This notice covers the public CuraLink website, contact and demo requests, and related business communications. Customer deployments and clinical products may be governed by separate agreements and privacy documentation.
Scope and who we are
CuraLink is a healthcare technology brand within the REAP ecosystem. In this policy, “CuraLink,” “we,” “us,” and “our” refer to the entity or entities responsible for operating this website and responding to inquiries submitted through it.
This policy applies when you browse this website, submit a contact or demo request, communicate with us, or otherwise interact with our website-based services. It does not replace privacy terms that may apply to a hospital, clinic, customer implementation, hosted product, support arrangement, or other contracted service.
Information we collect
The information we receive depends on how you use the website. We aim to collect only what is reasonably needed for the stated purpose.
Contact and professional details
Name, work email, telephone number, job role, organization, country, and any details you include in a message.
Inquiry and demo information
Solution interests, organization type, preferred contact details, project context, and communications with our team.
Website and security data
IP address, device or browser details, timestamps, requested pages, and security logs that may be generated by our hosting systems.
Consent and cookie choices
Your selected cookie categories, consent version, and the time at which the choice was saved on your device.
We may also receive information from the organization you represent, a business partner, or a public professional source when relevant to a legitimate business inquiry. If we receive information from another source, we handle it in line with applicable law.
How and why we use information
We may process personal information to:
- respond to messages, support questions, partnership inquiries, and demo requests;
- understand an organization’s needs and recommend relevant CuraLink or REAP solutions;
- arrange meetings and maintain a record of business communications;
- operate, secure, troubleshoot, and improve the website;
- prevent misuse, fraud, or unauthorized access;
- meet legal, regulatory, accounting, or compliance obligations; and
- send marketing communications where permitted and where the required choice or consent has been provided.
Legal grounds
Depending on where you are located, we rely on one or more lawful grounds: your consent; steps taken at your request before entering a contract; performance of a contract; our legitimate interests in operating and securing our business and responding to professional inquiries; and compliance with legal obligations. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful processing.
How information is shared
We do not sell personal information. We may disclose limited information when necessary to:
- CuraLink or REAP team members and affiliated entities involved in responding to your request;
- service providers supporting website hosting, security, communications, data storage, and business operations, subject to appropriate confidentiality and data-protection obligations;
- professional advisers, auditors, insurers, or transaction parties where reasonably required; and
- regulators, courts, law-enforcement bodies, or other parties where disclosure is required by law or needed to protect rights, safety, and security.
If the business is reorganized, merged, financed, sold, or transferred, relevant information may be disclosed as part of that process, subject to applicable safeguards.
International processing
CuraLink serves international markets. Personal information may therefore be accessed or processed outside the country where it was collected, including in countries whose privacy rules differ from yours. Where required, we use contractual, organizational, or other lawful safeguards for cross-border processing.
Information may also be subject to lawful access by courts, regulators, or public authorities in the jurisdiction where it is processed.
Retention and security
Retention
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including follow-up on an inquiry, maintaining business records, resolving disputes, and meeting legal obligations. Retention periods vary by record type, relationship, and applicable law. Information that is no longer required is deleted, anonymized, or securely disposed of.
Security
We use reasonable administrative, technical, and organizational measures intended to protect personal information against loss, misuse, unauthorized access, disclosure, alteration, or destruction. No internet transmission or storage method is completely secure, so absolute security cannot be guaranteed.
Your privacy rights
Subject to applicable law and limited exceptions, you may have the right to:
- ask whether we hold personal information about you and request access;
- request correction of inaccurate or incomplete information;
- request deletion or restriction of processing;
- object to certain processing or withdraw consent;
- request a portable copy of information you provided;
- opt out of marketing communications; and
- make a complaint to the privacy regulator in your jurisdiction.
Canada
Where Canadian private-sector privacy law applies, including PIPEDA or a substantially similar provincial law, you may request access to your personal information, challenge its accuracy, withdraw consent where permitted, and raise a concern about our privacy practices.
European Economic Area and United Kingdom
Where the GDPR or UK GDPR applies, rights may include access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and a complaint to the competent supervisory authority. You may also ask about the safeguards used for relevant international transfers.
California
Where the California Consumer Privacy Act applies, California residents may have rights to know, access, correct, or delete covered personal information and to receive equal service when exercising a right. The categories collected, sources, purposes, and recipient types are described in Sections 2–4 of this policy. CuraLink does not currently sell personal information or share it for cross-context behavioural advertising through this Website.
We may need to verify your identity before completing a request. We will respond within the period required by applicable law and explain any lawful reason that prevents us from fulfilling all or part of a request.
Healthcare and patient information
This public website is designed for corporate information and business inquiries. Where CuraLink technology processes health information for a healthcare provider, the provider typically determines why and how that information is processed, while the applicable customer agreement, deployment documentation, and healthcare privacy laws govern the service. Patients should direct requests concerning their clinical record to the healthcare provider responsible for that record.
Children and external links
This website is directed to healthcare organizations, professionals, and business users and is not intended for children. We do not knowingly use the public website to collect personal information from children. If you believe a child has provided information, please contact us so we can review and take appropriate action.
The website may link to third-party websites, including LinkedIn. Their privacy practices are controlled by their own policies, and we encourage you to review them before providing information.
Changes and contact
We may update this policy to reflect changes in our website, business practices, or legal obligations. The date at the top identifies the current version. Material changes may also be highlighted on the website where appropriate.
Privacy question or request?
Contact the CuraLink team and include “Privacy” in your subject line.
