Privacy notice
Chronix Health Group Ltd is controller for direct consumer accounts and the consumer processing described here. An organisation may be controller for a separately contracted module where Sumrex acts only on its documented instructions; that module uses the organisation DPA. The initial health-data scope is limited to an adult with capacity who personally consents.
Last updated 21 July 2026 · Chronix Health Group Ltd (company no. 16663224)
1. Who we are, and our two roles
Chronix Health Group Ltd (company no. 16663224) operates Sumrex and is registered with the Information Commissioner's Office (registration number ZB962513). Contact us about privacy at privacy@sumrex.app, or by post at our registered office (see our legal & company information). We have not appointed a statutory Data Protection Officer.
We are the controller for direct consumer accounts, billing, security, audit, product compliance and the consumer processing described in this notice. For an organisation module, the signed order and DPA may instead identify the organisation as controller and Sumrex as processor for defined customer content. Contract wording follows the actual purpose and control; it does not decide the role by itself.
2. Account, billing and security data we control
This is your name and email, your sign-in and security data, your subscription and payment status from Stripe, and the audit and security logs we keep to run the service safely. Our lawful basis is Article 6(1)(b) (performance of our contract with you) and, for the statutory records the law requires us to keep, Article 6(1)(c) (legal obligation). We do not sell your data, and we never match, introduce or list carers.
3. Restricted care-information scope
In the initial consumer service, care information may be recorded only about an adult aged 18 or over who has capacity, receives this notice and personally gives explicit, recorded consent before health information is stored or shared. Chronix Health Group Ltd is controller for that consumer processing. We do not interpret health data, make judgements from it or use it to train an AI model.
Health data relies on the adult’s explicit consent under Article 9(2)(a) within that restricted scope. Child records, lacks-capacity records, attorney/deputy routes and any general emergency or vital-interests route are unavailable unless a later DPIA, legal opinion and product release expressly approve them. An organisation using a separately contracted processor module remains responsible for its own lawful basis and Article 9 condition under the module data-processing terms.
The Evidence Readiness Review documents whether records exist; it does not ingest health data. Interview recordings are transient and deleted within seven days; the written record made from a recording is kept for up to 12 months.
4. Who we share it with (our sub-processors)
We use these providers to run the service, under written data-processing terms, and disclose data only where the law requires it. When we act as your processor for care information, these are our sub-processors and we give you advance notice of any change (see the sub-processor list):
- Supabase — database and authentication; your records are hosted in the UK/EU.
- Vercel — application hosting. Pages, server actions and route handlers run on Vercel's platform, so the data you submit — including care notes and capacity records — passes through Vercel's runtime in transit to Supabase; it is not stored there.
- Stripe — payments and subscription billing.
- Cloudflare — two separate things. First, authoritative DNS for sumrex.app: it answers the lookup that turns “sumrex.app” into an address your browser can reach, and what it handles there is DNS query metadata, usually reaching it from your internet provider's resolver rather than from you directly. Second, it holds a backup copy of the documents you upload — your certificates, insurance papers and signed agreements — in its object storage, because our database provider's backups cover the database and not the files themselves. Without that copy a restore would bring back records pointing at documents that were gone.
- Google — email hosting for our contact and privacy addresses (Google Workspace). When you email us — including to ask us about your data or to exercise your rights — your message, and anything you choose to put in it, is held in a mailbox Google operates for us.
- Anthropic — only on our Employer Plus plan, and only if you choose to use the in-app assistant. The assistant is not offered on any other plan, so most accounts send nothing to Anthropic. Where you do use it, the message and conversation you send are processed by Anthropic (api.anthropic.com) to generate a reply; don't paste anything into it you wouldn't want processed this way, and the rest of Sumrex works without it.
5. Where your data goes (international transfers)
Supabase hosting is in the UK/EU. Some providers are US-based. Where personal data is transferred to the United States, we rely on the UK Extension to the EU–US Data Privacy Framework (the “UK–US Data Bridge”) where the recipient participates in that framework — this covers Stripe and Vercel. As a fallback where the Data Bridge does not apply, transfers are made under the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, as set out in each provider's data-processing agreement, with a transfer risk assessment where required.
6. How long we keep it
We keep your data while your account is open, but not indefinitely — records are deleted on set periods once they are no longer needed:
- Care notes and care visits — deleted 2 years after the care arrangement ends.
- Care documents — deleted 6 years after the arrangement ends for agreements and receipts (which can be accounting records), and 2 years for insurance and other documents.
- Interviews — the recording is deleted within 7 days; the written record (transcript) made from it is deleted 12 months after the interview.
- Capacity and consent records — the evidence of the lawful basis for holding health data is kept as a safeguarding audit for as long as we hold the care records it covers.
Some records carry statutory minimums that override deletion — payroll and PAYE records (3 years from the end of the tax year; underlying accounting records 6 years), and billing records — and are retained for those periods. When you close your account or ask to be erased, we anonymise the personal data we can and retain only what the law requires us to keep, under the erasure and retention routines described in our internal records.
7. Your rights
You can access, correct, export, or erase your data, restrict or object to processing, and — where we rely on your consent — withdraw it at any time (which does not affect processing already carried out). The person whose care information is recorded may exercise rights directly; a family account holder cannot override that adult’s rights. For an organisation-controlled module, Sumrex assists the organisation under the applicable DPA. There is no solely-automated decision-making with legal or similarly significant effects. Email us at privacy@sumrex.app to exercise any of these. You can complain to the Information Commissioner's Office (ico.org.uk), though we hope you will contact us first.
8. Cookies
Sumrex uses only strictly-necessary cookies. See our cookie policy for details.