Legal Document

Privacy
Policy.

This policy explains how NUVOAI Private Limited collects, uses, stores, protects and deletes information in connection with RadioIQ.

Last Updated: June 2026 NUVOAI Private Limited Applies to RadioIQ
01Scope

Scope of this Privacy Policy

This Privacy Policy applies to RadioIQ accessible via supported web browsers and to personal information processed in connection with use of RadioIQ. It covers information collected through RadioIQ, information associated with user login and authorised access, usage information, technical logs, account-related information, support communications and related service records.

The Platform is intended to be used by authorised users only — not for independent public registration by general users. Access is created, approved or enabled through the authorised RadioIQ login/account process or by an authorised administrator, institution or authorised representative.

This Privacy Policy does not replace the privacy notices, consent forms or policies of hospitals, diagnostic centres, radiology groups or other institutions that may separately collect, control or use patient information.
02Registration

No Self-Registration

RadioIQ does not provide an independent self-registration process. Users cannot create unrestricted public accounts directly through RadioIQ.

User registration, onboarding, role assignment and access approval are handled through the authorised RadioIQ account/login process or by an authorised administrator. Users may log in using their registered credentials and the applicable authentication method enabled for their account.

Depending on the configuration, login may involve email/username and password authentication, OTP-based verification, single sign-on (SSO), role-based checks, institutional authorisation, or other security steps. Login credentials are used for identification, authentication, account access and service-related communications.

03Collection

Information We May Collect

We collect only information that is reasonably required to provide, secure, maintain and improve RadioIQ and related services. The exact information collected may vary depending on user role, institutional configuration, product features and applicable law.

Account & Login

Registered email address, name, user ID, role, organisation mapping, account status, authentication records, login timestamps, session tokens and security alerts.

Professional & Role

Designation, department, role, institutional affiliation, reporting permissions, workflow permissions and access category — used to provide role-based access.

Case & Workflow

Case lists, workflow status, report status, report content, timestamps, user activity, comments or other workflow information — accessible only by authorised users.

Browser & Technical

Browser type and version, operating system, IP address, referring URL, session duration, page interactions, crash logs, diagnostic logs, and approximate location derived from network information.

Support & Communication

Name, email, organisation, issue description, screenshots or supporting details shared when contacting us for support, feedback or account assistance.

04Medical Data

DICOM and Medical Data Handling

RadioIQ is primarily a controlled access and workflow interface. Where imaging or DICOM data is presented, it is streamed or rendered through secured backend systems — it is not independently stored or processed in the user's browser in an uncontrolled manner.

RadioIQ may store case-related information, report-related information, metadata, workflow records and other information in secured server-side systems as required to provide the service. Any technical handling of imaging-related information is performed through secured backend workflows with appropriate access controls.

Authorised users may access only the information made available to them through the RadioIQ platform, based on role and permissions. RadioIQ does not expose raw DICOM data outside of authorised, secured viewing contexts.
05Usage

How We Use Information

We use information for lawful, authorised and service-related purposes only.

  • To provide and operate RadioIQ.
  • To authenticate users and manage role-based access.
  • To support authorised healthcare workflow and report access.
  • To send OTPs, alerts and service-related notifications.
  • To maintain security, auditability and fraud prevention.
  • To troubleshoot issues and improve platform reliability.
  • To comply with legal, regulatory, contractual and institutional obligations.

We do not use the Platform to send unrelated marketing communications unless permitted by applicable law and user preference. Where possible, we use aggregated or de-identified information for analytics and improvement activities.

06Consent

Legal Basis and Consent

We process personal information where necessary to provide the RadioIQ service, manage authorised access, comply with applicable legal or contractual obligations, protect security, perform legitimate operational activities, respond to user requests, or where consent is required and obtained.

Where applicable, the user may withdraw consent or request deletion through the available process. Withdrawal or deletion may affect the ability to use the Platform or access certain services. Processing that occurred before withdrawal may remain valid as permitted by applicable law.

For institution-controlled workflows, the relevant healthcare institution or administrator may also have responsibilities regarding authorisation, access, retention, medical records and patient information.

07Storage

Storage of Information

Data associated with RadioIQ is stored in the RadioIQ server-side database or secured systems used to provide the service. RadioIQ may use browser storage mechanisms (such as session storage, local storage or cookies) where necessary for login sessions, user preferences, security tokens, cached display or platform functionality.

We use reasonable technical and organisational measures to protect stored information — including access control, authentication, secure communication (HTTPS), logging, monitoring, encryption where applicable, restricted administrative access and internal security procedures.

User account responsibilities

  • Use a strong, unique password and change it periodically.
  • Avoid accessing the platform from shared or untrusted devices.
  • Keep your browser and operating system updated.
  • Never share credentials, OTPs or session tokens with others.
  • Log out of the platform when your session is complete.
08Deletion

Account Deletion and Data Deletion

Users may request deletion or deactivation of their account through the process provided by NUVOAI Private Limited or the relevant authorised administrator. Once a user account is deleted, personal data associated with that account will be removed from active systems where required and feasible.

Certain information may be retained where necessary for legal, regulatory, contractual, medical record, audit, security, fraud prevention, dispute resolution, tax, compliance or legitimate business purposes. For example, security logs, audit trails, transaction records, support records or legally required records may be retained for the period required under applicable obligations.

Deletion of a user account may result in loss of access to the Platform, reports, case lists, workflow information, notifications, saved preferences and related services. If the user is associated with a healthcare institution, deletion or access removal may also require coordination with that institution.

09Sharing

Disclosure and Sharing of Information

We do not sell personal information. We may share information only where necessary and permitted:

  • With authorised users and institutions based on access permissions and role configurations.
  • With service providers who support hosting, messaging, analytics, security or support functions — under appropriate confidentiality and security obligations.
  • With legal, regulatory or government authorities where required by law, court order or legal process.
  • With professional advisers or business partners where necessary and lawful.
  • In connection with business restructuring, merger or transfer of assets, subject to appropriate safeguards.

Access to information shared with healthcare institutions or other users is intended to be limited to those who are authorised to view or act upon the relevant information based on role, workflow and permission settings.

10Security

Data Security

We apply reasonable safeguards designed to protect information from unauthorised access, disclosure, alteration, loss, misuse or destruction. Security measures may include authentication controls, role-based access, HTTPS encryption, secure session management, monitoring, logging, limited access rights and administrative controls.

No web platform, server, database, network or electronic transmission is completely secure. Users must follow safe practices and immediately report suspected account misuse, suspicious emails, unauthorised access or security concerns.

NUVOAI Private Limited may suspend or restrict access if we detect security risks, suspicious behaviour, misuse, compromised accounts or unauthorised activity.
11Retention

Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy — including service delivery, account management, legal compliance, contractual obligations, medical or audit requirements, security monitoring, dispute resolution and legitimate business purposes.

Retention periods may vary depending on the type of information, applicable law, institutional requirements, contract terms and operational need. When information is no longer required, we will delete, de-identify, anonymise or archive it in accordance with applicable procedures.

Where a user account is deleted, personal data linked to that account will be deleted from active systems unless retention is required or permitted for the reasons described above.

12Rights

User Rights and Choices

Subject to applicable law and verification of identity, users may exercise the following rights:

Access personal information
Correct inaccurate information
Request account deletion
Withdraw consent
Raise a privacy concern
Manage browser permissions

Some rights may be limited where information is controlled by an institution, required for legal or medical record purposes, necessary for security, or subject to contractual or regulatory retention requirements. Disabling browser permissions may affect certain features of the Platform.

13Minors

Children and Minors

RadioIQ is intended for authorised professional or institutional users and is not directed to children for independent use. We do not knowingly permit children to create independent accounts on the Platform.

If any information relating to a minor is included in authorised healthcare workflows, such information should be handled by authorised healthcare institutions and users in accordance with applicable law, consent requirements, medical record obligations and institutional policies.

14Transfer

International Transfer and Hosting

Depending on service configuration, hosting arrangements, service providers and institutional requirements, information may be stored or processed in India or other locations permitted by applicable law and contract.

Where information is transferred or processed outside its original location, we will take reasonable measures to ensure appropriate safeguards consistent with applicable legal and contractual requirements.

15Permissions

Browser Permissions and Web Features

RadioIQ may request access to certain browser features only where necessary for the relevant functionality. Examples may include browser notifications for workflow alerts, clipboard access where a feature requires it, file upload permissions for supported workflows, or other permissions depending on the enabled product configuration.

The Platform does not use browser permissions for unrelated purposes. Users can review and manage permissions through their browser settings. If a permission is denied or revoked, some features may not function correctly.

16Analytics

Cookies, Analytics and Similar Technologies

RadioIQ uses cookies, session storage, web analytics, crash reporting, logs and similar technologies to maintain sessions, improve performance, diagnose problems, detect security issues and understand how authorised users interact with the Platform.

Cookies may include strictly necessary cookies (required for login and session management), functional cookies (for preferences), and analytical cookies (for performance monitoring). Where required by applicable law, consent for non-essential cookies will be requested.

Where analytics are used, we aim to limit information to what is necessary for service improvement and security. We do not use sensitive information for unrelated advertising purposes.

17Updates

Updates to this Privacy Policy

We may update this Privacy Policy from time to time for legal, operational, product, security or business reasons. The updated policy will be published on RadioIQ and/or our website, and may be communicated through an in-platform notification or other appropriate method.

The updated Privacy Policy will be effective from the date stated in the policy unless otherwise specified. Continued use of the Platform after the update indicates acknowledgment of the revised Privacy Policy.

18Contact

Grievance, Questions and Contact

For privacy questions, account deletion requests, support issues, legal communication or complaints relating to this Privacy Policy, users may contact NUVOAI Private Limited using the details below.

CompanyNUVOAI Private Limited
Office Address135/139, Muktanand Marg, Bilakhia House, Chala, Vapi, Pardi, Vapi, Valsad, Gujarat (India) – 396191
Support Emailhelpdesk.nuvoai@gmail.com
Websitewww.radioiq.ai

This Privacy Policy is intended to provide clear information to users of RadioIQ. For any clarification, please contact NUVOAI Private Limited using the contact details above.