Book a Demo
hello@vani.one
Security & Compliance

Built to protect data
from day one.

Healthcare data deserves more care than a bolt-on privacy policy. Here's exactly how Vani One's architecture is built, and the standards it's built around.

How Data Moves

Protected at every step —
not just at the door.

Every piece of data passes through the same protected path, whether it's a patient record, a claim, or a staff login.

Data In
TLS 1.3 encrypted
Encrypted Processing
AES-256 at rest
India-Based Storage
Data residency enforced
Role-Based Access
Least-privilege by default
0%
Of patient data ever leaves Indian jurisdiction.
Not a target. A constraint we build to.
Regulatory Alignment

Architected around the standards
that matter to you.

Our systems are designed and built to align with the following frameworks. Where formal certification or audit is applicable, we'll share current status and documentation directly during a security review.

DPDP Act, 2023India
Data collection, consent, and retention practices are architected around the Digital Personal Data Protection Act — including data principal rights and grievance redressal.
ABDMIndia
Built to align with Ayushman Bharat Digital Mission's data sharing and interoperability standards for health records and ABHA ID integration.
HIPAAGlobal
Architecture follows HIPAA-aligned safeguards for protected health information — access controls, audit logging, and encryption standards.
GDPRGlobal
Data handling principles — purpose limitation, minimization, and the right to erasure — are built into the system design, aligned with GDPR standards.
Operating Practices

What actually happens
behind the badges.

Encryption
In transit and at rest. All data is encrypted using TLS 1.3 in transit and AES-256 at rest, without exception.
Access Control
Role-based, least-privilege. Every user — internal or at your institution — only sees what their role requires. Every access event is logged.
Data Residency
Stays in India. Patient and institutional data is stored on India-based infrastructure and does not leave the required jurisdiction.
Audit Logging
Full activity trail. Every read, write, and export is logged and retained — available to your institution on request.
Breach Response
Direct, not delayed. A documented incident response process with defined notification timelines, consistent with DPDP Act requirements.
Data Ownership
Yours, always. Your institution retains ownership of all data. We process it to run the platform — we don't sell it or use it for anything else.
Running a Security Review

Talk to us directly —
not a support ticket.

If your IT or security team needs documentation, a data processing agreement, or a walkthrough of our architecture, we'll get on a call and go through it together.

Contact our team

Privacy Policy

✓ DPDP Act, 2023 Compliant
Last updated: July 2026

Who we are

Vani One ("we", "us", "our") provides healthcare operations automation software to institutions in India. This policy explains how we collect, use, store, and protect personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable rules.

What data we collect

When you interact with our website or book a demo, we may collect:

  • Contact details you provide (name, email, phone, organisation name)
  • Information shared during calls or WhatsApp conversations
  • Basic website usage data (pages visited, general location, device type)

We do not collect patient health records through this website. Any clinical or patient data processed through the Vani One platform itself is governed by a separate data processing agreement with the contracting institution.

Why we collect it

We process your personal data only for specific, lawful purposes:

  • To respond to your enquiry and schedule a demo
  • To communicate with you about our services
  • To improve our website and understand how it is used

Your rights under the DPDP Act

As a Data Principal, you have the right to:

  • Access the personal data we hold about you
  • Request correction or erasure of your personal data
  • Withdraw consent at any time
  • Nominate another individual to exercise these rights on your behalf in the event of death or incapacity
  • Raise a grievance with our Grievance Officer, and subsequently with the Data Protection Board of India if unresolved

Where your data is stored

All personal data is stored on servers located in India. We do not transfer personal data outside India except where explicitly permitted under the DPDP Act and with appropriate safeguards.

Data retention

We retain enquiry and contact data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law, after which it is securely deleted.

Grievance redressal

For any questions, data access requests, or grievances regarding this policy, contact our Grievance Officer at hello@vani.one. We aim to respond within 30 days as required under the DPDP Act.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected with an updated revision date at the top of this page.