CuraFlow Care
Template — needs legal review. This Privacy Notice is a starting point drafted to UK GDPR / Data Protection Act 2018 norms. Because CuraFlow Care handles special category health data, have it reviewed by a UK solicitor or DPO before going live to paying customers.

Privacy Notice

Last updated: 20 September 2026

1. Two different roles — please read this first

CuraFlow Care handles two quite different kinds of personal data, and our legal role is different for each.

  • Care records — information about the people your organisation supports. Here you are the controller and we are your processor. We only act on your instructions. What we may and may not do is set out in the Data Processing Agreement you sign when you start using the service. If you are a person receiving care and you want to see or correct your records, please contact your care provider — they hold that decision, not us.
  • Account data — the details of the organisation and the staff who use the service. Here we are the controller, and the rest of this notice explains what we do with it.

2. Who we are

Cura Compliance UK Limited (company no. 15946204, registered in England and Wales). Registered office: Flat 4, 10 St. Marys Road, Doncaster DN1 2NP.

Contact: curacompliance@gmail.com.

3. What we collect as controller

  • Account data: name, work email address, role, and sign-in timestamps.
  • Organisation profile: business name, addresses, registered manager details, regulator IDs.
  • Subscription data: Stripe customer ID, plan, status. Card details are held only by Stripe — we never see or store them.
  • Audit records: which user created or amended an entry and when. This is required for a care record to be reliable.
  • Legal acceptances: which agreements you accepted, when, from which IP address, and a copy of the wording shown.
  • Operational data: server logs (IP address, user-agent, response codes) for security and debugging, retained for 30 days.

4. Why, and on what legal basis

  • To provide the service — performance of our contract with your organisation.
  • To keep the service secure and prevent misuse — our legitimate interests.
  • To meet our legal obligations — including keeping records of the agreements you accepted.
  • To contact you about the service — our legitimate interests. Service messages are not marketing, and you cannot opt out of essential ones while you hold an account.

We do not sell personal data, and we do not use it for advertising or profiling.

5. Care records: what we do and do not do

We store care records so your organisation can use them. Beyond that:

  • Our staff do not access care records in the ordinary course. Support access is limited to named personnel, requires a business reason and is logged.
  • Care records are never sent to any artificial intelligence provider. CuraFlow Care has no AI features.
  • Care records are never used to train models, build products or produce statistics about anything other than your own service.
  • Each organisation’s data is isolated by row-level security enforced in the database itself, not just in application code.

6. Who we share it with

Only the sub-processors we need to run the service. Each is bound by a written contract and may only act on our instructions:

  • Supabase — database, authentication and file storage. Hosted in the EEA (Paris, eu-west-3).
  • Vercel Inc. — application hosting and delivery. EEA regions; the company is US-headquartered.
  • Resend — transactional email only. No care records are sent to Resend.
  • Stripe — payment processing for subscriptions. No care records are sent to Stripe.

The full, current list with roles and locations is in Annex C of the Data Processing Agreement. We give 30 days’ notice before adding or replacing a sub-processor.

7. Where your data is stored

Care data is stored in the European Economic Area. Where any transfer outside the UK is necessary we rely on an appropriate Article 46 safeguard — normally the ICO’s International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses — together with a transfer risk assessment.

8. How long we keep it

  • Care records: for as long as your subscription is active. After it ends you have 90 days to export, after which we may delete. Backups purge on their normal rotation.
  • Account data: for the life of the account, then up to 12 months.
  • Legal acceptances: 6 years after the agreement ends, as a record of contract.
  • Server logs: 30 days.

Important:care records carry statutory retention periods — generally 8 years for adult social care, and in some cases until a child’s 75th birthday. Meeting those obligations is your responsibility as controller. Export and archive your records; we are not your archive.

9. Your rights

If we are the controller of the data in question (your account data), you have the right to access it, have it corrected or erased, restrict or object to processing, and receive it in a portable form. Contact us and we will respond within one month.

If your data is in a care record, contact the care provider — they are the controller and the decision is theirs. If you contact us, we will pass the request to them without undue delay and will not respond substantively ourselves.

10. Security

TLS 1.2+ in transit and encryption at rest; individual named accounts with role-based permissions; row-level database isolation; audit logging; encrypted daily backups; production data never copied into test environments. The full list is in Annex B of the Data Processing Agreement.

If a personal data breach affects your data we will tell you without undue delay and within 24 hours of becoming aware of it.

11. Cookies

CuraFlow Care sets only strictly necessary cookies. See our Cookie Policy.

12. Complaints

You can complain to the Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to put things right first.

13. Changes

We may update this notice. Material changes will be notified by email or in-app notice before they take effect.