Effective Date: July 16, 2026 | Last Reviewed: July 16, 2026
Edgestone Tech, Inc. | Headquarters: Louisville, Kentucky, USA | Global Delivery Center: Hyderabad, India
Edgestone Tech, Inc. (“Edgestone Tech,” “the Company,” “we,” “us,” or “our”) is a global information technology solutions provider headquartered in Louisville, Kentucky, USA, with a global delivery center in Hyderabad, India. We design, build, deploy, and maintain custom software, enterprise cloud infrastructure, and artificial intelligence and data analytics platforms for clients operating in highly regulated sectors, with a primary concentration in healthcare and pharmaceuticals.
This Privacy Policy (“Policy”) is intended to give both casual website visitors and enterprise healthcare procurement and compliance teams a clear, complete, and legally precise understanding of how Edgestone Tech collects, uses, discloses, and safeguards information. Because Edgestone Tech serves two fundamentally different populations — individuals browsing our public website and enterprise clients whose regulated data flows through the systems we build and operate — this Policy is deliberately organized into two distinct governance tracks, described in Section 1 below.
Nothing in this Policy is intended to, and nothing in this Policy shall, limit, modify, or override the terms of any executed contract, Master Services Agreement (MSA), Data Processing Agreement (DPA), or Business Associate Agreement (BAA) between Edgestone Tech and an enterprise client. Where any conflict exists between this Policy and an executed BAA or DPA, the terms of that executed agreement control.
Edgestone Tech interacts with information in two operationally and legally distinct capacities. Compliance officers and procurement teams evaluating Edgestone Tech should note this distinction carefully, as different legal frameworks, safeguards, and obligations attach to each.
This category covers any individual who visits www.edgestonetech.com, browses our public marketing pages, downloads whitepapers or case studies, or submits information through our “Get in Touch,” sales inquiry, careers, or newsletter subscription forms. In this capacity, Edgestone Tech acts as a data controller (or “business” under applicable state law) with respect to the ordinary business contact information voluntarily submitted, and processes that information under standard commercial privacy principles described in Sections 2, 6, and 7 of this Policy.
This category covers healthcare systems, hospitals, payors, pharmaceutical and life sciences companies, digital health vendors, and other regulated organizations that engage Edgestone Tech to design, build, host, migrate, or maintain custom software, enterprise cloud infrastructure, or AI/data analytics platforms that create, receive, maintain, or transmit Protected Health Information (“PHI”) or other regulated data on the client's behalf. In this capacity, Edgestone Tech does not act as a general data controller. Instead, Edgestone Tech acts strictly as a Business Associate (or subprocessor/data processor, as applicable) operating under the express written instructions of the client, governed by a signed Business Associate Agreement and/or Data Processing Agreement, as detailed fully in Section 2 below.
When Edgestone Tech provides healthcare software development, cloud hosting, data migration, AI/analytics, or related technical services that involve access to PHI, Edgestone Tech operates strictly as a “Business Associate” as that term is defined under the Health Insurance Portability and Accountability Act of 1996, as amended, and its implementing regulations, including the Privacy Rule, Security Rule, and Breach Notification Rule (collectively, “HIPAA”). Edgestone Tech is not a healthcare provider, health plan, or healthcare clearinghouse, and does not independently qualify as a “Covered Entity” under HIPAA.
All PHI processed, stored, transmitted, or otherwise handled within systems that Edgestone Tech builds, deploys, hosts, or maintains for a client is, and at all times remains, the sole property of the applicable client (the “Covered Entity” or, where applicable, the upstream Business Associate). Edgestone Tech claims no ownership interest in client PHI, does not use client PHI for any purpose outside the scope of the engagement, and accesses PHI solely to the extent necessary to perform the contracted development, hosting, maintenance, support, or analytics services.
Prior to any engagement involving PHI, Edgestone Tech executes a Business Associate Agreement with the client that satisfies the requirements of 45 C.F.R. § 164.502(e) and § 164.504(e). The executed BAA — not this general website Privacy Policy — is the controlling legal instrument governing permitted uses and disclosures of PHI, minimum necessary standards, breach notification timelines and procedures, subcontractor flow-down obligations, audit rights, and termination/data-return or destruction obligations. In the event of any inconsistency between this Policy and an executed BAA, the BAA governs without exception.
Edgestone Tech's engineering, security, and compliance programs are architected around the HIPAA Security Rule's requirement for reasonable and appropriate administrative, physical, and technical safeguards, and are further aligned to recognized frameworks including NIST SP 800-66, NIST SP 800-53, and SOC 2 Trust Services Criteria. The following controls apply, at a minimum, across every system Edgestone Tech builds or manages that processes regulated healthcare data.
No Use of Patient Data to Train Public or Shared AI Models
Marketing pixels, third-party web analytics tags, advertising cookies, session-replay tools, and any comparable tracking technologies are strictly prohibited from being deployed within any application, database, or infrastructure layer that creates, receives, maintains, or transmits PHI. Such tracking technologies are used, if at all, solely on Edgestone Tech's own public marketing website as described in Section 6, and are never embedded within client production systems, clinical workflows, or any environment that is subject to a BAA.
When you visit www.edgestonetech.com or submit an inquiry through our “Get in Touch” or sales contact forms, we may collect: your name, business email address, phone number, job title, company name, and the content of your inquiry; limited technical data such as IP address, browser type, device type, and pages visited, collected automatically through standard web analytics; and any information you voluntarily provide when subscribing to newsletters, registering for webinars, or downloading gated content (such as whitepapers or case studies).
We use this website-visitor information to: respond to inquiries and sales requests; provide requested content, demonstrations, or proposals; operate, secure, and improve our public website; and, where you have opted in, send marketing communications about Edgestone Tech's services. We do not use website-visitor form submissions to populate or train any client-facing production system, and no PHI should ever be submitted through public website forms.
In the course of delivering custom software development, enterprise cloud infrastructure, and AI/data analytics services, Edgestone Tech personnel may be granted access to client environments that contain PHI, personally identifiable information (PII), pharmaceutical research data, clinical trial data, or other regulated categories of information. This information is accessed and processed solely: (i) as instructed in writing by the client; (ii) as necessary to perform contracted development, testing, deployment, hosting, maintenance, or support services; and (iii) subject to the safeguards described in Section 3 and the terms of the applicable BAA/DPA. Edgestone Tech does not repurpose, sell, rent, or otherwise use client-controlled regulated data for its own independent business purposes, marketing, or model training.
| Data Category | Governing Framework |
|---|---|
| Business contact information submitted via public website forms | General commercial privacy law; Section 6 of this Policy |
| Protected Health Information (PHI) within client-hosted or Edgestone-managed systems | HIPAA Business Associate Agreement (BAA); Section 2 of this Policy |
| Pharmaceutical research, clinical trial, and life-sciences data | Client MSA/DPA; applicable FDA, GxP, and international research-data regulations |
| Personal data of EU/UK/EEA data subjects encountered in client systems | GDPR/UK GDPR via Data Processing Agreement and Standard Contractual Clauses; Section 6 |
| Employee and job-applicant data (Edgestone Tech workforce) | Applicable US state and Indian labor/employment data protection law |
Edgestone Tech relies on a limited set of vetted, enterprise-grade infrastructure and technology providers to deliver hosting, cloud compute, storage, and supporting managed services (which may include providers such as Amazon Web Services, Microsoft Azure, and Google Cloud Platform, among others, depending on client architecture requirements). Every subprocessor engaged in connection with a client engagement involving PHI or other regulated data is subject to the following minimum requirements:
Edgestone Tech does not permit any subprocessor to access, store, or process client PHI unless that subprocessor has first executed a compliant downstream BAA and passed Edgestone Tech's security and compliance review.
Edgestone Tech operates globally, with personnel and delivery capability in both Louisville, Kentucky, USA, and Hyderabad, India, and serves clients across multiple jurisdictions. Because engineering and support work may be performed by teams located outside a client's home jurisdiction, Edgestone Tech applies the following principles to ensure this Policy operates consistently with applicable regional data protection frameworks.
For US healthcare clients, Section 2 and Section 3 of this Policy, together with the executed BAA, govern the handling of PHI regardless of where within Edgestone Tech's global delivery organization the work is performed. Any cross-border access to PHI by Edgestone Tech's Hyderabad delivery center is expressly authorized under, and subject to the same safeguards required by, the client's BAA.
Where an engagement involves the personal data of individuals located in the European Economic Area or United Kingdom, Edgestone Tech acts as a “processor” or “sub-processor” under the General Data Protection Regulation (GDPR) and/or UK GDPR, and enters into a Data Processing Agreement incorporating the European Commission's Standard Contractual Clauses (SCCs) or an equivalent approved transfer mechanism to lawfully support any transfer of personal data outside the EEA/UK, including transfers to or processing performed from our Hyderabad delivery center or US headquarters.
Edgestone Tech recognizes that healthcare and pharmaceutical clients are frequently subject to data localization or data sovereignty requirements imposed by their own regulators, national health authorities, or internal governance policies. Where a client's jurisdiction or contract requires that PHI or other regulated data remain within a specific country or region (for example, remaining within US-based cloud regions, or complying with India's Digital Personal Data Protection Act, 2023, where applicable), Edgestone Tech configures hosting, backup, and processing architecture — including restricting personnel access by geography where required — to conform to those data residency requirements as documented in the applicable SOW, DPA, or BAA.
Depending on client location and applicable law, Edgestone Tech's contractual and technical framework is also designed to accommodate other regional privacy and health-data regimes, including US state privacy laws (such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act), India's Digital Personal Data Protection Act, 2023, and comparable frameworks in other jurisdictions where our clients operate. In all cases, the client-specific BAA or DPA governs the precise regulatory framework applicable to a given engagement.
Website-visitor business contact information is retained only as long as reasonably necessary to respond to inquiries, maintain business relationships, and comply with applicable marketing-consent and legal requirements, after which it is deleted or anonymized. PHI and other regulated data processed on behalf of enterprise clients is retained, returned, or destroyed strictly in accordance with the retention, return, and destruction schedule specified in the applicable BAA, DPA, or SOW, and Edgestone Tech retains no independent right to keep such data beyond the terms of that agreement.
Website visitors may have rights under applicable law (such as US state privacy statutes or the GDPR) to access, correct, delete, or restrict processing of their personal information, and to opt out of marketing communications at any time by using the unsubscribe mechanism in our communications or by contacting us using the details in Section 11.
Individuals whose PHI is processed within a client's system — such as patients, plan members, or research subjects — must direct any privacy rights request (including requests for access, amendment, or accounting of disclosures under HIPAA) to the applicable healthcare provider, health plan, or sponsor (the Covered Entity), as Edgestone Tech, acting as a Business Associate, does not maintain a direct relationship with those individuals and will refer any such request received directly to the appropriate client in accordance with the BAA.
Edgestone Tech may update this Policy from time to time to reflect changes in our services, technology, or legal and regulatory requirements. Material changes will be reflected by an updated “Effective Date” at the top of this Policy. This Policy governs website interactions and serves as a general disclosure of our compliance posture; updates to this Policy do not modify the terms of any executed BAA, DPA, or MSA, which may only be amended through the process specified in that agreement.
Questions regarding this Privacy Policy, our HIPAA compliance program, or requests related to an executed Business Associate Agreement should be directed to Edgestone Tech's Privacy Officer using the contact details below.
| Contact Channel | Details |
|---|---|
| Corporate Headquarters | Edgestone Tech, Inc., Louisville, Kentucky, USA |
| Global Delivery Center | Hyderabad, Telangana, India |
| Website | https://www.edgestonetech.com |
| Privacy / Compliance Inquiries | privacy@edgestonetech.com |
| HIPAA Security Officer | security@edgestonetech.com |
This Privacy Policy is provided for general informational and disclosure purposes and does not constitute legal advice. Enterprise clients should rely on their executed Business Associate Agreement, Data Processing Agreement, and Master Services Agreement as the controlling documents for their engagement with Edgestone Tech.