Privacy Policy
Last updated: 18 July 2026
Introduction
Elixir Global ("Elixir Global", "Elixir", "we", "us", or "our") is an enterprise technology and AI transformation firm operating across the Gulf, India, Singapore, and North America. Our services span consulting, digital transformation, intelligent operations, and industry-specific offerings, including healthcare revenue cycle management.
This Privacy Policy, which also serves as our Privacy Notice, explains how we collect, use, disclose, and protect information when you visit elixirglobal.com, communicate with us, or engage our services. Because much of our work involves sensitive business, financial, and healthcare information, we treat the protection of that information as a core responsibility.
Who we are and our role
Elixir Global delivers enterprise transformation and managed operations for organisations across regulated and non-regulated sectors. Depending on the engagement, our role in handling information differs:
- For our own business activities (running the website, responding to enquiries, recruiting, and managing client relationships), we determine how and why information is used, and we are responsible for that information.
- When delivering services to a client, we process information on behalf of and under the instruction of that client. In these cases the client remains responsible for the underlying data, and our handling is governed by the agreement we hold with them.
For healthcare revenue cycle management engagements, we act as a Business Associate under the U.S. Health Insurance Portability and Accountability Act (HIPAA). This means we process Protected Health Information (PHI) on behalf of Covered Entities such as hospitals and physician groups, governed by the Business Associate Agreement (BAA) we sign with each healthcare client.
Scope of this policy
This policy applies to:
- Visitors to elixirglobal.com and anyone who contacts us through the website, email, or phone.
- Representatives of prospective and current clients and partners who share business information with us.
- Candidates who apply for roles with us.
- Client data, including Protected Health Information, that we process in the course of delivering services, as governed by the applicable client agreement or Business Associate Agreement.
Information we collect
Information you provide to us
When you request information, submit a contact form, subscribe to our newsletter, apply for a role, or email us, we collect the details you choose to share. This typically includes your name, organisation, job title, email address, phone number, and the content of your message.
Information collected automatically
When you visit our website, we and our service providers may collect technical information such as your IP address, browser type, device information, pages viewed, referring pages, and the dates and times of your visits. We collect this through cookies and similar technologies, described in Cookies and tracking.
Client and service data
In the course of delivering services, we process data supplied by or on behalf of our clients. For enterprise engagements this may include business records, financial data, and operational information. For healthcare engagements this may include patient demographics, insurance and coverage details, clinical and diagnostic codes, claims data, and payment information. We collect and use this data only as permitted by the relevant client agreement, the applicable Business Associate Agreement, and applicable law, and only to perform the services requested.
How we use information
We use the information we collect to:
- Respond to enquiries, prepare proposals, and manage our relationships with clients, partners, and prospects.
- Deliver the services our clients engage us for, including transformation, managed operations, and healthcare revenue cycle management.
- Operate, maintain, and improve our website and services.
- Send updates, research, and marketing communications where you have asked to receive them or where we are otherwise permitted to do so. You can opt out at any time.
- Recruit and evaluate candidates who apply for roles with us.
- Meet our legal, regulatory, and contractual obligations.
- Protect the security and integrity of our systems and the information we hold.
We do not sell personal information or Protected Health Information, and we do not use Protected Health Information for marketing.
Healthcare data and our role as a HIPAA Business Associate
For healthcare revenue cycle management engagements, we are bound by the HIPAA Privacy Rule and Security Rule with respect to the PHI we handle. Our commitments include:
- Using and disclosing PHI only as permitted by the applicable Business Associate Agreement and by law.
- Applying administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of electronic PHI.
- Reporting security incidents and any breach of unsecured PHI to the relevant Covered Entity in line with our contractual and legal obligations.
- Requiring any subcontractor who handles PHI on our behalf to agree in writing to the same restrictions and conditions that apply to us.
- Making PHI available to support a Covered Entity's obligations regarding individual access, amendment, and accounting of disclosures.
Requests from patients relating to their own health information should be directed to the healthcare provider that holds the relationship with the patient. We will support that provider in responding to such requests as required under our agreement with them.
Our certifications and standards
We maintain independently recognised standards for information security and quality management:
- ISO/IEC 27001 for our Information Security Management System, covering the way we identify, assess, and manage information security risk.
- ISO 9001:2015 for our Quality Management System, covering the consistency and quality of the services we deliver.
- HIPAA compliance for healthcare engagements, with policies, controls, and staff training aligned to the HIPAA Privacy and Security Rules.
These certifications are subject to periodic external audit and surveillance to confirm ongoing compliance.
How we protect information
We apply a layered set of safeguards to protect the information we hold, including:
- Encryption of data in transit and at rest.
- Role-based access controls, so staff can access only the information they need to perform their duties.
- Secure authentication, including multi-factor authentication for access to systems that hold sensitive data.
- Network security controls, monitoring, and logging.
- Regular staff training on data protection, information security, and, where relevant, HIPAA.
- Documented incident response and breach notification procedures.
No method of transmission or storage is completely secure. While we protect your information using measures appropriate to its sensitivity, we cannot guarantee absolute security.
How we share and disclose information
We share information only where it is necessary and permitted. This may include disclosures to:
- Service providers and subcontractors who support our operations or service delivery, and who are bound by confidentiality and, where PHI is involved, by a written agreement carrying the same obligations we hold.
- Clients to whom the relevant data belongs, as part of delivering the contracted services.
- Group companies within Elixir Global, where necessary to deliver services and administer our business, under appropriate safeguards.
- Legal and regulatory authorities where we are required to disclose information by law, regulation, court order, or valid legal process.
- Professional advisers such as auditors and legal counsel, where reasonably necessary and subject to confidentiality obligations.
We do not sell or rent personal information or Protected Health Information to any third party.
Data retention
We retain personal information and client data only for as long as necessary to fulfil the purposes described in this policy, to meet the terms of our client agreements, and to comply with legal, regulatory, and tax obligations. Retention of PHI is governed by the applicable Business Associate Agreement and by law. When information is no longer required, we dispose of it securely.
International data handling
Elixir Global operates across the Gulf, India, Singapore, and North America, and information may be accessed or processed in countries other than the one in which it was collected. Where information is transferred across borders, we put appropriate contractual and technical protections in place so that it continues to be handled in line with this policy, the applicable client agreement, and the data protection laws that apply in the regions where we operate.
Cookies and tracking technologies
Our website uses cookies and similar technologies to help the site function, to remember your preferences, and to understand how visitors use the site. You can control cookies through your browser settings. Disabling certain cookies may affect how parts of the website work. Where required by law, we ask for your consent before setting non-essential cookies.
Your rights and choices
Depending on where you are located and the law that applies to you, you may have rights over the personal information we hold about you, including the right to request access, correction, deletion, or restriction of its use, the right to object to certain processing, and the right to withdraw consent where processing is based on consent.
To exercise any of these rights in relation to information we hold about you directly, contact us using the details below. Requests relating to patient health information should be directed to the healthcare provider responsible for that patient, and we will support the provider as described in Healthcare data and HIPAA.
Third-party links
Our website may contain links to third-party sites. We are not responsible for the privacy practices or content of those sites. We encourage you to read the privacy policy of any site you visit through a link from ours.
Children's privacy
Our website and services are directed at businesses and are not intended for children. We do not knowingly collect personal information from children through our website.
Contact us
If you have questions about this policy or how we handle information, contact us:
Elixir GlobalEmail: privacy@elixirglobal.com
Contact form: elixirglobal.com/contact
11800 Amber Park Drive, Suite 225
Alpharetta, GA 30009
Changes to this policy
We may update this policy from time to time to reflect changes in our practices, technology, or legal obligations. When we make material changes, we will update the effective date at the top of this page and, where appropriate, provide additional notice. We encourage you to review this page periodically.
Security and Compliance
Built for regulated environments
Elixir Global works with enterprises across regulated and non-regulated sectors, including healthcare, financial services, and the public sector. The information our clients trust us with, from financial records to Protected Health Information, is protected by a documented security programme, independently audited certifications, and staff who are trained to handle sensitive data correctly.
Certifications and standards
ISO/IEC 27001
Our Information Security Management System is certified to ISO/IEC 27001. It covers how we identify and manage information security risk across our people, processes, and technology, and is subject to regular external audit.
ISO 9001:2015
Our Quality Management System is certified to ISO 9001:2015, covering the consistency, repeatability, and quality of the services we deliver to clients.
HIPAA compliance
For healthcare revenue cycle management engagements, we operate as a Business Associate under HIPAA. Our controls and training are aligned to the HIPAA Privacy and Security Rules, and we sign a Business Associate Agreement with each healthcare client.
Information security
Our security controls include:
- Encryption of data in transit and at rest.
- Role-based access, so staff reach only the data their work requires.
- Multi-factor authentication for access to systems holding sensitive data.
- Continuous monitoring, logging, and network security controls.
- Vulnerability management and periodic security testing.
- A documented incident response and breach notification process.
Data privacy
We handle personal and client data in line with the data protection laws that apply in the regions where we operate, across the Gulf, India, Singapore, and North America. For healthcare data, our obligations are set by the applicable Business Associate Agreement. We do not sell client data or Protected Health Information, and we share information only where it is necessary and permitted. Our full approach is set out in our Privacy Policy.
Business continuity
We maintain business continuity and disaster recovery plans so that critical services remain available and client data remains protected during disruption. Our global delivery model provides continuity across time zones and locations.
Governance and training
Security and compliance are owned at the leadership level and reviewed regularly. Every team member completes data protection and security training on joining and at regular intervals, with additional role-specific training for staff who handle regulated data.
Certifications at a glance
- ISO/IEC 27001, Information Security Management
- ISO 9001:2015, Quality Management
- HIPAA compliant for healthcare engagements
