Legal
Privacy policy
This page explains how Curalune processes personal data in relation to platform use, Academy and the mobile app, support requests, and listing management. Last updated: 4 October 2026.
Last updated: 4 October 2026
Applies to contact requests, support messages, account data, and listing management.
Includes how Curalune handles public-source listings and B2B contact details.
Support requests, corrections, and objections can be sent to support@curalune.com.
1. Data controller
The data controller for processing activities carried out through the site is Curalune. For any questions regarding privacy you can contact us by email at support@curalune.com.
2. Types of data processed
Through Curalune we may process, in particular:
- Navigation data (for example IP address, device information, logs), mainly used for security and statistics.
- Contact data (such as name, surname, email and telephone number) if you write to us or submit a contact or support request.
- Data of structures and professionals (descriptions, services offered, photos), provided directly by them for publication on the platform.
- Business contact details of structures/professionals (for example generic email addresses such as info@…, PEC addresses or switchboard phone numbers) collected from public sources or provided by the structure/professional, to manage listings, verify updates and handle B2B communications.
3. Purposes and legal bases
Personal data are processed mainly for the following purposes:
- Provision of the service (managing the site, accounts and listings), on the basis of the contract or pre‑contractual measures requested by the user.
- Handling of requests for information and support, on the basis of Curalune's legitimate interest in ensuring correct functioning of the service.
- Security and prevention of abuse, always on the basis of legitimate interest and legal obligations where applicable.
- B2B communications with structures/professionals (for example requests to update listing information, invitations to provide institutional photos, or service-related proposals such as sponsored placement), on the basis of Curalune's legitimate interest in keeping listings accurate and maintaining a functional directory. You can object at any time (see section 6).
- Recognising requests already received from the same email address (to apply the one-free-verification-per-family limit, avoid duplicates, and link requests and purchases belonging to the same contact), on the basis of Curalune’s legitimate interest in providing the free service sustainably and consistently.
4. Data sources
Some information about structures and professionals may be collected from public sources (for example institutional websites, public directories or official registers) to create informational listings. If you represent a structure/professional, you can request an update or removal of inaccurate information by contacting support.
5. Data retention
Data are kept for the time strictly necessary to achieve the purposes for which they were collected and to comply with legal obligations. Support and update requests may be stored longer to maintain a history of communications and to manage any disputes.
Business contact details used for B2B communications are kept as long as they remain relevant for listing management, or until you object or unsubscribe. We may keep a minimal suppression record, such as your email, to ensure we respect your opt-out.
6. Recipients and transfers
Personal data may be shared with technology and service providers acting as processors on behalf of Curalune (for example hosting/CDN providers, database services, email delivery providers, analytics and payment providers), under appropriate contractual terms and instructions.
- Hosting and infrastructure (e.g. Vercel or equivalent providers).
- Database and storage (e.g. Supabase or equivalent providers).
- Email delivery (e.g. Resend or equivalent providers).
- Payments (e.g. Stripe) where you purchase paid services.
Data are not sold to third parties for their own independent marketing purposes. Some providers may be located outside the EEA. Where applicable, transfers take place under appropriate safeguards, such as standard contractual clauses, or other lawful mechanisms.
7. Rights of data subjects
Under the GDPR, users may at any time exercise their rights of access, rectification, erasure, restriction of processing and objection, as well as the right to data portability where applicable.
Right to object to B2B communications: you may object at any time by replying “STOP” to our emails or by contacting support. We will stop sending further communications to that address.
To exercise these rights or for any doubts about the protection of your personal data, you can write to support@curalune.com.
8. Curalune Academy and mobile app
Account and learning
We use your email address and account identifier for email-code sign-in. Exercise answers are sent to the service for checking. When you sign in, we retain course and lesson records, answer results, attempts, completion and review dates so you can recover your progress and access your courses.
Data on your device
The app stores your language, study goal, accessibility and reminder preferences, activity totals and guest trial progress on your device. Language is also sent with content requests. Session credentials are kept in protected operating-system storage and removed by the app when you sign out. Local preferences and progress are separate from data synced with your account.
Purchase verification
Verifying or restoring store purchases also uses Apple or Google services. We process the platform, product and transaction identifiers, purchase evidence or verification tokens, purchase and access dates, transaction status and its link to your Academy account. These details identify the purchase and support granting, restoring or revoking the relevant access.
App reminders
App reminders are optional and scheduled on your phone after notification permission is granted. You can turn them off in app or device settings. This feature uses local notifications and is separate from any website reminder subscriptions.
Deletion and retention
You can start deletion from your in-app profile or the dedicated website page, confirming account ownership with an email code. Deletion revokes access, including paid courses, and removes account-linked progress and website reminder subscriptions. Deletion in the app also cancels local reminders; a website request does not automatically remove data from every device.
Payment records needed for accounting and applicable obligations, and technical references that prevent the same purchase being reused after deletion, remain. They do not provide access to the deleted account. The retention criteria in section 5 apply; Academy deletion does not change cases held by other Curalune services. Preferences and trial progress may remain on your device and must be managed separately in the app’s local data.
Open the Academy account deletion process