Legal

Privacy Notice

Last updated: 16 May 2026  ·  Effective date: 16 May 2026

This notice applies to vigiams.com, beta.vigiams.com, the VigiAMS Android app (com.vigiams.amsp), and the VigiAMS API at vigiams.com/api/v1/.

Who we are

Operator
Radhakripa Medtech Pvt Ltd
Registered address
No. 93/2, 2nd Cross Road, Pipeline Road, Anjananagar, Viswaneedam, Bangalore North, Bangalore - 560091, Karnataka, India
Privacy contact
admin@vigiams.com

We are a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (the "DPDP Act"). This notice explains, in plain language, what personal data we collect, why we collect it, who we share it with, and your rights.

If you are accessing the platform on behalf of a hospital, the hospital is the primary Data Fiduciary for the patient data they upload. VigiAMS acts as a Data Processor on the hospital's instructions, governed by a written Data Processing Agreement under the DPDP Act (a HIPAA-style Business Associate Agreement is available on request).

What personal data we collect

From hospital staff (you, the user)

CategoryExamples
IdentityFull name, role, hospital affiliation
AccountUsername, hashed password (Argon2id, PBKDF2-SHA256 fallback), TOTP MFA seed
ContactWork email, optional work phone
Activity auditLogin timestamps, IP address, user-agent, every action taken in the app, hash-chained to detect tampering

From patient data uploaded by hospitals (PHI)

CategoryExamples
Patient identifierHospital-assigned MRN, ward, sex, age
Specimen + cultureSample type, organism, antibiogram, MIC values, susceptibility
Clinical contextAntibiotic prescriptions, duration, indication, outcome

We do not collect: caste, religion, sexual orientation, financial information, government IDs (Aadhaar/PAN), biometrics.

From the mobile app

In addition to the categories above, the Android app may collect:

We do not access: contacts, photos, location, calendar, microphone, camera, SMS, or any data outside the app's own sandbox.

Why we collect it

Under DPDP §6, we process personal data only for the purposes listed here. We will not use it for any other purpose without obtaining fresh consent.

PurposeLegal basis
Provide antimicrobial stewardship + surveillance services to your hospitalDPDP §6(1)
Authenticate users + enforce role-based accessDPDP §6(1)
Audit logging under Indian medical-records / clinical-establishment rules (HIPAA Security Rule controls followed as a voluntary benchmark only)Legal obligation (Indian law)
Breach detection + incident responseProtection of data principal
Send transactional alerts (e.g. break-glass access notifications)DPDP §6(1)
Aggregated, fully de-identified AMR statistics for ICMR / WHO surveillanceDPDP §17 — research/statistics

We do not use personal data for marketing, profiling, or sale to third parties. We do not run advertising on the platform.

How we keep it secure

Technical safeguards

Organisational safeguards

Where your data lives (residency)

All personal data is stored and processed within India under DPDP §16.

ServiceRegionHosted by
Application servers (Container Apps)Central India (Pune)Microsoft Azure
Database (PostgreSQL Flexible Server)Central India (Pune)Microsoft Azure
Cache (Redis)Central India (Pune)Microsoft Azure
Key management (Key Vault)Central India (Pune)Microsoft Azure
Object storage (Blob)Central India (Pune)Microsoft Azure
Document parsing (AI Document Intelligence)Central India (Pune)Microsoft Azure
AI inference (Azure OpenAI, GPT-4o)South India (Chennai)*Microsoft Azure
Email delivery (Communication Services)India (data-location pinned)Microsoft Azure
App telemetry (Application Insights + Log Analytics)Central India (Pune)Microsoft Azure
Edge / WAF (Front Door)Global edge — no PHI stored or processed at the edgeMicrosoft Azure

* Azure OpenAI (GPT-4o) is currently only available in southindia; both centralindia and southindia are Indian Azure regions. Document Intelligence and all storage of personal data remain in centralindia (Pune). The Front Door edge layer terminates TLS and applies the WAF only — it does not store or process personal data.

We do not transfer your data outside India. The DPDP Act §16 cross-border transfer mechanism (whitelisted countries) is currently not invoked.

Sub-processors

A "sub-processor" is a third party we use to deliver part of the service. We sign a DPA / BAA with every sub-processor.

The current list is maintained at /sub-processors — we will email account holders at least 30 days before adding any new sub-processor.

Retention

Data categoryRetentionReason
Audit events10 yearsIndian Clinical Establishments Act / medical-records rules (HIPAA §164.316(b)(2) followed as a voluntary control benchmark)
Patient lab results (PHI)10 yearsSame as above
User account recordsUntil deletion + 6 months graceAudit + dispute resolution
Login session cookies10–20 min role-based idle / 45 min absoluteSecurity baseline
Breach incident records10 yearsDPDP §8(6) (HIPAA §164.404 breach-record controls followed as a voluntary benchmark)
De-identified statisticsIndefiniteNo longer personal data

After the retention period, data is automatically purged or de-identified. The audit-archive blob storage is immutable for 10 years even to administrators.

Your rights as a Data Principal

Under DPDP §11–14 you have the right to:

RightWhat it meansHow to exercise
AccessGet a copy of your personal dataEmail admin@vigiams.com or use Data Rights in the app
CorrectionFix inaccurate dataSame channels
ErasureDelete your data (subject to retention)Same channels
Withdraw consentStop us processing your dataSame channels
GrievanceComplain about how we handle dataSee below
NominateDesignate a person to exercise rights on your behalfSame channels

We respond within 30 days. For patient-PHI requests we may direct you to your hospital (the primary Data Fiduciary).

Data Protection Officer

Name
Vishal T
Email
admin@vigiams.com
Phone
+91 94819 54900
Postal address
No. 93/2, 2nd Cross Road, Pipeline Road, Anjananagar, Viswaneedam, Bangalore North, Bangalore - 560091, Karnataka, India

The DPO monitors our compliance with the DPDP Act, advises on data protection risks, and is the contact point for the Data Protection Board of India.

Grievance Officer

Name
Vishal T
Email
admin@vigiams.com
Phone
+91 94819 54900
Postal address
No. 93/2, 2nd Cross Road, Pipeline Road, Anjananagar, Viswaneedam, Bangalore North, Bangalore - 560091, Karnataka, India

If you have a complaint about how we handle your personal data, contact the Grievance Officer first. We will respond within 15 days under DPDP §13(3). If you remain dissatisfied, you may escalate to the Data Protection Board of India.

Children's data

VigiAMS is a clinical surveillance platform — we do not knowingly collect personal data from children directly. Where pediatric patient data is uploaded by a hospital, the hospital obtains verifiable parental/guardian consent before processing under DPDP §9. We process such data only for the same clinical-stewardship purposes. We do not target advertising, behavioural monitoring, or tracking at children — none of which exist in our platform regardless of age.

Cookies + tracking

We use the minimum cookies necessary:

CookiePurposeLifetimeType
sessionAuthenticated session + CSRF token10–20 min role-based idle / 45 min absoluteStrictly necessary

We do not use third-party tracking, advertising cookies, cross-site analytics (no Google Analytics), or behavioural fingerprinting.

Changes to this notice

When we make material changes:

  1. We update this notice with a new "Last updated" date
  2. We email all account holders 30 days in advance
  3. We log the change in our public changelog
  4. For changes affecting consent, we re-prompt for fresh consent in the app

We will not retroactively apply changes to data already collected under the prior notice.

Change history

DateChangeType
16 May 2026 Accuracy corrections to align this notice with the platform as actually deployed: encryption description clarified (AES-256-GCM envelope encryption with the data key wrapped by a key in Azure Key Vault; the earlier "HSM" wording was removed); password hashing stated as Argon2id with PBKDF2-SHA256 fallback; audit-archive wording changed from "immutable WORM, undeletable" to content-hash sealing with retention enforced by storage-level policy where configured; session timeout corrected to 10–20 min role-based idle / 45 min absolute; data-residency table updated to list every deployed Azure service and region; email provider stated as Azure Communication Services (the GoDaddy / Zoho email references were removed as inaccurate); HIPAA references re-characterised as a voluntary control benchmark rather than an Indian legal obligation. Corrective & clarifying — not an adverse material change

The 16 May 2026 revisions are corrections that make this notice more accurate; they neither expand the data we collect nor reduce your rights. Because they are not adverse material changes, they take effect on publication and do not require fresh consent or the 30-day advance email reserved for material changes. They are recorded here for transparency.

Contact us

Privacy
admin@vigiams.com
DPO
admin@vigiams.com
Grievance
admin@vigiams.com
Security
admin@vigiams.com
24/7 incident hotline
+91 94819 54900
Postal address
No. 93/2, 2nd Cross Road, Pipeline Road, Anjananagar, Viswaneedam, Bangalore North, Bangalore - 560091, Karnataka, India
Hours
Mon–Fri, 10:00–18:00 IST

This notice is provided in compliance with §5 of the Digital Personal Data Protection Act, 2023. Where this notice conflicts with the Data Processing Agreement between VigiAMS and your hospital, that agreement governs the patient-PHI portion. For your own personal data (as a user), this notice always applies.