Privacy & Security Policy

Your Data. Your Control.

At VitalXCare, privacy isn't an afterthought — it's our foundation. We believe your health data is among the most personal information you have, and you should always maintain full control over it. This policy explains exactly how we handle your data with transparency, respect, and the highest security standards.

Effective Date: January 1, 2024 Last Updated: February 15, 2026 Version: 2.1

Our Privacy Principles

Six commitments that define how VitalXCare treats your data

📱

Local-First Storage

All your health readings are stored locally on your device by default. We don't upload your data to the cloud unless you explicitly choose to enable cloud backup. Your device, your data.

🔒

No Data Monetization

We make money by selling devices and premium services — never by selling your data. Your health information will never be sold to advertisers, insurance companies, or any third parties.

👤

No Account Required

You can use VitalXCare devices and the mobile app without creating an account. Anonymous usage is fully supported — start measuring right out of the box.

🌍

GDPR & CCPA Compliant

Built for the world's strictest privacy standards from day one. Full compliance with GDPR (EU), CCPA (California), and PIPEDA (Canada), including data portability and the right to deletion.

🔐

End-to-End Encryption

When you share data (e.g., with your doctor), it's encrypted end-to-end using AES-256 and TLS 1.3. Only you and your intended recipient can read it. No man-in-the-middle access.

🗑️

Easy Data Deletion

Delete all your data from the app with one tap. No waiting periods, no hoops to jump through, no dark patterns. Your data, your choice — always.

1. Scope & Applicability

This Privacy & Security Policy applies to all products and services provided by VitalXCare Inc., including:

  • VitalXCare Website (https://www.vitalxcare.com) — our public-facing website for product information, support, and purchases
  • VitalXCare Mobile Application — our Android and iOS apps for health monitoring and device management
  • VitalXCare Medical Devices — including the BP Monitor Pro, IR Thermometer, Pulse Oximeter, and future devices
  • VitalXCare Cloud Services — optional cloud backup, data synchronization, and healthcare provider sharing features
  • Customer Support — all interactions through email, phone, or the contact form

By using any of our products or services, you acknowledge that you have read, understood, and agree to the practices described in this policy. If you do not agree, please discontinue use and contact us to have any existing data deleted.

1.1 Data Controller

The data controller for your personal data is:

VitalXCare Inc.
18001 Sky Park Circle, Ste A
Irvine, CA 92614
United States
Phone: +1 657-999-1100
Email: [email protected]

2. What Data We Collect

2.1 Health & Measurement Data (Stored Locally)

When you use VitalXCare medical devices, the following health measurements are stored locally on your smartphone or tablet:

  • Blood Pressure Readings: Systolic pressure (mmHg), diastolic pressure (mmHg), pulse rate (BPM), irregular heartbeat indicator, measurement timestamp, and WHO/AHA classification category
  • Body Temperature: Temperature reading (°C/°F), measurement mode (forehead/ear), fever classification, measurement timestamp
  • SpO2 (Pulse Oximetry): Oxygen saturation percentage (%), pulse rate (BPM), perfusion index (PI), signal quality indicator, measurement timestamp
  • ECG Data (if applicable): Heart rhythm waveform data, heart rate, rhythm classification, measurement duration, timestamp
  • Device Metadata: Device model identifier, firmware version, battery level at measurement time, Bluetooth connection quality

Important: All health data is stored locally on your device by default. It is NOT automatically uploaded to our servers. You maintain full ownership and control at all times.

2.2 Account Information (Optional)

If you choose to create an account for cloud backup, multi-device sync, or healthcare provider sharing, we collect:

  • Required: Email address (used as your login identifier)
  • Optional: Full name, date of birth (for age-based health reference ranges), biological sex (for gender-specific health norms), profile photo
  • Authentication: Password (hashed using bcrypt with salt — we never store or see your plain-text password)

2.3 Contact Form & Communication Data

When you contact us through our website, email, or phone, we collect:

  • Name and email address you provide
  • Phone number (if provided voluntarily)
  • Organization name (if provided)
  • Nature of your inquiry and message content
  • Communication history for support follow-up

2.4 Purchase & Transaction Data

When you purchase our products, we collect:

  • Billing and shipping address
  • Order details and purchase history
  • Payment information (processed securely by Stripe — we never see or store your full card number, CVV, or other sensitive payment data)

2.5 Technical & Usage Data

To provide and improve our services, we automatically collect:

  • Device Information: Device model, operating system version, app version, screen resolution
  • Usage Analytics: App screens visited, features used, session duration, app crashes (anonymized and aggregated)
  • Website Analytics: Pages visited, time spent, referral source, browser type, general geographic location (country/region level only — never precise GPS)
  • Network Data: IP address (website visitors), connection type (Wi-Fi/cellular), Bluetooth connection logs for device pairing

Note: All analytics are anonymized and aggregated. We cannot and do not identify individual users from analytics data. You may opt out of analytics collection at any time in the app settings.

3. How We Use Your Data

3.1 Primary Service Delivery

  • Display Health Insights: Show you trends, averages, graphs, and WHO/AHA/medical classification of your readings
  • Generate Reports: Create shareable PDF health reports for doctor visits, at your explicit request
  • Smart Reminders: Medication reminders and measurement schedule prompts (if you enable them)
  • Multi-Device Sync: Keep your health data synchronized across your devices (requires opting in to cloud backup)
  • Device Management: Firmware updates, battery status tracking, and device troubleshooting

3.2 Service Improvement

  • Product Improvement: Anonymized, aggregated usage patterns help us improve the app interface and device accuracy
  • Bug Fixes: Crash reports help us identify and resolve technical issues quickly
  • Feature Development: Understanding which features are most used helps us prioritize development

3.3 Communication

  • Transactional Emails: Order confirmations, shipping updates, password resets
  • Service Announcements: Critical security updates, changes to terms of service, new device compatibility
  • Marketing (Opt-in Only): Product news, health tips, promotional offers — only if you explicitly subscribe. You can unsubscribe at any time with one click.

3.4 We Do NOT Use Your Data For

  • ❌ Advertising or marketing based on your health data
  • ❌ Selling to data brokers, advertisers, or any third parties
  • ❌ Insurance underwriting or risk assessment
  • ❌ Employment screening or background checks
  • ❌ Behavioral profiling, surveillance, or user scoring
  • ❌ Training AI models on your personal health data
  • ❌ Price discrimination or personalized pricing

5. Where & How Your Data is Stored

5.1 Local Storage (Default)

By default, all health readings are stored in a local SQLite database on your smartphone or tablet, protected by the device's built-in security (screen lock, biometric authentication). This data never leaves your device unless you explicitly enable cloud backup or choose to share a report with a healthcare provider.

5.2 Cloud Backup (Optional, Opt-in Only)

If you enable optional cloud backup, your data is stored with the following protections:

  • Data Center Location: EU-based data centers (Frankfurt, Germany and Amsterdam, Netherlands)
  • Encryption at Rest: AES-256 encryption for all stored data
  • Encryption in Transit: TLS 1.3 for all network communications
  • Infrastructure Provider: AWS Frankfurt region (certified under EU-US Data Privacy Framework, SOC 2, ISO 27001)
  • Access Control: Zero-knowledge architecture — your data is encrypted with keys derived from your password. Even VitalXCare engineers cannot read your health data.

Data Sovereignty: European users' data never leaves the EU. We do not transfer health data to the United States or other non-EU/non-adequate countries.

5.3 Data Retention Periods

  • Local Health Data: Retained until you manually delete readings or uninstall the app
  • Cloud Health Data: Retained until you delete your account, then permanently erased within 30 days
  • Account Information: Retained for the life of your account, plus 30 days for deletion processing
  • Contact Form Submissions: Retained for 2 years for customer support follow-up, then deleted
  • Purchase Records: Retained for 7 years as required by tax and financial regulations
  • Encrypted Backups: Retained for 30 days for disaster recovery, then permanently deleted
  • Anonymized Analytics: Aggregated (non-personal) analytics retained for up to 26 months for trend analysis
  • Server Logs: Automatically purged after 90 days

6. When & How We Share Your Data

6.1 You Control All Health Data Sharing

VitalXCare will NEVER share your health data without your explicit, informed permission. Every instance of sharing is initiated by you, and you can revoke sharing at any time.

6.2 Healthcare Provider Sharing (Your Choice)

When you use the "Share with Doctor" feature in the VitalXCare app:

  • You generate a professional PDF report or a time-limited secure link
  • You choose the exact date range and which health metrics to include
  • You select the delivery method: email, print, secure FHIR portal, or direct in-app share
  • Shared links automatically expire after 7 days (configurable)
  • All transmissions are encrypted end-to-end using TLS 1.3

6.3 Service Providers (Data Processors)

We work with a limited number of trusted service providers who process data on our behalf. All providers are bound by strict Data Processing Agreements (DPAs) and cannot use your data for their own purposes:

  • Cloud Infrastructure: Amazon Web Services (EU-only region, for optional cloud backup)
  • Payment Processing: Stripe (processes payment data only — has no access to health data)
  • Email Delivery: Our own mail servers (for transactional emails and contact form confirmations)
  • Website Analytics: Google Analytics with IP anonymization and consent-based activation via our cookie consent banner
  • App Analytics: First-party analytics only, anonymized and aggregated, with opt-out available

6.4 Legal & Safety Disclosures

We may disclose personal data when required or permitted by law:

  • To comply with a court order, subpoena, or valid legal process
  • To prevent imminent harm to life or physical safety
  • To comply with tax, financial, or medical device reporting obligations
  • To enforce our Terms of Service or protect our legal rights

We will notify you of legal requests for your data unless legally prohibited from doing so, and we will challenge any overly broad or unjustified requests.

6.5 Business Transfers

If VitalXCare is involved in a merger, acquisition, or asset sale, your personal data may be transferred to the successor entity. We will notify you via email and/or prominent notice on our website before any such transfer, and this privacy policy will continue to apply.

6.6 We Do NOT Share With

  • ❌ Advertisers or marketing agencies
  • ❌ Data brokers, data aggregators, or data marketplaces
  • ❌ Insurance companies or underwriters
  • ❌ Employers, recruiters, or HR departments
  • ❌ Social media platforms or ad networks
  • ❌ Government or law enforcement (unless legally compelled)
  • ❌ Any third party for their own commercial purposes

7. Your Privacy Rights

Depending on your location, you have the following rights under GDPR, CCPA, and other applicable privacy laws:

Right to Access

Request a complete copy of all personal data we hold about you. We'll provide it in a machine-readable format (JSON or CSV) within 30 days, free of charge.

Right to Deletion ("Right to be Forgotten")

Request complete erasure of all your data from our systems. In the app: Settings → Privacy → Delete All Data. We'll confirm deletion within 30 days. No questions asked, no retention tricks.

Right to Data Portability

Export your health data in standard formats to use with other apps or services. Supported export formats include: PDF reports, CSV spreadsheets, JSON, and HL7 FHIR for healthcare interoperability.

Right to Rectification

Correct inaccurate personal data. Edit or delete individual health readings directly in the app, or contact us to update your account information.

Right to Restriction

Request that we limit how we process your data while a complaint or dispute is being investigated. Your data will be stored but not actively processed.

Right to Object

Object to data processing based on our legitimate interests. We'll cease processing unless we demonstrate compelling legitimate grounds that override your interests.

Right to Withdraw Consent

Withdraw your consent for cloud backup, analytics, or marketing at any time. Go to Settings → Privacy → Manage Consent in the app. Withdrawal doesn't affect prior lawful processing.

Right to Lodge a Complaint

File a complaint with your national data protection authority if you believe we've violated your privacy rights. We welcome your feedback and aim to resolve concerns directly.

How to Exercise Your Rights

You can exercise any of these rights by:

We will verify your identity and respond within 30 calendar days. If we need additional time, we'll inform you within 30 days and explain the reason for the delay (maximum extension: 60 additional days).

8. Security Measures

We implement comprehensive technical and organizational measures to protect your personal and health data against unauthorized access, alteration, disclosure, or destruction.

8.1 Technical Security

  • Encryption at Rest: AES-256 for cloud-stored data; SQLCipher for local databases on your device
  • Encryption in Transit: TLS 1.3 (HTTPS) for all network communications; certificate pinning in our mobile apps
  • Bluetooth Security: BLE 5.0 pairing with authentication; no health data stored on the device hardware itself (only transmitted to the paired app)
  • Password Security: bcrypt hashing with per-user salts; minimum 8-character requirement; common password detection
  • Two-Factor Authentication: Optional TOTP-based 2FA via authenticator apps (Google Authenticator, Authy, etc.)
  • Infrastructure Security: Web Application Firewall (WAF), DDoS protection, intrusion detection systems, automated vulnerability scanning
  • Code Security: Regular static code analysis (SAST), dependency vulnerability scanning, mandatory code reviews for all changes

8.2 Organizational Security

  • Background checks and non-disclosure agreements for all employees
  • Principle of least privilege — employees access only the minimum data necessary for their role
  • Quarterly security awareness training for all staff
  • Documented incident response plan with defined roles and escalation procedures
  • Annual third-party penetration testing and security audits
  • Physical security controls for office spaces and data center access

8.3 Data Breach Response Protocol

In the unlikely event of a personal data breach:

  1. Detection & Containment: Immediate containment and investigation by our security team
  2. Assessment: Determine scope, severity, and affected individuals within 24 hours
  3. Authority Notification: Notify the relevant supervisory authority within 72 hours (as required by GDPR Art. 33)
  4. User Notification: Notify affected users without undue delay, including: what data was affected, what steps we are taking, and recommended protective actions
  5. Remediation: Implement fixes, conduct root cause analysis, and update security measures to prevent recurrence
  6. Post-Incident Report: Publish a transparency report summarizing the incident (without disclosing details that could aid further attacks)

9. Cookies & Tracking Technologies

9.1 What Are Cookies

Cookies are small text files placed on your device when you visit our website. They help us provide essential functionality, remember your preferences, and understand how our site is used so we can improve it.

9.2 Cookie Categories We Use

Strictly Necessary Cookies

These cookies are essential for the website to function. They cannot be disabled. They include:

  • Session Cookie (PHPSESSID): Maintains your session while browsing — expires when you close your browser
  • CSRF Token: Protects form submissions from cross-site request forgery attacks
  • Cookie Consent (vxc_cookie_consent): Remembers your cookie preferences — stored for 1 year

Analytics Cookies (Opt-in)

These cookies help us understand how visitors interact with our website. They are only activated after you give consent through our cookie banner:

  • Google Analytics (_ga, _ga_*): Anonymized pageview and session data — IP anonymization is enabled; data retained for 14 months
  • Google Tag Manager: Manages the loading of analytics tags based on your consent choices

Marketing Cookies (Opt-in)

These cookies are used to measure advertising campaign effectiveness. Only activated with your explicit consent:

  • Conversion tracking: Measures whether ad clicks lead to website interactions (anonymized)

Functional Cookies (Opt-in)

These cookies enable enhanced features and personalization:

  • Language preference: Remembers your preferred language
  • Form data: Saves partially completed form fields so you don't need to re-enter information

9.3 Managing Your Cookie Preferences

You can manage your cookie preferences at any time by:

  • Cookie Settings: Click the 🍪 cookie icon in the bottom-left corner of any page to open the Cookie Preferences panel
  • Browser Settings: Configure your browser to block or delete cookies (note: blocking essential cookies may impair website functionality)
  • Do Not Track: We respect the "Do Not Track" browser signal. When detected, we disable all optional analytics and marketing cookies.

9.4 Mobile App Tracking

The VitalXCare mobile app does NOT use:

  • Advertising identifiers (Apple IDFA / Google GAID)
  • Third-party analytics SDKs (no Firebase Analytics, no Mixpanel, no Amplitude)
  • Cross-app tracking or fingerprinting
  • Location tracking (GPS is never accessed)

In-app usage analytics are first-party only, anonymized, aggregated, and can be completely disabled in the app settings.

10. Children's Privacy

VitalXCare devices can be used to monitor children's health (e.g., fever tracking, oxygen saturation monitoring). We take children's privacy extremely seriously:

  • Age Requirement: Users under 16 years of age (or the applicable age in your jurisdiction) must have a parent or legal guardian create and manage their account
  • Parental Control: Parents/guardians have full control over all data sharing settings and account configuration
  • No Direct Collection: We do not knowingly collect personal data directly from children without verified parental consent
  • Parental Deletion: Parents can delete their child's data at any time from the app settings or by contacting us
  • COPPA Compliance: We comply with the U.S. Children's Online Privacy Protection Act (COPPA) for users under 13

If you believe we have inadvertently collected personal data from a child without appropriate parental consent, please contact us immediately at [email protected] or call +1 657-999-1100. We will investigate and delete the data promptly.

11. International Data Transfers

11.1 European Users (EU/EEA/UK)

Your data stays in the European Union. We use EU-based servers exclusively for European customers. Health data is never transferred outside the EU/EEA for storage or processing.

For non-EU service providers used by VitalXCare (e.g., email delivery tools), we ensure compliance through:

  • EU Standard Contractual Clauses (SCCs) approved by the European Commission
  • EU-US Data Privacy Framework certification (for US-based providers)
  • Supplementary technical measures (encryption of data in transit and at rest)
  • Regular Transfer Impact Assessments

11.2 US Users

For US-based users, data is processed and stored in US data centers operated by AWS, with optional EU-based backup available upon request.

11.3 Other Regions

Data may be stored in your region or in the EU, depending on infrastructure availability. All transfers comply with applicable local data protection laws and include appropriate safeguards.

12. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

12.1 Right to Know

You have the right to know what personal information we collect, the sources of collection, the business purposes for collection, and the categories of third parties with whom we share data. This information is detailed in the sections above.

12.2 Right to Delete

You may request deletion of your personal information, subject to certain exceptions (e.g., legal obligations, fraud prevention).

12.3 Right to Opt-Out of Sale

VitalXCare does NOT sell your personal information. We have never sold personal information, and we have no plans to do so. Therefore, there is no need to opt out of a sale.

12.4 Right to Non-Discrimination

We will not discriminate against you for exercising any of your CCPA rights. You will continue to receive equal service and pricing regardless of your privacy choices.

12.5 Categories of Information Collected (Last 12 Months)

  • Identifiers: Name, email address, phone number, IP address
  • Commercial Information: Product purchase history, order details
  • Internet/Network Activity: Browsing history on our website, app usage data
  • Sensitive Personal Information: Health data (collected with explicit consent, processed locally on your device)

To exercise your California privacy rights, contact us at [email protected] or call +1 657-999-1100. We will verify your identity and respond within 45 days.

13. Changes to This Policy

We may update this Privacy & Security Policy to reflect new features, changes in data protection laws, or improvements to our privacy practices. Here's how we handle updates:

13.1 Material Changes

  • 30-Day Advance Notice: Significant changes to data collection, sharing, or rights will be communicated 30 days before taking effect
  • Notification Methods: Email notification (if you have an account), in-app banner, and a prominent notice on our website
  • Consent When Required: If a change requires new consent under applicable law, we will seek your explicit opt-in before the change takes effect

13.2 Minor Updates

  • Clarifications, formatting changes, or updates to contact information will be posted on this page with an updated "Last Updated" date
  • The version number in the policy header will be incremented

13.3 Version History

  • v2.1 (February 15, 2026): Added CCPA/CPRA section, updated cookie policy to reflect Google Tag Manager and Analytics integration, expanded security measures
  • v2.0 (October 1, 2025): Major revision for GDPR compliance audit, added legal basis section, expanded data retention details
  • v1.0 (January 1, 2024): Initial privacy policy

Continued use of VitalXCare products and services after changes take effect constitutes acceptance of the updated policy. If you disagree with any changes, you may stop using our services and request deletion of your data.

14. Contact Us

We welcome your questions, concerns, and feedback about this Privacy & Security Policy. You can reach us through any of the following channels:

Privacy & Data Protection Inquiries
Email: [email protected]
Phone: +1 657-999-1100
Response Time: Within 2 business days
General Inquiries & Customer Support
Email: [email protected]
Support: [email protected]
Phone: +1 657-999-1100
Contact Form: www.vitalxcare.com/contact
Mailing Address
VitalXCare Inc.
Attn: Privacy Department
18001 Sky Park Circle, Ste A
Irvine, CA 92614
United States
Supervisory Authorities
Federal (US):
Federal Trade Commission (FTC)
Website: ftc.gov/about-ftc/contact

California (CCPA/CPRA):
California Attorney General's Office
Website: oag.ca.gov/privacy

We are committed to working with you to resolve any privacy concern. If we cannot resolve your complaint directly, you have the right to lodge a complaint with your country's data protection authority.

Our Compliance Standards

🇪🇺 GDPR Aligned
🔒 ISO 27001 Practices
HIPAA-Ready Architecture
📜 CE MDR Standards
🇺🇸 CCPA/CPRA Aligned
🛡️ SOC 2 Practices