Legal

Privacy Policy

Effective Date: May 1, 2026  |  Last Updated: May 4, 2026

Plain Language Summary: STFE Systems collects only the minimum information needed to operate our clinical decision support platform. We never sell your data. We never use advertising trackers. All Protected Health Information (PHI) is governed by our Business Associate Agreement (BAA). This document explains what we collect, why, and how.

1. Who We Are

STFE Systems Inc. ("STFE," "we," "our," or "us") is a healthcare technology company incorporated in Delaware, USA, with engineering operations in Chennai, India. We operate a deterministic clinical admission decision engine for Skilled Nursing Facilities (SNFs) and Critical Access Hospitals (CAHs) accessible at health.stfe.io and via API.

For purposes of HIPAA, STFE is a Business Associate to Covered Entities (healthcare facilities) that use our platform. We are not a Covered Entity ourselves.

Contact: privacy@stfe.io  |  STFE Systems Inc., 8 The Green Suite R, Dover, Delaware 19901, USA

2. Information We Collect

A. Account & Facility Information (Collected Directly)

B. Clinical Data (Processed on Behalf of Facilities — Governed by BAA)

Clinical data is processed under our Business Associate Agreement (BAA). Facilities are the Data Controllers for all PHI they submit. STFE is the Data Processor/Business Associate.

C. Usage Data (Collected Automatically)

We do not use advertising cookies, cross-site tracking, or behavioral analytics tools. We use only essential operational cookies.

3. How We Use Information

We never use clinical data for advertising, sell data to third parties, or use patient information for any purpose outside of operating the platform for the facility that submitted it.

4. HIPAA & Protected Health Information

STFE operates as a HIPAA Business Associate. All PHI submitted through the platform is:

To request a BAA or to report a potential HIPAA violation, contact: compliance@stfe.io

5. Data Sharing

We share information only in the following limited circumstances:

We never sell, rent, or trade personal data or clinical data to any third party for any purpose.

6. Data Retention

You may request earlier deletion of non-PHI account data by contacting privacy@stfe.io. PHI retention is governed by the BAA and applicable law.

7. Your Rights

For facility administrators and staff:

For patients: Patient rights regarding PHI are exercised through your healthcare facility (the Covered Entity), not directly through STFE. Contact the facility that submitted your information.

For California residents (CCPA): You have the right to know what personal information we collect, request deletion, and opt out of sale (we do not sell data). Submit requests to privacy@stfe.io.

8. Security

STFE maintains a comprehensive information security program including:

To report a security vulnerability: security@stfe.io

9. International Data Transfers

STFE's engineering team operates from Chennai, India. All production data and PHI remains on AWS infrastructure in the us-east-1 (N. Virginia) region and does not leave the United States. Engineering access to production systems is restricted and logged.

10. Children's Privacy

STFE is a B2B healthcare platform designed for use by licensed healthcare professionals. We do not knowingly collect information from individuals under the age of 18. The platform is not directed at minors.

11. Changes to This Policy

We will notify registered users by email at least 30 days before any material changes to this Privacy Policy. The "Last Updated" date at the top of this page reflects the most recent revision. Continued use of the platform after the effective date constitutes acceptance of the updated policy.

12. Contact

Effective Date: May 1, 2026  |  Last Updated: May 4, 2026  |  Document Version: 1.0