Trust & privacy

Your health data, handled the way it should be.

Health information is special-category data under UK GDPR (Article 9). Here's exactly how Suriva collects it, who sees it, and how you stay in control.

KORA & safety

A coach with a safety guardrail, not just a chatbot.

Every KORA reply passes a clinical safety check before it reaches you. KORA only has access to the data categories you've consented to share — withdraw one and it disappears from KORA's context, not just the display.

KORA is built to recognise the edge of what it should answer: for diagnosis, prescriptions, or anything urgent, it tells you plainly and points you to a person — your GP, a Suriva practitioner, or emergency services.

Security

How your data is protected

  1. 01

    Encrypted in transit and at rest

    All data moves over encrypted connections and is encrypted in storage.

  2. 02

    Access is logged

    Every time your record is viewed by a practitioner or a member of our team, it's written to your personal access log — visible to you.

  3. 03

    Named sub-processors only

    Third parties that ever touch your data (wearable sync, payments, hosting) are named in your Privacy settings — nothing hidden behind "partners".

  4. 04

    Independent review

    Our security and consent model is reviewed as we scale toward general launch, ahead of any formal certification.

Your rights

Export, correct, or delete — any time

Export everything

Download a complete copy of your record, in a portable format, whenever you want it.

Delete your account

Deleting your account deletes the data with it, subject only to what we're legally required to retain briefly.

See who's looked

Your access log shows every practitioner or staff view of your record, with a reason and a timestamp.

Correct anything

Edit or remove any logged entry yourself, or ask us to correct it on your behalf.

Questions about how we handle your data?

Our team can walk you through the consent model in detail before you join.