Privacy Notice
Last updated: 23 July 2026
1. Who we are
Cura Compliance UK Limited (“we”, “us”, “our”), registered in England & Wales (company no. 15946204), is the data controller for personal data collected about your account and users via CuraFlow Compliance. Where you enter personal data about your own staff or service users into the Service, you are the controller and we act as your processor.
Contact: info@curacompliance.co.uk.
2. What we collect
- Account data: name, work email address, password (stored only as a secure hash), sign-in timestamps.
- Organisation profile: business name, service type, registered manager and contact details, CQC/Ofsted IDs, logo image.
- Compliance content you enter: audits, audit responses, action plans, mock-inspection records, calendar events, workforce records and evidence files you upload. These may include personal data about your staff and service users that you choose to enter.
- Subscription data: Stripe customer ID, plan tier, seat count, subscription status. Card details are stored only by Stripe — we never see or store them.
- Communications: messages you send us by email or via the app.
- Operational data: server logs (IP address, user-agent, response codes) for security and debugging, retained for 30 days.
3. Lawful bases
We rely on the following lawful bases under UK GDPR:
- Contract — to provide the Service you signed up for.
- Legitimate interests — to keep the Service secure, debug, and improve usability.
- Legal obligation — to keep tax / accounting records of payments and to respond to lawful requests.
- Consent — for any marketing emails (you can opt out at any time).
Where the compliance content you enter includes special-category data (for example health information about service users), you are responsible for identifying your own lawful basis and Article 9 condition as controller.
4. Data processors and where data lives
We use the following processors, each under an appropriate Data Processing Agreement:
- Supabase (database, authentication, file storage) — region: EU.
- Vercel (application hosting) — global edge with EU primary processing.
- Stripe (payment processing) — EU + global banking infrastructure.
- Resend (transactional email — invites, notifications) — EU.
5. Retention
- Account + organisation data: while your account exists; deleted on request.
- Compliance content (audits, action plans, evidence): while your account exists, then deleted or exported on request, subject to any statutory record-keeping period that applies to your service.
- Stripe transaction records: 7 years (UK tax / accounting requirements).
- Server logs: 30 days.
6. Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request deletion (subject to retention obligations);
- restrict or object to processing;
- data portability;
- withdraw consent at any time where consent is the lawful basis.
To exercise any right, email info@curacompliance.co.uk. We will respond within one month. Where we process data on behalf of your organisation, we will refer requests from your staff or service users to you as controller.
7. Cookies
We use cookies that are strictly necessary for the Service to function (authentication session, security). We do not use advertising or analytics cookies that require consent under UK PECR.
8. Complaints
If you have a concern about how we handle your data, please contact us first. You also have the right to complain to the Information Commissioner's Office: ico.org.uk.
9. Changes
We may update this Privacy Notice. Material changes will be notified via email or in-app notice before they take effect.