Skip to content

Legal

Privacy Policy

Oriaris Health Intelligence, Inc. · version 1.0 · effective October 4, 2026

This policy explains how Oriaris handles personal data, including cookies, across everything we do: this website and its forms, the internship program, and the five product lines, Academy, Nexus, Horizon, Core and Relay, as each one opens. It is written to satisfy Republic Act 10173, the Data Privacy Act of 2012, and to be readable by a Data Protection Officer conducting a vendor review. The central fact is short: we do not retain patient data.

1The controller

Oriaris Health Intelligence, Inc., Level 21 Unit 2116, Park Triangle Corporate Plaza, North Tower, 32nd Street Corner 11th Avenue, Bonifacio Global City, Fort Bonifacio, Taguig City 1635, Philippines. Our Data Protection Officer is Cindy Rico Macadaan, Chief Operations Officer, reachable at oriaris.health@gmail.com.

2No clinical decision making

Oriaris trains, advises, reports and builds software for healthcare institutions. Across all of it, Oriaris does not diagnose, does not treat, does not determine medical necessity, and does not practice medicine.

Every clinical and coding determination is made by a licensed human professional employed by or contracted to the healthcare institution. Nothing Oriaris produces, whether a guide, a training program, advice, a report or a software suggestion, is medical advice.

3No automated submission

No Oriaris service transmits, or will transmit, a claim, correction or record to PhilHealth, to any health maintenance organization, or to any other payer without an explicit, recorded verdict from an authorized human reviewer.

For Oriaris Core and Oriaris Relay this is a property of the system design. There will be no configuration setting, license tier or contractual arrangement under which automated submission is enabled.

4Zero retention of personal health information

Oriaris collects no personal health information today, through any product line, form or program. Training and internship work use synthetic cases only, and no form on this website asks for a patient name, a claim, a chart or a diagnosis.

Oriaris Core is being designed so that personal health information transmitted to it is processed in volatile memory within the scope of a single request and is not written to persistent storage at any point. It will never be returned to the caller in an error response, so a malformed claim is rejected by naming the field at fault, never by quoting the payload back.

The only artifacts that will persist are a salted SHA-256 hash of case identifiers and non-identifying aggregate counters. The hash is not reversible and is not used to re-identify any individual.

5What we process, and why

Academy, Nexus and Horizon collect nothing yet, because none of them is running. Before any of them collects personal data, for example who enrolled in a training program, the table below gains a row saying what, why and for how long.

CategoryWhat it isLawful basisRetention
Claim payloads, Oriaris Core only, once it runsClinical abstract, coding, vitals transmitted by a hospital systemContract with the healthcare institution, which remains the controllerNone. Volatile memory within request scope only
Anonymized hashSalted SHA-256 digest of case identifiersLegitimate interest in audit integrityKept for as long as the audit record it indexes, currently the term plus ten years. It is not reversible and identifies nobody, and deleting it would break the integrity of the append-only log it anchors
Audit log entriesRule identifier, confidence, the verdict, the timestamp, the anonymization hash, and the name or identifier of the reviewer who decidedLegal obligation and compliance evidenceRetained for the term of the hospital's agreement plus any period the law requires, currently ten years for hospital records
Inquiry detailsName, role, institution, work email, bed count rangeConsent, given when you submit the pilot form, which links to this policy at the point of collectionUntil you ask us to delete it, or two years of inactivity
Internship applicationsName, email, phone, school, program and year, the track applied for, whether you need OJT or practicum hours and how many, when you can start, an optional link, and your written answerConsent, given when you submit the internship form, which links to this policy at the point of collectionUntil you ask us to delete it, or two years of inactivity
Website analyticsNone. We collect no analytics of any kindNot applicableNothing to retain

6Roles under the Data Privacy Act

For claim data in Oriaris Core, the healthcare institution will be the Personal Information Controller and Oriaris a Personal Information Processor under written instruction. A written data processing agreement, signed before any claim is processed, will govern that relationship. Any Nexus engagement or Horizon report that uses an institution's data will follow the same roles, under a written agreement signed before any data is shared.

For website inquiries, internship applications and, when Academy opens, training enrollment, Oriaris is the controller.

7Who else sees data

We use a small number of service providers, listed below by what each one does, what it can reach and where it is. No provider receives personal health information, because no personal health information persists beyond the request in which it is processed.

Providers are described by role rather than by name, so this page is not a map of our systems for anyone looking for a way in. A healthcare institution receives the named list in writing before any engagement begins, and a data subject may ask our Data Protection Officer which provider holds their data.

We do not sell personal data, and we do not share it for advertising purposes under any circumstances.

ProviderWhat it doesWhat it can reachLocation
Website hostingHosts this website, serves it through a global network, and handles its formsWhat a visitor sends through a form, while it is handled, and a backup copy in short-lived server logs. No claim data and no patient dataForms in Singapore, pages served globally
Domain and networkRegisters and resolves the oriaris.ai domainWebsite traffic may pass through its network, including form submissions. No claim data and no patient dataGlobal
Business messagingAlerts our founders to meeting, pilot and internship requestsThe details and answers sent through those forms. No claim data and no patient dataGlobal
Email deliveryDelivers the same requests to our inboxThe same details as the messaging alert. No claim data and no patient dataUnited States
Email inboxReceives those requests, and any message sent to us directlyContact details and messages people choose to send us. No claim data and no patient dataGlobal

8Whether your data leaves the Philippines

For claim data the answer is that there is nothing to transfer. Patient data is processed in volatile memory within the request and is never written anywhere, so it is never moved, copied, backed up or replicated to another jurisdiction.

For the small amount of personal data we do hold, inquiry details and internship applications sent through the forms on this site, processing happens with the providers in the table under Who else sees data, with each one's location stated there. We choose providers in jurisdictions that offer a comparable level of protection, and we update that table before a change takes effect, never after.

Where a transfer becomes necessary, we remain accountable for the data under this policy regardless of where it is processed, and a hospital may object under its data processing agreement before the change takes effect.

9Cookies and similar technologies

This website sets no cookies. Not one, on any page.

There is no analytics, no advertising pixel and no tracking identifier. The only thing this site writes to your browser is a draft of a form while you fill it in, kept in session storage so a refresh does not lose what you typed. It never leaves your browser until you press submit, it is deleted when you send the form, and your browser deletes it when you close the tab. Nothing is written to local storage. You do not have to take our word for it: open your browser developer tools and look under storage.

That is why there is no consent banner here. Consent is required for cookies that are not strictly necessary, and we set neither kind. Cookies are a privacy matter rather than a contractual one, which is why they are covered in this policy rather than in the Terms of Use.

10When you book a meeting, request a pilot or apply for an internship

Three forms on this site ask you for personal data, and using any of them is entirely your choice. Booking a meeting asks for your name, your role, your hospital or network, your work email, your phone number, an approximate bed count, and when and how you would like to meet. If you ask us to visit your hospital we also ask which city and region, so we can tell you honestly whether we can get there.

Requesting a pilot asks for the same contact details and a few more about the engagement: your monthly inpatient claim volume, whether an executive has agreed to own the pilot, which hospital information system you run, and whether that system can send data to an outside address. Those last two decide whether a pilot can work at all, and asking now saves both sides discovering it in week three.

Applying for an internship asks for your name, email, phone, school, program and year, the track you want, whether you are a student needing OJT or practicum hours or a recent graduate, how many hours you need and when you can start, an optional link to your work, and a few lines in your own words. We use it only to review your application and to contact you about it.

None of that is patient data. We never ask for a patient name, a claim, a chart or a diagnosis, at any stage of a conversation with us, and you should refuse any request that looks like one.

What we store is smaller than what you send. Your name and contact details are delivered to our team and live in the mailbox and messaging account we use to reply to you. If we hold a meeting time so that nobody else is offered it, we keep only the date and time for that purpose, never your name or contact details.

Details from any of these forms reach our founders through a business messaging service and by email, which means those providers process them in transit under their own privacy policies rather than ours. We use messaging because it is where our team actually reads messages, and a request that sits unread is a request we failed. Both are listed under Who else sees data for that reason.

We keep a request for as long as the conversation it belongs to is live, and delete it on request. Write to us and it is gone.

11What we deliberately do not use

  • Advertising or retargeting pixels of any kind
  • Cross-site tracking identifiers
  • Social media embed trackers of any kind
  • Session recording or heat mapping tools
  • Third-party scripts that read page content

12Why that list is so short

Every third-party script is a privacy claim we would then have to defend on our Trust Center, and a cost to page performance. Given that our entire architecture argument is about not collecting things, loading a tracking pixel would be difficult to explain and impossible to justify.

13If that ever changes

If we later add privacy-respecting analytics, this policy is updated before the first script loads, and anything beyond strictly necessary is placed behind explicit opt-in consent with a working control on this site.

We will not quietly begin collecting. The statement above is dated, and the change would be visible in the effective date at the top of this page.

14Your rights as a data subject

  • The right to be informed about how your data is processed
  • The right to access the personal data we hold about you
  • The right to rectify inaccurate or incomplete data
  • The right to erasure or blocking, where grounds under the Act apply
  • The right to object to processing, including withdrawal of consent
  • The right to data portability in a commonly used electronic format
  • The right to damages for inaccurate, false or unlawfully obtained use of your data
  • The right to lodge a complaint with the National Privacy Commission

15The audit log names the reviewer, and why it cannot be erased

Every approval, edit and rejection records the reviewer who made it. That is personal data about a member of hospital staff, and we declare it rather than bury it, because the same log is the evidence a hospital hands to a regulator.

The log is append only. Entries are never updated and never deleted, including by us. A request to erase an entry cannot be honored, because the record is retained under a legal obligation and as compliance evidence, which the Data Privacy Act recognizes as grounds that override erasure for that specific data.

The protection this gives a reviewer is real. The log shows exactly what evidence they were shown and exactly what they decided, which is what stands behind them if a claim is ever questioned.

16How to exercise a right

Write to our Data Protection Officer at oriaris.health@gmail.com. We respond within the period prescribed by the Act. If your request concerns patient data held by a hospital, that hospital is the controller and we will support their response rather than act independently.

If you are not satisfied with our response, you may complain to the National Privacy Commission. Its current contact details and complaint procedure are published at privacy.gov.ph. You do not need our permission or our involvement to do that, and we will not ask you to come to us first.

17No automated decision making about you

No Oriaris service makes a decision affecting any individual on its own. In Oriaris Core, rule evaluation will produce a suggestion for a licensed human reviewer, and nothing will be transmitted to a payer without that person's recorded verdict. Internship applications are read and decided by people.

This means the concerns that usually attach to automated processing, profiling and scoring do not arise here. There is no profile, no score, and no automated outcome to contest.

18If something goes wrong

In the event of a personal data breach we notify the National Privacy Commission and the affected parties within the period the Data Privacy Act requires, with the nature of the breach, the data involved, the likely consequences and the measures taken.

Where the data belongs to a hospital, that hospital is the Personal Information Controller and leads notification to its own data subjects. We notify the hospital without undue delay and give it everything it needs to do so.

19Regulatory registration

Our Data Protection Officer is Cindy Rico Macadaan, Chief Operations Officer, and the corporation maintains a Data Privacy Compliance Manual for registration with the National Privacy Commission. Registration status and the current certificate are available to any institution on request during a privacy review.

20Security measures

These measures apply to everything we build. For Oriaris Core, each hospital's data processing agreement will make them contractual, in the same words as this list.

  • Encryption in transit with a freshly generated initialization vector on every operation
  • Salted SHA-256 anonymization applied before any downstream processing
  • Claim payloads held in volatile memory within request scope, with no personal health information written to storage, to a log, to a cache, or to an error response
  • Secrets held in environment configuration, never in source code
  • Access restricted to an explicit allowlist of origins, never a wildcard
  • Append-only audit logging of every rule firing and human verdict, never updated and never deleted
  • Synthetic data used for all development, testing and demonstration
  • Notification of a personal data breach to the affected institution and to the National Privacy Commission

21Children

This website is for healthcare professionals, students applying for internships and, through NeuroBloom when it opens, parents and caregivers. It is not directed at children, and we do not knowingly collect a child's personal data.

Before NeuroBloom collects anything about a child, it will be reviewed against professional, privacy and safeguarding requirements, and this policy will say what is collected, why and with whose consent. Pediatric cases that appear in claim data processed for a hospital will be subject to the same zero-retention design as all other cases.

22Governing law

This policy is governed by the laws of the Republic of the Philippines, principally Republic Act 10173 and its implementing rules. Nothing here limits a right you hold under that Act or under any other law that applies to you. Where a hospital is the controller of the data you are asking about, that hospital's own policy governs its handling and this policy governs ours.

23Changes to this policy

This is version 1.0, effective October 4, 2026, printed at the top of this page. Material changes are published here with a new version number and a revised effective date, and notified to institutional customers in advance where the change affects processing.

Every superseded version is kept, and any prior version is available on request by number, with the dates it was in force. A privacy commitment you relied on should be provable after the fact, not only while it is on screen.