Skip to main content

Privacy Policy

Last updated: 7 September 2026

Who this policy covers

This privacy policy explains how CURN LTD, a company registered in England and Wales (company number 16442743) ("CURN", "we", "our", "us"), handles personal data when you visit curn.io, contact us, book a call, work with us, or use a service that we have expressly made available to you.

CURN combines advisory services with product capability under development. A feature described in product or sales material is not necessarily active. Before client employee or workflow data is processed, the relevant service boundary, roles, providers, retention and controls must be documented in the engagement or pilot terms.

We are the controller for website, booking, enquiry and CURN business-relationship data. Where a client instructs us to process its employee or workflow data, the client will normally be the controller and CURN the processor. Those roles are fixed in writing before that processing begins.

Our registered office is 4th Floor, Silverstream House, 45 Fitzroy Street, London, England, W1T 6EB. CURN holds Information Commissioner's Office registration reference ZB987705. The public ICO record still needs to be updated from our former company name and address; the company identity and registered office above are current. You can contact us at privacy@curn.io or by post at the registered office address above. Based on our current documented scope, we do not presently believe a statutory Data Protection Officer is required. Our privacy lead handles enquiries, and we review that assessment when our processing changes.

Information we collect

Depending on how you interact with CURN, we may collect:

  • Enquiry and booking information: Your name, email address, company, optional company website, role, company size, message, selected meeting time and related attribution such as the page or campaign that led to the enquiry.
  • Website AI chat: The messages you enter and the replies generated during the conversation, including any contact details and company website you share, and public website text read for context. If you request a call from the chat, we receive the brief, contact details and website address you review in the form.
  • Business-relationship information: Correspondence, meeting notes, proposals, contract information and records needed to manage an advisory or commercial relationship.
  • Public professional and editorial-research information: A person's name, role, organisation, public social handle, profile or post URL, public post or reply text, and our research tags or notes where relevant to CURN's editorial research, source attribution, or proportionate content strategy.
  • Website information: Pages viewed, interactions, device and browser information, and approximate location where you have consented to analytics.
  • Security information: IP address, request metadata and diagnostic information needed to protect and operate the website.
  • Explicitly scoped service information: Information a client or authorised user provides during an engagement or controlled pilot. The applicable data categories are documented before real employee or workflow data is admitted.

Booking a CURN call does not give us access to your personal calendar. The website checks a CURN organiser calendar for available times and, after you confirm, creates an appointment with you as an attendee.

We collect information directly from you, from an authorised account holder, and from public professional profiles or posts. Required booking fields are marked on the form; if you do not provide them, we cannot arrange the appointment. Other fields are optional.

How we use your information

We use personal data to:

  • respond to enquiries and arrange conversations;
  • help you prepare a call request through the website chat;
  • assess, enter into and deliver advisory or service engagements;
  • maintain an appropriate business-relationship record;
  • conduct proportionate editorial research, source attribution and content strategy using public professional information;
  • operate, secure and diagnose the website;
  • understand website use where you have consented; and
  • send marketing communications where you have asked to receive them.

Legal basis for processing

Under the UK GDPR, we must have a lawful basis for each type of processing. The bases we rely on are:

  • Steps before a contract and contract performance: Responding to a request, arranging a meeting, preparing an engagement and providing a service you have asked us to provide.
  • Consent: Non-essential website analytics, marketing measurement and marketing communications. You may withdraw consent at any time.
  • Legitimate interests: Handling relevant business enquiries, maintaining proportionate customer-relationship records, securing the website, preventing abuse and improving our operations, and conducting proportionate editorial research, source attribution and content strategy using public professional information. We balance these interests against your rights and are completing a specific assessment for the public-professional research.
  • Legal obligation: Keeping records required for tax, accounting, regulatory or legal purposes.

A client remains responsible for identifying its own lawful basis where it asks CURN to process employee or other participant data on its behalf. Employee consent is not treated as the default basis for workplace observation.

Cookies

We use the following categories of cookies and similar storage:

  • Essential: Remembering your privacy preferences, protecting forms from automated abuse and keeping your AI chat connected. When your first chat message receives a reply, a secure cookie stores a random identifier for 30 minutes. It contains no messages or contact details.
  • Analytics: Understanding website use through PostHog and Plausible after you opt in.
  • Marketing measurement: Measuring whether an advertisement led to a confirmed enquiry after you separately opt in.

We do not load analytics or marketing measurement until the relevant consent is present. You can change your choices through the cookie controls or by clearing your browser data and revisiting the site.

Analytics

With analytics consent, Plausible and PostHog help us understand which pages and journeys are useful. Our website configuration masks form inputs, blocks booking forms and the AI chat from session recording, excludes chat text from analytics, and removes request and response bodies from captured network metadata. Provider-side IP handling and retention settings are part of our current configuration-evidence review. With separate marketing consent, Google Ads records a conversion after a confirmed enquiry.

Website AI chat

The AI assistant helps you prepare a request for a call with CURN. It asks about what you would like to discuss, your name and email address. Company and website are optional. It is not a live conversation with a member of CURN. Please leave out confidential documents and sensitive personal information. The chat does not accept files or audio recordings.

When you send a message, the current conversation passes through our server to Google's paid Gemini API to generate a reply and fill in your call request. This includes any contact details you type in the chat and any public website text we read for context. Gemini selects excerpts from your messages for the brief and identifies the contact details you provide. You can review and edit these before submitting. Replies can be inaccurate and should be checked before you act on them.

If you share a company website in chat, our server may read a limited extract from its public HTTPS page without running scripts. The extract provides business context for the assistant.

We hold the conversation in the open page's memory. Starting again or reloading the page clears that copy. We do not save chat transcripts in our own database, analytics or session recordings. Our security controls record request metadata and usage counts without the text of your conversation. We temporarily cache the website address, lookup status and any extracted public page text in Upstash until the original chat session expires, at most 30 minutes after it began.

Under Google's paid-service terms, prompts and replies are not used to improve its products. Google's abuse-monitoring policy states that prompts, context and replies are retained for 55 days for abuse prevention, service security and required legal disclosures. Flagged material may be reviewed by authorised Google personnel. Clearing the chat here does not delete Google's retained copy.

Chatting or reviewing your details does not book a call or send an enquiry. Choosing a time carries your reviewed brief, contact details and optional website address into the booking form. You then select a time and confirm the appointment, as described below. You can instead submit a call request: the brief, contact details and reviewed website address go to CURN through Attio and Resend so we can reply by email. The rest of the chat and the extracted website text are not included.

Bookings and Google Calendar

The website uses a server-side connection to a CURN-owned Google Calendar to read availability and create an appointment after you submit the booking form.

  • The availability response contains open CURN meeting times, not the titles or contents of calendar events.
  • A confirmed booking sends your name, email, meeting time, company and optional message to the CURN organiser calendar and our CRM.
  • The connection does not access the contents of your calendar or connect to your Google account.
  • Server credentials are not exposed to the browser.

Our use of Google Calendar data is limited to checking CURN availability and managing appointments. We do not use it for advertising, sell it or use it to build advertising profiles.

Internal Content OS

CURN uses an internal Content OS for its own content planning and measurement. It is not a customer product integration. Authorised team members may upload analytics exports from accounts they control. We may also record limited information from public professional profiles and posts to plan useful editorial work, understand relevant conversations and attribute source material.

  • The current LinkedIn connection is identity-only. CURN does not use LinkedIn's API to read post analytics, follower totals, member feeds or messages.
  • LinkedIn performance data is imported manually from an export supplied by the authorised account holder.
  • Public research may include a name, role, organisation, handle, profile or post URL, public post or reply text, and a proportionate CURN research note or tag.
  • We do not use this information for recruitment, covert surveillance or decisions with legal or similarly significant effects about another LinkedIn member.
  • Content OS records are subject to an internal review and to validated objection, correction and erasure requests where the relevant right applies.

Where we did not obtain this information directly from you, it came from the public sources or authorised-account exports described above. You can contact us to ask what we hold, correct it or object to the processing.

Product pilots and AI processing

CURN does not use AI to make decisions with legal or similarly significant effects about you. The website chat processing described above is separate from any client engagement or product pilot.

CURN's product is under controlled development. Private cloud processing of real workflow data, remote model routes, embeddings and public third-party product connections are not activated merely because the code or product plan supports them. Before a real-data pilot, CURN requires an approved data protection impact assessment, processing terms, provider and transfer review, fixed retention, and tested rights and deletion paths.

Where an engagement uses AI, the written processing profile identifies the purpose, material, provider, location and retention before relevant client material is processed. Client material is not used to train models, and AI output remains subject to human review.

Who receives personal data

We do not sell your personal data. We may share data only in the following circumstances:

  • Service providers: Providers needed to host and protect the website, arrange appointments, deliver email, maintain our CRM and run consented analytics.
  • Professional advisers: Lawyers, accountants, insurers or other advisers where necessary and subject to appropriate duties.
  • Legal requirements: We may disclose data if required by law, regulation, or legal process.
  • At your direction: Where you ask us to share material with a named participant or service.

Principal website and business providers and recipients

Not every provider receives every category of data. The principal current set for the processing described on this page includes:

  • Vercel: Website hosting and server-side website functions.
  • Cloudflare: Traffic protection, security controls and form abuse prevention.
  • Google Workspace and Google Calendar: Email, CURN organiser availability, appointments and business records.
  • Google Fonts: Typography resources requested by the browser, with associated request metadata.
  • Google Gemini API: Website AI chat replies and preparation of call requests, including optional public website context.
  • Upstash: AI chat rate limits, session counters, spending controls and temporary public website context.
  • Attio: Customer relationship management and enquiry records.
  • Resend: Transactional enquiry and acknowledgement email.
  • PostHog and Plausible: Website analytics after analytics consent.
  • Google Ads: Conversion measurement after separate marketing consent.
  • LinkedIn: Identity-only sign-in for authorised users of CURN's internal Content OS.
  • GitHub: Private repositories used for Content OS source and internal records.

Product and engagement subprocessors are not treated as current merely because a possible integration or provider route exists in code. The applicable set is fixed in the written processing scope before it receives client material.

International transfers

Some current providers operate in, or permit access from, the United States and other countries outside the UK. Their service terms include data-processing and transfer provisions. We are recording the legal entity, role, location and applicable transfer position for each active route. No additional product route is activated until its provider and transfer review is complete. You may contact us for the current recorded position.

Data retention

We keep personal data only for as long as the stated purpose requires:

  • AI chat security counters: Upstash stores rate-limit counters linked to a hashed IP address for up to two days after use, and counters linked to a random session identifier for up to one hour. A monthly spending total, which contains no visitor identifiers, expires within 40 days of use. These records contain no chat text.
  • AI chat website context: Upstash retains the website address, lookup status and extracted public page text until the original chat session expires, at most 30 minutes after it began.
  • Email delivery checks: We keep email receipt IDs, enquiry references and delivery status for up to seven days to identify delivery problems. These records do not include your message or contact details.
  • Enquiries and bookings: Kept while the conversation or resulting relationship is active. We are implementing a manual review with a working 24-month period after meaningful contact, subject to any continuing contractual, legal or legitimate need.
  • Client, contract and financial records: Kept for the engagement and the period required for legal, accounting, insurance and claims purposes, normally up to six years after the relationship ends.
  • Analytics: Consented analytics follow the provider configuration. We are verifying and recording the exact project-level retention and IP-handling settings rather than publishing a period we cannot yet evidence.
  • Content OS records: Kept while they remain relevant to the stated internal purpose, with a manual annual review and earlier action on a validated objection, correction or erasure request where applicable.
  • Security logs: Provider-configured periods are being documented. We retain them only while needed to operate and protect the service, investigate an incident or meet a legal obligation.
  • Product or pilot material: No real employee or workflow-data route is activated without a fixed material-by-material schedule covering working data, kept evidence, derivatives, provider copies and backups.

Deletion from a live system may be followed by expiry from provider backups under the applicable backup cycle. We do not describe a provider-held copy as deleted before the provider's supported deletion or expiry point.

Data protection and security

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • TLS for website traffic and security headers that restrict browser capabilities.
  • Server-only handling of booking, CRM, email and anti-abuse credentials.
  • Separation of public browser code from server-held secrets.
  • Business-system access controls are being tightened towards least privilege, with remaining MFA, access-review and account-lifecycle work tracked in our security programme.
  • Consent-gated analytics with masked inputs and blocked booking forms and AI chat.
  • Abuse prevention, diagnostic logging and a documented breach-escalation procedure. Named roles and a tabletop test remain required before any real-data product pilot.
  • Additional processing-profile, encryption, isolation and deletion gates before private product data is activated.

Your rights

Depending on the processing and the lawful basis, UK data-protection law may give you the following rights:

  • Access (Art. 15): Request a copy of the personal data we hold about you.
  • Rectification (Art. 16): Request correction of inaccurate or incomplete data.
  • Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten").
  • Restriction (Art. 18): Request that we limit how we process your data in certain circumstances.
  • Data portability (Art. 20): Where the legal conditions apply, receive qualifying data you provided to us in a structured, commonly used, machine-readable format.
  • Withdraw consent (Art. 7(3)): Where we rely on consent, withdraw it at any time without affecting earlier lawful processing.
  • Automated decision-making (Art. 22): You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not currently make such decisions.

Your right to object: You may object at any time to direct marketing. You may also object to processing based on legitimate interests, including the public professional information described above. We will stop unless we can demonstrate a lawful reason to continue that overrides your interests, rights and freedoms, or the processing is needed for legal claims.

To exercise any of these rights, please contact us at privacy@curn.io. Requests are handled manually after proportionate identity verification. We are documenting and testing the system-by-system search, export and deletion paths. We will respond within one month. In complex cases, we may extend this by a further two months, and we will inform you if we need to do so.

You also have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint, telephone 0303 123 1113. If you are in the EU, you may contact the supervisory authority in your country of residence.

Children

CURN's website and services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can investigate and take appropriate action.

Changes to this policy

We update this policy when our processing changes. We will post the revised policy here, change the date above and provide additional notice where a material change requires it.

Contact us

If you have questions about this privacy policy or our practices, please contact us at:
privacy@curn.io

CURN LTD
Company number: 16442743
ICO registration: ZB987705
4th Floor, Silverstream House, 45 Fitzroy Street, London, England, W1T 6EB
Registered in England and Wales

30-minute conversation

Choose a time that works.

Tuesdays to Thursdays, UK time.