Credolex Consumer Health Data Privacy Policy
Effective date: September 1, 2026
Regulated entity: Credolex LLC, 806 Chewiliken Valley Rd, Riverside, WA 98849
Contact: privacy@credolex.com
This Consumer Health Data Privacy Policy is published to meet the requirements of the Washington My Health My Data Act, Chapter 19.373 RCW ("MHMDA"), and similar laws in other states, including the Nevada consumer health data law (SB 370) and the Connecticut consumer health data provisions. It supplements the Credolex Privacy Policy and applies to "consumer health data" as those laws define it: personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status.
Credolex is a record-keeping and reminder tool that healthcare facilities and other employers use to track the credentials, screenings, health items, and training of their own personnel. Most of the health-related information in Credolex is processed by a facility about its own workforce in an employment context, which MHMDA and comparable laws generally exclude. We publish this Policy anyway, because the workforce a facility tracks may include contractors, agency workers, volunteers, and students, because we believe the people whose dates are in Credolex are entitled to know how the information is handled regardless of the technical reach of any statute, and because we act as a processor for facilities that may themselves be regulated entities.
1. Categories of consumer health data we collect
Credolex, acting as a processor on a facility's instructions, stores the following categories of consumer health data about the facility's personnel when the facility chooses to record them:
- Tuberculosis screening: the date of a baseline or annual tuberculosis screening or test, and the date it is next due.
- Hepatitis B vaccination or declination: the date a hepatitis B vaccination series was completed, or the date a declination was signed.
- Influenza vaccination: the date of an annual influenza vaccination, or the date of a declination or exemption.
- Respirator fit testing: the date of a respirator fit test and the date it is next due.
- Health items a facility adds itself: a facility may create its own tracked item, such as a pre-employment drug screen, an immunity titer, or another immunization, and record dates against it.
- Reminder emails: the outbox record of each reminder that mentions one of the items above by name, sent to the address the facility designated.
What we do not collect. Each item above is stored as a date, a completion or declination status, and any note the facility chooses to type. The Service is not designed to hold, and facilities agree in our Terms of Service not to enter, laboratory results, test values, diagnoses, treatment information, reasons for a declination or exemption, or any other clinical detail. Credolex does not collect biometric data, genetic data, precise location data, reproductive or sexual health data, gender-affirming care data, or data about mental health services, and does not infer health status from any other information.
Credolex, acting on its own behalf as the business, does not collect consumer health data about website visitors, people who submit an access request, or account holders.
2. Sources of consumer health data
All consumer health data in Credolex is entered by the facility that employs or engages the individual, through one of three doors: a roster file the facility uploads, columns the facility pastes from its own spreadsheet, or a form the facility completes one record at a time. Credolex does not obtain health data from the individual directly, from laboratories, clinics, or pharmacies, from public records, from data brokers, or from any other third party.
3. Purposes for which we collect and use consumer health data
We collect and use consumer health data only for the following purposes, each of which is necessary to provide the product or service the facility requested:
- to store the dates the facility records and display them to the facility's authorized users;
- to compute and display whether each item is current, due soon, expired, or missing, based on the recorded dates and the current date;
- to send email reminders at 30, 15, 7, and 0 days before an item lapses, to the facility's designated notification address and, where the facility entered one, to the individual's own address;
- to keep an append-only change log of who changed which record and when, so the facility can answer that question;
- to keep an outbox record of reminders sent, so that no reminder is sent twice;
- to produce spreadsheet exports when the facility requests them; and
- to secure the Service, detect and investigate unauthorized access, and comply with law.
We do not use consumer health data for advertising, marketing, profiling, product research, model training, or any purpose other than those listed. We do not use it to make any decision about the individual; the facility makes every such decision.
4. Sharing of consumer health data
We do not sell consumer health data, and we have not done so. We do not share consumer health data with affiliates, advertisers, or data brokers. We share it only as follows.
Processors acting on our behalf. The following providers process consumer health data as part of hosting and operating the Service. Each is bound by a written contract that limits its use of the data to providing its service to us and requires it to protect the data.
| Processor | What it does | Categories of data it processes |
|---|---|---|
| Supabase, Inc. (on Amazon Web Services, us-west-1, United States) | Hosts the database, authentication, and the scheduled reminder job | All categories in Section 1, as encrypted database contents |
| Resend, Inc. (United States) | Delivers reminder emails | The recipient address, the individual's first name, the name of the item that is due, the facility name, and the due date |
| Cloudflare, Inc. (United States) | Delivers the application to the browser and protects it from network attack | Encrypted traffic between the browser and the database passes through Cloudflare's network; Cloudflare does not store consumer health data |
No other third party receives consumer health data. Our uptime monitor receives only a job success or failure signal. Google Fonts receives only the browser's IP address when typefaces load.
The facility. The facility that entered the data, and the authorized users it designates, can view, export, and change it.
Legal process. We may disclose consumer health data if required by a valid subpoena, court order, or other legal demand. Where the law permits, we will notify the facility first so that it may object.
Geofencing. Credolex does not use geofencing of any kind.
5. Your rights
If you are a Washington resident, or a resident of another state with a consumer health data law, you have the right to:
- Confirm and access: confirm whether we are collecting, sharing, or selling consumer health data about you, access that data, and receive a list of all third parties and affiliates with whom we have shared or to whom we have sold it, with an email address or other online mechanism to contact each one. Our third parties are listed in Section 4; each can be reached at the privacy contact published on its website.
- Withdraw consent: withdraw any consent you gave to the collection or sharing of your consumer health data.
- Delete: have your consumer health data deleted, including from our processors and from backups within the retention periods described below.
- Not be discriminated against for exercising any of these rights.
How to exercise these rights. Because the facility that employs or engages you entered your data and controls it, the fastest route is to ask your facility's administrator, who can view, correct, and delete your records in the application immediately. You may also contact us directly at privacy@credolex.com or by mail at the address above. We will verify your identity by confirming that you control the email address the facility has on file for you, or by asking the facility to confirm your identity. We will forward your request to the facility, assist it in responding, and act on the facility's instruction, or act directly where the law requires us to. We will respond within 45 days of receipt, which we may extend by a further 45 days where reasonably necessary, with notice to you.
Deletion mechanics. When a record is deleted in the application, it is removed from the production database immediately and permanently. Reminder outbox rows that reference the record are removed with it. Copies in database backups expire and are overwritten within 30 days. Where a facility is required by law to retain a record, it may decline a deletion request on that basis, and we will tell you so.
Appeals. If we deny your request, we will tell you why and how to appeal. To appeal, reply to our decision with "Appeal" in the subject line. A different person will review your request and respond in writing within 45 days. If your appeal is denied, you may contact the Washington State Attorney General's Office at atg.wa.gov/file-complaint or your own state's attorney general.
6. Retention
Consumer health data is retained for as long as the facility keeps the record in the application. When a facility's account ends, we delete its data from production systems within 90 days and from backups as they expire. Reminder outbox records are retained for the life of the facility's account so that the facility can demonstrate what was sent.
7. Security
Consumer health data is encrypted in transit and at rest. Access is restricted in the database itself to the authorized users of the facility that entered it, so that no facility can reach another's data and no application server sits between the browser and that check. Every change is written to an append-only log. Credolex staff do not access facility data except at a facility's request to provide support, and any such access is logged.
8. Changes to this Policy
We will post any update to this Policy at credolex.com/consumer-health-data with a new effective date and will notify facilities by email of any material change. We will not use consumer health data for a new purpose without first updating this Policy and, where the law requires, obtaining consent.
9. Contact
Email: privacy@credolex.com
Mail: Credolex LLC, Attn: Privacy, 806 Chewiliken Valley Rd, Riverside, WA 98849
Log in