Privacy Policy
Polaristek
Introduction & Overview
Welcome to Polaristek (“Polaristek,” “we,” “us,” or “our”). Polaristek serves as an extended business operations, healthcare administrative, and digital transformation partner headquartered at:
Polaristek
4000 Calle Tecate, Suite 116
Camarillo, CA 93012, USAContact Email: info@polaristek.com
We respect your privacy and are committed to protecting personal data and protected health information (PHI). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit [https://polaristek.com/] (https://polaristek.com/), utilize our web development and digital marketing services, or engage us for operational and administrative support (including Revenue Cycle Management, Healthcare Operations, Credentialing & Compliance, Finance & Accounting, HR, and Business Operations Support).
Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access or use the site or our services.
Information We Collect
We collect information directly from you, automatically when you navigate our site, and through third-party business partners or clients.
A. Personal Data Provided Voluntarily
- Contact & Business Identifiers: Full name, corporate email address, telephone number, job title, company name, and physical office address when you complete contact forms, request consultations, or inquire about our services.
- Financial & Billing Information: Invoices, banking details, or corporate payment information necessary to process contracts and retainers.
- Recruitment Data: Resumes, work history, educational background, and references submitted via our Careers portal.
B. Protected Health Information (PHI) & Healthcare Operations Data
In our capacity as a Business Associate for healthcare providers, clinical practices, and medical organizations, we process data on behalf of our clients, which may include Protected Health Information (PHI).
Important Note on PHI: All PHI handled through our Revenue Cycle Management (RCM), Healthcare Operations, Credentialing, and Patient Access workflows is managed strictly in accordance with HIPAA / HITECH regulations and individual Business Associate Agreements (BAAs).
C. Automatically Collected Information & Tracking
- Device & Usage Data: IP addresses, browser types, operating systems, referring URLs, access times, pages viewed, and device parameters.
- Cookies & Pixels: We use essential, performance, and analytics cookies to optimize site navigation, analyze user traffic, and improve our digital marketing campaigns.
How We Use Your Information
We process personal and operational data for legitimate business purposes, including:
- Service Delivery & Back-Office Operations: Executing contracts, managing RCM/billing operations, practice management workflows, finance and accounting support, and HR/talent coordination.
- Communication & Inquiry Response: Responding to sales inquiries, scheduling operational assessments, and delivering customer support.
- Marketing & Website Optimization: Analyzing web performance, personalizing user experience, and optimizing B2B digital marketing strategies.
- Legal Compliance & Security: Detecting, preventing, and investigating fraud, security breaches, or non-compliance with applicable law.
Disclosure & Sharing of Information
Polaristek does not sell, rent, or trade your personal data or Protected Health Information. We share data strictly under the following conditions:
- Affiliated Global Entities: To our managed delivery centers to deliver 24/7 extended operational support, governed by standard contractual clauses and security frameworks.
- Third-Party Service Providers: Vetted vendors who provide cloud infrastructure, IT security, communication channels, and administrative hosting services under strict confidentiality agreements.
- Healthcare Business Associates: When executing administrative healthcare operations, we interact with covered entities, payors, clearinghouses, and EMR platforms as authorized under executing BAAs.
- Legal Requirements: When required by law, subpoena, court order, or regulatory bodies to protect our rights, client safety, or public health compliance.
Regional Compliance & Privacy Rights
HIPAA / HITECH Compliance (Healthcare Operations)
For all healthcare solutions (RCM, Credentialing, Patient Access, Practice Operations):
- Business Associate Agreements (BAAs): We enter into comprehensive BAAs with all covered entities prior to processing any patient or clinical data.
- Safeguards: We maintain administrative, physical, and technical safeguards complying with the HIPAA Security Rule (including data encryption in transit and at rest, zero-trust network access, and operational role-based controls).
- Incident Response: We enforce documented breach notification procedures to notify affected covered entities without unreasonable delay in the event of a security incident.
California Consumer Privacy Act (CCPA / CPRA)
If you are a resident of California, you have specific rights regarding your Personal Information:
- Right to Know / Access: Request disclosure of personal information collected, used, or shared over the preceding 12 months.
- Right to Delete: Request deletion of personal information collected from you (subject to legal exceptions).
- Right to Correct: Request corrections to inaccurate personal information.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA privacy rights.
- Opt-Out of Sale / Sharing: Polaristek does not sell personal information.
To exercise your California rights, contact us at info@polaristek.com
General Data Protection Regulation (GDPR – UK & EU Residents)
If you interact with us from the European Union or United Kingdom, Polaristek acts as a Data Controller for web visitor data and a Data Processor for B2B/client operational data.
- Legal Bases for Processing: Performance of a contract, legitimate business interest, compliance with legal obligations, or explicit user consent.
- Data Subject Rights: Right of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, and objection to processing.
- Cross-Border Transfers: Transfers of data between the US, UK, and India are secured using EU/UK Standard Contractual Clauses (SCCs) and robust organizational security measures.
Data Security & Retention
We employ enterprise-grade technical and organizational security measures to protect data against unauthorized access, loss, or alteration. These measures include:
- End-to-end data encryption (TLS 1.3 in transit, AES-256 at rest).
- Multi-factor authentication (MFA) and strict role-based access control (RBAC).
- Regular vulnerability assessments and HIPAA/SOC-2 alignment audits.
We retain personal information only as long as necessary to fulfill the purposes outlined in this policy, comply with legal obligations, or resolve disputes.
Third-Party Links & External Sites
Our website (polaristek.com) may contain links to third-party sites, blogs, or external software platforms. Polaristek is not responsible for the privacy practices, cookie policies, or content of external websites not owned or controlled by Polaristek.
Updates to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our operational practices, regulatory updates, or legal obligations. When changes are made, we will revise the “Last Updated” date at the top of this policy.
Contact Us
If you have questions, comments, or complaints regarding this Privacy Policy or our data handling practices, please reach out to our privacy compliance officer:
- Email: info@polaristek.com
- Address: Polaristek LLC, 4000 Calle Tecate, Suite 116, Camarillo, CA 93012, USA