Privacy Policy
Last updated: July 27, 2026
This policy covers two apps published by Adrisco LLC:
- Artemis Care (also referred to as DCC One) is a nurse-call pager app used by care staff in assisted-living and long-term-care communities to receive and respond to resident alarms.
- Artemis Setup is a companion app used by installers and technicians to configure Artemis hardware at a community.
Both apps are workplace tools. They are provisioned by a care community for its own staff on community-owned devices. There are no consumer accounts, no sign-up, and no advertising.
How the system works
Understanding the architecture explains most of this policy.
Each community runs its own on-premise Artemis server. A device is provisioned by scanning a QR code generated from the community's admin console; from then on, the app communicates with the on-site server over the community's own local network using QUIC with encrypted transport. Many communities operate air-gapped networks with no internet connectivity at all, and in that configuration data never leaves the building.
Alarm information flows from the on-site server to staff devices on the community's network. Adrisco does not route resident data through consumer cloud services, and the apps do not communicate with Adrisco, Apple, or any third party to deliver alarm content.
Information processed
Resident health information
To deliver alarms, the app processes:
- Resident names
- Room and location information
- Alarm types (for example, a pull-cord or pendant activation) and their timestamps
This information originates from the community's own on-site server and is displayed to authorized staff so they can respond to residents. We treat it as protected health information (see the HIPAA section below).
Staff and user information
- Staff sign in with a PIN validated against the community's own configuration. There are no consumer accounts and no sign-up.
- Session information (who is signed in on which device) is held by the community's server and on the device.
Device and diagnostic information
- The app stores alarms, session state, and diagnostic logs locally on the device.
- A debug-log export exists for troubleshooting. It runs only when a user explicitly triggers it, and the user must share the resulting file themselves (for example, via AirDrop). It is never transmitted automatically anywhere.
- The apps contain no analytics SDKs, no advertising SDKs, no tracking, and no advertising identifiers.
Where data is stored and processed
- On the community's server. The primary copy of alarm and configuration data lives on the on-premise Artemis server operated at the community.
- On the device. The app keeps a local store of alarms, session data, and logs on the community-owned device.
- Data residency. Where data is hosted on servers, those servers are located in the country of origin, the United States or Canada, and data stays in-region.
HIPAA and the business-associate relationship
Resident data handled by these apps is treated as protected health information (PHI) under the U.S. Health Insurance Portability and Accountability Act (HIPAA), and under applicable Canadian provincial health privacy law for Canadian communities.
The care community is the covered entity (in Canadian terms, the custodian or data controller) and remains the owner of its residents' data. Adrisco acts as a business associate to the community and processes resident data only to provide the nurse-call service to that community.
What we do not do
- We never sell, rent, or distribute your data to anyone.
- We do not send resident or staff data to Apple or to any third party.
- We use no analytics SDKs, no advertising, and no tracking of any kind.
- We do not put protected health information in push notifications (see below).
- Data does not leave its region of origin (United States or Canada).
Push notifications
When a staff device has no live connection to the community's local network, the on-site server can send an Apple Push Notification as a fallback so the device can alert staff.
That push payload deliberately carries no protected health information: no resident name, no room, no alarm details. It contains only an opaque alarm identifier. When the device receives the notification, it looks up the alarm details from its own local store. As a result, resident information is never exposed to Apple's push infrastructure or to any party outside the community's system.
Data retention and deletion
The community controls its own data. Retention periods for alarm history and related records are determined by each community according to its own policies and legal obligations; Adrisco does not impose or override them.
Data stored locally on a device is removed when the device is de-provisioned or the app is deleted. Requests concerning a specific resident's records should be directed to the care community, which is the covered entity and controller of that data.
Security
- All communication between the app and the community's server is encrypted in transit (QUIC/TLS).
- Device credentials are held in the device's secure hardware keychain.
- Access to the app is gated by a staff PIN validated against the community's configuration.
- The apps run on community-owned, community-managed devices, not personal phones.
- In air-gapped deployments, the system operates with no internet connectivity at all.
Demo mode
Artemis Care includes a demonstration mode used solely for App Store review. Demo mode contacts no server and uses only simulated, fictitious data. No real resident or community information is involved.
Children's privacy
Artemis Care and Artemis Setup are workplace tools for care-community staff and installers. They are not directed at children, and we do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be reflected on this page before they take effect.
Contact
For questions about this policy or our privacy practices, contact Adrisco LLC at [email protected].
For questions about a specific resident's data, contact the care community where the system is deployed. The community is the covered entity responsible for that data.