Skip to main content

Privacy

Privacy notice.

How NAVNIA Ltd handles information across the public website, beta products, contact routes and authorised workspaces. Effective 9 August 2026.

Public beta

Do not enter another person's information into a public demo unless you are authorised to do so. Do not use Navnia for an emergency.

Who is responsible

NAVNIA Ltd is responsible for the public website, beta-account administration and direct enquiries. Where a healthcare organisation deploys Navnia for its own service, that organisation may be the controller for the patient information it asks Navnia to process. Contact [email protected] for the correct route.

Information we handle

The information depends on what you use. It can include account identity and verified email, access-request and audit records, clinic and consultation identifiers, conversation transcripts and structured clinical outputs, uploaded coding documents, simulation responses, technical security records, and the details you choose to send through contact or feedback forms.

  • Public contact and feedback forms must not contain patient-identifiable information.
  • Voice and text demos may process health information that the signed-in user chooses to provide.
  • Activation keys are stored as hashes; plaintext is shown only when an administrator creates a key.

Why we use it

We use information to authenticate users, enforce access, provide the selected product, maintain consultation and coding state, prepare review outputs, respond to enquiries, prevent misuse, investigate failures and improve the beta. The legal basis depends on the relationship and may include contract, legitimate interests, consent, legal obligations, or instructions from a healthcare controller.

Services that process data

Navnia uses service providers for hosting and edge security, authentication, voice and telephony, model inference, observability and public forms. Current product architecture includes Cloudflare, Firebase, LiveKit and, where configured, Twilio and model providers. Formspree processes the public contact, walkthrough and feedback forms. Providers receive only the data needed for their part of the service and are subject to the applicable configuration and contract.

Access and sharing

Protected product information is returned only after server-side identity, role, ownership or clinic-scope checks. It may be available to authorised people in the relevant healthcare or Navnia workspace. We do not sell patient information. We may disclose information where law requires it or where necessary to protect the service and its users.

Retention and deletion

Retention depends on the product, account status, healthcare workflow and legal requirements. Product records are not kept merely because a browser remains signed in. Administrators can revoke product access, and account or data requests can be raised through the contact route. Some audit or security records may need to be retained after access is revoked.

International processing

Some service providers may process information outside the United Kingdom. Where that occurs, the responsible controller must use an appropriate transfer mechanism and assess the provider and configuration for the intended deployment.

Your choices and rights

Depending on the circumstances, you may have rights to access, correct, erase, restrict or object to processing, and to obtain a copy of personal data. You can also complain to the Information Commissioner's Office. Contact [email protected] and identify the account, service and organisation involved without sending clinical details by email.

Next step

Need a walkthrough, support, or deployment help?

Contact Navnia