Privacy Policy and Terms and Conditions
Orcheston Terms and Conditions and Privacy Policy
Effective May 1, 2026
Orcheston. Where science scales. The operating system of medical innovations.
Front Matter
1. Document Identification
This document contains the Terms and Conditions (Part I) and the Privacy Policy (Part II) for the Orcheston system. Both parts apply to every Orcheston Account.
2. About Orcheston
Orcheston is operated by Bene Studio LLC, 50 Milk St, 16th Floor, Boston, MA 02109 (“Orcheston”, “we”, “us”). Orcheston provides a validated execution system on which Licensors deliver clinical Apps to Organizations, Practitioners and Patients. Orcheston is not a healthcare provider and does not manufacture the Apps.
3. Acceptance, Eligibility and Registration
By creating an Orcheston Account or using the system you accept this document. If you do not accept, do not register or use the system.
You must be at least 18, or have a parent, guardian or authorized proxy accept on your behalf. Proxy access to a Patient’s data is granted and revoked by the Organization according to its own policies and applicable law.
4. Definitions
- App — a clinical software application or platform, including any associated sensor, device or algorithm, provided by a Licensor and hosted on the system.
- Licensor — the entity that licenses an App to Organizations, Practitioners or Patients and is the legal manufacturer of that App.
- Organization — a hospital, health center or other entity that licenses Apps and authorizes Practitioners and Patients to use them.
- Practitioner — an individual working for or on behalf of an Organization who uses Apps within that Organization.
- Patient — an individual whose health data is collected through an App and who can access it in their Personal Health Repository.
- Personal Health Repository (PHR) — the Patient-controlled area of the system where a Patient’s collected data is stored and where the Patient manages sharing consent.
- System — the Orcheston software, hosted infrastructure, shared hardware and services, excluding the Apps.
- PHI — protected health information as defined under HIPAA.
Part I – Terms and Conditions
5. The System and Hosted Apps
Orcheston provides the system: account management, App hosting and execution, audit logging, shared hardware and support. The Apps are provided by Licensors under their own regulatory clearance, labeling and intended use. Orcheston does not provide clinical services, clinical judgment of its own.
6. Roles and Responsibilities
Licensor. Responsible for the App’s regulatory status, intended use, labeling, clinical performance and the accuracy of its outputs. Responsible for App-level post-market surveillance and for informing Orcheston of changes affecting the system.
Organization. Responsible for authorizing and deprovisioning its Practitioners and Patients, for the lawfulness of its use of PHI, for its Notice of Privacy Practices, for on-site handling of shared hardware and for clinical governance of App use within the Organization.
Practitioner. Responsible for using Apps within their professional scope and the Organization’s policies, for exercising independent clinical judgment and for protecting their credentials.
Patient. Responsible for protecting their credentials, for the accuracy of information they enter and for their consent decisions in the PHR.
7. Order of Precedence
If documents conflict, the following order applies, highest first:
- Applicable law and regulation.
- The agreement and Business Associate Agreement between Orcheston and the Organization.
- The license agreement between the Licensor and the Organization, including the App’s labeling and instructions for use.
- This document.
Nothing in this document reduces an Organization’s or Licensor’s obligations under 2 or 3.
8. Accounts, Credentials and Security Obligations
Your Orcheston Account is personal and may not be shared. You must keep credentials confidential, use multi-factor authentication, log out of shared devices and notify your Organization and Orcheston without delay if you suspect unauthorized use. You are responsible for activity under your Account until you report it.
9. Acceptable Use
You must not: impersonate another person; access data you are not authorized to access; interfere with the system, its security or its audit logs; reverse engineer, copy or resell the system or any App; use the system outside an App’s intended use; upload unlawful, harmful or infringing content; or use the system in a way that could harm any person.
10. Clinical Disclaimer
The system and Apps support, but do not replace, professional medical judgment. Output from an App is information for a qualified Practitioner, not a diagnosis or treatment decision by Orcheston. Clinical responsibility remains with the Practitioner and the Organization. The intended use of each App is defined by its Licensor.
Do not use the system for emergencies. If you need urgent care, contact your care team or local emergency services.
11. Shared Hardware and Kiosk Use
Kiosks, tablets and sensing modules on Organization premises are system hardware. Use them only as instructed, do not tamper with or remove them and end your session when finished. Orcheston may restrict or disable hardware that has been altered.
12. Service Availability and Service Levels
Standard Service Level. The system is available 99.9% of the time during Business Hours: 8:00 a.m. to 9:00 p.m. Eastern Time on business days (Monday to Friday, excluding U.S. federal holidays), measured yearly.
Critical Service Level. If an Organization separately orders it for a specific App, Orcheston provides availability of up to 99.999%, 24 hours a day, 7 days a week, measured yearly.
Maintenance. Under the Standard Service Level, Orcheston may perform maintenance outside Business Hours; that time is excluded from the availability calculation. Under the Critical Service Level, maintenance windows are agreed with the Organization in the order.
Exclusions. Unavailability caused by the Organization’s network or systems, the Licensor’s App, force majeure or emergency security fixes does not count against the Service Level. Measurement methodology and remedies are in Annex A and the Organization’s agreement. Service Levels are commitments to the Organization; individual users have no separate claim under them.
13. Support, Incident and Adverse Event Reporting
Support is available through the channels published in the system. Report suspected system defects to Orcheston. Report suspected App malfunctions, incorrect outputs or events affecting patient safety to your Organization and to Orcheston; Orcheston forwards App-related reports to the Licensor, who is responsible for regulatory reporting.
14. Communications from Orcheston
By registering you agree to receive electronic communications about your Account, the system and this document, including service, security and legal notices. You cannot opt out of these while you hold an Account. You may opt out of additional, optional communication.
15. Intellectual Property and Feedback
The system, including all validation documentation, is owned by Bene Studio LLC. Apps are owned by their Licensors. You receive a limited, revocable, non-transferable right to use the system for its intended purpose within your role. Any feedback you provide may be used by Orcheston without obligation to you.
16. Third-Party Services and Integrations
The system may connect to Organization systems such as electronic health records and single sign-on. Those systems are governed by the Organization. Supported browsers and devices are published in the system; unsupported environments may be blocked.
17. Suspension and Termination
Orcheston may suspend or terminate an Account for breach of this document, on instruction of the Organization, or when required for security or by law. Organizations control provisioning and deprovisioning of their users. Patients may close their Account at any time; data retained for regulatory reasons is handled per Section 27. Sections 15, 18 and 20 survive termination.
18. Disclaimers, Limitation of Liability and Indemnification
Except as expressly stated in this document or the Organization’s agreement, the system is provided “as is” and Orcheston disclaims all implied warranties. Orcheston is not liable for the performance, outputs or intended use of any App, which remain the Licensor’s responsibility.
To the extent permitted by law, Orcheston is not liable for indirect, incidental or consequential damages, and its total liability to any user under this document is limited to USD 100. Nothing limits liability that cannot be limited by law, including for gross negligence or willful misconduct.
You agree to indemnify Orcheston against claims arising from your breach of this document or your unlawful use of the system.
19. Changes to This Document and the Service
Orcheston may update this document. Material changes are notified at least 30 days before they take effect through the system or by email. Continued use after the effective date is acceptance. Orcheston may modify the system, provided Organization Service Levels and regulatory commitments are maintained.
20. Governing Law, Disputes and General Provisions
This document is governed by the laws of the Commonwealth of Massachusetts, excluding conflict-of-law rules. Disputes are resolved in the state or federal courts located in Boston, Massachusetts, unless the Organization’s agreement provides otherwise for that Organization’s users.
You may not assign your rights. If a provision is unenforceable the rest remains in effect. This document, with the agreements listed in Section 7, is the entire agreement between you and Orcheston regarding the system. Notices to Orcheston go to the contact in Section 30.
Part II — Privacy Policy
21. Scope and Orcheston’s Privacy Roles
This Policy covers information processed through the system. Orcheston acts in three roles:
- Business Associate for PHI processed on behalf of an Organization, under HIPAA and the Business Associate Agreement.
- Personal Health Repository vendor for data in a Patient’s PHR, where the Patient controls sharing.
- Controller for account data and system operational data of all users.
Each Organization’s own Notice of Privacy Practices governs the Organization’s use of PHI.
22. Information We Collect and How
All users: name, contact details, role, Organization, credentials, authentication events, device and browser data, IP address, and audit logs of system activity.
Patients: health data collected by Apps (including measurements from connected sensors), data entered by Practitioners or Patients, App outputs and consent records.
Practitioners: professional role, actions taken within Apps and Organization identifiers.
Licensors and Organization administrators: business contact details and configuration records.
We collect this information directly from you, from your Organization or Licensor, from Apps and connected devices and automatically as you use the system.
23. How We Use Information and Legal Bases
We use information to: operate the system and deliver Apps; authenticate users; maintain audit trails and regulatory records; secure the system and investigate incidents; provide support; measure availability and performance; and comply with law.
PHI is used only as permitted by the Business Associate Agreement and HIPAA. PHR data is shared only according to the Patient’s consent. Account and operational data is used to perform this agreement and to meet legal and regulatory obligations.
24. Patient Consent and the Personal Health Repository
Patients can view the data collected about them in the PHR. Patients decide, per recipient, whether to share PHR data with Organizations, Practitioners or Licensors beyond the sharing required to deliver care they have requested, and can revoke consent at any time in the PHR.
Revocation stops future sharing. It does not recall data already delivered to a recipient, and does not remove records the Organization or Licensor must retain under law or regulation. Every consent grant and revocation is recorded in an audit trail.
25. Information Sharing
We share information only with: your Organization and its authorized Practitioners; the Licensor of the App you use, to operate the App and meet its regulatory obligations; sub-processors that host and support the system (Annex B), bound by written confidentiality and security terms; authorities when required by law; and a successor in a merger or acquisition, under this Policy.
26. Cookies and Local Storage
The system uses necessary cookies and local storage for authentication, session security and system settings.
27. Data Security, Retention and Deletion
We protect information with encryption in transit and at rest, role-based access controls, multi-factor authentication, logging and monitoring, and a quality management system aligned to medical software standards.
Account data is retained while the Account is active and deleted or de-identified within 12 months after closure, unless a longer period is legally required. PHI is retained as instructed by the Organization and its Business Associate Agreement. Audit logs and records required by medical device regulation are retained for the period required by law, and cannot be deleted on request during that period. De-identified data, from which individuals cannot reasonably be identified, may be retained for system performance and safety analysis.
28. Security Incident and Breach Notification
If PHI is compromised, we notify the affected Organization without unreasonable delay and within the time required by HIPAA and the Business Associate Agreement; the Organization notifies affected individuals. If PHR data not covered by HIPAA is compromised, we notify affected Patients and, where required, the Federal Trade Commission under the Health Breach Notification Rule. We notify Licensors where App data or safety is affected.
29. Your Rights and Choices
Patients can access, download and correct PHR data and manage consent directly in the system. Requests concerning PHI held by an Organization (access, amendment, accounting of disclosures) are directed to that Organization; we assist the Organization in responding.
Practitioners, Licensors and administrators can view and update account details in the system and request account deletion through their Organization or Licensor.
State law. Residents of California may exercise CCPA/CPRA rights over information not covered by HIPAA. Residents of Washington have rights under the My Health My Data Act over consumer health data not covered by HIPAA. To exercise any right, contact us under Section 30; we verify identity before responding and respond within the time required by law. We do not discriminate against you for exercising rights.
Minors. Data of Patients under 18 is collected only under an authorization with parental, guardian or proxy consent as applicable law requires.
International users. The system is hosted in the United States. If you use it from outside the United States, your data is transferred to and processed in the United States.
30. Changes to This Policy, Privacy Officer and Contact
Material changes are notified per Section 19. Questions, requests and complaints go to:
Privacy Officer, Bene Studio LLC 50 Milk St, 16th Floor, Boston, MA 02109 [privacy@benestudio.co]
You may also complain to the U.S. Department of Health and Human Services Office for Civil Rights or your state attorney general.
Annexes
Annex A – Service Level Definitions and Measurement
Available means the system login and App execution functions respond to requests. Unavailable means they do not, as recorded by Orcheston’s monitoring, measured in one-minute intervals.
Standard availability = (Business Hours minutes − Unavailable Business Hours minutes) ÷ Business Hours minutes, per calendar month, excluding maintenance outside Business Hours and the exclusions in Section 12.
Critical availability = (total minutes − Unavailable minutes) ÷ total minutes, per calendar month, excluding agreed maintenance windows and the exclusions in Section 12.
Remedies for missed Service Levels are set out in the Organization’s agreement.
Annex B – Sub-processor List
| Sub-processor | Purpose | Location |
| Microsoft Azure | Infrastructure hosting | United States |
| Google, FreshDesk | Support ticketing | United States |
| Microsoft Azure | Availability monitoring | United States |
Changes notified 30 days in advance to Organizations.
Bene Studio – Who we are
Our website address is: https://benestudio.co.
What personal data we collect and why we collect it
Comments
When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
Media
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
Contact forms
Cookies
If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
Embedded content from other websites
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
Analytics
Who we share your data with
How long we retain your data
If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.
For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
What rights you have over your data
If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
Where we send your data
Visitor comments may be checked through an automated spam detection service.