Security & data protection

VCare handles patients’ personal data, so the security came first. Data stays in Singapore and every access is controlled and recorded. This page is the factual record of how that works, and it claims nothing that is not already true.

Hosted in Singapore onlyEncrypted in transit & at restDeny-by-default access, 2FAEvery access audit-logged

Data residency

  • VCare runs exclusively in the AWS Singapore region (ap-southeast-1).
  • Patient data, including database replicas and backups, never leaves Singapore. There are no overseas mirrors and no cross-border transfers.
  • Where health information is stored is a question every clinic must be able to answer under MOH’s security requirements. Ours is one word: Singapore.

Encryption

  • All traffic between the patient app, the clinic dashboard and our servers is encrypted with TLS. There are no unencrypted endpoints.
  • Data is encrypted at rest, and that includes the database and its backups.
  • Especially sensitive identifiers get extra treatment: NRIC/FIN numbers are field-level encrypted, displayed masked in the interface, and excluded from logs. They are never used as a login ID or authentication factor.

Access control

  • Access is role-based and deny-by-default: every role starts with nothing and is granted only what the job requires.
  • Front-desk staff run the queue and appointments; they structurally cannot open clinical records. It is not a setting a busy admin can toggle off; the role simply has no path to that data.
  • Clinic staff sign in with mandatory two-factor authentication using an authenticator app, not optional and not SMS. Sensitive actions such as data exports require re-authentication.
  • Patients authenticate with a one-time code sent to their email, or with Singpass. There is no patient password to steal. Dormant staff accounts are automatically suspended, and offboarded accounts are disabled immediately, never quietly left active.

Auditability

  • Every access and every action, who viewed what, who changed what, and when, is written to an append-only audit log. Entries cannot be edited or deleted, by anyone.
  • Audit records are retained for six years, and access to the logs themselves is restricted and logged.
  • For clinics this maps directly to MOH audit-trail expectations: when you need to show who accessed a record, the answer is one query away.

Data lifecycle

  • We keep data only as long as there is a legal or service reason to. Queue entries are de-identified 30 days after the visit, so the patient linkage is removed and only anonymous statistics (visit counts, waiting times) remain.
  • Stale artefacts, such as unused notification tokens and expired queue data, are purged automatically under PDPA’s retention-limitation obligation.
  • Full retention schedules, including what happens when you close your account, are in our Privacy Policy.

PDPA compliance

Singapore’s Personal Data Protection Act is built into how VCare works. Here is exactly how the obligations fall.

Data intermediary: clinic patient data

For bookings, queue entries and (in future) clinical data, your clinic is the organisation in charge and VCare is its data intermediary. We process that data only on the clinic’s behalf, only for the clinic’s purposes, and only under a written data-processing agreement signed with every clinic, so protection and retention obligations apply to us directly.

Organisation: VCare account data

For the data patients give us directly (login details, app settings, notification tokens), Vantrexis LLP is the responsible organisation in its own right, carrying the full set of PDPA obligations: consent, purpose limitation, protection, retention limits and accountability.

  • Data Protection Officer. Our DPO is Sol Davis, reachable at admin@app-vantrexis.com. Put “Data protection” in the subject line so it reaches the right person quickly.
  • Your PDPA rights. Patients can request access to their data, ask for corrections, or withdraw consent at any time. Where a request concerns data a clinic controls (like appointment history), we route it to the clinic and help them respond, and we never leave a requester bouncing between parties. Details in our Privacy Policy.
  • Breach readiness. Health information is a “significant harm” category under the PDPA’s breach rules, so we treat even a single-record incident as notifiable. If a breach affects clinic-controlled data, we notify the affected clinics without undue delay so they can meet their duty to inform the PDPC within three calendar days; for data we control, we notify the PDPC directly.
  • NRIC discipline. In line with PDPC rules, NRIC numbers are never used for login, lookup or account recovery. Where healthcare requires the NRIC as a record identifier, it is encrypted, masked on screen and kept out of logs.
  • If you are not satisfied. You can complain to the Personal Data Protection Commission at pdpc.gov.sg. We would rather you told us first, but the route exists, and you should know it.

Responsible disclosure

Found a vulnerability? We want to hear about it. Email admin@app-vantrexis.com with the subject “Security” and enough detail to reproduce the issue. A human reads every report and will respond. Please avoid accessing patient data in the course of your research, and give us reasonable time to fix the issue before any public disclosure.

Security questions before you commit?

Bring your IT lead or DPO to a demo. We will walk through the architecture, the role model and the audit trail, and answer the hard questions on the spot.

Book a Demo