The short version
- We collect what a booking needs and almost nothing else.
- We do not collect your medical records. The platform will not accept them.
- We do not use advertising or analytics trackers. There are none on this site.
- We do not sell your data, and we never will.
- Your data is stored in Singapore, outside the country most of our patients live in. That is a deliberate choice and it is explained below.
Who is responsible for your data
Cura Global Technologies, Inc., a Delaware corporation, decides how and why your personal information is used, and is responsible for it. For anything about your data, write to privacy@curaglobaltech.com. For anything else, info@curaglobaltech.com reaches us just as well.
What we collect
Only what the platform actually asks for:
- When you register: your name, email address, and a password. The password is stored only as an irreversible hash, so nobody at CURA can read it.
- If you are a patient: your date of birth and nationality, which providers need to answer a request, and optionally a phone number.
- If you make a booking: the treatment, the hospital, your preferred dates, the price at the time you booked, and anything you type into the request.
- Optionally, a passport number and an emergency contact, if you choose to give them.
- Optionally, a scan of your passport, if a booking needs one. It is visible to you and to the provider you sent it to.
- If you write to us: your name, email, and the message.
- Automatically: your IP address and browser identifier, kept so we can tell an attack from ordinary traffic.
- If you are a provider: your organisation’s details, services, prices, and the documents you upload to support them.
What we deliberately do not collect
CURA does not hold medical records, imaging, test results, diagnoses, or any clinical history. The upload endpoint refuses those categories outright, so it is not a matter of policy alone.
Anything clinical stays between you and the hospital treating you. If a provider asks you for records, send them to the provider directly, not through CURA.
Why we are allowed to hold it
- To provide the service you asked for: an account, a booking, a reply. Without this data there is no booking.
- Because you consented, for the optional things: a passport scan, a passport number, an emergency contact. You can withdraw that consent and ask us to delete them.
- Because we have to: keeping records of what was agreed, and of moderation decisions, so we can answer a complaint or a regulator.
- Because we have a legitimate interest in keeping the platform up and safe, which is why we keep an IP address against abuse.
A passport scan and a passport number are sensitive information in most places we operate. We ask for them only where a booking needs them, we never require them to browse, and you can ask us to remove them.
Who else sees it
A short list, and it is the whole list:
- The hospital or clinic you send a booking request to sees that request and its attachments. That is the point of sending it.
- Resend, which delivers our email. It sees the address we are writing to and the contents of that message.
- Cloudflare R2, which holds our encrypted backups.
- Our own staff, when answering a support question or reviewing a provider.
- A court or regulator, if we are legally required to disclose something.
Translation between English and Chinese runs on our own server. No third party sees the text of your booking or your messages in order to translate them.
Where your data lives, and why it crosses a border
Our servers are in Singapore. If you are in mainland China, using CURA means your personal information is sent out of China to Singapore, and on to the country of any hospital you send a booking request to.
That transfer is not incidental, it is how a cross-border booking works: a hospital in Japan cannot answer a request it cannot see. We are telling you plainly rather than burying it, because it is the one thing about this platform a reader in China most needs to know before signing up.
How long we keep it
- Your account and profile: until you ask us to delete them.
- Bookings and their history: kept after the treatment, because they are the record of what was agreed between you and a hospital.
- A passport scan: deleted on request, and you can send a booking without one.
- Contact messages: kept while we deal with them and for a period afterwards, so "I wrote and nobody replied" can be checked.
- Abuse records such as IP addresses: kept briefly, then discarded.
What you can ask for
Write to privacy@curaglobaltech.com and we will act on any of these:
- A copy of what we hold about you.
- A correction, if something is wrong.
- Deletion of your account and the data that is not part of a booking record we are required to keep.
- Withdrawal of consent for anything optional, such as a passport scan.
- An explanation of anything in this policy that is not clear.
Depending on where you live, you may also have the right to complain to a data protection authority. We would rather you told us first, but that right is yours either way.
How it is protected
- Passwords are hashed with argon2id and are never stored or logged in a readable form.
- Passport numbers are not returned by the API by default.
- Uploaded documents are reached through short-lived links that are authorised each time, never through a guessable address.
- Passwords, tokens, cookies, and passport numbers are stripped from our logs.
- Access to production data is limited to people who need it.
No system is perfectly secure, and we do not claim otherwise. If we discover a breach affecting you, we will tell you.
Children
CURA is not for children. Do not create an account for someone under the age at which they can agree to this where they live. A parent or guardian arranging treatment should use their own account.
Changes
If we change how we use your data, we will change this page and update the date at the top. Where the change is significant, we will tell you rather than rely on you noticing.