Can a data engineering company based in India work with a US healthcare client under HIPAA?
Yes, and we do. Geography does not determine HIPAA compliance — controls do. We work inside your own cloud tenancy under a Business Associate Agreement where one is required, with least-privilege access, encryption in transit and at rest, full audit logging, and masked data in every non-production environment. Our healthcare delivery includes an Azure platform unifying 12 EMR sources at 99.9% uptime.
How does GDPR work when the data processor sits outside the EU?
Two answers. Contractually, transfers outside the EEA are governed by Standard Contractual Clauses with supplementary technical measures. Practically, most of our EU engagements never raise the question: we work inside the client's own EU-region cloud tenancy, so personal data stays where it already is and we hold access rather than copies. EU delivery is led from our Dublin office.
What working-hour overlap can we actually expect with our team?
We commit to named overlap hours in the contract rather than claiming 24/7 in the abstract. Dublin covers UK and European hours; Sydney covers Australia and New Zealand; Dubai covers the GCC; Bangkok covers ASEAN; Bengaluru, Delhi and Hyderabad overlap the European morning and the full Gulf and Asia-Pacific day. For North American clients we staff a guaranteed overlap window in your morning and schedule demos inside it.
Which legal entity holds the contract, and can you pass our procurement process?
Contracts are held by Vipra Software Private Limited, registered in India, unless a regional arrangement is agreed during scoping. We complete standard enterprise vendor onboarding as a matter of course: NDA before any data discussion, security questionnaires (SIG, CAIQ, or your own format), insurance documentation, and background verification for engineers on regulated work.
Can you meet data residency requirements in the EU, UK, GCC, or Australia?
Yes. Default delivery is inside your cloud tenancy in the region you choose, so the data does not move. Where residency also constrains who may access an environment — EU-only or India-only staffing, for example — we staff from the matching region and record that constraint in the engagement agreement.
Do you have an office in our country?
Probably not, and we will not pretend otherwise. We keep eight offices: Bengaluru (HQ), Muzaffarpur, New Delhi, Hyderabad, Dublin, Sydney, Dubai, and Bangkok. Everywhere else across our 30 priority markets is service coverage — remote-first delivery with timezone-aligned hours, staffed by the same senior engineers. A local address you cannot visit helps nobody.
What currency do you invoice in, and how is tax handled?
Proposals are quoted in USD as standard. If procurement requires another currency, raise it during scoping and we will quote accordingly. Indian GST treatment for exported services, and any withholding tax applicable in your jurisdiction, are set out explicitly in the contract so there are no surprises at invoice stage.
We have never worked with an overseas vendor before. How does this start?
With a small, reversible step. Most first engagements begin as a two-to-four week assessment that produces an architecture review and a costed roadmap you own outright — useful to you even if you never hire us again. Security review and NDA run in parallel. Nothing about a first engagement should require betting a quarter on a supplier you have not worked with.