Legal
Privacy Policy
Last reviewed: 24 September 2026
Overview
This policy explains, in plain language, what information the VigorEcon Care platform may collect and how that information is used. VigorEcon Care is a healthcare operations platform used by care teams at healthcare facilities. This page describes the platform generally; it is not directed at children under 13, and the platform is not offered for general public self-registration — accounts are created by the operating institution.
Questions about this policy can be directed to St. Augustine Hospital, Patasi, Kumasi, Ghana, +233 24 000 0000.
Information the service may collect
Account information. When a workspace administrator provisions your account, the platform stores your name, email address, assigned role (for example physician, nurse, laboratory, pharmacy, patient) and the facility or zone you belong to. Accounts cannot be created through public self-registration.
Contact and profile information. Names and email addresses are used to identify you within your workspace and, where the messaging features are used, to route messages between care-team members and patients.
Healthcare-related information. If you use the platform as a patient or a care-team member, the facility that manages your care may record healthcare information in your record — for example encounters, vital signs, laboratory results, prescriptions, pharmacy activity and care messages. This information is entered and managed by your care team as part of providing care.
Technical information. The platform uses a strictly necessary sign-in session cookie, records an audit trail of actions taken in the system (including the acting account and, where available, network origin information) for security and accountability, and stores interface preferences (such as theme and sidebar state) on your own device.
How information is used
Information on the platform is used to:
- provide the healthcare workflows you or your facility use — patient charts, encounters, laboratory work, prescriptions, pharmacy stock and care-team communication;
- verify who you are when you sign in, and enforce multi-factor authentication where your role requires it;
- enforce access controls, so each account only sees the records its role and facility assignment permit;
- keep an audit trail for security, accountability and troubleshooting;
- operate and maintain the service, including protecting it against misuse.
Information is not used for advertising, and it is not sold.
Security and access controls
Access to records is restricted by role and by facility: patient records are scoped to the facility that created them, and a user from one facility cannot query, list or open a patient belonging to another facility. The application enforces these rules on every request, and the underlying database applies row-level isolation underneath the application. Every record access and significant action is written to the audit log. Platform-level administration accounts manage accounts and availability but are not granted a clinical role and cannot open patient charts.
Sessions are protected with HttpOnly cookies, and multi-factor authentication (TOTP authenticator codes and, where enabled, passkeys) is enforced for roles that require it. No internet-connected service can guarantee absolute security, and the operator encourages strong passwords and enabled multi-factor authentication.
Data sharing and service providers
The platform does not sell your information, and it does not share patient records with third parties for marketing. Information may be processed by the hosting and infrastructure providers that operate the service on behalf of the operating institution, under instructions limited to running the platform. Where the operator uses specific sub-processors, the current list and agreements are maintained by St. Augustine Hospital [SUB-PROCESSOR LIST TO BE CONFIRMED BY THE OPERATOR].
Disclosure may also occur where the operating institution is legally required to produce records, or where disclosure is necessary to protect the rights and safety of patients and staff, in line with applicable professional obligations.
Retention
Account and audit information is retained for as long as needed to operate the platform and meet the operating institution's accountability requirements. Healthcare records are retained in line with the record-keeping practices of the operating facility. Specific retention periods are set by the operating institution [RETENTION PERIODS TO BE CONFIRMED BY THE OPERATOR].
Your rights
If you have an account, you may ask the administrator of your workspace to review the account information held about you and to correct it. Patients may ask their care team to correct factual errors in their record. Requests relating to your information can be raised with St. Augustine Hospital at the contact details above, and will be handled by the operating institution. The availability of formal data-protection rights depends on the laws applicable to you and to the operating institution.
Cookies and similar technologies
The platform sets only strictly necessary and functional cookies and local storage: a sign-in session cookie (HttpOnly), an interface-preference cookie for the sidebar state, and local storage entries that remember choices like your preferred theme and voice-assistant settings. These are needed for the service to work as intended.
The platform does not currently use analytics, advertising or third-party tracking cookies. If that changes, this policy and the cookie notice will be updated before such technologies are introduced.
Analytics
The public pages of this website do not currently run web analytics. The platform itself records operational and audit events (described above) for security and service operation — not for behavioural profiling.
Policy updates
This policy may be updated to reflect changes in the service or in the law. Material changes will be published on this page with a revised review date. Continued use of the platform after changes are published constitutes acceptance of the updated policy.