This notice applies to vigiams.com, beta.vigiams.com,
the VigiAMS Android app (com.vigiams.amsp), and the VigiAMS API
at vigiams.com/api/v1/.
Who we are
- Operator
- Radhakripa Medtech Pvt Ltd
- Registered address
- No. 93/2, 2nd Cross Road, Pipeline Road, Anjananagar, Viswaneedam, Bangalore North, Bangalore - 560091, Karnataka, India
- Privacy contact
- admin@vigiams.com
We are a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (the "DPDP Act"). This notice explains, in plain language, what personal data we collect, why we collect it, who we share it with, and your rights.
If you are accessing the platform on behalf of a hospital, the hospital is the primary Data Fiduciary for the patient data they upload. VigiAMS acts as a Data Processor on the hospital's instructions, governed by a written Data Processing Agreement under the DPDP Act (a HIPAA-style Business Associate Agreement is available on request).
What personal data we collect
From hospital staff (you, the user)
| Category | Examples |
|---|---|
| Identity | Full name, role, hospital affiliation |
| Account | Username, hashed password (Argon2id, PBKDF2-SHA256 fallback), TOTP MFA seed |
| Contact | Work email, optional work phone |
| Activity audit | Login timestamps, IP address, user-agent, every action taken in the app, hash-chained to detect tampering |
From patient data uploaded by hospitals (PHI)
| Category | Examples |
|---|---|
| Patient identifier | Hospital-assigned MRN, ward, sex, age |
| Specimen + culture | Sample type, organism, antibiogram, MIC values, susceptibility |
| Clinical context | Antibiotic prescriptions, duration, indication, outcome |
We do not collect: caste, religion, sexual orientation, financial information, government IDs (Aadhaar/PAN), biometrics.
From the mobile app
In addition to the categories above, the Android app may collect:
- Device identifier (push notifications + session pinning)
- Crash logs, anonymised, sent to Azure Application Insights in
centralindia - App-version + OS-version metadata
We do not access: contacts, photos, location, calendar, microphone, camera, SMS, or any data outside the app's own sandbox.
Why we collect it
Under DPDP §6, we process personal data only for the purposes listed here. We will not use it for any other purpose without obtaining fresh consent.
| Purpose | Legal basis |
|---|---|
| Provide antimicrobial stewardship + surveillance services to your hospital | DPDP §6(1) |
| Authenticate users + enforce role-based access | DPDP §6(1) |
| Audit logging under Indian medical-records / clinical-establishment rules (HIPAA Security Rule controls followed as a voluntary benchmark only) | Legal obligation (Indian law) |
| Breach detection + incident response | Protection of data principal |
| Send transactional alerts (e.g. break-glass access notifications) | DPDP §6(1) |
| Aggregated, fully de-identified AMR statistics for ICMR / WHO surveillance | DPDP §17 — research/statistics |
We do not use personal data for marketing, profiling, or sale to third parties. We do not run advertising on the platform.
How we keep it secure
Technical safeguards
- Encryption at rest: Sensitive fields are encrypted with AES-256-GCM envelope encryption; the data-encryption key is wrapped by a key held in Azure Key Vault. All managed storage (database, blob) is additionally encrypted at the platform layer.
- Encryption in transit: TLS 1.2+ everywhere (HSTS 1-year + includeSubDomains), terminated behind Azure Front Door
- Edge protection: Azure Front Door with a Web Application Firewall (WAF) in front of the application
- Authentication: Argon2id password hashing (with PBKDF2-SHA256 fallback; legacy hashes auto-upgraded on next login) and mandatory TOTP multi-factor authentication enforced on every account
- Access control: Role-based permissions, hospital-tenant isolation, time-boxed break-glass emergency access (always logged)
- Audit trail: Hash-chained ISO 27789-style audit log with a SHA-256 chain to detect tampering, 10-year retention, archived to object storage with content-hash sealing; immutability is enforced by a storage-level retention policy where configured
- Malware scanning: Uploaded files are scanned with ClamAV (where configured) plus an EICAR sentinel test; infected files are rejected and never executed
- Region pinning: All personal-data processing stays in
Indian Azure regions (Pune, Chennai), enforced both in application code
(
assert_dpdp_residency) and at the cloud-resource layer
Organisational safeguards
- Designated Data Protection Officer (see below)
- Documented breach response with 72-hour Data Protection Board notification
- Workforce training on PHI handling
- Sanctions policy for staff who violate privacy controls
- Annual third-party security assessment (planned)
Where your data lives (residency)
All personal data is stored and processed within India under DPDP §16.
| Service | Region | Hosted by |
|---|---|---|
| Application servers (Container Apps) | Central India (Pune) | Microsoft Azure |
| Database (PostgreSQL Flexible Server) | Central India (Pune) | Microsoft Azure |
| Cache (Redis) | Central India (Pune) | Microsoft Azure |
| Key management (Key Vault) | Central India (Pune) | Microsoft Azure |
| Object storage (Blob) | Central India (Pune) | Microsoft Azure |
| Document parsing (AI Document Intelligence) | Central India (Pune) | Microsoft Azure |
| AI inference (Azure OpenAI, GPT-4o) | South India (Chennai)* | Microsoft Azure |
| Email delivery (Communication Services) | India (data-location pinned) | Microsoft Azure |
| App telemetry (Application Insights + Log Analytics) | Central India (Pune) | Microsoft Azure |
| Edge / WAF (Front Door) | Global edge — no PHI stored or processed at the edge | Microsoft Azure |
* Azure OpenAI (GPT-4o) is currently only available in
southindia; both centralindia and
southindia are Indian Azure regions. Document Intelligence and
all storage of personal data remain in centralindia (Pune).
The Front Door edge layer terminates TLS and applies the WAF only — it
does not store or process personal data.
We do not transfer your data outside India. The DPDP Act §16 cross-border transfer mechanism (whitelisted countries) is currently not invoked.
Sub-processors
A "sub-processor" is a third party we use to deliver part of the service. We sign a DPA / BAA with every sub-processor.
The current list is maintained at /sub-processors — we will email account holders at least 30 days before adding any new sub-processor.
Retention
| Data category | Retention | Reason |
|---|---|---|
| Audit events | 10 years | Indian Clinical Establishments Act / medical-records rules (HIPAA §164.316(b)(2) followed as a voluntary control benchmark) |
| Patient lab results (PHI) | 10 years | Same as above |
| User account records | Until deletion + 6 months grace | Audit + dispute resolution |
| Login session cookies | 10–20 min role-based idle / 45 min absolute | Security baseline |
| Breach incident records | 10 years | DPDP §8(6) (HIPAA §164.404 breach-record controls followed as a voluntary benchmark) |
| De-identified statistics | Indefinite | No longer personal data |
After the retention period, data is automatically purged or de-identified. The audit-archive blob storage is immutable for 10 years even to administrators.
Your rights as a Data Principal
Under DPDP §11–14 you have the right to:
| Right | What it means | How to exercise |
|---|---|---|
| Access | Get a copy of your personal data | Email admin@vigiams.com or use Data Rights in the app |
| Correction | Fix inaccurate data | Same channels |
| Erasure | Delete your data (subject to retention) | Same channels |
| Withdraw consent | Stop us processing your data | Same channels |
| Grievance | Complain about how we handle data | See below |
| Nominate | Designate a person to exercise rights on your behalf | Same channels |
We respond within 30 days. For patient-PHI requests we may direct you to your hospital (the primary Data Fiduciary).
Data Protection Officer
- Name
- Vishal T
- admin@vigiams.com
- Phone
- +91 94819 54900
- Postal address
- No. 93/2, 2nd Cross Road, Pipeline Road, Anjananagar, Viswaneedam, Bangalore North, Bangalore - 560091, Karnataka, India
The DPO monitors our compliance with the DPDP Act, advises on data protection risks, and is the contact point for the Data Protection Board of India.
Grievance Officer
- Name
- Vishal T
- admin@vigiams.com
- Phone
- +91 94819 54900
- Postal address
- No. 93/2, 2nd Cross Road, Pipeline Road, Anjananagar, Viswaneedam, Bangalore North, Bangalore - 560091, Karnataka, India
If you have a complaint about how we handle your personal data, contact the Grievance Officer first. We will respond within 15 days under DPDP §13(3). If you remain dissatisfied, you may escalate to the Data Protection Board of India.
Children's data
VigiAMS is a clinical surveillance platform — we do not knowingly collect personal data from children directly. Where pediatric patient data is uploaded by a hospital, the hospital obtains verifiable parental/guardian consent before processing under DPDP §9. We process such data only for the same clinical-stewardship purposes. We do not target advertising, behavioural monitoring, or tracking at children — none of which exist in our platform regardless of age.
Cookies + tracking
We use the minimum cookies necessary:
| Cookie | Purpose | Lifetime | Type |
|---|---|---|---|
session | Authenticated session + CSRF token | 10–20 min role-based idle / 45 min absolute | Strictly necessary |
We do not use third-party tracking, advertising cookies, cross-site analytics (no Google Analytics), or behavioural fingerprinting.
Changes to this notice
When we make material changes:
- We update this notice with a new "Last updated" date
- We email all account holders 30 days in advance
- We log the change in our public changelog
- For changes affecting consent, we re-prompt for fresh consent in the app
We will not retroactively apply changes to data already collected under the prior notice.
Change history
| Date | Change | Type |
|---|---|---|
| 16 May 2026 | Accuracy corrections to align this notice with the platform as actually deployed: encryption description clarified (AES-256-GCM envelope encryption with the data key wrapped by a key in Azure Key Vault; the earlier "HSM" wording was removed); password hashing stated as Argon2id with PBKDF2-SHA256 fallback; audit-archive wording changed from "immutable WORM, undeletable" to content-hash sealing with retention enforced by storage-level policy where configured; session timeout corrected to 10–20 min role-based idle / 45 min absolute; data-residency table updated to list every deployed Azure service and region; email provider stated as Azure Communication Services (the GoDaddy / Zoho email references were removed as inaccurate); HIPAA references re-characterised as a voluntary control benchmark rather than an Indian legal obligation. | Corrective & clarifying — not an adverse material change |
The 16 May 2026 revisions are corrections that make this notice more accurate; they neither expand the data we collect nor reduce your rights. Because they are not adverse material changes, they take effect on publication and do not require fresh consent or the 30-day advance email reserved for material changes. They are recorded here for transparency.
Contact us
- Privacy
- admin@vigiams.com
- DPO
- admin@vigiams.com
- Grievance
- admin@vigiams.com
- Security
- admin@vigiams.com
- 24/7 incident hotline
- +91 94819 54900
- Postal address
- No. 93/2, 2nd Cross Road, Pipeline Road, Anjananagar, Viswaneedam, Bangalore North, Bangalore - 560091, Karnataka, India
- Hours
- Mon–Fri, 10:00–18:00 IST
This notice is provided in compliance with §5 of the Digital Personal Data Protection Act, 2023. Where this notice conflicts with the Data Processing Agreement between VigiAMS and your hospital, that agreement governs the patient-PHI portion. For your own personal data (as a user), this notice always applies.