Legal
Privacy Policy
Effective date: 03 June 2026. Last reviewed: 03 June 2026. Version 1.0.
1. Who this policy is about
This Privacy Policy applies to information collected by RevenueLink LLP (“RevenueLink”, “we”, “our”), a Limited Liability Partnership incorporated under the Indian Limited Liability Partnership Act, 2008, with its registered office at Myworkarea, 24, Benaka Complex, 3rd Floor, Sirur Park Road, Seshadripuram, Bangalore — 560022, Karnataka, India.
This policy governs (a) information you submit through this website (revenuelinkllp.com and its sub-paths) and (b) RevenueLink's general approach to personal-data handling at the corporate entity layer.
2. What we collect through this website
The website collects only what you choose to submit. We do not run third-party advertising trackers. We do not sell information to anyone.
- Contact form submissions. Name, corporate email, organisation, role, topic of enquiry, and the message you write.
- Careers form submissions. Name, email, phone number, primary certification, years of HCC experience, current city, uploaded resume, and any optional note you add.
- Server access logs. Standard webserver logs (IP address, user-agent, request timestamps), retained for not more than 90 days for security and operational diagnostics.
- Cookies. The website uses only essential cookies required for basic functioning (e.g., remembering the mobile-menu state during your session). We do not deploy advertising, behavioural, or third-party analytics cookies.
3. How we use the information
- To respond to your enquiry. Contact-form submissions are routed to the named owner of the topic you selected and are responded to within two business days.
- To evaluate your application. Careers-form submissions are routed to the recruitment team for review against published role minima.
- To improve the website. Server logs are used for diagnostics only, and only by RevenueLink personnel.
We do not use submitted information for marketing or promotional outreach without your explicit consent.
4. Engagement-layer data (PHI and client data)
This Privacy Policy does not govern the handling of Protected Health Information (“PHI”) or client operational data processed in the course of an active client engagement. That handling is governed by the engagement's Master Service Agreement and the executed Business Associate Agreement (“BAA”), and is structurally constrained as follows:
- Engagement perimeter. PHI does not leave the engagement perimeter agreed in the BAA. Under the on-site delivery model, team members operate on the client's infrastructure inside the client's facility; under the in-house delivery model, team members access the client's systems from RevenueLink's HIPAA-compliant Bangalore production facility through controlled channels (site-to-site VPN, SFTP, or REST API over TLS 1.2 or higher) with no local storage of PHI on endpoints.
- HIPAA / HITECH alignment. Every deployed team member undergoes onboarding HIPAA training, annual refresher training, and signs a personal binding confidentiality undertaking before floor or system access. Sanction policy applies to violations.
- Minimum necessary. Access to PHI is scoped per-engagement, role-based, and limited to the smallest set of named team members required to perform the contracted services.
- Audit logging. Access to client systems is logged and reviewable. Logs are retained for the period specified in the engagement contract.
- Incident response. Suspected breaches are escalated through the channels and timelines specified in the BAA, with notification to the client's designated security or compliance officer within HIPAA-aligned windows.
5. Indian DPDPA, 2023
For personal data of individuals located in India, RevenueLink operates under the framework of the Indian Digital Personal Data Protection Act, 2023 (“DPDPA”), in addition to any sector-specific obligations.
- Lawful purpose. Personal data submitted via this website is processed for the specific purpose stated at the point of collection (responding to your enquiry; evaluating your application).
- Your rights. Subject to the conditions in the DPDPA, you have the right to access, correct, and erase the personal data you have submitted, and the right to withdraw consent for its continued processing. Contact us at privacy@revenuelinkllp.com to exercise any of these rights.
- Retention. Contact-form data is retained for up to 24 months unless an active engagement requires longer retention. Careers-form data is retained for up to 12 months after the application is closed, after which it is deleted or anonymised. You may request earlier deletion at any time.
- Data Protection contact. privacy@revenuelinkllp.com
6. International transfers
For enquiries originating outside India, your submitted information is stored on infrastructure located in India. Where a client engagement requires data residency outside India, the arrangement is governed by the engagement's MSA and BAA and is not handled through this website's forms.
7. Security
Form submissions are transmitted over TLS. Access to submitted information at the entity layer is restricted, on a least-privilege basis, to the smallest set of RevenueLink personnel necessary to act on the enquiry. Resume uploads are stored only for the period required to evaluate the application and are then deleted or anonymised.
8. Children
This website is not directed at, and does not knowingly collect information from, children under the age of 18.
9. Changes
We may revise this Privacy Policy from time to time. Revisions take effect from the date posted at the top of this page. Material changes will be flagged on this page for a minimum of 30 calendar days from the date of revision.
10. Contact
For privacy questions, data-subject requests, or breach notifications affecting submitted website data, write to privacy@revenuelinkllp.com. For HIPAA / BAA-related matters arising out of an active engagement, follow the contact protocol specified in the engagement's BAA.