Skip to main content
TECHNICAL GOVERNANCE & PRIVACY

Security, Data Isolation & Practice Trust

How Luce Vistaa protects clinical refraction records, financial transactions, and store intelligence through principled architecture and strict adherence to India's DPDP Act 2023.

Direct Governance Statement

Optical store data belongs exclusively to the optical practice. Luce Vistaa operates on a zero-monetization policy: we never sell, broker, or aggregate your customer phone numbers, clinical refraction measurements, or lens sales margins. Every practice operates within an isolated tenant boundary governed by verifiable audit logs.

Architectural Safeguards

Engineered for Clinical & Retail Integrity

Factual technical specifications of our database, authentication, and compliance systems.

Tenant Data Isolation

Practices are separated by logical tenant boundaries at the database query layer. No store can query, inspect, or accidentally bleed customer records, pricing tiers, or spectacle jobs into another store’s space.

Encryption in Transit & At Rest

All communications are encrypted using modern Transport Layer Security (TLS 1.3) with strict HTTP Strict Transport Security (HSTS) preloading. Production database volumes use AES-256 block-level encryption.

Role-Based Access Control (RBAC)

Granular store permissions ensure optometrists access clinical refraction charts, dispensing staff handle POS billing, lab workshop staff see job specs without financial figures, and only authorized owners approve discounts.

Immutable Audit Logs

Critical administrative actions — including price overrides, manual stock adjustments, cash drawer reconciliations, and bulk customer data exports — are permanently timestamped with user IDs and cryptographically recorded.

DPDP Act 2023 Compliance

Built in accordance with India’s Digital Personal Data Protection Act 2023. Explicit consent capture, customer right-to-erasure workflows, SHA-256 IP address hashing, and zero plain-text logging of sensitive customer details.

Automated Backups & Resilience

Daily automated point-in-time recovery backups stored in geo-redundant Indian cloud data centers. Routine failover drills ensure continuous store operations during peak festival and seasonal eyecare rush hours.

Responsible Vulnerability Disclosure

We welcome responsible security disclosures from ethical researchers and developers. If you discover a vulnerability or security flaw in any Luce Vistaa service, please review our standardized disclosure guidelines at /.well-known/security.txt or contact our technical team directly at support@lucevista.com.

Next-Generation Optical Commerce

Have specific enterprise compliance requirements?

Speak directly with our Chief Technology Officer regarding on-premise audits, custom data residency, or multi-branch security protocols.

Dedicated Optometrist SetupBulk Excel Import & Onboarding30-Day Risk-Free Guarantee