Last updated: 21 April 2026
This Privacy Policy explains how Curénium (the “Platform”), operated by Plannorium Limited (“Curenium”, “we”, “us”, “our”), collects, uses, stores and protects personal data globally. While we are headquartered in the UK and comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we apply high-fidelity privacy standards across all regions where the Platform is accessible.
Curenium is a global cloud-based platform designed for hospitals and healthcare providers to manage clinical workflows, patient data, scheduling and analytics. We act as a data processor when handling patient or clinical data on behalf of hospitals (the data controllers). For our own users (hospital staff accounts, contact details), we act as the data controller. We actively work to acquire and maintain necessary licenses and regulatory approvals within every country and jurisdiction where we operate, ensuring compliance with local healthcare and data sovereignty laws.
We collect the following types of data:
We do not collect special category data directly from individuals unless you (the hospital) upload it as part of using the service.
| Purpose | Lawful Basis | Special Condition |
|---|---|---|
| Provide & improve the Platform | Contract (Art 6(1)(b)) | Not applicable or explicit consent / substantial public interest (hospital-controlled) |
| Account management & support | Contract / Legitimate interests | – |
| Analytics & service improvement | Legitimate interests | – |
| Legal compliance & security | Legal obligation / Legitimate interests | – |
| Marketing (only with consent) | Consent | – |
We handle your data with global transparency:
We do not sell personal data. International transfers are protected by standard contractual clauses and appropriate safeguards.
We implement military-grade technical and organisational measures. This includes end-to-end encryption for messaging, robust access controls, and regular backups. Our technical infrastructure via MongoDB Atlas includes advanced data protection, point-in-time recovery, and 24/7 security monitoring. While no system is 100% secure, we follow rigorous international industry standards.
We keep data only as long as necessary for the purposes above or as required by law. Hospital-controlled clinical data is deleted/returned when your contract ends (in line with our DPA).
You have the right to:
To exercise any right, email privacy@plannorium.com.
We use essential cookies for the Platform to function. Non-essential analytics cookies require your consent. See our Cookie Policy for more details.
We may update this page. We will notify you of material changes via email or in-app notice.
Data Protection Officer / Privacy enquiries:
Plannorium Limited
London, United Kingdom
Email: privacy@curenium.plannorium.com