Privacy Notice
How Chronicle Health Handles Your Health Data
Full details of how your health data is processed are in the Data Protection Terms at Annex 1 of the Client Contract. In summary:
- You are the data controller. Your health data belongs to you. Chronicle Health processes it on your instructions as a data processor
- Processing is temporary. Your health data, including any identity documents provided for SARs, is deleted at the next scheduled fortnightly deletion sweep on or after delivery plus 14 days; the effective maximum delay is 28 days. Right-to-erasure requests are actioned the same day they are received
- Health data processors:
- Proton AG (Switzerland): Encrypted storage and email services for raw identifiable health data
- Amazon Web Services (UK): Used in the London region for two separate purposes. First, AI processing of pseudonymised (direct identifiers removed) health data only: identifier removal, document classification, transcription of handwritten medical notes, and generation of the narrative deliverables (record summary, clinical timeline, plain-English documents). Zero data retention by AWS for this processing (evidence for this is available on request). Second, encrypted storage of the identity documents and records you upload to us, and of your finished pack while it is awaiting download; this storage is encrypted at rest and is cleared on the deletion schedule above.
For full technical detail on encryption, pseudonymisation, device security, and deletion procedures, see How Your Data Is Protected.
Gift Purchases
If someone buys the service as a gift:
- At purchase, only the purchaser’s data is processed. Their name, email address, and payment details, plus an optional recipient first name, are processed to take payment and to issue and email the certificate. The lawful basis is contract and pre-contract steps. No health data, and no other recipient personal data, is involved at this stage
- The recipient’s data is only processed later, and only if they choose to redeem. When the recipient independently redeems the certificate and authorises the request for their own record, their health data is processed under the same basis and terms as any other client, set out in the Client Contract. The purchaser has no role in, and no access to, that data relationship
- What we keep: A voucher record (the code, the purchaser’s name and email, the optional recipient first name, purchase date, and redemption status) is retained to administer and account for the purchase, alongside our other administrative records
- Payment processor: Payment is handled by Stripe as an independent controller (see Sharing below). Card details are entered with Stripe, not with Chronicle Health
Cookies and Analytics
We collect as little as a website can reasonably run on, and nothing that follows you once you leave.
This website sets no cookies of its own, on any page. We use Cloudflare Web Analytics to count pageviews and referrers in aggregate: it is cookieless, does not collect personal data, and does not use fingerprinting or cross-site identifiers. No third-party trackers and no profiling.
We also measure how far down our pages people read and how long a page holds their attention, using counters rather than a third-party tool. When you leave a page, it reports three things to this website’s own server: the address of the page, how far down was scrolled (rounded to the nearest 20%), and how many seconds the page was on the screen. The two measurements are then added to separate running counts for that page and that day, so what we hold is a tally of how many people reached each depth and stayed for each length of time. Nothing is stored on or read from your device, no identifier or visit number is created, your IP address is not recorded, and the two measurements are never linked back to each other, so there is no record of any individual visit. If your browser sends a “Do Not Track” or Global Privacy Control signal, the page does not measure or report anything at all.
One page carries a little more of the same kind of counting. On the page showing our published example record, we also count how the page’s own controls are used: which of the example documents was opened, how often pages were turned or shown full screen, which of the questions at the foot of the page were expanded, and whether the links onward from the page were followed. Each of those is a plain running count for that control and that day, sent in the same way as the reading measurements when you leave the page, and held to the same rules: no cookie, no identifier, no IP address, no record of any individual visit, and never which page of the record you looked at. The same “Do Not Track” and Global Privacy Control signals switch it off entirely.
Two things on this site come from another company, and neither one loads on its own. The booking calendar on our Book a Free Call page is run for us by Cal.com on its European service, and it appears only after you have chosen what you would like to talk about. The explainer videos are on YouTube, loaded from its no-cookie domain, and one plays only after you press play. Until you take that step your browser makes no request to either company, so neither of them is told you are here at all.
When you do load one, it behaves as though you had visited that company’s own website. Cal.com’s booking page sets a security cookie that its host uses to tell real visitors apart from bots, and if you go on to book, the name, email address and notes you type go to Cal.com rather than to us directly, so that it can hold the appointment. Both are click-to-load on purpose, so the choice stays yours.
You may have found us through a paid advert: we buy a modest amount of search advertising so that people looking for this service can find it. What we do not do is let the advertising platform follow you here. We have not installed Google’s conversion-tracking tag, so there are no Google cookies on this site, Google is not told what you do here, and we cannot retarget you afterwards. It is also why no cookie banner appeared when this page loaded: there is nothing to consent to.
One small thing we do record, to learn which of our adverts work: if you arrived via an advert and then send us an enquiry, the enquiry includes the referral labels the advertising platform placed in the address of the page you landed on (which advert and which search term brought you here), along with the address of the page you came from. This information travels one way: it reaches us as part of your enquiry and is kept with it, and nothing about your visit or enquiry is sent back to the advertising platform. This is the least privacy-invasive method we could find to determine whether the money we’re spending on advertising was leading to sales.
The Chat Panel
Most pages on this site offer a chat panel in the corner. It is ours rather than a chat company’s: the panel, the answers and the record of the conversation all stay on this website and on our own systems. Nothing about the conversation is shared with an advertiser, and opening it sets no cookie.
An automated assistant answers first. It can only answer from what is already published on these pages, and it is instructed to say so when it does not know rather than to guess. To produce a reply, what you type is sent to Amazon Web Services in the London region, which runs the AI model on our instructions. It is not used to train any model, and AWS does not retain it.
A human operator can join the conversation. You can leave an email address so that we can reply later. Leaving an address is the only point at which the chat asks you for anything personal.
Please do not type health details, an NHS number, a date of birth or an address into the chat. There is no step that needs them, the assistant is instructed not to ask for them and not to repeat them back, and a question can always be asked in general terms. If you do share something like that, it is deleted on the schedule below along with the rest of the conversation.
What we hold: The messages in the conversation, the address of the page you opened it on, the country your browser reports, and an email address if you chose to leave one. We do not record your IP address, your browser, or any identifier that would let us recognise you on a later visit.
Keeping the conversation together: Your browser stores one random reference for the conversation so that the panel can show you your own thread, alongside a couple of plain notes of what you have already done with the panel, such as whether you closed it. None of them identifies you or leaves your browser. They are held in session storage rather than in cookies, they are not used for analytics or advertising, and your browser discards them when you close the tab. This is strictly necessary for a chat you started, which is why no consent banner appears for it.
Retention: Conversations are deleted 30 days after the last message. If your enquiry becomes an engagement, the correspondence that follows is kept under the administrative retention rules below instead.
Kept apart from our analytics: Chat conversations are stored separately from the reading counters described above and are never combined with them.
Your rights: You can ask us to delete a conversation at any time, including by typing the request into the chat itself. If you tell us in the chat, ask before you close the tab so that the reference is still to hand, or email us and we will find it from your email address.
How Chronicle Health Uses Your Administrative Information
This notice also covers how Chronicle Health handles your contact and billing information, and the agreements you sign with us.
Data We Collect
- Client contact details (name, email, phone, address)
- Billing and invoicing information
- The agreements you sign with us. For Option A clients, the Letter of Authority that lets us ask your GP practice for your records contains your date of birth, NHS number, and address, because the practice needs those to identify you.
- Contract records
Purpose
We use this information for:
- Administrative communication
- Service provision
- Invoicing
- Legal record-keeping
- Reminding you about something you started and did not finish, described below
Reminders About an Unfinished Enquiry
If you start setting up an engagement with us and stop partway, an automated process may send you a reminder. It looks for enquiries that have stalled at a known step, such as a set of documents opened but never signed, and it emails you about that step and nothing else. You will get at most two messages about the same unfinished step, and usually only one.
Some things this deliberately is not. It is not a marketing sequence, and it never sends you anything about our other services, offers or content. It does not run on people who only asked for the free guide or requested a call. It stops permanently if you ask it to, if your address bounces, or once you complete the step.
To do this we keep a small log of reminders: which enquiry it relates to, which step, whether a message was sent, and when. That log holds a one-way keyed digest of your email address rather than the address itself, so it can recognise that we have already written to you without storing who you are. It is kept as our record of what we sent you, and it is separate from your health records. A copy of each reminder also goes to our own operations inbox so a human can see exactly what was sent.
The legal basis is legitimate interests: you asked us to start something, and finishing it is what you came for. If you would rather not receive these, tell us and we will stop, using the contact details at the end of this notice.
Legal Basis
- Contract: Necessary to provide the service you’ve requested
- Legitimate interests: Business administration, legal compliance, and the reminders described above
Legal/Contractual Requirement
Providing your contact and billing information is necessary for us to perform our contract with you, and we cannot provide the service without it. You are not obliged to provide this data by law.
Retention
Contact and billing information retained for up to six years for HMRC obligations.
Signed agreements, including the Letter of Authority, are kept for six years from the end of your engagement. They are kept for a different reason than your health record: they are the evidence of what you asked us to do and what you agreed to, which we are required to be able to produce. They are held encrypted in the United Kingdom, separately from your health records, and deleted automatically when the six years are up rather than at anyone’s discretion.
Sharing
Independent Controllers (who determine their own purposes for processing):
- Our UK clearing bank: Processes payment transactions as an independent data controller under its own privacy policy. Your name and payment details (no health data) are processed when you make payments to Chronicle Health.
- Stripe (our payment processor for gift purchases): When you buy the service as a gift, Stripe processes your name, email address, and card or payment details (no health data) to take the payment, as an independent data controller under its own privacy policy. Stripe is used only for gift purchases and is not part of the chain that processes any health data.
- HMRC: Financial records (no health data) may be shared as legally required for tax purposes.
Our Data Processors (who process data on our instructions):
- A UK accounting software provider: Stores client names, contact details, and billing information for bookkeeping and tax compliance (no health data).
- Amazon Web Services (UK / EU): Two purposes, both in the London region. First, email delivery: transmits contact form submissions to our inbox, where the data is transient, delivered and not retained long-term. Second, the AI model behind the chat panel, on the terms set out above. Both are covered by the existing AWS GDPR DPA.
- Cal.com (EU): Runs the booking calendar for free introductory calls, on its European service. Processes the name, email address and any notes you enter when booking, plus the date and time you choose, so that the appointment can be made and reminders sent. No health record is shared with Cal.com, and there is no need to put anything sensitive in the notes box.
We have data processing agreements in place with each processor listed above.
No other sharing: Your administrative data is not shared with any other third parties beyond those listed above.
Your Rights
You have the right to:
- Access: Request copies of your personal data
- Rectification: Correct inaccurate information
- Erasure: Request deletion (subject to legal retention requirements)
- Restriction: Limit how we use your data
- Portability: Receive your data in a portable format
- Objection: Object to processing based on legitimate interests
Supervisory Authority
You have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
Data Protection Officer
We are not required to appoint a Data Protection Officer under UK GDPR Article 37, as we do not process special category data on a large scale. For data protection queries, contact us at the details above.
Automated Decision-Making
We do not make automated decisions that have a legal effect on you or that significantly affect you in a similar way, and we do not profile you.
One process does run automatically, and we would rather name it than let the sentence above imply otherwise: the reminder described under Reminders About an Unfinished Enquiry decides without a person’s involvement whether to email you about an enquiry you left unfinished. Its only outcome is whether you receive one reminder, nothing about your engagement or your record turns on it, and you can ask us to stop at any time.
Your Right to Withdraw Consent
Where we process your data based on consent, you have the right to withdraw that consent at any time by contacting us. This will not affect the lawfulness of processing before withdrawal.
Contact Information
Chronicle Health Ltd
- Representative: Thomas Millross
- Email: hello@chroniclehealth.co.uk
- Companies House No: 16934023
- ICO Registration: ZC084723