Legal & Governance
Privacy Policy
Effective Date: June 1, 2026 · Last Updated: June 1, 2026
Summary: CURA collects limited professional and usage data to operate and improve our regulatory intelligence platform. We do not sell your data. You have meaningful controls over your information. For questions, contact info@cura-intel.com.
1. Introduction
CURA Inc. ("CURA," "we," "our," or "us") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you access or use the CURA Clinical, Unerring, Regulatory, Analytics platform (the "Platform"), our websites, APIs, and related services (collectively, the "Services").
This policy applies to all users of our Services, including enterprise clients, individual subscribers, and visitors. By using our Services, you acknowledge that you have read and understood this Privacy Policy.
If you have questions or concerns about this policy or our data practices, please contact our Data Protection Officer at info@cura-intel.com.
2. Information We Collect
2.1 Information You Provide Directly
We collect information you provide when you register for an account, request a consultation, or contact us:
• Identity data: full name, job title, professional credentials
• Contact data: business email address, phone number, mailing address
• Account credentials: username and password (stored in encrypted form)
• Organization data: company name, industry sector, billing information
• Communication data: messages, feedback, support tickets, and survey responses
2.2 Information Collected Automatically
When you use our Platform, we automatically collect:
• Usage data: pages visited, features accessed, search queries, session duration, click patterns
• Device data: IP address, browser type and version, operating system, device identifiers
• Log data: access logs, error logs, API call records with timestamps
• Cookie and tracking data: session cookies, analytics identifiers, preference tokens
2.3 Information from Third Parties
We may receive information about you from:
• Identity verification providers and Know Your Business (KYB) services
• Public regulatory databases (FDA, EMA, EUDAMED, ClinicalTrials.gov) used to enrich platform data
• Business intelligence and enrichment partners
• Single Sign-On (SSO) providers used by your organization
2.4 Sensitive Professional Data
As a regulatory intelligence platform, CURA processes industry data that may include references to clinical trial participants, adverse event reports, and regulatory submissions. This data is sourced exclusively from public regulatory databases. We do not collect or process personal health information about identifiable patients or clinical trial participants.
3. How We Use Your Information
We process your personal data for the following purposes, each grounded in a lawful legal basis:
Provision of Services (contractual necessity): To create and manage your account, deliver the Platform's regulatory intelligence features, process payments, and provide customer support.
Platform Improvement (legitimate interests): To analyze usage patterns, identify bugs, improve feature performance, and develop new capabilities that serve our user base.
Compliance and Legal Obligations: To fulfill our obligations under applicable laws, including financial record-keeping, regulatory reporting, and responding to lawful government requests.
Communications (consent or legitimate interests): To send service announcements, security alerts, product updates, and — where you have opted in — marketing communications about CURA offerings relevant to your role.
Safety and Security (legitimate interests): To detect fraudulent activity, unauthorized access, and threats to Platform integrity.
AI and Analytics Improvement (legitimate interests): To improve the accuracy of our AI-driven regulatory models, drug pipeline intelligence, and clinical trial monitoring systems, using aggregated and de-identified data only.
4. Data Sharing and Disclosure
CURA does not sell your personal data to third parties. We share information only in the following circumstances:
Service Providers: We engage vetted third-party processors — including cloud infrastructure providers (AWS, Google Cloud), analytics services, payment processors, and communication platforms — under strict data processing agreements that limit their use of your data to the services they provide to us.
Enterprise Administration: If you access CURA through your employer's enterprise license, your organization's administrators may have access to your account information and usage data as permitted by your employer's agreement with CURA.
Regulatory and Legal Compliance: We may disclose information to regulatory authorities, law enforcement, or courts when required by applicable law, subpoena, or court order, or when necessary to protect rights, property, or safety.
Business Transfers: In the event of a merger, acquisition, or sale of assets, personal data may be transferred as part of the transaction, subject to the acquiring entity honoring the commitments in this Privacy Policy.
With Your Consent: We may share information for purposes not described here when we have obtained your explicit consent.
5. Data Retention
We retain your personal data for as long as your account is active or as necessary to provide the Services. Specific retention periods include:
• Account data: retained for the duration of your subscription plus 3 years to satisfy contractual and audit obligations
• Usage logs and analytics: retained for 24 months
• Support and communication records: retained for 5 years
• Financial records: retained for 7 years as required by applicable tax and accounting regulations
When your data is no longer required, we securely delete or anonymize it using industry-standard procedures. You may request early deletion of your account data subject to our legal retention obligations.
6. Your Privacy Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Right of Access: Request a copy of the personal data we hold about you and information about how it is processed.
Right of Rectification: Request correction of inaccurate or incomplete personal data.
Right of Erasure: Request deletion of your personal data, subject to our legal retention obligations.
Right to Restrict Processing: Request that we limit how we use your data in certain circumstances.
Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
Right to Object: Object to processing based on legitimate interests, including direct marketing.
Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
Right Against Automated Decision-Making: Not be subject to purely automated decisions that produce significant legal or professional effects.
To exercise any of these rights, contact our Data Protection Officer at info@cura-intel.com. We will respond within 30 days. We may need to verify your identity before processing your request.
7. Data Security
We implement enterprise-grade security measures to protect your personal data:
• Encryption in transit: TLS 1.3 for all data transmission
• Encryption at rest: AES-256 encryption for stored data
• Access controls: Role-based access control (RBAC), multi-factor authentication (MFA), and principle of least privilege
• Infrastructure: SOC 2 Type II certified cloud infrastructure
• Monitoring: Continuous intrusion detection, anomaly monitoring, and security incident response
• Personnel: Background checks, security training, and confidentiality agreements for all staff with data access
• Audits: Annual third-party penetration testing and security assessments
Despite these measures, no electronic transmission or storage system is 100% secure. We cannot guarantee absolute security and encourage you to use strong passwords and notify us immediately of any suspected unauthorized access.
8. International Data Transfers
CURA is headquartered in the United States. If you access our Services from the European Economic Area (EEA), United Kingdom, or other jurisdictions with data transfer restrictions, your information may be transferred to and processed in the United States.
For transfers of personal data from the EEA and UK, we rely on approved transfer mechanisms including Standard Contractual Clauses (SCCs) issued by the European Commission, and where applicable, the EU-U.S. Data Privacy Framework. For more information about our transfer mechanisms, contact info@cura-intel.com.
10. Children's Privacy
Our Services are designed for healthcare, life sciences, and regulatory professionals and are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us at info@cura-intel.com and we will promptly delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will notify you by email (if we have your email address) or by posting a prominent notice on the Platform at least 30 days before the changes take effect.
Your continued use of the Services after the effective date of the updated policy constitutes your acceptance of the changes.
12. Contact Us
For privacy-related questions, requests, or concerns:
Data Protection Officer
CURA Inc.
C G Road, Ahmedabad - 380009
Gujarat, India
Email: info@cura-intel.com
Phone: +91 7351206353 / +91 8460770445
For EEA and UK residents who believe their privacy rights have been infringed, you have the right to lodge a complaint with your local data protection supervisory authority.
Translate