, so that PHI does not transit to shared, multi-tenant, or public inference infrastructure unless explicitly authorized in writing by the client.
  • Network segmentation and hardening: production environments handling PHI are logically and, where required, physically segmented from development, staging, and non-regulated workloads, with intrusion detection, vulnerability management, and regular penetration testing.
3.2 Administrative Safeguards
  • A designated Security Officer and Privacy Officer oversee HIPAA compliance, workforce training, and incident response.
  • Workforce members are subject to background screening (where legally permitted), signed confidentiality obligations, and mandatory recurring HIPAA and security-awareness training prior to and throughout any assignment involving PHI.
  • Formal risk analysis and risk management processes are conducted at least annually and upon any material change to systems or architecture handling PHI.
  • A documented Incident Response Plan and Business Continuity/Disaster Recovery Plan govern detection, containment, notification, and recovery for any security event.
3.3 Physical Safeguards
  • Data centers and cloud regions used to host regulated workloads maintain independently audited physical security certifications (including SOC 2 Type II and/or ISO 27001) from the underlying infrastructure provider.
  • Facility access at Edgestone Tech's Louisville and Hyderabad delivery centers is controlled through badge-based access control, visitor logging, and monitored entry points for any workspace where regulated data may be viewed or processed.
  • Workstation and device controls, including full-disk encryption, remote wipe capability, and restrictions on removable media, apply to all personnel with access to PHI.
3.4 AI and Machine Learning: Strict Data Isolation

No Use of Patient Data to Train Public or Shared AI Models

  • Patient data, PHI, and other regulated client data processed within Edgestone Tech-built systems is strictly private and secure at all times.
  • Such data is NEVER used to train, fine-tune, or improve any public, third-party, shared, or general-purpose machine learning or generative AI model.
  • Any AI/ML or analytics model that touches PHI is trained, hosted, and served exclusively within the client's isolated, access-controlled environment (private cloud, VPC, or on-premises), and outputs remain the exclusive property of the client.
  • Where a client engagement uses a third-party foundation model provider (e.g., for natural-language processing), Edgestone Tech configures such integrations under zero-data-retention or enterprise-grade contractual terms that prohibit the provider from using client data for its own model training.
3.5 Prohibition on Tracking Technologies Within Regulated Systems

Marketing pixels, third-party web analytics tags, advertising cookies, session-replay tools, and any comparable tracking technologies are strictly prohibited from being deployed within any application, database, or infrastructure layer that creates, receives, maintains, or transmits PHI. Such tracking technologies are used, if at all, solely on Edgestone Tech's own public marketing website as described in Section 6, and are never embedded within client production systems, clinical workflows, or any environment that is subject to a BAA.

4. Information We Collect and How We Use It

4.1 Information Collected from Website Visitors

When you visit www.edgestonetech.com or submit an inquiry through our “Get in Touch” or sales contact forms, we may collect: your name, business email address, phone number, job title, company name, and the content of your inquiry; limited technical data such as IP address, browser type, device type, and pages visited, collected automatically through standard web analytics; and any information you voluntarily provide when subscribing to newsletters, registering for webinars, or downloading gated content (such as whitepapers or case studies).

We use this website-visitor information to: respond to inquiries and sales requests; provide requested content, demonstrations, or proposals; operate, secure, and improve our public website; and, where you have opted in, send marketing communications about Edgestone Tech's services. We do not use website-visitor form submissions to populate or train any client-facing production system, and no PHI should ever be submitted through public website forms.

4.2 Information Processed on Behalf of Enterprise Clients

In the course of delivering custom software development, enterprise cloud infrastructure, and AI/data analytics services, Edgestone Tech personnel may be granted access to client environments that contain PHI, personally identifiable information (PII), pharmaceutical research data, clinical trial data, or other regulated categories of information. This information is accessed and processed solely: (i) as instructed in writing by the client; (ii) as necessary to perform contracted development, testing, deployment, hosting, maintenance, or support services; and (iii) subject to the safeguards described in Section 3 and the terms of the applicable BAA/DPA. Edgestone Tech does not repurpose, sell, rent, or otherwise use client-controlled regulated data for its own independent business purposes, marketing, or model training.

Data Category Governing Framework
Business contact information submitted via public website forms General commercial privacy law; Section 6 of this Policy
Protected Health Information (PHI) within client-hosted or Edgestone-managed systems HIPAA Business Associate Agreement (BAA); Section 2 of this Policy
Pharmaceutical research, clinical trial, and life-sciences data Client MSA/DPA; applicable FDA, GxP, and international research-data regulations
Personal data of EU/UK/EEA data subjects encountered in client systems GDPR/UK GDPR via Data Processing Agreement and Standard Contractual Clauses; Section 6
Employee and job-applicant data (Edgestone Tech workforce) Applicable US state and Indian labor/employment data protection law

5. Downstream Subprocessors and Infrastructure Providers

Edgestone Tech relies on a limited set of vetted, enterprise-grade infrastructure and technology providers to deliver hosting, cloud compute, storage, and supporting managed services (which may include providers such as Amazon Web Services, Microsoft Azure, and Google Cloud Platform, among others, depending on client architecture requirements). Every subprocessor engaged in connection with a client engagement involving PHI or other regulated data is subject to the following minimum requirements:

  • Formal due-diligence review of the subprocessor's security certifications (e.g., SOC 2 Type II, ISO 27001, HITRUST CSF, as applicable) prior to onboarding.
  • Execution of a downstream Business Associate Agreement (or equivalent Data Processing Agreement) with each subprocessor that flows down obligations substantially equivalent to those Edgestone Tech has committed to under its client-facing BAAs, consistent with 45 C.F.R. § 164.504(e)(1)(i) and (5).
  • Contractual commitments from each subprocessor regarding encryption, breach notification timelines, audit cooperation, and data return/destruction upon offboarding.
  • Maintenance of an up-to-date subprocessor inventory, made available to enterprise clients upon request and, where required by the applicable BAA or DPA, subject to advance notice of any new subprocessor and a right to object.

Edgestone Tech does not permit any subprocessor to access, store, or process client PHI unless that subprocessor has first executed a compliant downstream BAA and passed Edgestone Tech's security and compliance review.

6. Regional Compliance and Cross-Border Data Transfers

Edgestone Tech operates globally, with personnel and delivery capability in both Louisville, Kentucky, USA, and Hyderabad, India, and serves clients across multiple jurisdictions. Because engineering and support work may be performed by teams located outside a client's home jurisdiction, Edgestone Tech applies the following principles to ensure this Policy operates consistently with applicable regional data protection frameworks.

6.1 HIPAA (United States)

For US healthcare clients, Section 2 and Section 3 of this Policy, together with the executed BAA, govern the handling of PHI regardless of where within Edgestone Tech's global delivery organization the work is performed. Any cross-border access to PHI by Edgestone Tech's Hyderabad delivery center is expressly authorized under, and subject to the same safeguards required by, the client's BAA.

6.2 GDPR and UK GDPR (European Union / United Kingdom)

Where an engagement involves the personal data of individuals located in the European Economic Area or United Kingdom, Edgestone Tech acts as a “processor” or “sub-processor” under the General Data Protection Regulation (GDPR) and/or UK GDPR, and enters into a Data Processing Agreement incorporating the European Commission's Standard Contractual Clauses (SCCs) or an equivalent approved transfer mechanism to lawfully support any transfer of personal data outside the EEA/UK, including transfers to or processing performed from our Hyderabad delivery center or US headquarters.

6.3 Data Sovereignty and Client-Directed Data Residency

Edgestone Tech recognizes that healthcare and pharmaceutical clients are frequently subject to data localization or data sovereignty requirements imposed by their own regulators, national health authorities, or internal governance policies. Where a client's jurisdiction or contract requires that PHI or other regulated data remain within a specific country or region (for example, remaining within US-based cloud regions, or complying with India's Digital Personal Data Protection Act, 2023, where applicable), Edgestone Tech configures hosting, backup, and processing architecture — including restricting personnel access by geography where required — to conform to those data residency requirements as documented in the applicable SOW, DPA, or BAA.

6.4 Other Regional Frameworks

Depending on client location and applicable law, Edgestone Tech's contractual and technical framework is also designed to accommodate other regional privacy and health-data regimes, including US state privacy laws (such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act), India's Digital Personal Data Protection Act, 2023, and comparable frameworks in other jurisdictions where our clients operate. In all cases, the client-specific BAA or DPA governs the precise regulatory framework applicable to a given engagement.

7. Data Retention

Website-visitor business contact information is retained only as long as reasonably necessary to respond to inquiries, maintain business relationships, and comply with applicable marketing-consent and legal requirements, after which it is deleted or anonymized. PHI and other regulated data processed on behalf of enterprise clients is retained, returned, or destroyed strictly in accordance with the retention, return, and destruction schedule specified in the applicable BAA, DPA, or SOW, and Edgestone Tech retains no independent right to keep such data beyond the terms of that agreement.

8. Your Privacy Rights

Website visitors may have rights under applicable law (such as US state privacy statutes or the GDPR) to access, correct, delete, or restrict processing of their personal information, and to opt out of marketing communications at any time by using the unsubscribe mechanism in our communications or by contacting us using the details in Section 11.

Individuals whose PHI is processed within a client's system — such as patients, plan members, or research subjects — must direct any privacy rights request (including requests for access, amendment, or accounting of disclosures under HIPAA) to the applicable healthcare provider, health plan, or sponsor (the Covered Entity), as Edgestone Tech, acting as a Business Associate, does not maintain a direct relationship with those individuals and will refer any such request received directly to the appropriate client in accordance with the BAA.

9. Changes to This Policy

Edgestone Tech may update this Policy from time to time to reflect changes in our services, technology, or legal and regulatory requirements. Material changes will be reflected by an updated “Effective Date” at the top of this Policy. This Policy governs website interactions and serves as a general disclosure of our compliance posture; updates to this Policy do not modify the terms of any executed BAA, DPA, or MSA, which may only be amended through the process specified in that agreement.

10. Contact Us

Questions regarding this Privacy Policy, our HIPAA compliance program, or requests related to an executed Business Associate Agreement should be directed to Edgestone Tech's Privacy Officer using the contact details below.

Contact Channel Details
Corporate Headquarters Edgestone Tech, Inc., Louisville, Kentucky, USA
Global Delivery Center Hyderabad, Telangana, India
Website https://www.edgestonetech.com
Privacy / Compliance Inquiries privacy@edgestonetech.com
HIPAA Security Officer security@edgestonetech.com

This Privacy Policy is provided for general informational and disclosure purposes and does not constitute legal advice. Enterprise clients should rely on their executed Business Associate Agreement, Data Processing Agreement, and Master Services Agreement as the controlling documents for their engagement with Edgestone Tech.

back top