Log in

Credolex Privacy Policy

Effective date: September 1, 2026
Who we are: Credolex LLC, 806 Chewiliken Valley Rd, Riverside, WA 98849 ("Credolex," "we," "us," or "our")
Privacy contact: privacy@credolex.com

This Privacy Policy explains what personal information Credolex collects, how we use and share it, how long we keep it, and the choices and rights you have. It applies to credolex.com, app.credolex.com, the Credolex application, the public sandbox, our reminder and service emails, and our communications with you (together, the "Service").

Health-related information is also covered by our separate Consumer Health Data Privacy Policy, which is published alongside this Policy and applies in addition to it.


1. Two roles: when we decide, and when a facility decides

Credolex handles personal information in two different capacities, and your rights differ depending on which one applies.

Credolex as the business (controller). For the information we collect directly for our own purposes, such as a request submitted on our website, an account login, billing details, and support correspondence, Credolex decides how and why the information is used. Sections 2 through 8 of this Policy describe that information.

Credolex as a service provider (processor) for a facility. When a healthcare facility or other organization (a "Customer") uses the Credolex application to track credentials, screenings, health items, and training for its own personnel, the Customer decides what information to enter, whom to enter it about, and how to use it. Credolex processes that information only on the Customer's instructions under our Terms of Service and, where signed, our Data Processing Addendum. If you are an employee, contractor, agency worker, volunteer, or student whose information a Customer has entered into Credolex, the Customer is responsible for that information. Please direct questions and requests about it to your facility. We will refer any request we receive from you to the Customer and assist the Customer in responding. Section 9 describes what we hold on Customers' behalf.


2. Information we collect as the business

Access requests. When you submit the request form on credolex.com we collect your full name, work email address, facility name, state, approximate number of beds, and any note you type. We also record the date and time of the submission. We use a hidden form field to detect automated submissions; it collects nothing from a human visitor.

Account and login information. When a Customer invites you to the application we collect your email address, the role assigned to you (owner, staff, or read-only), the facility you belong to, and the time your account was created. Sign-in is by a one-time link sent to your email; we do not collect or store a password. Our authentication provider records the time and IP address of sign-in events for security purposes.

Facility settings. The facility name, state, facility type, time zone, and the notification email address a Customer designates to receive reminder digests.

Billing information. For paid plans, the billing contact's name and email address, the plan tier, and billing history. Payment card details are collected and stored by our payment processor, not by Credolex; we receive only a confirmation of payment and the last four digits and expiration of the card used.

Support and other correspondence. The content of emails and other messages you send us, including to hello@credolex.com, support@credolex.com, privacy@credolex.com, and security@credolex.com.

Usage and technical information. When you use the Service, our hosting and database providers automatically receive standard technical information from your browser, including your IP address, browser type and version, operating system, the pages or screens requested, and timestamps, in server logs kept for security and operations. We do not use analytics tools, advertising pixels, session-recording tools, or tracking cookies of any kind. The application uses your browser's local storage only to keep you signed in and to remember two preferences: your text-size setting and which facility you last viewed. The application loads typefaces from Google Fonts, which means Google receives your IP address when the font files are requested; Google's handling of that request is described in its privacy policy at policies.google.com/privacy.

Sandbox activity. Anything you type into the public sandbox at app.credolex.com/#/sandbox is stored in a shared demonstration facility that every visitor can see and edit, and is deleted every night. Do not enter real personal information in the sandbox. We do not associate sandbox activity with any account.

We do not collect Social Security numbers, dates of birth, home addresses, government identification numbers, precise geolocation, or biometric information, and the Service is not designed to hold them.


3. How we use information

We use the information described in Section 2 to:

  1. evaluate access requests and contact you about onboarding;
  2. create and secure accounts, deliver one-time sign-in links, and enforce roles;
  3. provide the Service, including sending reminder emails and digests to the addresses a Customer designates;
  4. bill for paid plans and maintain billing records;
  5. respond to support, privacy, and security inquiries;
  6. monitor, detect, investigate, and prevent security incidents, abuse, and fraud, and maintain audit logs;
  7. send service communications, such as notices of changes to the Service, these terms, or scheduled maintenance;
  8. comply with legal obligations and enforce our Terms of Service; and
  9. analyze usage in de-identified, aggregated form to understand how the Service is used and to improve it.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use personal information for advertising of any kind, and we do not use it to train artificial intelligence or machine-learning models. We will send marketing email only to people who have requested information from us, and every such email includes a working unsubscribe link.


4. How we share information

We share personal information only in the following circumstances.

Service providers (subprocessors). We use a small number of third-party providers to host and operate the Service. Each processes information only on our instructions and under contractual confidentiality and security obligations. Our current providers are:

ProviderPurposeLocation of processing
Supabase, Inc.Database, authentication, scheduled jobs, and serverless functions that run the ServiceUnited States (AWS us-west-1, Northern California)
Amazon Web Services, Inc.Cloud infrastructure underlying SupabaseUnited States
Cloudflare, Inc.Hosting and delivery of the website and application, DNS, and network securityUnited States, with global edge network
Resend, Inc.Delivery of one-time sign-in links, reminder emails, and service emailsUnited States
Healthchecks.io (SIA Monkey See Monkey Do)Monitoring that the nightly reminder job completed. Receives only a success or failure signal and a delivery count; receives no personal informationEuropean Union
Google LLCFont delivery (Google Fonts). Receives the IP address of the requesting browserUnited States

Our payment processor, once paid plans are billed, will be added to this list and to the subprocessor list in our Data Processing Addendum before it receives any information.

Customers. If you are an Authorized User of a facility's account, the facility's owners can see your email address, role, and the actions you take in the application, which are recorded in the facility's change log.

Legal requirements. We may disclose information if we believe in good faith that disclosure is required by law, subpoena, court order, or governmental request, or is necessary to protect the rights, property, or safety of Credolex, our customers, or the public. Where legally permitted, we will notify the affected Customer before disclosing Customer information in response to a legal demand so that the Customer may seek protective treatment.

Business transfers. If Credolex is involved in a merger, acquisition, financing, reorganization, or sale of all or part of its assets, personal information may be transferred as part of that transaction. We will require the recipient to honor this Policy or provide notice and an opportunity to delete your information before it is used in a materially different way.

With your direction or consent. We will share information in other ways when you direct us to or consent.


5. How long we keep information

InformationRetention
Access requests24 months from submission, then deleted, unless you become a Customer
Account and login informationFor the life of the account, then deleted with the Customer's data under Section 9
Billing records7 years after the transaction, as required for tax and accounting purposes
Support and other correspondence3 years after the last message in the thread
Server and authentication logs held by our providersUp to 90 days
Sandbox activityDeleted nightly

We may retain information longer where required by law, to resolve a dispute, or to enforce our agreements, and we may retain de-identified, aggregated information indefinitely.


6. Security

We protect personal information with safeguards that include encryption in transit (TLS) and at rest, database-enforced isolation between customers so that each facility can reach only its own data, database-enforced roles, one-time sign-in links in place of passwords, a strict content-security policy and related browser protections on the application, an append-only change log that records who changed what and when, and a scheduled job that can be started only with a secret held outside the application. Our Data Processing Addendum describes these measures in more detail.

No system is perfectly secure. If you believe your account or information has been compromised, contact security@credolex.com immediately. We acknowledge security reports within two business days.


7. Your choices and rights

Regardless of where you live, you may ask us to:

  1. tell you what personal information we hold about you as the business;
  2. correct inaccurate information;
  3. delete your information, subject to the retention obligations in Section 5;
  4. provide a copy of your information in a portable format; and
  5. stop sending you marketing email.

Send requests to privacy@credolex.com from the email address associated with the information, or write to us at the address above. We will verify your identity by confirming control of that email address and will respond within 45 days. We will not discriminate against you for exercising these rights. If we decline a request, we will explain why, and you may appeal by replying to our response with the word "Appeal" in the subject line; a different person will review the appeal and respond within 45 days.

Residents of Washington, California, and other states with consumer privacy laws. Credolex does not currently meet the revenue or volume thresholds that make most state consumer privacy statutes apply to it, and much of the information it handles is processed in an employment context that those statutes exclude. We nonetheless honor the requests listed above for everyone. Health-related information is subject to the Washington My Health My Data Act, and our Consumer Health Data Privacy Policy describes the rights that law provides. If you believe we have not resolved your concern, you may contact the Washington State Attorney General's Office at atg.wa.gov or your own state's attorney general.

If your information was entered by your facility. Your facility controls that information. Ask your facility's administrator to view, correct, or delete it, or to stop reminder emails to your address. If you contact us instead, we will forward your request to the facility and help it respond. Reminder emails to workers are sent at the facility's direction and contain only your first name, the item that is due, the facility name, and the date.


8. Children, international visitors, and links

The Service is intended for businesses and organizations in the United States and for adults acting on their behalf. We do not knowingly collect information from anyone under 18. If you believe a minor has provided information to us, contact privacy@credolex.com and we will delete it.

The Service is hosted in the United States. If you access it from elsewhere, you understand that your information will be transferred to, stored, and processed in the United States, where privacy laws may differ from those in your jurisdiction.

The Service may contain links to regulatory sources and third-party sites. This Policy does not apply to those sites.


9. Information we hold on behalf of Customers

This Section describes, for transparency, what the Credolex application stores on a Customer's behalf. The Customer, not Credolex, decides to collect it and is responsible for it.

For each person on the facility's roster: full name; job role; worker type (employee, contract, agency, volunteer, or student); department; hire date; end date, if any; whether the person is active; and, if the facility enters it, an email address for reminders.

For each tracked requirement: the dates the facility records (for example, an issue date, an expiration date, or a completion date), a number of hours where a requirement accumulates hours, a topic, and any note the facility types. Requirements include professional licenses and registry listings, certifications such as CPR, training and in-service completion, employment eligibility verification, background and exclusion screening status, and employee health items such as tuberculosis screening, hepatitis B vaccination or declination, influenza vaccination, and respirator fit testing. Health items are stored as dates and completion status only. The Service does not ask for, and Customers agree not to enter, clinical results, diagnoses, or medical details.

Derived information: a status (current, due soon, expired, or missing) that the application computes from the recorded dates and the current date each time it is viewed, and is never stored.

Reminder emails: an outbox record of each reminder queued and sent, containing the recipient address, subject, body, and send time, kept so that the same reminder is never sent twice and so the facility can see what was sent.

Change log: an append-only record of every change to a person's file, the account that made it, and when.

Customers may export all of this information at any time, may delete individual records at any time, and may request deletion of the entire facility by emailing support@credolex.com from an owner's address. We complete facility deletion within 30 days of the request and, after a Customer's account ends, delete its data from production systems within 90 days and from backups as they expire.


10. Changes to this Policy

We may update this Policy from time to time. We will post the updated Policy at credolex.com/privacy with a new effective date. If a change materially reduces your rights or materially expands how we use personal information, we will give at least 30 days' notice by email to account holders and, where required, obtain consent before the change takes effect.


11. Contact us

Email: privacy@credolex.com
Mail: Credolex LLC, Attn: Privacy, 806 Chewiliken Valley Rd, Riverside, WA 98849

Security reports: security@credolex.com. Support: support@credolex.com. General inquiries: hello@credolex.com.

Questions about this document: legal@credolex.com. Privacy requests: privacy@credolex.com.