Privacy & data protection

Privacy & data protection.

What we collect

For enquiries we may collect contact details, country, treatment area, a short case description, consent information and enquiry-source information. The public enquiry form is not intended for medical records.

Patient portal

After a case is accepted into the KRVF workflow, an authorised team member may invite a patient to the secure portal. Portal data can include profile details and documents the patient chooses to upload. Uploaded documents are encrypted before database storage and remain quarantined until reviewed.

Why we process information

We use information to respond to enquiries, coordinate international healthcare services, communicate with patients, administer accounts, maintain security, and meet applicable legal and contractual obligations.

Security

KRVF uses access controls, password hashing, encrypted document storage, audit logging and security headers in the portal. These technical measures do not by themselves constitute a certification or guarantee of security.

Data protection framework

KRVF is based in India and will operate its data practices with regard to applicable Indian data-protection requirements, including the Digital Personal Data Protection framework, and applicable requirements in countries where patients are served. Cross-border processing, retention, data-subject rights and contractual safeguards will be documented as the service is operationalised.

Your choices

Patients may contact KRVF to request information about their personal data, account access, correction or deletion where applicable. Specific rights and response procedures will be set out in the final counsel-reviewed privacy notice.

Important

This is an operational privacy notice for the current platform and is not legal advice. Before processing substantial medical records from UK/US patients, KRVF should have counsel review the final notice, consent language, vendor contracts, international transfers and retention schedule.