Privacy and data handling
Privacy Policy
This notice explains how information moves through an account, case preparation, human review and case-specific coordination. It does not by itself authorise a new use of medical records. Navelia is the controller for coordination-account data. The treating hospital is the controller for the clinical record.
Last reviewed 2026-09-06 · privacy-v2026-09-06. This page is a public summary; a signed agreement governs if one exists. Nothing here is legal advice.
Free enquiries before an account
- The free form requires an email address and an enquiry-goal choice. Name, country or region, and preferred language are optional. Do not submit medical files or detailed health history here.
- We use these details to respond to your request. A call request also records your preferred date, local time, time zone and its corresponding instant; it is not an appointment confirmation.
- An enquiry that has not become a formal case enters controlled retention review 30 days after receipt. This is a review deadline, not a promise of automatic deletion. Formal cases and audit evidence follow their own retention rules.
- For an enquiry privacy request without an account, contact the team with your request reference. Identity must be verified before access, correction or other handling. The reference alone grants no access to personal information.
Information covered
- Account and identity details, contact preferences, submitted health information, medical records, consent choices, and case communications.
- Technical and security records needed for authentication, fraud prevention, access control, audit, and service reliability.
- Health data is sensitive / special-category personal data. We process the minimum needed. We do not build advertising profiles.
Why information is used
- To create and protect an account, organize a case, check record readiness, coordinate requested services, and deliver a reviewed consultation report.
- AI may assist with extraction, translation, organization and drafts. Patient-facing or clinical use requires human review. AI never diagnoses.
- For people in the EEA/UK: ordinary data on contract or legitimate interests; health data on explicit consent (GDPR Arts. 6 and 9). For people in China: PIPL separate consent and necessity for sensitive personal information.
Access and external sharing
- Access is role-based, case-scoped, and recorded. A user must be authorized for the relevant patient, case, or assigned review task.
- Selected records are shared with a doctor, hospital, or care partner only for the requested purpose and after the required sharing authorization.
Private files and safety checks
- Original files use private object storage and permission-checked, time-limited transfer links rather than public file URLs.
- Uploaded material must pass malware scanning and the required extraction or de-identification stage before it becomes eligible for AI-assisted processing.
- We do not sell records or contact details to advertisers or brokers. Applicable processing locations and external recipients must be disclosed for the service you authorize. This website does not collect payment-card numbers.
Cross-border processing and choices
- Cross-border processing for international coordination requires a separate service authorization. External recipients and disclosures remain case-specific.
- Optional de-identified model-improvement permission is separate from the core service and can be declined without preventing basic case coordination.
Retention, requests, and incidents
Information is retained according to the applicable record schedule, active service needs, security requirements, and legal holds. Deletion or access requests may be limited where records must be preserved. You may request access, correction, deletion, restriction and, where applicable, portability. Use the authenticated patient portal for case, access, correction, deletion, withdrawal, and other privacy-rights requests; never send medical records through an unverified public channel. The team verifies identity, applicable preservation requirements and the authorized handling before confirming the outcome of a request. Free-enquiry review after 30 days does not set the retention period for a clinical case or promise deletion within 30 days.
Official reference register
Traceable, not a certification claim
These official sources identify legal principles considered in the policy design. They do not certify Navelia. Qualified counsel must still review the verified entity before launch.
- Personal Information Protection Law of the People’s Republic of China — Articles 28–30 address sensitive personal information, including medical and health information, separate consent, necessity, and heightened protection.
- Personal Information Protection Law — official Chinese text — Primary Chinese-language reference for purpose limitation, transparency, sensitive information, individual rights, and cross-border processing obligations.
- What personal data is considered sensitive? — Official EU guidance identifies health data as a special category and summarizes the stricter Article 9 processing conditions.