Data processing and privacy
The information schedule for DPA, privacy and procurement review.
Last updated 9 September 2026
Purpose. An information schedule for privacy, legal and information-governance review: what Cura processes, where it is held, who processes it alongside us, how long it is kept and how data-subject rights are met. The executed Data Processing Agreement remains the contractual record.
At a glance
The short version, for anyone who needs the assurance without reading the schedule. Every point below is set out in full in the sections that follow.
Cura is built for UK GDPR and PECR. Employee data is processed on a legitimate-interests basis for core service delivery; marketing email requires separate explicit consent, which a member can withdraw at any time. The terms and privacy-policy version each member accepted is recorded.
Cura asks for as little as it can. The service needs a name, a work email address and the organisation a person belongs to. Everything else on a member's profile, including job role, seniority and any demographic detail, is optional and entirely up to the member. Cura holds no passwords, no payment or bank details, no government or national identifiers, and no HR, payroll or medical records, and it keeps no Microsoft or Google sign-in token after a member has signed in.
All client data is processed and stored in the UK and EU. Compute, database and backups are in London; supporting media and storage services are in Ireland and other EU points of presence.
Every supplier that touches the data is named, with its purpose and location, in section 3. The current subprocessor register is available on request.
An individual's answers are never shown to their employer as their own. Client reporting is aggregated and applies privacy thresholds, so a member's personal responses and wellbeing insights are not identifiable to their organisation.
Data-subject rights are built into the product, not handled by hand. A member can request an export of their data, edit their own profile directly, control optional communications from their notification preferences, and have their personal record anonymised so their activity history remains but is no longer attributable to them.
The executed Data Processing Agreement is the contractual record, and Cura's own suppliers provide DPA documentation suitable for UK GDPR.
1. Processing description
Field | Description |
|---|---|
Subject matter | Provision of Cura, an invitation-only cloud service that delivers short learning experiences, missions, reminders and client-level reporting. |
Nature of processing | Collection, hosting, organisation, retrieval, display, analysis, support, backup, export, anonymisation and deletion as needed to provide the service. |
Purpose | Account administration, secure access, content delivery, user progress, recommendations, communications, service operation, client reporting and support. |
Frequency | Ongoing during the pilot and subscription term. |
Data subjects | Authorised users, client administrators and client contacts. |
2. Personal-data categories
Category | Examples |
|---|---|
Identity and account | Name, work email, organisation, user identifier |
Profile | User-entered profile details, preferences |
Authentication | OAuth identifiers/tokens or Magic Link events |
Activity | Content viewed/completed, missions, habits, timestamps |
Responses | Onboarding, pulse, reflection and check-in responses |
Communications | Invitation, notification and preference records |
Technical | IP address, device/browser data, logs and security events |
Client administration | Admin actions, upload/import events |
3. Hosting, transfers and subprocessors
Core compute, database and backups are in London, with supporting media and storage services in the EU. Exact supplier legal entities and contractual safeguards are confirmed in the executed DPA.
Service | Purpose | Location |
|---|---|---|
DigitalOcean | Application server, managed PostgreSQL and backup storage | London |
Cloudflare | Edge delivery, WAF, bot controls and rate limiting | Global edge; origin in London |
Amazon Web Services | Logos/avatars, live streaming and recordings | Ireland (eu-west-1) |
Bunny.net | On-demand video | EU points of presence |
4. Retention, return and deletion
Data or event | Position |
|---|---|
Active account data | Retained for the service term |
Termination | Customer data available for export for 30 days; it may then be securely deleted |
User erasure | The current flow anonymises the personal record while retaining unattributed activity |
Database recovery | Daily backups and point-in-time recovery retained for seven days |
Logical backups | Weekly copy retained for 30 days |
5. Data-subject rights
Right | Handling |
|---|---|
Access | User data can be prepared as a file and delivered by email |
Rectification | Users can edit their own profile |
Erasure | Anonymisation flow removes attribution |
Objection and preferences | Notification preferences control optional communications |
6. Technical and organisational measures
Passwordless authentication using Microsoft OAuth, Google OAuth or a time-limited Magic Link.
Invitation-only access and logical tenant isolation enforced centrally at the database query layer.
TLS in transit; object storage and database backups encrypted at rest; stored third-party integration credentials, such as a workspace chat token, encrypted at application level. No Microsoft or Google sign-in token is retained at all.
Secure session cookies, CSRF protection, Cloudflare WAF, managed rules, bot mitigation and rate limiting.
Short-lived signed media links, administrative logging, automated checks and human review before release.
Daily backups, point-in-time recovery, weekly off-provider logical backup, monitoring and rollback capability.
Your Cura contact can supply the current subprocessor register, the agreed retention schedule and the security measures as an annex to the DPA, and can coordinate rights-request, incident-notification and audit-assistance procedures with your privacy team.