Privacy policy
- Version
1. Scope of this policy
This policy explains how Curved Stone Limited (trading as Curvestone, “we”, “us”, “our”) collects, uses and protects personal data as a data controller. It covers personal data relating to (a) visitors to our website (www.curvestone.io) and our prospective and existing business contacts; (b) individuals who apply for roles with us; and (c) individuals authorised by a Curvestone platform customer (“Customer”) to access and use our platform (“Authorised Users”), in relation to the account, authentication, security and usage data we hold about them as controller.
It does not cover personal data that we process on behalf of our Customers when providing our platform, for example data contained in source files, applications or supporting documents that a Customer submits for processing. For that data, Curvestone acts solely as a data processor, on the Customer’s documented instructions. The terms on which we process that data - including our sub-processors, security measures and international transfer arrangements - are set out in the Data Processing Agreement forming part of the Platform Services Agreement between Curvestone and the relevant Customer, and that Data Processing Agreement takes precedence over this policy in relation to that data.
If you believe your personal data has been processed through our platform by one of our Customers (for example, because you used the services of a company that uses our platform), that Customer is the controller of your data and is responsible for responding to you directly. Please contact them in the first instance. We will assist our Customers in responding to such requests in accordance with our contractual obligations to them.
2. Who we are
Curved Stone Limited (trading as Curvestone) provides this website (www.curvestone.io). Our correspondence address is:
Unit D, 21 Heathman’s Road, London, SW6 4TJ
3. How to contact us
You can contact us at any time regarding this policy or your personal data:
The Data Protection Officer, Curvestone, Unit D, 21 Heathman’s Road, London, SW6 4TJ
Email: dpo@curvestone.io
4. Personal data we collect
If you are a visitor to our website or a business contact we may collect and process the following personal data about you:
- Email address
- Name
- Company name
- Website cookies, website usage data, and browser technical information
If you are an Authorised User of our platform, we may also collect and process:
- Name, work email address and login credentials
- Your employer (our customer) and your role or permission level
- Authentication and session data
- IP address, device and browser information
- Usage and audit log data, such as the actions you take on the platform and when you take them
5. How we collect this information
Most of the personal data we collect is provided directly by you, for example when you contact us or request information. We also collect information through your use of cookies and similar technologies on our website. Further detail on the cookies we use and how to manage your preferences is available via our website’s cookie settings tool.
Authorised User account data is provided either by the relevant Customer when it sets up your account, or directly by you when you access or use the platform (for example, login and usage data generated as you use it).
6. Why we collect and use this information
We rely on different lawful bases depending on the purpose of the processing, as set out below.
Website visitors and business contacts
| What we use it for | Our lawful basis |
|---|---|
| Operating, securing and improving our website and understanding how visitors use it | Legitimate interests: keeping our website secure, functional and useful to visitors and prospective customers |
| Responding to enquiries and providing the information, content or support you request | Legitimate interests, or performance of steps taken at your request where applicable |
| Sending direct marketing about our products, services, news and events | Consent, where required under the Privacy and Electronic Communications Regulations (e.g. email marketing to individuals), or legitimate interests where permitted (e.g. existing business relationships), always subject to your right to object at any time |
| Cookies and similar technologies on our website | Consent, except for strictly necessary cookies and cookies that fall within the statistical or appearance exemptions under the Privacy and Electronic Communications Regulations, which instead require a simple, free opt-out |
| Complying with our legal, regulatory and accounting obligations | Legal obligation |
| Establishing, exercising or defending legal claims, and in connection with a corporate transaction | Legitimate interests |
Authorised users of our platform
| What we use it for | Our lawful basis |
|---|---|
| Creating, administering and authenticating your Authorised User account | Performance of a contract, where you are a party to the relevant agreement, or our legitimate interests in providing the platform to Customers and their Authorised Users where you are not |
| Maintaining the security of the platform, including access controls, audit logging, and detecting or investigating misuse or unauthorised access | Legitimate interests, and, where relevant, compliance with our security obligations to Customers and applicable law |
| Measuring and recording platform usage for billing and service management under the applicable Platform Service Agreement | Performance of a contract with the Customer, and our legitimate interests in accurate service administration |
| Providing support to Authorised Users | Legitimate interests, or performance of a contract where applicable |
| Maintaining, administering and improving the platform itself | Legitimate interests |
| Complying with our legal, regulatory and accounting obligations | Legal obligation |
| Establishing, exercising or defending legal claims, and in connection with a corporate transaction | Legitimate interests |
Where we rely on your consent, you can withdraw it at any time by contacting us using the details above or via the unsubscribe link in our emails, without affecting the lawfulness of processing carried out before withdrawal. Where we rely on legitimate interests for direct marketing, you have an absolute right to object at any time.
7. Who we share your information with
We do not sell your personal data. We may share it with:
- IT infrastructure, hosting, email and marketing service providers who process personal data on our behalf as our processors, strictly to operate this website and respond to your enquiries;
- the relevant Customer, where you are an Authorised User, for example to administer its account with us or to provide usage reporting;
- our professional advisers, including lawyers, accountants and insurers, where necessary for the purposes described above;
- any authority or regulator, or law enforcement body, as required to comply with a legal obligation or to respond to a lawful request, court order or legal process; and
- a prospective buyer, investor or their advisers in connection with a corporate transaction, subject to appropriate confidentiality protections.
This section does not cover the sub-processors we use to provide our platform services to Customers (for example, our AI model and cloud infrastructure providers). Those are disclosed to the relevant Customer under the Data Processing Agreement forming part of its Platform Services Agreement and are not personal data we hold as a controller.
8. International transfers
Some of the service providers referred to above may be based, or store data, outside the UK. Where we transfer personal data outside the UK, we put in place an appropriate safeguard recognised under UK data protection law, such as the UK’s data protection adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s Standard Contractual Clauses, to ensure your data continues to receive an appropriate level of protection. You can request details of the safeguard used for a particular transfer by contacting us using the details above.
9. How we store and retain your information
Your information is stored securely, using reputable third-party cloud service providers. We keep personal data only for as long as necessary for the purpose for which it was collected. In general, business contact details are retained for the duration of our relationship with you or your organisation and for a reasonable period afterwards to allow us to handle follow-up enquiries and meet our legal obligations, and website analytics data is retained in accordance with the retention settings of the relevant analytics tool. Authorised User account data is retained for the duration of the applicable Platform Services Agreement and for a reasonable period afterwards to support the Customer’s data export requests and any Customer-specific retention requirements. Usage and audit log data arising from your use of the platform is retained for as long as needed for security, audit and legal purposes, in each case consistent with our obligations to the relevant Customer under its Platform Services Agreement. We delete or anonymise personal data once it is no longer needed, unless we are required by law, accounting or regulatory obligations to keep it for longer, or you ask us to delete it sooner and we have no continuing lawful basis to retain it.
10. Your data protection rights
Under data protection law, you have rights including:
- Right of access: you can ask us for copies of your personal data.
- Right to rectification: you can ask us to correct information you think is inaccurate, and to complete information you think is incomplete.
- Right to erasure: you can ask us to erase your personal data in certain circumstances.
- Right to restriction of processing: you can ask us to restrict the processing of your personal data in certain circumstances.
- Right to object: you can object to our processing of your personal data in certain circumstances, including direct marketing.
- Right to data portability: you can ask us to move, copy or transfer your personal data in certain circumstances.
- Right to opt out: you can ask that your data is not processed and revoke any previous permission, regardless of how or when it was given.
- Right to be informed of a data breach: we will notify you within 72 hours of becoming aware of any data breach concerning your data, where we are required to do so.
You are not required to pay any charge to exercise your rights. If you make a request, we have one month to respond to you. Please contact us using the details in section 3 to make a request.
11. How to complain
If you are unhappy with how we have used your personal data, or with how we have responded to a request to exercise your rights, please contact us using the details in section 3 in the first instance. We will acknowledge your complaint within 30 days and aim to resolve it as quickly as possible.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s independent supervisory authority for data protection:
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113 or Website: ico.org.uk
12. Changes to this policy
We may update this policy from time to time, for example to reflect changes in the law or in how we process personal data. We will post any updated version on our website together with its effective date.