01About us and this Policy
Navelia Health is operated by a company established in the United States. We help patients prepare cases, organize and translate medical materials, arrange authorized professional review, communicate service needs, and coordinate planned care in China. This Policy explains how we collect, use, retain, protect, and disclose personal information and how you may exercise relevant rights. The contracting entity, public address, and privacy contact information will be identified in the published version and applicable service order.
02Scope and related documents
This Policy covers the websites linking to it, free enquiries, accounts, the patient portal, case preparation, and authorized communications and coordination. Care delivered independently by a healthcare institution, its independent medical records, and third-party products you use directly are also governed by their own notices and rules. Our Terms of Service govern commercial and service arrangements. This Policy does not replace a purpose-specific patient authorization, medical informed consent, or a healthcare institution's applicable Notice of Privacy Practices (NPP). Reading or accepting this Policy does not authorize every use of health information, disclosure, marketing activity, or research project.
03Our HIPAA Business Associate role
When processing protected health information (PHI) on behalf of a HIPAA-covered healthcare organization or another authorized principal, Navelia acts as a Business Associate or applicable downstream business associate. We comply with the HIPAA Privacy, Security, and Breach Notification requirements applicable to that role and the relevant Business Associate Agreement (BAA). We process PHI only under that agreement, lawful instructions, and applicable law. This Policy grants no independent right to sell PHI or use it for marketing, research, or model training. Applicable law and restrictions in a valid BAA take precedence over general website wording concerning PHI. This Policy does not characterize Navelia as a hospital or HIPAA Covered Entity and is not an NPP issued on behalf of a commissioning healthcare organization.
04PHI and other personal information
Health information is sensitive, but whether particular data qualifies as PHI under HIPAA depends on its source, holder, and service relationship, not solely on its content. Free-enquiry information, general website activity, or information obtained through services provided directly to individuals does not automatically become PHI because Navelia is a Business Associate in other engagements. We protect non-PHI personal information under this Policy, our actual commitments, and applicable privacy and consumer health data laws. We distinguish these processing relationships and do not use our Business Associate status to exclude other applicable obligations.
05Information we collect
| Category | Scope |
|---|---|
| Enquiries and contact | Email and enquiry goal; optional name, country or region and language; requested call date, time, time zone and handling records. |
| Account and identity | Name, contact details, age or adult eligibility, account identifiers, protected authentication information and session records; additional identity evidence only where necessary for a specific service. |
| Case and health information | Authorized submissions concerning history, diagnoses, medicines, allergies, tests, pathology, imaging, prior treatment, medical questions and related documents. |
| Processing and review materials | Extracted text, translations, structured information, drafts, review findings, final reports, and correction or missing-record history, which may also be sensitive. |
| Representation and permissions | Representative identity, contact details, evidence of authority, signatures and withdrawals, recipient choices and authorization versions. |
| Services, fees and travel | Scope and quotes, orders, payment verification and refund records; appointment, travel, companion or visa details only as needed for selected services. |
| Communications, security and technical data | Case messages, service requests, complaints, IP address, device/browser details, access times, authentication and necessary audit records. |
Enquiries and contact
- Scope
- Email and enquiry goal; optional name, country or region and language; requested call date, time, time zone and handling records.
Account and identity
- Scope
- Name, contact details, age or adult eligibility, account identifiers, protected authentication information and session records; additional identity evidence only where necessary for a specific service.
Case and health information
- Scope
- Authorized submissions concerning history, diagnoses, medicines, allergies, tests, pathology, imaging, prior treatment, medical questions and related documents.
Processing and review materials
- Scope
- Extracted text, translations, structured information, drafts, review findings, final reports, and correction or missing-record history, which may also be sensitive.
Representation and permissions
- Scope
- Representative identity, contact details, evidence of authority, signatures and withdrawals, recipient choices and authorization versions.
Services, fees and travel
- Scope
- Scope and quotes, orders, payment verification and refund records; appointment, travel, companion or visa details only as needed for selected services.
Communications, security and technical data
- Scope
- Case messages, service requests, complaints, IP address, device/browser details, access times, authentication and necessary audit records.
The table does not require you to provide every category at once. We collect what is needed at each service stage and do not require medical records, passports, insurance details, or a detailed health history merely to browse the website. Public free-enquiry forms do not accept medical files or detailed histories; submit these through an authorized secure channel.
06Sources and information about others
Information may come from you, a verified authorized representative, a healthcare organization or principal permitted to provide records, and necessary technical records generated by use of the service. We also create case-organization and review records. You must have appropriate authority before submitting another person's information. Family relationship, payment for someone else, or knowledge of a case reference does not automatically grant access or decision-making authority. We process family-member information only to the extent necessary for the current service. Tell us about mistaken uploads, unauthorized submissions, or incorrect attribution so we can restrict use, investigate, and correct them.
07Purposes and authority for processing
We process information to answer enquiries, establish and protect accounts, perform defined services, organize and translate records, identify missing or conflicting information, arrange professional review, carry out authorized coordination, verify fees and refunds, handle corrections and complaints, prevent misuse, and meet legal obligations. We do not treat “service improvement” as unlimited permission to repurpose health information. PHI uses are limited by the BAA and the principal's lawful authority; other information is processed on grounds available under applicable law. Where sensitive-data consent, disclosure authorization, or another specific permission is required, we obtain it before the relevant activity. Processing without consent is limited to purposes and scope permitted by applicable law.
08U.S. storage and servers
Navelia's platform servers and business-data storage under our control are located in the United States. This arrangement covers the platform's primary databases, original uploaded materials, case-processing and review records, and backups, disaster-recovery copies, and personal-information-containing logs that we manage. We use AWS for cloud storage and AI services and require relevant configurations to meet U.S. regional storage and processing restrictions. We do not treat a U.S. account or entry point as sufficient proof that all processing occurs in the United States.
U.S. platform storage does not mean that information is never viewed or received by authorized recipients in China. The China remote-access and minimum-data-package arrangements below, and records independently created or legally retained by Chinese hospitals, have separately described processing boundaries. A China operating partner does not receive access to the whole platform, its backups, or administrative privileges merely because of the partnership.
09AWS and service-provider governance
AWS services involving PHI may be used only within the applicable AWS BAA and the relevant HIPAA-eligible service and feature scope. We remain responsible for account, permission, encryption, logging, regional, and data-flow configurations. The storage products, AI services, models, processing regions, and other recipients must be recorded in a controlled inventory. Providers may perform services only within their authorized scope and are subject to appropriate confidentiality, purpose, security, incident-reporting, and return-or-deletion obligations. Changes affecting your rights, processing locations, or authorization scope are notified as required, and new permission is obtained where necessary.
10AI assistance and human review
Within authorized services, AI may assist document extraction, translation, organization, summaries, missing-information prompts, and drafting. We limit the information sent to AI and reduce identifying fields where the task permits. Removing a name or replacing identity with a reference does not by itself establish HIPAA-compliant de-identification; the data remains protected according to its actual sensitivity. AI may omit, mistranslate, misassociate, or generate inaccurate information. Outputs require the applicable human and clinician reviews before becoming formal patient-facing deliverables. AI does not autonomously diagnose, prescribe, determine treatment, guarantee hospital acceptance, or decide fitness to travel.
11AI retention, training and optional uses
Submitting a case is not permission for general-purpose model training, fine-tuning, a public knowledge base, advertising profiles, or public case publication. Service inference, security detection permitted by law or contract, retained case drafts, and model training are different purposes and require separate management of scope, recipients, and retention. We do not promise that every AI input and output has zero retention or can never undergo human review without verifying the specific service and model. Separate uses such as model improvement, research, teaching, public case studies, or marketing require compliance with applicable law, the principal's BAA permissions, and necessary authorizations. A separate checkbox cannot override a BAA or law. Declining optional uses does not affect unrelated basic services.
12Remote access by the China operating partner
Named personnel at the China operating partner may remotely view specified case information in the U.S. platform to perform coordination tasks you have selected and authorized. Access is limited by case, role, purpose, and duration and is logged for security and compliance review. Remote viewing is access and processing in China even when the original data remains stored in the United States. Access authorization does not include unrestricted bulk searching, downloading, copying other cases, sharing accounts, or accessing databases or backups. Relevant access is restricted or revoked when personnel leave, tasks end, authorization expires, or security concerns arise.
13Minimum necessary data packages for China
Where there is lawful authority and any required patient authorization, we may also send a designated China partner or healthcare institution a minimum-data package necessary for a specific task. The package must identify the recipient, purpose, selected fields or files, transfer method, duration, whether controlled copies are permitted, and return or deletion arrangements. It may contain a reviewed case summary and relevant tests for professional pre-review, identity-verification fields for an appointment, or necessary contact and travel details for confirmed logistics. A need for information at one stage does not justify giving every partner access to the entire medical record.
Receiving a package differs from remote viewing and may create a controlled recipient copy. Without a task-specific written arrangement, recipients may not establish a China mirror case database, retain long-term operational copies, forward materials to personal email or messaging accounts, upload them to unapproved cloud storage or AI, use them for independent marketing, or pass them to unlisted recipients. Any necessary temporary copy or hospital statutory record must be described, with its scope and retention arrangements, before disclosure. One authorization does not automatically extend to a new hospital, purpose, or set of materials.
14Applying minimum necessary controls
We use task-based data minimization as an operational control for China coordination. HIPAA's statutory minimum necessary standard has defined limits and exceptions and is not mandatory in every treatment disclosure, individual-access disclosure, or patient-authorized disclosure. Even where a HIPAA exception applies, the China operating partner remains limited to the disclosed coordination scope. Minimization must not conceal necessary history, allergies, or other critical clinical information. If a treating clinician needs more information, the recipient, necessary scope, and lawful sharing authority must be confirmed again.
15Hospitals and other independent recipients
Chinese hospitals, clinicians, laboratories, insurers, and travel providers may independently process information for their own service responsibilities. A China partner acting for Navelia has a different role from a hospital independently delivering treatment. We determine processing, BAA, or other disclosure arrangements from the actual relationship rather than treating every recipient as a HIPAA business associate. A hospital providing care in China may be legally required to create, retain, and manage its own records there; those records are outside the U.S. platform backup commitment. You may exercise applicable rights with that institution, and we assist within our authority. Information held by another recipient is not necessarily protected by U.S. HIPAA.
16Other permitted disclosures
Within permissions or requirements of applicable law and the BAA, we may disclose information to authorized authorities, professional legal and audit advisers, or necessary service providers, for example for mandatory reporting, valid legal process, prevention of serious and imminent harm, security investigations, or protection of lawful rights. We verify the authority and necessary scope and provide notice where required and legally permitted. A foreign authority's request does not automatically authorize unrestricted disclosure. A merger, restructuring, or business transfer remains subject to applicable law, BAAs, confidentiality, and purpose restrictions; information does not become freely tradable merely because such a transaction occurs.
17Uses we restrict
We do not sell medical records or contact details to advertisers or data brokers, build advertising profiles from case contents, allow marketing compensation to determine clinical review conclusions, or permit China partners to use patient information as an independent customer list. Necessary service-provider processing does not authorize the provider's own use. Public patient stories, identifiable photographs, clinical details in reviews, and teaching materials require appropriate separate permission. Data with direct identifiers removed may remain identifiable; anonymization or de-identification must meet the applicable standard and remains subject to the underlying contractual permissions.
18Cookies, logs and website technologies
We use session, security, and preference technologies necessary to operate the service. Optional analytics, advertising, third-party embeds, and other non-essential technologies must be described in the applicable technology inventory, including provider, purpose, information categories, and duration, with choices provided as required by law. Medical records, complete case pages, health-form inputs, and authentication credentials may not be sent to advertising pixels, unapproved session replay, or public analytics services. Technical logs should minimize medical content. Handling of browser privacy signals must reflect applicable law and actual functionality rather than a general statement substituting for configuration.
19Email, messaging and recordings
Enabled service notifications are sent for their actual purpose and should use prompts without diagnoses or medical-record contents where possible, directing you to the secure patient portal. Marketing preferences are distinct from necessary transaction or security notices. Do not send complete records through public forms, ordinary chats, or unverified email addresses. If a service includes telephone or video communications and recording, we explain the recording, purpose, participants, retention, and choices before it begins. Booking a call does not imply recording consent. Recordings and transcripts are also governed by this Policy. Communication availability depends on the services actually offered.
20Security measures and responsibilities
We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including role- and case-based access, staff identity verification and multi-factor authentication, encryption in transit and at rest, restricted file links, access records, security monitoring, access revocation, and controlled backups. Uploads undergo security checks, and unauthorized files or content may be quarantined or rejected. These measures should be supported by continuing risk assessment, workforce training, vendor management, and recovery verification. Protect your account, use trusted devices, and report suspicious activity promptly. No system can promise absolute security; this statement does not waive our statutory or contractual obligations.
21Retention and ending use
We retain information by category according to service needs, principal instructions, applicable law, and necessary preservation requirements, for no longer than justified by the relevant purpose. Free enquiries not converted to a formal case enter controlled retention review 30 days after receipt; this is a review date, not an automatic-deletion promise. Formal cases, medical reviews, financial records, authorizations, audit evidence, and backups require separately determined schedules. HIPAA's six-year requirements for certain compliance documentation are not a universal six-year medical-record rule, and system archive defaults are not statutory retention periods.
Closing an account, cancelling an order, or withdrawing a specific consent does not automatically erase records required by law or a valid BAA. Necessary preservation is limited to the relevant legal, security, dispute, or service purpose and does not justify continued marketing or unauthorized training. At expiry, authorized processes delete, return, or de-identify data to the applicable standard, and backups age out under controlled schedules. Data pending deletion in backups must not be returned to ordinary use. The published retention schedule will identify periods or clear determination criteria, start events, and backup handling.
22Your rights and how to exercise them
Depending on applicable law and the data relationship, you may request information, access or copies, correction, deletion or restriction, withdrawal of consent or authorization, objection to certain processing, and, where applicable, portability or an appeal. We reasonably verify identity and representative authority without using verification to cause unjustified delay. Information not displayed directly in the portal for security or legal reasons is handled through the applicable request process, rather than categorically denied simply because it is an internal record. A full or partial refusal includes the applicable reason and available review route.
Use the authenticated patient portal for case requests where possible. People without accounts, unable to log in, or making free enquiries may use the published privacy contact without purchasing another service. Initially provide non-clinical information sufficient to locate the request; do not attach records to a first ordinary email. We respond within applicable deadlines and explain reasons and expected completion dates for lawful extensions. Deadlines differ by right and law; 30 days is not a universal deadline for every request.
23HIPAA rights through the responsible healthcare organization
For PHI we maintain for a covered organization, its NPP and the BAA determine who handles requests. Navelia assists directly or promptly forwards them according to its responsibilities without restarting statutory timelines. Rights may include access and copies of a designated record set, amendment, an accounting of certain disclosures, particular use restrictions, confidential communications, an NPP copy, and complaints. HIPAA access requests generally require action within 30 calendar days of receipt, with one extension of up to 30 days when permitted and explained in writing beforehand; shorter applicable legal deadlines still apply. Other rights have separate rules, and disclosure accounting is not the same as access to every technical audit log. HIPAA does not itself grant an unconditional right to erase all medical records.
24Withdrawal, refusal and previously disclosed information
You may withdraw using the method in the authorization. We record when withdrawal takes effect, stop relevant future processing within our authority, and notify processors that need to act. Withdrawal generally does not invalidate prior authorized processing or guarantee recovery of records lawfully delivered to a hospital that must retain them. If sharing is necessary for a particular coordination service, we explain the affected step and available alternatives. Refusal is not treated as consent and does not automatically remove unrelated services or access to existing records. Required preservation, reporting, or processing under law or a BAA is explained separately.
25Representatives and minors
Family members and other representatives may submit, view, or receive information only within verified authority. We distinguish contact, administrative, payment, disclosure-consent, and medical decision-making permissions. Changes, expiry, or withdrawal of authority must be communicated promptly. General patient accounts are intended for adults able to contract. Any individual service for a minor or a person lacking full decision-making capacity requires separate confirmation of availability, applicable law, and valid guardianship or representation. General website wording does not establish acceptance of pediatric or guardianship services. Where minors may independently consent to particular care by law, representative access is restricted accordingly.
26International processing and regional rights
U.S. storage and a HIPAA Business Associate arrangement do not exclude other applicable laws. For processing governed by EEA or UK rules, or information accessed, used, created in China or subsequently provided to the United States, we determine the required authority, notices, safeguards, and permissions from the actual parties, locations, data, and activities. Information protected by applicable U.S. state privacy or consumer health data laws may carry additional rights; a separate consumer health data policy will be provided where required. Consent, a BAA, or a minimum-data agreement cannot authorize a legally prohibited transaction or access. Where sharing cannot lawfully proceed, we pause that step and explain its service impact.
27Incidents, notifications and complaints
On discovering an incident that may affect personal information, we take containment, investigation, necessary evidence-preservation, and remediation steps appropriate to our role. For entrusted PHI, we notify the principal without unreasonable delay under the applicable BAA and law and assist in identifying affected information and making required notifications. Notices to individuals or regulators are made by the legally responsible party or by us when authorized. HIPAA outer deadlines do not permit avoidable delay, and contracts or other laws may require earlier action. Required notices to you describe the incident, information categories, measures taken, protective steps you may take, and contact methods. Privacy complaints and exercise of rights do not result in retaliation.
28Updates, language and contacting us
The published Policy states its effective date and version. Material changes are communicated through appropriate channels. Where a changed purpose, recipient, or other matter requires renewed authorization, we complete that process rather than treating continued browsing as specific health-data authorization. The Chinese and English versions are intended to express consistent rights and duties. We explain ambiguities affecting rights and comply with mandatory applicable law. Contact us through the portal's privacy-request route or published privacy contact, or complain to the relevant commissioning healthcare organization and applicable regulator. Publication requires the U.S. operator's identifying information, public mailing address, privacy email, an access route for people unable to log in, and a way to obtain any applicable NPP.