export default function Privacy() { return (
{/* Header */}
STTIL Solutions LLC

Signal Privacy Policy

Effective Date: June 7, 2026

{/* Who We Are */}

Who We Are

STTIL Solutions LLC ("STTIL", "we", "us") operates Signal, a documentation readiness tool for DMEPOS suppliers. Signal helps supplier staff identify patients whose documentation may need attention before supplies are shipped or claims are submitted. This Privacy Policy describes how Signal handles the data uploaded to our platform.

{/* What We Process */}

What Data Signal Processes

When your staff uploads a CSV file to Signal, we process:

  • Your internal patient identifier (MRN or account number) โ€” used as a de-identified tracking key only
  • Device type (e.g., Dexcom G7, FreeStyle Libre 3)
  • Most recent supply shipment date
  • Payer name (Medicare, Medicaid, Commercial)
  • Quantity shipped
  • Documentation status fields if included in your CSV (SWO status, PA status, PECOS flag)

Signal produces a prioritized documentation worklist as output.

{/* What We Do NOT Store */}

What Signal Does NOT Store

Signal is designed to operate without storing protected health information (PHI). We never store:

  • Patient names
  • Social Security numbers
  • Dates of birth
  • Home addresses
  • Phone numbers or email addresses
  • Diagnosis codes (ICD codes)
  • Clinical notes or records

The connection between a patient identifier and a real patient identity stays with your staff. STTIL never holds that crosswalk.

{/* How We Store */}

How We Store What We Do Collect

Patient identifiers are hashed using SHA-256 before storage โ€” we store a cryptographic fingerprint of the identifier, not the identifier itself. The hash cannot be reversed to recover the original value. All stored data is associated with your organization's account and protected by row-level security (RLS) policies. Your data is not accessible to other Signal customers. All data in transit is encrypted via HTTPS. All data at rest is encrypted using AES-256.

{/* Patient Outreach */}

Patient Outreach

Signal does not contact patients. All outreach and supply decisions remain with your staff. Signal surfaces documentation conditions โ€” your team acts on them. All prescriber outreach flags go to the prescriber office, never to the patient.

{/* Data Retention */}

Data Retention and Deletion

Your data is retained for the duration of your subscription plus 90 days. Upon written request, all data associated with your account will be deleted within 10 business days, and we will confirm deletion in writing. Audit logs are retained for 7 years for compliance purposes.

{/* HIPAA */}

HIPAA

Signal processes de-identified operational data. To the extent that any data processed by Signal could be considered protected health information under HIPAA, STTIL Solutions has executed a Business Associate Agreement (BAA) with its cloud infrastructure providers and operates appropriate administrative, physical, and technical safeguards. If you believe a BAA is required for your engagement with Signal, please contact us before uploading any data.

{/* Security Incidents */}

Security Incidents

In the event of a security incident affecting your organization's data, STTIL Solutions will notify you within 72 hours of discovery. We will provide a description of the incident, the data affected, and the steps taken to address it.

{/* Contact */}

Contact

Questions about this Privacy Policy or your data:
STTIL Solutions LLC
Email:{" "} kisasttil@gmail.com

{/* Footer */}

Signal is operated by STTIL Solutions LLC.{" "} signal.sttilsolutions.com {" "}ยท We may update this policy from time to time. We will notify active customers of material changes by email. Continued use of Signal following notice constitutes acceptance.

); }