Skip to main content

Legal information · Version 1.0

Privacy Notice

Effective 8 August 2026 · Last reviewed 8 August 2026

Review required before launch. This product-specific draft must be approved by qualified Indian privacy and healthcare counsel. Replace every “to be confirmed” operator detail before making the service publicly available.

1. Scope, operator and privacy roles

This Notice explains how Review1M (“R1M”, “we”, “us”) handles personal data through review1m.in and the R1M web application. Operator address: Kerala.

R1M provides pseudonymous follow-up infrastructure. For account administration, security, messaging and platform operations, R1M determines why and how data is handled. A connected doctor independently determines the clinical purpose and professional use of records they create, request or review and may have separate legal and professional obligations. Ask the doctor or institution for its own privacy notice where relevant.

“Pseudonymous” does not mean anonymous. A PID, DID, account, device or combination of records may still relate to an identifiable person and is protected accordingly.

2. Personal data we handle

CategoryExamplesHow obtained
Patient accountPID, password hash, MFA configuration, recovery-code hashes, account status and preferencesFrom the patient and generated by R1M
Doctor and administrator identityDID, name, email, phone, professional registration, institution, credentials, profile image, verification and approval recordsFrom the professional, administrators and verification process
Follow-up and health recordsConnections, care episodes, questionnaire answers and scores, alerts, doctor findings, interpretations, schedules and revisionsFrom patients and connected doctors
Messages and notificationsEncrypted message content, delivery/read status, document-share messages and generic notification recordsFrom users and generated by R1M
External document sharingEncrypted cloud file identifiers and titles, file type/size, recipient, expiry, permission and access events. R1M does not intentionally copy the underlying Google Drive file to its serverFrom the patient, cloud provider and viewing doctor
Technical and security dataSession identifiers, timestamps, IP and user-agent hashes, authentication events, audit records, push subscription keys, error and abuse-prevention dataAutomatically from devices and service operation
Privacy communicationsAccess/correction/erasure/withdrawal requests, grievances, supporting details and resolution recordsFrom the requester and privacy team

Patients are instructed not to provide names, email addresses, phone numbers, Aadhaar numbers, full dates of birth or residential addresses in patient account fields, messages or free text unless genuinely necessary for care and permitted by the relevant doctor. R1M does not use live facial recognition or store face captures.

3. Purposes and lawful handling

We handle data only for stated and reasonably expected purposes, including to:

  • create and secure patient, doctor and administrator accounts;
  • verify healthcare professionals and administer permissions;
  • connect patients and doctors with mutual approval;
  • provide questionnaires, schedules, messages, follow-up records and patient-authorised document sharing;
  • send generic service notifications without clinical details in external payloads;
  • maintain audit trails, investigate misuse, protect users and operate backups;
  • respond to privacy requests, grievances, legal obligations and valid government directions;
  • measure reliability and improve accessibility using appropriately minimised operational information.

Depending on the context and the provisions then in force, handling may rely on your consent, your voluntary provision of data for a specified purpose, performance of requested platform functions, permitted legitimate uses, compliance with law, or protection against security incidents and legal claims. Consent can be withdrawn through the Privacy and Access page where applicable, but withdrawal does not invalidate prior lawful handling or require deletion where retention is legally necessary.

R1M does not sell personal data or use health records for behavioural advertising. R1M will not use identifiable clinical records for research, model training or unrelated analytics without a separate documented legal basis and any required consent or ethics approval.

4. Disclosure and service providers

Data may be disclosed only as needed to:

  • the patient and mutually connected, authorised doctors;
  • authorised R1M administrators acting under role-based access;
  • hosting, database, email, queue, security, logging and support providers under appropriate contractual and confidentiality controls;
  • Google Drive or another patient-selected cloud provider when the patient connects an account or grants/revokes document permission;
  • regulators, courts, law-enforcement or emergency authorities when legally required or necessary to protect life and safety;
  • a successor entity during a reorganisation, subject to applicable notice and protection requirements.

Cloud, email, security and infrastructure providers may process information in other locations. Any cross-border transfer will be assessed against applicable Indian restrictions and contractual safeguards. A doctor may retain information outside R1M in accordance with professional, institutional and legal duties; that separate handling is the doctor's or institution's responsibility.

5. Security, storage and retention

Controls include pseudonymous identifiers, encrypted sensitive database fields, password hashing, MFA, role-based authorisation, signed immutable follow-up records, access logging, rate limits, secure session settings, revocable document permissions and restricted administrator access. No online service can promise absolute security.

Records are retained only as long as needed for the stated purpose, patient safety, continuity, dispute handling, security, backup integrity and applicable legal or professional duties. Account, clinical, audit, grievance and backup categories may require different periods. R1M will publish an approved retention schedule before production launch; until then, users should not assume immediate deletion. Expired backups are removed through controlled rotation, and records subject to a legal hold may be retained until the hold ends.

If we become aware of a personal-data breach, we will investigate, contain and notify affected individuals and the competent authority when and in the form required by applicable law.

6. Your choices and data rights

Subject to applicable law and identity verification, you may request access to a summary of data and disclosures, correction or completion, erasure where retention is no longer required, withdrawal of consent, grievance redressal, and nomination of another person where that right applies. Some requests may be limited to protect another person, preserve clinical-record integrity, comply with law or retain evidence of security and consent events.

Signed clinical records are not silently overwritten. A correction is recorded as a signed revision so the clinical and audit history remains understandable. Revoking a doctor connection stops future access through R1M but may not delete records already lawfully retained by the doctor or institution.

Authenticated users can use Privacy and Access to submit requests or grievances. We may ask for PID/DID, MFA or other proportionate verification and will never ask for a password or recovery code by email. If dissatisfied after using our grievance process, you may approach the Data Protection Board of India or another competent authority when the relevant statutory mechanism applies.

7. Children and persons requiring lawful representation

R1M is currently designed for adults aged 18 or older. It does not yet provide verified parental-consent or lawful-guardian workflows. Do not create an account for a child or a person unable to provide valid consent until R1M expressly introduces and documents an approved representative process.

8. Contact and grievance redressal

Privacy enquiries
info@review1m.in
Grievance contact
[Will update soon]
Postal address
Kerala
Product support
info@review1m.in

For account-specific matters, the authenticated grievance form is safer than ordinary email. Do not include passwords, MFA codes, recovery codes or unnecessary health details in email.

9. Changes to this Notice

We may update this Notice when features, providers or legal requirements change. Material changes will be highlighted in the application and, where required, fresh notice or consent will be requested. The version and effective date above identify the governing text.