Privacy Notice
How Chronicle Health Handles Your Health Data
Full details of how your health data is processed are in the Data Processing Terms in the Client Contract. In summary:
- You are the data controller. Your health data belongs to you. Chronicle Health processes it on your instructions as a data processor
- Processing is temporary. Your health data, including any identity documents provided for SARs, is deleted at the next scheduled fortnightly deletion sweep on or after delivery plus 14 days; the effective maximum delay is 28 days. Right-to-erasure requests are actioned the same day they are received
- Health data processors:
- Proton AG (Switzerland): Encrypted storage and email services for raw identifiable health data
- Amazon Web Services (UK): Used in the London region for two separate purposes. First, AI processing of pseudonymised (direct identifiers removed) health data only: identifier removal, document classification, transcription of handwritten medical notes, and generation of the narrative deliverables (record summary, clinical timeline, plain-English documents). Zero data retention by AWS for this processing (evidence for this is available on request). Second, encrypted storage of the identity documents and records you upload to us, and of your finished pack while it is awaiting download; this storage is encrypted at rest and is cleared on the deletion schedule above.
For full technical detail on encryption, pseudonymisation, device security, and deletion procedures, see How Your Data Is Protected.
Gift Purchases
If someone buys the service as a gift:
- At purchase, only the purchaser’s data is processed. Their name, email address, and payment details, plus an optional recipient first name, are processed to take payment and to issue and email the certificate. The lawful basis is contract and pre-contract steps. No health data, and no other recipient personal data, is involved at this stage
- The recipient’s data is only processed later, and only if they choose to redeem. When the recipient independently redeems the certificate and authorises the request for their own record, their health data is processed under the same basis and terms as any other client, set out in the Client Contract. The purchaser has no role in, and no access to, that data relationship
- What we keep: A voucher record (the code, the purchaser’s name and email, the optional recipient first name, purchase date, and redemption status) is retained to administer and account for the purchase, alongside our other administrative records
- Payment processor: Payment is handled by Stripe as an independent controller (see Sharing below). Card details are entered with Stripe, not with Chronicle Health
Cookies and Analytics
We collect as little as a website can reasonably run on, and nothing that follows you once you leave.
This website sets no cookies of its own, on any page. We use Cloudflare Web Analytics to count pageviews and referrers in aggregate: it is cookieless, does not collect personal data, and does not use fingerprinting or cross-site identifiers. No third-party trackers and no profiling.
We also measure how far down our pages people read and how long a page holds their attention, using counters of our own rather than a third-party tool. When you leave a page, the page reports three things to this website’s own server: the address of the page, how far down the page you scrolled (rounded to the nearest 20%), and how many seconds the page was in front of you. Those two measurements are then added to separate running counts for that page and that day, so what we hold is a tally of how many people reached each depth and stayed for each length of time. Nothing is stored on or read from your device, no identifier or visit number is created, your IP address is not recorded, and the two measurements are never linked back to each other, so there is no record of any individual visit. We use this to work out which pages are worth reading and which ones lose people halfway down. If your browser sends a “Do Not Track” or Global Privacy Control signal, the page does not measure or report anything at all.
Two things on this site come from another company, and neither one loads on its own. The booking calendar on our Book a Free Call page is run for us by Cal.com on its European service, and it appears only after you have chosen what you would like to talk about. The explainer videos are on YouTube, loaded from its no-cookie domain, and one plays only after you press play. Until you take that step your browser makes no request to either company, so neither of them is told you are here at all.
When you do load one, it behaves as though you had visited that company’s own website. Cal.com’s booking page sets a security cookie that its host uses to tell real visitors apart from bots, and if you go on to book, the name, email address and notes you type go to Cal.com rather than to us directly, so that it can hold the appointment. We arranged both of these as click-to-load on purpose, so that the choice is yours to make rather than something that already happened before you finished reading this sentence.
You may have found us through a paid advert: we buy a modest amount of search advertising so that people looking for this service can find it. What we do not do is let the advertising platform follow you here. We have not installed Google’s conversion-tracking tag, so there are no Google cookies on this site, Google is not told what you do here, and we cannot retarget you afterwards. We give up some advertising efficiency by working this way, and consider it a fair price for your privacy. It is also why no cookie banner appeared when this page loaded: there is nothing to consent to.
One small thing we do record, to learn which of our adverts work: if you arrived via an advert and then send us an enquiry, the enquiry includes the referral labels the advertising platform placed in the address of the page you landed on (which advert and which search term brought you here), along with the address of the page you came from. This information travels one way: it reaches us as part of your enquiry, is kept with it, and nothing about your visit or enquiry is sent back to the advertising platform.
The Chat Panel
Most pages on this site offer a chat panel in the corner. It is ours, not a third party’s: the panel, the answers and the record of the conversation all stay on this website and on our own systems. No chat company is involved, nothing about the conversation is shared with an advertiser, and opening it sets no cookie.
An automated assistant answers first. It can only answer from what is already published on these pages, and it is instructed to say so when it does not know rather than to guess. To produce a reply, what you type is sent to Amazon Web Services in the London region, which runs the AI model on our instructions. It is not used to train any model, and AWS does not retain it.
Tom can join the conversation himself when he is at his desk, and the panel says whether he is online. If he is not, you can leave an email address so that he can reply later. Leaving an address is the only point at which the chat asks you for anything personal.
Please do not type health details, an NHS number, a date of birth or an address into the chat. There is no step that needs them, the assistant is instructed not to ask for them and not to repeat them back, and a question can always be asked in general terms. If you do share something like that, it is deleted on the schedule below along with the rest of the conversation.
What we hold: The messages in the conversation, the address of the page you opened it on, the country your browser reports, and an email address if you chose to leave one. We do not record your IP address, your browser, or any identifier that would let us recognise you on a later visit.
Keeping the conversation together: Your browser stores one random reference for the conversation so that the panel can show you your own thread, alongside a few plain notes of what you have already done with the panel: whether you closed it, and whether you have put away the notice above the box. None of them identifies you or leaves your browser. They are held in session storage rather than in cookies, they are not used for analytics or advertising, and your browser discards them when you close the tab. It is strictly necessary for a chat you started, which is why no consent banner appears for it.
Retention: Conversations are deleted 30 days after the last message. If your enquiry becomes an engagement, the correspondence that follows is kept under the administrative retention rules below instead.
Kept apart from our analytics: Chat conversations are stored separately from the reading counters described above and are never combined with them. Those counters remain what they say they are: totals with no record of any individual visit.
Your rights: You can ask us to delete a conversation at any time, including by typing the request into the chat itself. If you tell us in the chat, ask before you close the tab so that the reference is still to hand, or email us and we will find it from your email address.
How Chronicle Health Uses Your Administrative Information
This notice also covers how Chronicle Health handles your contact and billing information, and the agreements you sign with us.
Data We Collect
- Client contact details (name, email, phone, address)
- Billing and invoicing information
- The agreements you sign with us. For Option A clients, the Letter of Authority that lets us ask your GP practice for your records contains your date of birth, NHS number, and address, because the practice needs those to identify you.
- Contract records
Purpose
We use this information for:
- Administrative communication
- Service provision
- Invoicing
- Legal record-keeping
Legal Basis
- Contract: Necessary to provide the service you’ve requested
- Legitimate interests: Business administration and legal compliance
Legal/Contractual Requirement
Providing your contact and billing information is necessary for us to perform our contract with you. Without this information, we cannot provide our services. You are not obliged to provide this data by law.
Retention
Contact and billing information retained for up to six years for HMRC obligations.
Signed agreements, including the Letter of Authority, are kept for six years from the end of your engagement. This is a shorter list of data than your health record and it is kept for a different reason: it is the evidence of what you asked us to do and what you agreed to, which we are required to be able to produce. It is held encrypted in the United Kingdom, separately from your health records, and deleted automatically when the six years are up rather than at anyone’s discretion.
Sharing
Independent Controllers (who determine their own purposes for processing):
- Our UK clearing bank: Processes payment transactions as an independent data controller under its own privacy policy. Your name and payment details (no health data) are processed when you make payments to Chronicle Health.
- Stripe (our payment processor for gift purchases): When you buy the service as a gift, Stripe processes your name, email address, and card or payment details to take the payment, as an independent data controller under its own privacy policy. No health data is shared with Stripe. Stripe is used only for gift purchases and is not part of the chain that processes any health data.
- HMRC: Financial records (no health data) may be shared as legally required for tax purposes.
Our Data Processors (who process data on our instructions):
- A UK accounting software provider: Stores client names, contact details, and billing information for bookkeeping and tax compliance (no health data).
- Amazon Web Services (UK / EU): Two purposes, both in the London region. First, email delivery: transmits contact form submissions to our inbox, where the data is transient, delivered and not retained long-term. Second, the AI model behind the chat panel described above: what you type is processed to produce a reply, is not used to train any model, and is not retained by AWS. Both are covered by the existing AWS GDPR DPA.
- Cal.com (EU): Runs the booking calendar for free introductory calls, on its European service. Processes the name, email address and any notes you enter when booking, plus the date and time you choose, so that the appointment can be made and reminders sent. No health record is shared with Cal.com; what you choose to type in the notes box is up to you, and there is no need to put anything sensitive in it.
We have data processing agreements in place with each processor listed above.
No other sharing: Your administrative data is not shared with any other third parties beyond those listed above.
Your Rights
You have the right to:
- Access: Request copies of your personal data
- Rectification: Correct inaccurate information
- Erasure: Request deletion (subject to legal retention requirements)
- Restriction: Limit how we use your data
- Portability: Receive your data in a portable format
- Objection: Object to processing based on legitimate interests
Supervisory Authority
You have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
Data Protection Officer
We are not required to appoint a Data Protection Officer under UK GDPR Article 37, as we do not process special category data on a large scale. For data protection queries, contact us at the details above.
Automated Decision-Making
We do not use automated decision-making or profiling.
Your Right to Withdraw Consent
Where we process your data based on consent, you have the right to withdraw that consent at any time by contacting us. This will not affect the lawfulness of processing before withdrawal.
Contact Information
Chronicle Health Ltd
- Representative: Thomas Millross
- Email: [email protected]
- Companies House No: 16934023
- ICO Registration: ZC084723