export default function Privacy() { return (
Effective Date: June 7, 2026
STTIL Solutions LLC ("STTIL", "we", "us") operates Signal, a documentation readiness tool for DMEPOS suppliers. Signal helps supplier staff identify patients whose documentation may need attention before supplies are shipped or claims are submitted. This Privacy Policy describes how Signal handles the data uploaded to our platform.
When your staff uploads a CSV file to Signal, we process:
Signal produces a prioritized documentation worklist as output.
Signal is designed to operate without storing protected health information (PHI). We never store:
The connection between a patient identifier and a real patient identity stays with your staff. STTIL never holds that crosswalk.
Patient identifiers are hashed using SHA-256 before storage โ we store a cryptographic fingerprint of the identifier, not the identifier itself. The hash cannot be reversed to recover the original value. All stored data is associated with your organization's account and protected by row-level security (RLS) policies. Your data is not accessible to other Signal customers. All data in transit is encrypted via HTTPS. All data at rest is encrypted using AES-256.
Signal does not contact patients. All outreach and supply decisions remain with your staff. Signal surfaces documentation conditions โ your team acts on them. All prescriber outreach flags go to the prescriber office, never to the patient.
Your data is retained for the duration of your subscription plus 90 days. Upon written request, all data associated with your account will be deleted within 10 business days, and we will confirm deletion in writing. Audit logs are retained for 7 years for compliance purposes.
Signal processes de-identified operational data. To the extent that any data processed by Signal could be considered protected health information under HIPAA, STTIL Solutions has executed a Business Associate Agreement (BAA) with its cloud infrastructure providers and operates appropriate administrative, physical, and technical safeguards. If you believe a BAA is required for your engagement with Signal, please contact us before uploading any data.
In the event of a security incident affecting your organization's data, STTIL Solutions will notify you within 72 hours of discovery. We will provide a description of the incident, the data affected, and the steps taken to address it.
Questions about this Privacy Policy or your data:
STTIL Solutions LLC
Email:{" "}
kisasttil@gmail.com
Signal is operated by STTIL Solutions LLC.{" "} signal.sttilsolutions.com {" "}ยท We may update this policy from time to time. We will notify active customers of material changes by email. Continued use of Signal following notice constitutes acceptance.