Legal information · Version 1.0
Privacy Notice
Effective 8 August 2026 · Last reviewed 8 August 2026
1. Scope, operator and privacy roles
This Notice explains how Review1M (“R1M”, “we”, “us”) handles personal data through review1m.in and the R1M web application. Operator address: Kerala.
R1M provides pseudonymous follow-up infrastructure. For account administration, security, messaging and platform operations, R1M determines why and how data is handled. A connected doctor independently determines the clinical purpose and professional use of records they create, request or review and may have separate legal and professional obligations. Ask the doctor or institution for its own privacy notice where relevant.
“Pseudonymous” does not mean anonymous. A PID, DID, account, device or combination of records may still relate to an identifiable person and is protected accordingly.
2. Personal data we handle
| Category | Examples | How obtained |
|---|---|---|
| Patient account | PID, password hash, MFA configuration, recovery-code hashes, account status and preferences | From the patient and generated by R1M |
| Doctor and administrator identity | DID, name, email, phone, professional registration, institution, credentials, profile image, verification and approval records | From the professional, administrators and verification process |
| Follow-up and health records | Connections, care episodes, questionnaire answers and scores, alerts, doctor findings, interpretations, schedules and revisions | From patients and connected doctors |
| Messages and notifications | Encrypted message content, delivery/read status, document-share messages and generic notification records | From users and generated by R1M |
| External document sharing | Encrypted cloud file identifiers and titles, file type/size, recipient, expiry, permission and access events. R1M does not intentionally copy the underlying Google Drive file to its server | From the patient, cloud provider and viewing doctor |
| Technical and security data | Session identifiers, timestamps, IP and user-agent hashes, authentication events, audit records, push subscription keys, error and abuse-prevention data | Automatically from devices and service operation |
| Privacy communications | Access/correction/erasure/withdrawal requests, grievances, supporting details and resolution records | From the requester and privacy team |
Patients are instructed not to provide names, email addresses, phone numbers, Aadhaar numbers, full dates of birth or residential addresses in patient account fields, messages or free text unless genuinely necessary for care and permitted by the relevant doctor. R1M does not use live facial recognition or store face captures.
3. Purposes and lawful handling
We handle data only for stated and reasonably expected purposes, including to:
- create and secure patient, doctor and administrator accounts;
- verify healthcare professionals and administer permissions;
- connect patients and doctors with mutual approval;
- provide questionnaires, schedules, messages, follow-up records and patient-authorised document sharing;
- send generic service notifications without clinical details in external payloads;
- maintain audit trails, investigate misuse, protect users and operate backups;
- respond to privacy requests, grievances, legal obligations and valid government directions;
- measure reliability and improve accessibility using appropriately minimised operational information.
Depending on the context and the provisions then in force, handling may rely on your consent, your voluntary provision of data for a specified purpose, performance of requested platform functions, permitted legitimate uses, compliance with law, or protection against security incidents and legal claims. Consent can be withdrawn through the Privacy and Access page where applicable, but withdrawal does not invalidate prior lawful handling or require deletion where retention is legally necessary.
R1M does not sell personal data or use health records for behavioural advertising. R1M will not use identifiable clinical records for research, model training or unrelated analytics without a separate documented legal basis and any required consent or ethics approval.
5. Security, storage and retention
Controls include pseudonymous identifiers, encrypted sensitive database fields, password hashing, MFA, role-based authorisation, signed immutable follow-up records, access logging, rate limits, secure session settings, revocable document permissions and restricted administrator access. No online service can promise absolute security.
Records are retained only as long as needed for the stated purpose, patient safety, continuity, dispute handling, security, backup integrity and applicable legal or professional duties. Account, clinical, audit, grievance and backup categories may require different periods. R1M will publish an approved retention schedule before production launch; until then, users should not assume immediate deletion. Expired backups are removed through controlled rotation, and records subject to a legal hold may be retained until the hold ends.
If we become aware of a personal-data breach, we will investigate, contain and notify affected individuals and the competent authority when and in the form required by applicable law.
6. Your choices and data rights
Subject to applicable law and identity verification, you may request access to a summary of data and disclosures, correction or completion, erasure where retention is no longer required, withdrawal of consent, grievance redressal, and nomination of another person where that right applies. Some requests may be limited to protect another person, preserve clinical-record integrity, comply with law or retain evidence of security and consent events.
Signed clinical records are not silently overwritten. A correction is recorded as a signed revision so the clinical and audit history remains understandable. Revoking a doctor connection stops future access through R1M but may not delete records already lawfully retained by the doctor or institution.
Authenticated users can use Privacy and Access to submit requests or grievances. We may ask for PID/DID, MFA or other proportionate verification and will never ask for a password or recovery code by email. If dissatisfied after using our grievance process, you may approach the Data Protection Board of India or another competent authority when the relevant statutory mechanism applies.
7. Children and persons requiring lawful representation
R1M is currently designed for adults aged 18 or older. It does not yet provide verified parental-consent or lawful-guardian workflows. Do not create an account for a child or a person unable to provide valid consent until R1M expressly introduces and documents an approved representative process.
8. Contact and grievance redressal
- Privacy enquiries
- info@review1m.in
- Grievance contact
- [Will update soon]
- Postal address
- Kerala
- Product support
- info@review1m.in
For account-specific matters, the authenticated grievance form is safer than ordinary email. Do not include passwords, MFA codes, recovery codes or unnecessary health details in email.
9. Changes to this Notice
We may update this Notice when features, providers or legal requirements change. Material changes will be highlighted in the application and, where required, fresh notice or consent will be requested. The version and effective date above identify the governing text.