Legal
Acceptable Use Policy
Last updated: September 2026
This Acceptable Use Policy ("AUP") applies to every user of the Renvia platform. It exists to protect patients, clinicians and the integrity of the service. By using Renvia you agree to this AUP in addition to the Terms of Service.
1. Clinical use
- Renvia supports clinical decision-making. It does not replace clinical judgement, and it is not a substitute for emergency care — in an emergency, call 999.
- Only enrol patients you are clinically responsible for, or that fall within your facility's contracted pathway.
- Act on prioritised signals in line with your facility's local escalation protocol and clinical governance.
2. Account & credential hygiene
- Do not share accounts, credentials or MFA devices. Every user must have a unique account.
- Enable MFA when prompted; clinical and admin roles are MFA-enforced.
- Sign out on shared devices and lock unattended workstations.
3. Data handling
- Enter only accurate, minimum-necessary patient data. Do not enter free-text identifiers into notes fields intended for clinical observations.
- Export patient data only for a lawful purpose consistent with your facility's data-protection policies.
- Do not upload data belonging to patients outside your facility's contracted cohort.
4. Prohibited activities
- Attempting to bypass authentication, RLS or audit controls.
- Probing, scanning or load-testing the platform without written permission from Renvia.
- Uploading malicious code, or content that is unlawful, discriminatory or infringing.
- Using Renvia to send unsolicited marketing.
- Reverse-engineering, scraping or reselling platform outputs.
5. Reporting concerns
Report suspected misuse, credential compromise or clinical safety issues to security@renvia.health without delay. Coordinated vulnerability disclosure is welcomed — see our Security page.
6. Enforcement
Renvia may suspend or revoke access where use of the platform violates this AUP or presents a risk to patients or other users. Where appropriate, incidents are reported to the responsible facility admin, Data Protection Officer, and regulator.