Business Processes Redefined LLC
Effective July 27, 2026

Privacy Policy

Introduction

BPR is committed to protecting the privacy and security of all personal, confidential, and business information entrusted to us by our clients, customers, and partners. This Privacy Policy outlines how BPR collects, uses, shares, and protects personal and confidential data across all lines of business, in accordance with applicable regulations and industry standards. Where BPR handles Protected Health Information (PHI) on behalf of a client, that data is additionally subject to the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH); this policy applies to all personal and confidential data BPR handles, not only PHI.

Policy Updates and Notification

  • BPR may periodically update this Privacy Policy to reflect changes in regulations, business practices, or security measures.
  • Minor updates that do not impact personal data handling may be made without direct notification.
  • Substantial changes affecting how personal information is collected, used, or disclosed will be communicated to affected individuals through appropriate channels.
  • Any change to this policy will not retroactively alter the way previously collected information is handled without first notifying individuals and obtaining their consent when required.

Collection and Protection of Personal Information

BPR follows strict security controls to protect all client, customer, and business information against unauthorized access, disclosure, and misuse. This policy applies to all forms of data, including but not limited to:

  • Electronic communications (e.g., online data transmissions, emails, client portals)
  • Telephone conversations (e.g., customer support interactions)
  • Written correspondence (e.g., mailed documents, contracts, and signed agreements)

Types of Information Collected

BPR may collect the following categories of personal and confidential data:

  • Service-related information – Details of services performed or provided to a client or customer.
  • Demographic data – Client and customer name, address, date of birth, and contact details.
  • Personal identifiers – Unique identifiers such as Social Security numbers, account numbers, or, where applicable, patient identification numbers.
  • Financial data – Billing and payment information, and, where applicable, insurance coverage details.
  • Protected Health Information (PHI), where applicable – For clients in healthcare-related lines of business only, subject to HIPAA/HITECH requirements.

Access Control and Data Security

  • Access to personal and confidential data is restricted to authorized personnel based on job roles and responsibilities.
  • Encryption is required for highly sensitive information.
  • No employee is permitted to copy or remove confidential data from BPR systems without explicit authorization.

Data Sharing and Disclosure

BPR does not sell, rent, loan, or otherwise make personally identifiable information available to third parties for marketing or non-business-related purposes.

Permissible Data Sharing

BPR may share personal data under the following conditions:

  • With necessary service providers – When required to perform essential business functions (e.g., contracted agencies, IT security vendors, cloud hosting providers). Any third-party service provider must comply with equivalent privacy and security standards (see the Third-Party Vendor Data Security and Compliance Policy).
  • For legal or regulatory compliance – When required by law, court order, subpoena, or government request, provided such disclosure is in accordance with applicable privacy laws.
  • With explicit client or customer consent – If an individual authorizes data sharing for a specific purpose.

Compliance with Industry Standards and Regulations

BPR is committed to complying with all applicable privacy regulations, including:

  • HIPAA & HITECH, where applicable – Protection of Protected Health Information (PHI) for clients in healthcare-related lines of business, in accordance with federal healthcare privacy standards.
  • SOC 2 Type 2 (AICPA Trust Services Criteria) – Security, Availability, and Confidentiality controls applicable to all personal and business data BPR handles, regardless of industry.
  • General data protection and security best practices – Implementation of industry-standard encryption, access controls, and monitoring to safeguard all personal and confidential data.

Additionally, BPR honors and complies with client and customer privacy requests in accordance with legal obligations.

Conclusion

BPR upholds the highest standards of privacy and data protection to ensure confidentiality, integrity, and security of personal and confidential information across every line of business. We remain dedicated to implementing robust security measures, enforcing strict access controls, and ensuring transparency in how personal and confidential data is handled.

Get in touch

Questions about this policy?

Reach us directly and we'll get you an answer.

Start a conversation →