All resources

Data processing and privacy

The information schedule for DPA, privacy and procurement review.

Last updated 9 September 2026

Purpose. An information schedule for privacy, legal and information-governance review: what Cura processes, where it is held, who processes it alongside us, how long it is kept and how data-subject rights are met. The executed Data Processing Agreement remains the contractual record.

At a glance

The short version, for anyone who needs the assurance without reading the schedule. Every point below is set out in full in the sections that follow.

  • Cura is built for UK GDPR and PECR. Employee data is processed on a legitimate-interests basis for core service delivery; marketing email requires separate explicit consent, which a member can withdraw at any time. The terms and privacy-policy version each member accepted is recorded.

  • Cura asks for as little as it can. The service needs a name, a work email address and the organisation a person belongs to. Everything else on a member's profile, including job role, seniority and any demographic detail, is optional and entirely up to the member. Cura holds no passwords, no payment or bank details, no government or national identifiers, and no HR, payroll or medical records, and it keeps no Microsoft or Google sign-in token after a member has signed in.

  • All client data is processed and stored in the UK and EU. Compute, database and backups are in London; supporting media and storage services are in Ireland and other EU points of presence.

  • Every supplier that touches the data is named, with its purpose and location, in section 3. The current subprocessor register is available on request.

  • An individual's answers are never shown to their employer as their own. Client reporting is aggregated and applies privacy thresholds, so a member's personal responses and wellbeing insights are not identifiable to their organisation.

  • Data-subject rights are built into the product, not handled by hand. A member can request an export of their data, edit their own profile directly, control optional communications from their notification preferences, and have their personal record anonymised so their activity history remains but is no longer attributable to them.

  • The executed Data Processing Agreement is the contractual record, and Cura's own suppliers provide DPA documentation suitable for UK GDPR.

1. Processing description

Field

Description

Subject matter

Provision of Cura, an invitation-only cloud service that delivers short learning experiences, missions, reminders and client-level reporting.

Nature of processing

Collection, hosting, organisation, retrieval, display, analysis, support, backup, export, anonymisation and deletion as needed to provide the service.

Purpose

Account administration, secure access, content delivery, user progress, recommendations, communications, service operation, client reporting and support.

Frequency

Ongoing during the pilot and subscription term.

Data subjects

Authorised users, client administrators and client contacts.

2. Personal-data categories

Category

Examples

Identity and account

Name, work email, organisation, user identifier

Profile

User-entered profile details, preferences

Authentication

OAuth identifiers/tokens or Magic Link events

Activity

Content viewed/completed, missions, habits, timestamps

Responses

Onboarding, pulse, reflection and check-in responses

Communications

Invitation, notification and preference records

Technical

IP address, device/browser data, logs and security events

Client administration

Admin actions, upload/import events

3. Hosting, transfers and subprocessors

Core compute, database and backups are in London, with supporting media and storage services in the EU. Exact supplier legal entities and contractual safeguards are confirmed in the executed DPA.

Service

Purpose

Location

DigitalOcean

Application server, managed PostgreSQL and backup storage

London

Cloudflare

Edge delivery, WAF, bot controls and rate limiting

Global edge; origin in London

Amazon Web Services

Logos/avatars, live streaming and recordings

Ireland (eu-west-1)

Bunny.net

On-demand video

EU points of presence

4. Retention, return and deletion

Data or event

Position

Active account data

Retained for the service term

Termination

Customer data available for export for 30 days; it may then be securely deleted

User erasure

The current flow anonymises the personal record while retaining unattributed activity

Database recovery

Daily backups and point-in-time recovery retained for seven days

Logical backups

Weekly copy retained for 30 days

5. Data-subject rights

Right

Handling

Access

User data can be prepared as a file and delivered by email

Rectification

Users can edit their own profile

Erasure

Anonymisation flow removes attribution

Objection and preferences

Notification preferences control optional communications

6. Technical and organisational measures

  • Passwordless authentication using Microsoft OAuth, Google OAuth or a time-limited Magic Link.

  • Invitation-only access and logical tenant isolation enforced centrally at the database query layer.

  • TLS in transit; object storage and database backups encrypted at rest; stored third-party integration credentials, such as a workspace chat token, encrypted at application level. No Microsoft or Google sign-in token is retained at all.

  • Secure session cookies, CSRF protection, Cloudflare WAF, managed rules, bot mitigation and rate limiting.

  • Short-lived signed media links, administrative logging, automated checks and human review before release.

  • Daily backups, point-in-time recovery, weekly off-provider logical backup, monitoring and rollback capability.

Your Cura contact can supply the current subprocessor register, the agreed retention schedule and the security measures as an annex to the DPA, and can coordinate rights-request, incident-notification and audit-assistance procedures with your privacy team.