Privacy Policy

OrcHealth is committed to protecting your privacy and handling personal data with transparency, security, and care under India's Digital Personal Data Protection Act.

Last updated: 24 August 2026

1.Introduction

This Privacy Policy describes how Vestcodes ("OrcHealth", "we", "us", "our") collects, uses, discloses, and protects personal information in connection with our Remote Patient Monitoring platform and related services (the "Services").

We handle personal data in accordance with India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") and other applicable Indian laws. This policy applies to all users of our Services, including patients, healthcare providers, and partners who enrol into monitoring programmes operated on our platform.

2.Information We Collect

We collect personal information you provide directly to us — including name, contact details, and health information supplied by your enrolling healthcare provider — as well as information generated by your use of the Services (session logs, device readings, care-team messages).

We also receive limited device telemetry from connected monitoring devices (e.g. blood-pressure cuffs, pulse oximeters, ECG patches) that has been paired to your account, along with technical information such as IP address, browser, and diagnostic logs used to keep the platform reliable.

Learn more about the data we collect

3.How We Use Information

We use personal information to provide and improve the Services, to monitor and route clinical signals on behalf of the healthcare provider that enrolled the patient, to communicate with users about their care and account, to secure the platform, and to fulfil legal and regulatory obligations.

We do not use personal or sensitive health data to train third-party AI models. Any internal analytics used to improve the platform operate on de-identified or aggregated data.

Learn more about how we use data

4.Data Sharing & Disclosure

We do not sell your personal information. We share data with the healthcare provider that enrolled you, with trusted processors acting on our documented instructions (hosting, communications, telemetry ingestion), and with authorities where we are legally required to do so.

Every processor is bound by written contracts covering confidentiality, purpose limitation, and security controls appropriate to the sensitivity of the data handled.

Learn more about data sharing

5.Data Security

We apply technical and organisational safeguards commensurate with the sensitivity of health information — including encryption in transit and at rest, role-based access controls, audit logging, and periodic reviews of our controls and dependencies.

No system can guarantee absolute security. We treat hardening as an ongoing programme rather than a one-time exercise, and we welcome disclosures from researchers who find issues in our stack.

6.Your Rights

Under the DPDP Act you have rights of access, correction, completion, updating, and erasure of your personal data, together with the right to nominate another individual and to grievance redressal.

You can exercise these rights, or contact our Grievance Officer, by writing to privacy@vestcodes.co. We aim to respond within the timelines set out under the DPDP Act.

7.Data Retention

We retain personal information only for as long as necessary to deliver the Services to your enrolling provider and to meet our legal, accounting, and regulatory obligations.

Retention periods vary by data category and are reviewed periodically. When personal data is no longer required, it is deleted or irreversibly de-identified.

8.Cookies & Tracking

Our public website uses a small number of cookies for essential functionality (session, security, preferences) and to understand aggregate usage patterns. We do not use cross-site advertising cookies.

You can control non-essential cookies through your browser settings. Turning them off will not affect access to any part of the Services you already use.

9.International Transfers

Personal data collected through the Services is primarily stored and processed on infrastructure located in India. Where a limited cross-border transfer is required — for example, to a specific engineering support tool — it is carried out only in accordance with the DPDP Act and any conditions notified by the Central Government.

We publish the list of sub-processors we rely on and update it before onboarding new ones that process personal data.

10.Children's Privacy

The DPDP Act defines a child as an individual under the age of eighteen. Where a monitoring programme includes a child, we process personal data only after verifiable consent from the parent or lawful guardian, and only for purposes that are not detrimental to the well-being of the child.

We do not undertake tracking, behavioural monitoring for advertising, or targeted advertising directed at children.

11.Changes to This Policy

We may update this policy from time to time to reflect changes in our practices, our platform, or in the law. When we do, we will update the "Last updated" date at the top of this page and, where the change is significant, notify enrolling providers so they can inform their patients.

12.Contact Us

Questions about this policy, or requests to exercise your rights under the DPDP Act, can be sent to privacy@vestcodes.co.

Our registered office is Vestcodes, Imlichatti, Muzaffarpur, Bihar 842001, India. Postal correspondence should be marked to the attention of the Grievance Officer.

Questions about this policy?
If you have any questions or concerns about this Privacy Policy or how we handle your data, please contact us.
Contact Us