Legal
Privacy Policy
How we handle personal data about you — as a visitor, a demo requester, or a user of Corryk Terminal — together with our full data-protection compliance position.
Contents
- Who we are, and which law applies
- Scope of this policy
- What we collect
- Cookies and tracking
- Lawful bases
- Our roles: controller and processor
- Sub-processors and service providers
- International transfers
- Security
- How long we keep it
- Your rights
- Personal data breaches
- Records and accountability
- Contracting with us
- Complaints
- Changes to this policy
1. Who we are, and which law applies
Corryk is a trading name of Endenex Limited, a company registered in England and Wales (company number 17061688), with its registered office at 6th Floor, 37 Lombard Street, London EC3V 9BQ. We are the data controller for the personal data described in this policy.
We are established in the United Kingdom and subject to the UK GDPR and the Data Protection Act 2018. Because our dataset includes personal data relating to individuals in the EEA and we offer services to organisations in the EEA, the EU GDPR also applies to that processing.
| Item | Detail |
|---|---|
| Controller | Endenex Limited (trading as Corryk), company number 17061688 |
| Registered office | 6th Floor, 37 Lombard Street, London EC3V 9BQ |
| ICO registration | Registration pending |
| Data protection contact | privacy@corryk.com |
| EU representative (Art. 27) | To be appointed prior to commencement of services to EEA data subjects |
| Statutory DPO | Not required under Art. 37; the named contact above holds responsibility |
2. Scope of this policy
This policy covers personal data about you: because you visited this website, asked us for a demo, corresponded with us, or use Corryk Terminal.
It does not cover the data inside our product. Corryk compiles information about healthcare businesses from public registers, and some of that information relates to identifiable individuals — company officers, and sole practitioners whose business is themselves. That is a different processing activity with a different lawful basis, and it is described separately in our Data Sourcing Statement. If you are here because you believe your details appear in our dataset, that is the document you want.
3. What we collect
When you browse this website
Our hosting provider processes standard server and security logs, which include IP address, user agent, requested URL and timestamp. These are used to deliver the site and to protect it from abuse. We do not use them to build a profile of you and we do not attempt to identify you from them.
When you request a demo
The demo form asks for your first name, last name, work email address, company, job title, country and organisation type. A phone number is optional. Submissions are emailed to us and we reply by email.
When you use Corryk Terminal
We process the account details you or your organisation provide — name, work email, organisation and role — together with authentication records and product usage logs (such as which screens and saved views you use). Usage data helps us keep the service running, secure and useful. Where you save notes, watch-lists or target lists, those belong to your organisation.
When you correspond with us
We keep business correspondence and the contact details within it.
4. Cookies and tracking
This website sets no cookies. It carries no analytics, no advertising pixels and no third-party trackers. Typefaces are self-hosted; loading a page does not make requests to any third-party font service. Corryk Terminal uses a strictly necessary session cookie to keep users signed in.
5. Lawful bases
| What | Why | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Server and security logs | Deliver the site; prevent abuse | Legitimate interests — operating a secure website |
| Demo request details | Respond to your enquiry and arrange a demonstration | Steps at your request prior to entering a contract; legitimate interests in responding to business enquiries |
| Account and authentication data | Provide Corryk Terminal | Performance of a contract with your organisation, Art. 6(1)(b) |
| Product usage logs | Security, support, reliability and product improvement | Legitimate interests — running and improving the service |
| Personal data in the Corryk dataset (officers, sole practitioners, modelled owner-age) | Provide market intelligence to professional investors | Legitimate interests, Art. 6(1)(f) — assessment documented; see Data Sourcing Statement |
| Business correspondence | Manage the relationship | Legitimate interests — ordinary business communication |
| Records kept for accounting and tax | Meet statutory obligations | Legal obligation, Art. 6(1)(c) |
We do not sell your personal data, we do not share it with advertisers, and we do not use it for automated decision-making that produces legal or similarly significant effects. We process no special category data under Art. 9 and no criminal offence data under Art. 10. In particular, we hold no patient data and no health data relating to any individual.
6. Our roles: controller and processor
We act in two distinct capacities, and the distinction matters for any data processing agreement:
- Controller for the Corryk dataset itself, for our website, and for our own customer and prospect records. We determine what is collected and why.
- Processor for content our customers create inside Corryk Terminal — notes, watch-lists, target lists and any personal data a customer chooses to enter. That content belongs to the customer, who is the controller of it. We process it only on their documented instructions.
7. Sub-processors and service providers
We use a small number of service providers who process personal data on our instructions under written terms. As of the date of this policy they are:
| Provider | Function | Primary location |
|---|---|---|
| Cloudflare | Website hosting, DNS and security | Global edge network |
| Supabase | Application database | European Union |
| Fly.io | Application hosting | United Kingdom |
| Clerk | Authentication for Corryk Terminal | United States |
| Resend | Transactional email delivery | United States |
| Anthropic | Language-model processing for classifying and extracting from public business records | United States |
We give customers advance notice of changes to this list and a right to object. Customer content is not used to train third-party models. We may also disclose personal data to professional advisers, or where required by law. If Corryk is ever sold or merged, personal data may transfer as part of that transaction, and we will tell you before it does.
8. International transfers
Our primary application database is hosted in the European Union. Certain sub-processors listed above are established outside the UK and EEA. For those transfers we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on the relevant adequacy regulations where these apply, together with a transfer risk assessment.
9. Security
Measures appropriate to the risk under Art. 32 include: encryption in transit (TLS) and at rest; authentication with role-based access control; least-privilege access to production systems, restricted to personnel who require it; segregated environments; audit logging; managed infrastructure with vendor-maintained patching; and regular backups. Personal data in the dataset is not commingled with customer-controlled content.
Corryk does not currently hold ISO 27001 or a SOC 2 report. Security questionnaires are completed on request.
10. How long we keep it
| Data | Retention |
|---|---|
| Server and security logs | Up to 90 days |
| Demo requests that do not become a relationship | 24 months, then deleted |
| Customer account data | Duration of the contract, then 12 months |
| Business correspondence | Up to 6 years |
| Accounting and tax records | 6 years, as required by law |
| Dataset records | Retained while the underlying business remains within scope, and refreshed from source. Records suppressed following a successful objection are retained only as a minimal suppression entry, so we do not reintroduce the data at the next refresh. |
11. Your rights
Under UK and EU data protection law you have the right to ask us for a copy of the personal data we hold about you; to have inaccurate data corrected; to have data erased in certain circumstances; to restrict processing; to receive data you gave us in a portable format; and to object to processing carried out on the basis of legitimate interests. Where our processing is automated in ways that produce legal or similarly significant effects, you have the right not to be subject to it — though we carry out no such processing.
To exercise any of these, email privacy@corryk.com. We acknowledge within five working days and respond within one month, extendable by two months for complex requests with notice. No fee is charged unless a request is manifestly unfounded or excessive. We may require verification of identity before disclosing personal data.
Where a request concerns customer-controlled content in Corryk Terminal, we will refer the individual to the relevant customer and assist that customer in responding, as our processor obligations require.
12. Personal data breaches
We maintain an internal breach procedure. Where a breach is likely to result in a risk to individuals' rights and freedoms we notify the ICO, and the relevant EU supervisory authority where applicable, within 72 hours of becoming aware. Where the risk is high we notify affected individuals without undue delay. Where we act as processor, we notify the affected customer without undue delay so that they can meet their own obligations.
13. Records and accountability
We maintain records of processing activities under Art. 30, a documented legitimate interests assessment for the dataset, a transfer risk assessment, and this published transparency information. Data protection is considered at design stage — the decision to model owner-age from published aggregate statistics rather than hold individuals' dates of birth is an example of data minimisation applied in practice.
14. Contracting with us
A data processing agreement incorporating the UK Addendum and EU Standard Contractual Clauses is available on request and can be executed alongside a subscription agreement. Contact privacy@corryk.com.
15. Complaints
If you are unhappy with how we have handled your personal data, please tell us first so we can try to put it right. You also have the right to complain to the Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113), or to the supervisory authority in your EU member state of residence.
16. Changes to this policy
We will post any changes on this page and update the version and date at the top. Where a change materially affects how we handle your personal data, we will tell customers directly.