1. Scope & Privacy Commitment
Vantis Health Private Limited ("Vantis Health", "we", "us") is dedicated to protecting the privacy and confidentiality of individuals who visit vantishealth.org or engage our international healthcare concierge services. This Privacy Policy governs our data handling practices globally and adheres to the European Union General Data Protection Regulation (GDPR), the UK GDPR, the United States Health Insurance Portability and Accountability Act (HIPAA) Security Principles, and Indiaβs Digital Personal Data Protection (DPDP) Act 2023.
2. Data Controller & Data Protection Officer (DPO)
Vantis Health Private Limited serves as the primary Data Controller for personal data processed through our web portal and administrative desks.
We have designated a dedicated Data Protection Officer (DPO) to oversee legal compliance and respond to patient privacy requests:
Vantis Health Private Limited
Diplomatic Enclave, Chanakyapuri, New Delhi - 110021, India
Email:
dpo@vantishealth.org | privacy@vantishealth.org
3. Information We Collect
To provide high-accuracy medical estimates and travel coordination, we collect the following categories of information:
A. Personal Identifiable Information (PII)
- Full Legal Name, Date of Birth, Gender, and Contact Information (Email, Phone Number, WhatsApp Number).
- Country of Residence, Nationality, Passport Copy (strictly for e-Medical Visa processing).
- Emergency Contact details and companion travel details.
B. Protected Health Information (PHI) & Sensitive Personal Data
- Medical History, Current Symptoms, Prescriptions, Allergies, and Primary Physician Notes.
- Diagnostic Radiology Scans (MRI, CT Scans, X-rays, DICOM files) and Laboratory Blood Work.
- Surgeon Second Opinion reviews and hospital cost estimates generated by accredited specialists.
C. Technical & Usage Data
- IP address, browser type, device identifiers, time zone setting, operating system, and interaction telemetry.
4. Legal Basis for Processing Health Data
Under global data protection laws (including GDPR Art. 6 & 9 and DPDP Act 2023 Sec. 6), we process your sensitive health data only under explicit lawful grounds:
- Explicit Consent: You provide clear, affirmative consent when submitting diagnostic records via our intake forms for case evaluation.
- Performance of Facilitation Agreement: Processing is necessary to deliver requested concierge services, obtain doctor opinions, and arrange hospital admission.
- Compliance with Legal Obligations: Retaining financial transaction records or immigration-related visa documentation as required by law.
5. Sharing Health Records with Partner Hospitals
Your Protected Health Information (PHI) is shared strictly on a need-to-know basis with credentialed medical institutions for clinical evaluation:
- Accredited Hospitals & Lead Surgeons: Secure transmission to International Patient Departments (IPDs) of JCI & NABH accredited partner hospitals in India (such as Apollo Hospitals, Fortis Healthcare, Max Healthcare, Medanta, Manipal Hospitals, Artemis, etc.).
- Logistical Service Providers: Sharing relevant travel dates and accessibility requirements with ground transport partners and medical escort teams.
We mandate that all receiving partner hospitals execute legally binding Data Processing Agreements (DPAs) promising non-disclosure and HIPAA-level security compliance.
6. Cross-Border International Data Transfers
When you request medical coordination in India from abroad, your personal and health data is transferred across international borders to our secure cloud servers and partner hospital networks in India.
We ensure appropriate safeguards for cross-border transfers through:
- Executing European Commission Standard Contractual Clauses (SCCs) with international data processors.
- Utilizing HIPAA-compliant encrypted vault cloud architecture with localized region data isolation.
7. Data Security Safeguards
We maintain rigorous physical, administrative, and technical security controls to protect your data from unauthorized access, loss, or disclosure:
| Security Layer | Implementation Standard |
|---|---|
| Data in Transit | TLS 1.3 / SSL 256-bit end-to-end encryption for all web forms and file uploads. |
| Data at Rest | AES-256 military-grade encryption on cloud databases and DICOM image servers. |
| Access Controls | Strict Role-Based Access Control (RBAC) & Multi-Factor Authentication (MFA) for concierge staff. |
| Audit Logs | Immutable server logging tracking all record access, transfers, and file views. |
8. Data Retention Policy
We retain personal and health data only for as long as necessary to fulfill the purposes outlined in this policy or satisfy statutory retention requirements. Medical files submitted for preliminary quotes without subsequent treatment booking are automatically archived after twelve (12) months and permanently deleted upon request.
9. Your Data Protection Rights
Depending on your jurisdiction (EU, UK, US, GCC, or India), you possess the following rights regarding your personal and health data:
- Right to Access: Request a copy of all personal and medical data held by Vantis Health.
- Right to Rectification: Request correction of inaccurate or incomplete medical records.
- Right to Erasure ("Right to be Forgotten"): Request complete deletion of your personal records, subject to statutory legal record-keeping obligations.
- Right to Restrict or Object: Limit how your data is processed or object to specific administrative communications.
- Right to Data Portability: Obtain your diagnostic files in a structured, machine-readable format.
- Right to Revoke Consent: Withdraw previously granted consent at any time without affecting prior lawful processing.
To exercise any of these rights, please contact our DPO at dpo@vantishealth.org. Requests are processed free of charge within thirty (30) days.
10. Cookies & Tracking Technologies
Our website utilizes essential and performance cookies to optimize site navigation, remember your preferred currency selection (USD, EUR, GBP, AED, SAR, NGN, etc.), and analyze web traffic performance. You may modify your browser settings to block cookies; however, certain site features may function with reduced performance.
11. Policy Updates & Supervisory Complaints
We may update this Privacy Policy periodically to reflect technological advancements or legislative changes. Material updates will be highlighted on this page with a revised effective date.
If you believe our data processing infringes your privacy rights, you have the right to lodge a complaint with your national Data Protection Authority (e.g., the ICO in the UK, DPB in India, or EU Data Protection Board) or contact our DPO directly for resolution.