How Ankorium handles your data, in plain English.

No badges. No "we take your privacy seriously". Just the substance: where your data lives, who processes it, how it's secured, and the contract that puts all of this in writing.

Last reviewed: 8 May 2026

Who is responsible for what

UK data protection law splits responsibility between two roles: the Controller (who decides what to collect and why) and the Processor (who handles it on the Controller's instructions). Ankorium's job is to make this division clear, not to muddy it.

You - the practitioner

You're the Data Controller for your clients' data.

  • You decide what to collect from your clients (contact details, booking history, course progress, treatment notes if you choose).
  • You decide why - to deliver your services to them.
  • You hold the relationship with your client and you're accountable to them.
  • You answer the ICO if a client makes a complaint about how their data was handled.
  • Your obligations under UK GDPR don't change because you use Ankorium - they would be the same if you used Word docs and Mailchimp.
Ankorium - your platform

We're your Data Processor.

  • We host the infrastructure, run the database, and deliver the features - following your instructions.
  • We don't decide what you collect or what you do with it.
  • We don't access your clients' personal data except where strictly required to operate, troubleshoot, or back up the service.
  • We never sell, share, or analyse your data for our own purposes.
  • We sign a Data Processing Agreement (DPA) with you that puts all of this in writing.

The Data Processing Agreement

The contract that turns this page from "claims" into "binding". Read it before signing up - or send it to your solicitor.

Read & download →

Your data sits on a UK server. Full stop.

The Ankorium application and database run on a dedicated server physically located in the United Kingdom. We do not replicate your data outside the UK or EEA except where a sub-processor (listed below) is doing a specific job on your behalf - for example, Stripe processing a payment.

UK
Primary server location
TLS 1.3
All data encrypted in transit
Daily
Encrypted backups, 30-day retention
24h
Breach notification commitment to you

Sub-processors

These are the third parties that process some of your data on our behalf, with what each one does and where they're based. Each one has been chosen for a specific job, has a current Data Processing Agreement with us, and is bound to GDPR-equivalent standards. We update this list whenever it changes; material changes are notified to tenants by email at least 14 days in advance.

Provider What they process Location Transfer safeguard
Stripe Card payment processing for tenants who connect their own Stripe account. The tenant is the merchant of record and funds settle directly to them; card data never touches our servers, and Stripe holds it as an independent controller. UK / IE / US UK adequacy + SCCs
Postmark Transactional and campaign email delivery (booking confirmations, password resets, newsletters). Processes recipient email addresses and message content. US (ActiveCampaign Inc.) SCCs + DPA
Anthropic Claude AI features: content generation drafts, course building, AI assistant queries. Inputs are not used for training. Anthropic processes only the prompt content sent for each request. US SCCs + Anthropic DPA, no-training opt-out
Bunny.net Video hosting and global delivery (CDN) for tenant video libraries and recorded calls. Video files only - no end-user personal data. EU (Slovenia) Within UK adequacy / EEA
Zoom Optional video meeting integration. Active only for tenants who connect their own Zoom account. Processes meeting metadata and attendee details for those tenants. US SCCs + Zoom DPA
Speechmatics Real-time speech-to-text for the live session scribe. Receives session audio while a session is being transcribed. Active only for tenants who enable live transcription, and only where the client has given recording consent. EU Within UK adequacy / EEA
Google (Calendar API) Optional calendar sync. Appointment details including client name, email and phone are written into the tenant's own Google Calendar. Active only for tenants who connect Google Calendar. US SCCs + Google DPA
Eventbrite Optional event-ticketing integration. Attendee name and email are exchanged. Active only for tenants who connect Eventbrite. US SCCs + Eventbrite DPA
Pitchup Optional pitch/site booking sync for hospitality tenants. Guest name, email and phone are exchanged. Active only for tenants who connect Pitchup. UK Within UK adequacy
VPS infrastructure provider The physical server that hosts the Ankorium application and database. Provider is contractually bound to UK datacenter location for our servers. UK Within UK adequacy
Offsite backup provider A second hosting provider holding the encrypted offsite backup of the primary server, so that loss of the primary does not take the backups with it. UK Within UK adequacy

Self-hosted on the same UK server, not third-party processors: LiveKit (video conferencing), Qdrant (vector search), Ollama (local AI embeddings). These run inside our infrastructure - no data leaves our environment for them to function.

What "appropriate technical and organisational measures" actually means.

UK GDPR Article 32 requires "appropriate technical and organisational measures" for data security. That phrase is famously vague. Here's the concrete version of what we do.

Encryption

All connections to Ankorium use TLS 1.3. Data is encrypted in transit between you, your members, our server, and every sub-processor. Clinical and personal free-text — consultation notes, session transcripts, AI session summaries — is encrypted at the application layer (AES-256-GCM) before it is written to the database. Backups are encrypted. Uploaded files and the underlying server disk are not encrypted at rest; they are held outside any publicly served directory and reachable only through authenticated, tenant-scoped routes.

Tenant isolation

Every database query is scoped to a single tenant. There is no architectural path for one tenant's data to appear in another's interface, even by mistake. This is enforced at the middleware layer and tested.

Access control

Owners log in with email + password and JWT-secured sessions. Members log in with bearer tokens. Admin access (us) requires a separate authentication path and is logged. We do not share, sell, or maintain a master password.

Input sanitisation & rate limiting

All user-submitted content is sanitised against script injection and event handlers. Database queries are parameterised, never string-concatenated. Rate limits prevent brute-force attempts: 300 reads / 60 writes / 15 auth attempts per 15 minutes.

Backups

Database backups run nightly, encrypted, retained for 30 days, tested monthly for restorability. They are held on a separate server at a second hosting provider, so that losing the primary server does not take the backups with it.

Payment data isolation

Card numbers, CVCs, and bank details never touch our infrastructure. Stripe holds and processes all payment instruments under PCI-DSS Level 1; we hold only Stripe's reference IDs.

Your clients' rights, and how to fulfil them

Under UK GDPR, your clients have rights over their personal data. As Controller, the duty to fulfil those rights sits with you - but Ankorium gives you the tools to do it without contacting us.

Right How you fulfil it in Ankorium
Access Export a member's complete record (profile, bookings, course progress, messages) from the dashboard as a JSON file.
Rectification Edit member details directly in the Clients section of your dashboard.
Erasure ("right to be forgotten") Delete a member from your dashboard. We cascade-delete their personal data within 30 days. Financial records (invoices) are retained for 7 years per HMRC requirement; these can be pseudonymised on request.
Portability Same as Access - the JSON export is machine-readable.
Object / withdraw consent Members can unsubscribe from marketing emails with a one-click link. They can leave courses, communities, and groups themselves from their member profile.
Restriction Mark a member as restricted in your dashboard - their data is retained but not actively processed.

If you ever need help with a complex subject access request - for example, a client wants their data including past community posts where their name was tagged by other members - email [email protected] and we'll help you produce the export.

Our breach notification commitment to you.

Under UK GDPR, you (as Data Controller) have 72 hours from awareness of a personal data breach to notify the ICO if it's likely to risk people's rights. For you to meet that deadline, you need us to tell you fast.

  • If we become aware of a personal data breach affecting your tenant, we will notify you within 24 hours by email and dashboard alert.
  • The notification will include: what happened, what data was involved, when we became aware, what we've done to contain it, and what we're doing to prevent recurrence.
  • We will support your investigation and your communication with affected clients and the ICO at no additional cost.
  • We maintain an internal incident response procedure that prioritises containment, evidence preservation, and accurate communication over speed of resolution.

Things we explicitly don't do

A short list. Easier to say what we don't do than to claim everything we do.

  • We don't sell data, ever. There is no business in which Ankorium would benefit from doing so.
  • We don't use third-party advertising pixels, marketing trackers, or behavioural fingerprinting on tenant sites or our own.
  • We don't read your clients' private messages or community posts unless investigating a specific abuse report you have raised.
  • We don't claim to be HIPAA-compliant. We aren't, because we don't need to be - UK practitioners aren't covered by HIPAA. We are bound by UK GDPR, which is broader and arguably stronger.
  • We don't claim to be a clinical record system. The Clinical Notes module (when shipped) is a private practice journal designed for non-prescribing UK practitioners. If you bill insurance or prescribe medication, you'll want a system like Practice Better or Jane alongside Ankorium.
  • We don't display a "GDPR Compliant" badge. There is no certification body that issues one. This page is the substance.

Questions about how we handle your data?

Direct line to a real person. No support tickets, no escalation queue.

[email protected]

Last reviewed: 8 May 2026 · Read the DPA · Privacy policy