Skip to main content
Privacy notice

Care Vault privacy.

A family's shared record for a person they care for. Chronix Health Group Ltd is the controller for Care Vault.

Care records (conditions, allergies, medications, observations, documents)

Our role: controller. Chronix Health Group Ltd is the controller. This is kept under review: if a future feature lets families set their own purposes, the position may become joint control.

Why: A shared family record for coordination: conditions, allergies, medications, observations, contacts, documents, and the emergency card.

Lawful basis: Contract with the account holder; legitimate interests with a documented assessment for the cared-for person's data. Health data: explicit consent from the person themselves where they have capacity — or, where they lack capacity, a health-and-welfare attorney or court deputy with the instrument on file. The emergency card relies on vital interests. Where the person lacks capacity and no attorney or deputy exists, a record exists only as part of a genuine care arrangement, and health data is processed for the provision of health or social care under Article 9(2)(h) UK GDPR with Schedule 1 paragraph 2 of the Data Protection Act 2018: every carer granted access first gives an express confidentiality undertaking, owed to the person themselves and enforceable by them, satisfying the duty-of-confidentiality condition in section 11(1) of that Act. These records are marked with that purpose permanently, each grant records who granted it and under what authority, it is revocable at any time with immediate effect, and every access by every party is kept on a 7-year audit trail.

Special-category data: Health data — the capacity and consent rules are enforced in the database and closed by default. The Article 9(2)(h) care-arrangement route above is also enforced in the database: no confidentiality undertaking and no care-purpose grant means no record.

Who receives it: Circle members and linked carers according to the family's permissions. Service providers: Supabase, Vercel, Cloudflare, Resend (sending email), Google Workspace (hosting our role mailboxes — anything you email to safeguarding@, support@, privacy@ or reply@ is stored by Google, as is anything we send to them). No AI processor receives vault data.

How long we keep it: Carer unlinked: access ends immediately. Family cancellation: export offered, then deletion after the documented grace period. Recorded death: retained only as needed, then deleted.

Visit statistics

We keep aggregate statistics about visits to our sites — the page visited, the website that referred you, and the country of the request. These records contain no cookies, no IP addresses and no identifiers, so they cannot be linked to you or to any other visit. We keep them for 12 months.

International transfers

Data is resident in the UK/EU. No AI processor currently receives vault data.

Your rights

You can ask for access to your data, correction, deletion, restriction, and a portable copy, and you can object to processing based on legitimate interests. Where we act as a processor, we pass your request to the controller (the organisation or clinician) without delay.

Complaints

Tell us first if you can — use the data complaints form (no account needed). We acknowledge every complaint when it is made and respond within a month. You can also complain to the Information Commissioner's Office (ICO), the UK regulator, at any time, and you have the right to an effective judicial remedy.

Care Vault privacy notice — Chronix Health Group · Care World