Privacy Notice
Draft information notice for the Chronix Health foundation build.
Draft for review
This page is a draft information notice for review. It is not a final legal policy. Before any real pilot or live deployment, Chronix should obtain legal and privacy review and replace this notice with the reviewed version. The text below is intended to describe the current foundation build only.
About Chronix Health
Chronix Health is a health and care-coordination platform foundation. The current build includes a staff app, a patient portal, and a carer portal. Chronix is not a medical device, is not certified by the NHS, and does not claim ISO 27001, SOC 2, UK GDPR, HIPAA, NHS DSPT, or any other formal certification.
Chronix is not for emergency monitoring. For urgent medical help, contact your GP, NHS 111, or 999 (UK).
Types of information the platform may handle
The foundation build may record the following categories:
- account and profile details
- organisation membership details
- patient core details
- assessments
- vitals and progress values
- care-plan and task information
- calendar and reminder records
- document records (no real document files in this build)
- support requests
- billing placeholder data (no real payment data)
- audit and security event logs
Current placeholder boundaries
Several surfaces are placeholder-only in the foundation build. Specifically:
- No real payment card number, PAN, or CVV is collected or stored. The billing surface uses placeholder data (brand, last four digits, expiry month/year) only.
- No real document downloads or uploads. The document surfaces record metadata only — no Supabase Storage bucket is wired.
- No AI diagnosis, autonomous clinical decisions, or risk-prediction summaries shown to patients or carers.
- No emergency monitoring or automatic escalation.
- No real SMS, email, push, or call dispatch from any Chronix surface in this build.
- Exports remain placeholder-only.
Role-based access
Access is scoped by role and by organisation through Supabase row-level security. The four roles are Administrator, Care Coordinator, Patient, and Carer.
- Staff see information for patients in the organisations where they hold an active membership.
- Patients see their own approved data only — not other patients, not staff-only notes, not the staff messenger.
- Carers see data for patients who have approved a carer link with them, and only for the permission categories the patient has allowed. The patient’s consent settings additionally control top-level carer access.
Patient and carer sharing
Carer access depends on an approved carer link plus per-category permissions a patient (or authorised staff) has allowed. Patients can change or revoke any category through their portal. The platform does not auto-approve carer links.
Security posture
The application is designed around role-based access and row-level security policies, with same-organisation consistency checks on cross-table linkages and append-only audit logging on sensitive admin actions.
Contact and support
Support forms inside the staff, patient, and carer portals are placeholders. They record an intent to contact support but do not send email, SMS, push, or external alerts in this build. They are not emergency channels.
Public contact pages do not yet record real submissions; a reviewed contact workflow will be wired before any pilot.
Urgent or emergency situations
Do not use Chronix for emergency medical help.
Chronix is not monitored for emergencies and does not dispatch urgent clinical alerts. If you or a person you care for is unwell, please use local emergency services (in the UK: your GP, NHS 111, or 999).
