We may collect the following types of data:
Data is used to:
All data is stored on secure infrastructure in the EU (London region).
We use encryption in transit (HTTPS) and at rest. Access is controlled via role-based permissions.
We do not sell, rent, or share patient data with third parties.
Data may be processed by infrastructure providers strictly for system operation.
Data is retained while your account is active.
Upon account closure, data is permanently deleted within 30 days unless legally required otherwise.
You have the right to:
Carelyx uses AI to analyze structured patient data and generate insights.
AI outputs are designed to be explainable and assist clinical decision-making — not replace it.
Carelyx is designed with GDPR principles and healthcare data protection standards in mind.
Formal certifications are in progress (target: Q2 2026). See Security & Compliance for details.
We may update this policy from time to time. Updates will be posted on this page.
For privacy-related inquiries, contact: [email protected]
Contact us at [email protected] — we respond within 24 hours.