Data-processing terms
These Article 28 terms apply only to a separately contracted organisation module whose order identifies the customer as controller and Sumrex as processor for defined content. They do not apply to the initial direct-consumer care-information service, for which Chronix Health Group Ltd is controller under the privacy notice.
Last updated 21 July 2026 · Chronix Health Group Ltd (company no. 16663224)
1. Roles and scope
For the content listed in the signed organisation order, the customer iscontroller and Chronix Health Group Ltd (company no. 16663224) (“Sumrex”, “we”) is processor. The order must state the subject matter, duration, nature, purpose, data types, special-category data (if any), data subjects and documented instructions. If the actual product facts make Sumrex a controller or joint controller for an activity, these processor terms do not relabel that activity.
2. Processing only on your documented instructions
We process this care information only on your documented instructions — which are the actions you take in the product and these terms — including for transfers, unless the law requires otherwise (in which case we tell you, unless the law forbids it). We do not decide what you record, we do not interpret health data, and we never use this information for our own purposes, for analytics, for product improvement, or to train any AI model. If we ever believe an instruction breaches data-protection law, we will tell you.
3. Confidentiality
Everyone we authorise to process this information is bound by a duty of confidentiality and only accesses it where needed to provide the service.
4. Security (Article 32)
We keep appropriate technical and organisational measures: encryption in transit and at rest, authentication, row-level access controls that scope each account to its own data, least-privilege database grants, and server-side handling of sensitive writes. We do not run advertising, analytics or tracking on care information.
5. Sub-processors
You authorise us to use the sub-processors below to provide the service. We impose data-protection terms on each that are no less protective than these, and we remain responsible for their performance. We will give you advance notice of any addition or replacement so you can object.
| Sub-processor | What it does | Location / transfer basis |
|---|---|---|
| Supabase | Database and authentication — where your records are stored. | UK/EU |
| Vercel | Application hosting — care information passes through Vercel's runtime in transit to Supabase; it is not stored there. | US (UK–US Data Bridge; IDTA fallback) |
| Anthropic | The optional in-app assistant, Employer Plus only — processes only what you type into the assistant, if you use it. | US (UK–US Data Bridge; IDTA fallback) |
6. Helping you meet data-subject rights
Taking into account the nature of the processing, we help you respond to requests from the people you record — access, correction, erasure, restriction, objection and portability — mostly through the product, which lets you view, edit, export and delete the information directly. Where you need more, contact us at privacy@sumrex.app.
7. Assisting you with your obligations
We assist you, taking into account the information available to us, with your security, breach-notification, data-protection-impact-assessment and prior-consultation obligations under Articles 32 to 36.
8. Personal-data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting this information, with the information you need to meet your own notification duties.
9. Deletion or return on termination
When your account ends, or on your request, we delete or return this care information and delete existing copies, except where the law requires us to keep a record — in which case we keep only what the law requires, for no longer than it requires. The retention periods and the erasure routine are described in the privacy notice.
10. Audit
We make available the information needed to demonstrate compliance with these terms and, on reasonable notice and subject to confidentiality, allow for and contribute to audits of the processing carried out for you.