Legal
Upstream Privacy Policy
Version: 1.0
Effective date: 2026-07-10
Last updated: 2026-07-11
This Privacy Policy explains how ByteWorthy LLC, a Texas limited liability company offering the Upstream service ("Upstream," "we," "us," or "our"), collects, uses, discloses, and protects personal information. It applies to the Upstream websites, applications, APIs, support channels, and related services (the "Service").
This Policy is a notice, not a Business Associate Agreement. Protected Health Information ("PHI") that Upstream processes for a healthcare organization is governed by that organization's Business Associate Agreement ("BAA") with Upstream and the organization's own privacy practices.
1. Roles and Scope
Upstream acts as a business or controller for account administration, billing administration, website operations, security, and its direct business communications. Upstream acts as a service provider or processor when it processes personal information on a customer's documented instructions. The Data Processing Addendum ("DPA") governs that processor activity for non-PHI personal data. The BAA governs PHI.
The Service is intended for organizations and their authorized workforce, not for personal, family, or household use. It is not directed to children under 18.
2. Information We Collect
Depending on how a person or organization uses the Service, Upstream may collect:
- Account and organization information: name, work email, title, role, organization name, organization identifiers, NPI, authentication settings, and team membership.
- Commercial and billing information: selected plan, subscription status, transaction references, invoice and usage information, and Stripe customer and tokenized payment references. Payment entry and management occur through Stripe-hosted checkout and billing portal surfaces; Upstream does not receive or store full payment-card numbers.
- Customer operations data: payer, provider, procedure, authorization, claim, evidence, workflow, integration, approval, transmission, and outcome information submitted by or obtained on instructions from a customer.
- PHI: patient or member information needed to provide contracted healthcare operations services after the BAA gate is satisfied.
- Device, usage, and security information: IP address, browser and device attributes, timestamps, pages or features used, authentication events, audit events, diagnostics, and security telemetry.
- Communications: support requests, business correspondence, feedback, and records of legal or operational notices.
- Public demo information: business contact and non-PHI workflow details intentionally entered into a demo or lead form. Public forms are not authorized for PHI.
3. Sources
Upstream receives information directly from users and customers; from systems a customer connects, such as EHR, payer, clearinghouse, or payment services; from service providers acting for Upstream; and from security, analytics, and communications systems used to operate the Service.
4. How We Use Information
Upstream uses personal information to:
- create and administer accounts and workspaces;
- provide, secure, support, and troubleshoot the Service;
- perform customer-approved payer and healthcare operations workflows;
- process subscriptions, invoices, and usage charges;
- authenticate users, prevent fraud and abuse, and investigate incidents;
- communicate about the Service, support, security, and legal updates;
- comply with law, enforce agreements, and establish or defend legal claims; and
- evaluate and improve the Service using information permitted by the applicable agreement.
Upstream does not sell personal information. Upstream does not share personal information for cross-context behavioral advertising. Upstream does not use identifiable PHI to train models shared across customers.
5. PHI and Healthcare Data
Upstream processes PHI only for a customer under an effective BAA and only to provide the services and follow instructions permitted by that BAA. PHI is subject to tenant access controls, encryption, audit controls, and fail-closed restrictions on external processing.
Patients and plan members should direct HIPAA access, amendment, restriction, or accounting requests to the healthcare organization that controls their record. Upstream assists that organization as required by the BAA. Upstream is not the healthcare provider or health plan and does not independently decide treatment, coverage, or payment.
Public marketing forms, demos, and non-PHI model lanes must not receive PHI.
6. Disclosures
Upstream may disclose personal information:
- to subprocessors that provide infrastructure, payments, communications, analytics, monitoring, AI, and healthcare transaction services under contract;
- to payer, provider, EHR, clearinghouse, portal, or other recipients a customer directs Upstream to contact;
- within a customer's workspace according to customer-configured roles;
- in connection with a merger, financing, reorganization, or sale, subject to appropriate confidentiality and continued protection;
- when required by law or a valid legal process; or
- when reasonably necessary to protect rights, safety, security, and service integrity.
The Subprocessor List, version 1.0 effective July 10, 2026, identifies Upstream's current service providers and their functions. A provider may process PHI only when the BAA permits it and the required written protections are in force.
7. Cookies and Analytics
Upstream uses cookies and similar local technologies needed for authentication, security, session continuity, and preferences. Upstream may use privacy-configured analytics on public and product surfaces to understand aggregate usage and diagnose problems. Analytics events are not authorized to contain PHI. Upstream does not use them to build third-party advertising profiles.
Browser controls can block or remove nonessential cookies. Blocking essential authentication or security storage may prevent parts of the Service from working.
8. Retention and Deletion
Upstream retains information for the period needed to provide the Service, maintain security and audit evidence, comply with the Services Agreement and applicable law, resolve disputes, and enforce agreements.
- Customer operations data and PHI are returned, deleted, or protected after termination as stated in the BAA, DPA, and order form.
- Account, billing, legal acceptance, security, and audit records may be retained for applicable legal, tax, fraud-prevention, contract, and compliance periods.
- Transient workflow content is deleted or cleared according to the Service's documented lifecycle.
- Deleted data may remain in protected backups until the backup lifecycle expires and is not restored except for disaster recovery or legal necessity.
A legal hold or binding legal requirement may extend a retention period. Upstream will retain only the information reasonably necessary for that purpose.
9. Security
Upstream uses administrative, technical, and organizational safeguards designed for the nature of the information, including encryption in transit and for designated sensitive fields at rest, role-based access, tenant scoping, audit logging, secret management, and incident response. No system can guarantee absolute security.
Report suspected security issues to security@upstream.cx. Do not include PHI or credentials in an unencrypted report.
10. Privacy Choices and Requests
Depending on applicable law and Upstream's role, a person may request access, correction, deletion, or a copy of personal information, or may object to or restrict certain processing. Send a request to privacy@upstream.cx. Upstream may verify identity and authority before acting and may retain information where an exception or legal duty applies.
For information Upstream processes only for a customer, Upstream may refer the request to that customer and assist under the DPA or BAA. Authorized users can update certain account information through the Service.
11. United States Service and International Use
Upstream is operated by a United States company. The Service has not been contractually cleared for international transfers merely because this Policy or the DPA exists. A customer that intends to transfer personal data governed by the laws of the European Economic Area, United Kingdom, Switzerland, or another jurisdiction requiring a transfer mechanism must arrange the required transfer terms with Upstream before that transfer.
12. Changes
Upstream may update this Policy as its practices, Service, or legal obligations change. The version and effective date identify the current notice. Upstream will provide reasonable notice of a material change and obtain a new contractual acceptance where the Terms or another acceptance gate requires it.
13. Contact
Privacy questions and requests: privacy@upstream.cx
Legal notices: legal@upstream.cx
Security reports: security@upstream.cx
ByteWorthy LLC
220 Town Park Avenue
Princeton, TX 75407-9846
United States
End of Privacy Policy version 1.0.