About this Privacy Policy
This Privacy Policy explains how Curénium, also referred to as the Platform, operated by Plannorium Limited, also referred to as Curenium, we, us, or our, collects, uses, stores and protects personal data globally. While we are headquartered in the UK and comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we apply high-fidelity privacy standards across all regions where the Platform is accessible.
Who we are
Curenium is a global cloud-based platform designed for hospitals and healthcare providers to manage clinical workflows, patient data, scheduling and analytics. We act as a data processor when handling patient or clinical data on behalf of hospitals (the data controllers). For our own users (hospital staff accounts, contact details), we act as the data controller. We actively work to acquire and maintain necessary licenses and regulatory approvals within every country and jurisdiction where we operate, ensuring compliance with local healthcare and data sovereignty laws.
Personal data we collect
We collect the following types of data:
- Account & contact data: Name, email, phone, job title, hospital name (from hospital staff).
- Usage data: IP address, browser type, login times, pages visited.
- Health/clinical data (as processor only): Any patient or clinical records you upload or enter via the Platform (e.g. records, notes, images).
- Technical data: Logs, cookies, analytics (Google Analytics or similar).
We do not collect special category data directly from individuals unless you (the hospital) upload it as part of using the service.
How we use your personal data
| Purpose | Lawful basis | Condition |
|---|---|---|
| Provide & improve the Platform | Contract (Art 6(1)(b)) | Not applicable or explicit consent / substantial public interest (hospital-controlled) |
| Account management & support | Contract / Legitimate interests | – |
| Analytics & service improvement | Legitimate interests | – |
| Legal compliance & security | Legal obligation / Legitimate interests | – |
| Marketing (only with consent) | Consent | – |
Lawful basis for processing
Health information is special-category data. Processing it lawfully requires both a basis under Article 6 of the UK GDPR and a separate condition under Article 9. Where Curenium acts as processor, the hospital as controller determines the basis and we process only on their documented instructions. The table below sets out the bases we and our customer organisations typically rely on.
| Purpose | Lawful basis | Condition |
|---|---|---|
| Delivering care: clinical records, observations, prescribing, results | Article 6(1)(e) — public task, or 6(1)(b) contract for private providers | Article 9(2)(h) — provision of health or social care and treatment |
| Patient safety: allergy screening, critical result escalation, duplicate-therapy checks | Article 6(1)(c) — legal obligation, and 6(1)(e) public task | Article 9(2)(h) — health care, and 9(2)(i) public health quality and safety |
| Audit trail: who accessed and changed a record | Article 6(1)(c) — legal obligation under Article 5(2) and 32 | Article 9(2)(h) — management of health care systems |
| Staff accounts, authentication and access control | Article 6(1)(b) — contract, and 6(1)(f) legitimate interests in securing the service | Not applicable — not special-category data |
| Biometric staff identity verification, where an organisation enables it | Article 6(1)(f) — legitimate interests, or 6(1)(c) where required | Article 9(2)(a) explicit consent, or another condition identified by the organisation |
| Billing and payment | Article 6(1)(b) — contract, and 6(1)(c) legal obligation for financial records | Article 9(2)(h) where the record reveals treatment received |
| Service security, fault diagnosis and abuse prevention | Article 6(1)(f) — legitimate interests in operating a secure service | Article 9(2)(h) where clinical data is incidentally involved |
We do not rely on consent as the basis for delivering care. Consent can be withdrawn, and a clinical record cannot lawfully or safely be deleted mid-treatment because consent was withdrawn — so consent would be the wrong basis and would mislead patients about the control they have. Where consent genuinely applies, such as optional biometric verification, it is asked for separately and can be withdrawn without affecting care.
Data security & Technical Measures
We implement strong technical and organisational measures. Messages are carried over authenticated, encrypted connections — a session is only established after the user's token is verified — and clinical data is encrypted in transit and at rest. Access is controlled by role and recorded in an audit trail, and backups run regularly. Our infrastructure via MongoDB Atlas includes advanced data protection, point-in-time recovery and 24/7 security monitoring. We do not claim end-to-end encryption for clinical messaging, and deliberately so. End-to-end encryption means the provider cannot read the content — which would also mean we could not maintain the audit trail that Articles 5(2) and 32 require, could not disclose records lawfully when compelled, and could not preserve the medico-legal record a hospital depends on. Clinical messages form part of the patient record, so they are protected by encryption and access control rather than made unreadable to us. While no system is 100% secure, we follow rigorous international industry standards.
Data retention
We keep data only as long as necessary for the purposes above or as required by law. Hospital-controlled clinical data is deleted/returned when your contract ends (in line with our DPA).
Your data protection rights
You have the right to:
- Access, correct, or delete your data
- Restrict or object to processing
- Data portability
- Withdraw consent (where applicable)
- Lodge a complaint with the ICO (ico.org.uk)
To exercise any right, email contact@plannorium.com.
Changes to this Privacy Policy
We may update this page. We will notify you of material changes via email or in-app notice.
Contact us
Contact us if you have any need of privacy issue clarification:
Plannorium Limited
London, United Kingdom
Email: support@plannorium.com