TESTING MODE — Payment processing is disabled. Not for production use.

Privacy Policy

Last updated: June 1, 2026

1. Overview

Navaryn ("we," "our," or "us") is operated by Jeskel Group. This Privacy Policy describes how we collect, use, disclose, and protect information when you use the Navaryn platform (the "Service").

We are designed for use by healthcare organizations and their staff. Navaryn does not store, process, or transmit Protected Health Information (PHI) in identifiable form. All patient identifiers are tokenized at the application layer before any processing occurs. The tokenized references stored in Navaryn are not PHI.

2. Information We Collect

Account and Organization Information: When you register, we collect your name, work email address, organization name, and role. For billing purposes, we collect payment information, which is processed by our payment processor and not stored on Navaryn servers.

Usage Data: We collect logs of how you interact with the Service — pages visited, agent interactions initiated, documents created, approvals made, and timestamps. This data is used for audit trail generation, service improvement, and security monitoring.

Device and Technical Data: We collect standard technical information including IP address, browser type, operating system, and session identifiers for security and fraud prevention purposes.

Communications: If you contact us, we retain records of that communication.

3. What We Do Not Collect

Patient Health Information (PHI): Navaryn does not accept, store, or process PHI in its identifiable form. Our architecture requires that all 18 HIPAA-defined patient identifiers be replaced with opaque tokens before data enters the platform. We do not have the technical capability to receive PHI through our standard application interfaces.

Personal Health Data: We do not collect health information about our users.

4. How We Use Your Information

We use the information we collect to:

- Provide, operate, and improve the Service - Authenticate users and enforce access controls - Generate and maintain immutable audit trails required for compliance operations - Send transactional communications (account confirmations, billing receipts, security alerts) - Respond to support requests and inquiries - Detect and prevent fraud, abuse, and security incidents - Comply with legal obligations

We do not use your information for behavioral advertising or sell it to third parties.

5. How We Share Information

We share information only in the following circumstances:

Service Providers: We use third-party vendors for infrastructure (cloud hosting), payment processing, and email delivery. These vendors are bound by data processing agreements and may only use your data to provide services to us.

Legal Requirements: We may disclose information if required by law, regulation, court order, or in response to lawful requests by government authorities.

Business Transfers: If Navaryn or Jeskel Group is involved in a merger, acquisition, or sale of assets, customer information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on the Service before your information becomes subject to a different privacy policy.

With Your Consent: We may share information for any other purpose with your explicit consent.

We do not sell, rent, or share your personal information with third parties for their own marketing purposes.

6. Data Retention

We retain account and organization data for the duration of your subscription and for 7 years following account termination, consistent with standard healthcare records retention guidance.

Audit logs are retained for a minimum of 6 years from the date of the logged action, in alignment with HIPAA documentation requirements under 45 CFR §164.530(j).

You may request deletion of your account data at any time. We will fulfill deletion requests subject to our legal retention obligations. Audit logs cannot be deleted while in the legally required retention period.

7. Security

We implement technical and organizational measures designed to protect your information, including:

- AES-256 encryption at rest for all stored data - TLS 1.3 encryption for all data in transit - Organization-isolated data environments with row-level security - Multi-factor authentication support - Regular third-party penetration testing - SOC 2 Type II certification (annual)

No transmission over the internet is completely secure. While we use commercially reasonable security practices, we cannot guarantee absolute security.

8. HIPAA and Business Associate Agreements

Navaryn is designed to support HIPAA-compliant workflows. Because Navaryn does not receive PHI in identifiable form, a Business Associate Agreement (BAA) may not be required for standard platform use. However, we provide BAAs for Team and Enterprise plan customers as a matter of best practice and to satisfy the requirements of cautious compliance officers.

Customers are responsible for ensuring their own use of the Service complies with applicable healthcare privacy laws, including HIPAA, state privacy laws, and applicable international regulations.

9. Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal information:

  • Access::Request a copy of the personal information we hold about you
  • Correction::Request correction of inaccurate or incomplete information
  • Deletion::Request deletion of your personal information (subject to legal retention requirements)
  • Portability::Request a machine-readable export of your data
  • Objection::Object to certain processing activities

To exercise these rights, contact us at privacy@navaryn.com. We will respond within 30 days.

10. Cookies

We use strictly necessary cookies to maintain your authenticated session. We do not use advertising cookies or cross-site tracking cookies.

We use first-party analytics to understand how users interact with the Service. This data is aggregated and anonymized and is not used to identify individual users.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a prominent notice in the Service at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

12. Contact

If you have questions or concerns about this Privacy Policy or our data practices, contact us at:

**Jeskel Group — Navaryn Privacy** privacy@navaryn.com

For security-related inquiries: security@navaryn.com