Legal

Privacy Policy

Last updated: 16/07/26

1. Introduction

At Curato, trust begins with transparency. This Privacy Policy explains how Curato Intelligence Private Limited ("Curato", "we", "us", or "our") collects, uses, stores, protects, and shares information when you use our website, platform, and related services (collectively, the "Platform"). Whether you're exploring agencies, submitting a project brief, applying as an agency, or browsing content, we are committed to handling your information responsibly and securely.

By accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Platform.

2. Scope of This Policy

This Privacy Policy applies to all visitors, businesses, agencies, applicants, and other users who access or interact with Curato through our website, Platform, or related services. It is designed to comply with applicable data protection laws, including, where relevant, the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"). Where a specific law grants you rights beyond what is described here, that law will govern.

This Policy does not apply to:

  • Information handled directly by marketing agencies once an introduction has been made and they act as independent data controllers (see Section 10).
  • Third-party websites or services we link to but do not control (see Section 20).

3. About Curato

Curato is a marketplace and recommendation platform that helps businesses discover and connect with carefully vetted marketing agencies. We simplify finding a trusted marketing partner based on your goals, industry, and stage of growth. Curato does not perform marketing services; we facilitate discovery and introductions between businesses and independent third-party agencies.

4. Information We Collect

We collect different types of information depending on how you interact with Curato.

4.1 Information You Provide Directly

When you contact us, submit a project brief, request a consultation, apply as an agency, register an account, or sign up for communications, you may provide:

  • Full name, job title, and company name
  • Email address and phone number
  • Country or region and company address
  • Company website and social links
  • Marketing goals, business requirements, estimated project budget, and preferred timeline
  • Content of forms, messages, and uploaded documents (e.g., briefs, RFPs, portfolios)
  • Payment information when applicable (note: we may use third-party payment processors; see Section 9)
  • If you apply as an agency: business registration details, services offered, portfolio materials, experience, certifications, and similar evaluation information.

Providing this information is voluntary, though some information is necessary for us to respond to your request or to provide the requested service.

4.2 Information Collected Automatically

When you visit our website or use the Platform, we automatically collect technical and usage information, including:

  • IP address, browser type/version, device and operating system information
  • Language preferences and time zone
  • Pages viewed, time spent on pages, click interactions, and navigation patterns
  • Referring websites, search queries, and geographic region (approximate)
  • Date and time of visits, session identifiers, and performance metrics

This information is collected primarily through cookies, analytics, and similar technologies (see Section 8).

4.3 Information From Third-Party Services

We may receive information from third-party services that support the Platform (for example, analytics providers, scheduling platforms, form providers, authentication services, and hosting providers). We work only with providers that process data under appropriate contractual and security obligations.

4.4 Sensitive Information

We do not intentionally collect sensitive personal data (also called special category data) such as health information, racial or ethnic origin, political opinions, religious beliefs, or similar. Please do not submit sensitive information through our forms or communications. If we learn we have collected such information unintentionally, we will delete it promptly.

5. How We Collect Information

We collect information when you:

  • Visit and browse the Curato website and Platform pages
  • Submit a contact, inquiry, or project brief form
  • Book consultations or request agency recommendations
  • Create an account or apply to join Curato as an agency
  • Subscribe to newsletters or other communications
  • Contact our team by email, telephone, or other channels
  • Respond to surveys or provide feedback
  • Interact with Platform features such as search, matching, or messaging

6. How We Use Your Information

We use information to provide, maintain, improve, and protect Curato and the services we deliver, including:

  • Providing services: recommend suitable agencies, evaluate agency applications, facilitate introductions, schedule consultations, and respond to requests.
  • Improving the Platform: analyze usage to improve functionality, search, recommendations, content, and performance.
  • Communicating with you: send confirmations, respond to inquiries, deliver requested information, provide service updates, and send marketing (where permitted).
  • Security and fraud prevention: detect, investigate, and prevent fraud, abuse, or other malicious activity.
  • Legal compliance: comply with legal obligations, enforce our terms, and protect our rights and safety.

We process personal data only for the purposes described in this Policy and for compatible purposes.

7. Legal Bases for Processing (GDPR)

If you are located in the EEA, UK, or Switzerland, we rely on the following legal bases under GDPR Article 6:

  • Performance of a contract or steps prior to entering a contract: facilitating agency introductions, consultations, responding to service requests.
  • Legitimate interests: platform improvement, fraud prevention, security monitoring, and limited communications necessary for providing services (we balance these interests against your rights).
  • Consent: where required by law (for example, certain analytics or marketing tracking). You may withdraw consent at any time; withdrawal does not affect processing already carried out lawfully.
  • Legal obligation: processing required to comply with applicable laws.

8. Cookies, Analytics & Third-Party Technologies

Cookies are small files stored on your device that help the Platform recognize your browser and remember preferences.

8.1 Types of Cookies We Use

  • Essential: required for core site functionality, security, and navigation. These cannot be disabled without affecting site operation.
  • Analytics: help us understand traffic and usage patterns. Can be disabled via cookie settings or browser controls.
  • Performance: measure and improve speed and usability. Can be disabled via cookie settings or browser controls.

A detailed and current list of cookies (name, purpose, provider, duration) is available through our cookie consent tool.

8.2 Analytics Providers

We use analytics tools such as Google Analytics, Microsoft Clarity, and similar providers to collect aggregated data about page visits, session duration, navigation patterns, device/browser information, and general geographic location. Where required by law, these tools are used only after obtaining appropriate consent.

8.3 Managing Cookies

You can manage or disable cookies through the cookie banner on our site or through your browser settings. Disabling certain cookies may reduce functionality or prevent some features from working.

9. How We Share Your Information

We do not sell your personal information. We share information only when necessary to provide our services, operate the Platform, or comply with the law:

  • Marketing agencies: when you request introductions or recommendations, we share only the information necessary to facilitate that connection (e.g., brief, contact details). Once an introduction is made, the agency becomes an independent controller for subsequent data processing (see Section 10).
  • Service providers: hosting, cloud infrastructure, analytics, customer support, email delivery, scheduling, payment processors, security monitoring, and similar providers who process data on our behalf under contract.
  • Legal and regulatory authorities: to comply with legal obligations, respond to lawful requests, protect rights, or investigate fraud or illegal activity.
  • Business transactions: in the event of a merger, acquisition, or sale of assets, your information may be transferred. Any successor will be bound to protect your information in accordance with this Policy unless otherwise notified.
  • Aggregated or anonymized data: we may share de-identified, aggregated statistics and trends that do not identify individuals.

10. Agency Partners: Independent Data Practices

When Curato introduces you to a marketing agency, that agency is an independent data controller for information you subsequently share with them. Curato is not responsible for how the agency collects, uses, or protects data after the introduction. We encourage you to review each agency's privacy policy before sharing information.

11. Automated Processing & Agency Recommendations

We may use rules-based logic and platform data (such as stated goals, industry, and budget) to surface relevant agency matches. This automated processing supports human review and does not make legally binding decisions about you. If we begin to perform profiling that results in significant automated decisions, we will update this Policy and provide required notices and rights.

12. International Data Transfers

Curato operates globally and works with service providers across different countries. Your information may be processed or stored outside your country of residence. Where we transfer personal information from the EEA, UK, or Switzerland to countries without an adequacy decision, we rely on recognized safeguards such as Standard Contractual Clauses, the UK International Data Transfer Addendum, or other permitted mechanisms to ensure adequate protections.

13. Data Retention

We retain personal information only as long as necessary for the purposes described and as required by law. Typical retention periods include:

  • Inquiry/contact form submissions: up to 24 months from last contact, unless otherwise required.
  • Agency application materials: during active consideration, plus a limited retention period for records (e.g., up to 24 months) unless you request deletion.
  • Account and platform usage data: while the account is active, and for a limited period after deactivation to meet legal or business requirements.
  • Analytics data: retention as set in the analytics provider's settings; aggregated data may be retained indefinitely.

When information is no longer needed, we delete, anonymize, or otherwise dispose of it securely.

14. Data Security

We implement administrative, technical, and organizational measures to safeguard personal information, including HTTPS encryption, access controls and authentication, secure cloud infrastructure, regular patching, monitoring, backup and recovery, and internal access limits. If we become aware of a breach affecting personal information, we will notify affected individuals and regulators as required by applicable law without undue delay. No system is completely secure; we cannot guarantee absolute security.

15. Your Privacy Rights

Depending on your jurisdiction, you may have rights to:

  • Access personal information we hold about you.
  • Correct inaccurate or incomplete information.
  • Request deletion of personal information (subject to exceptions).
  • Withdraw consent where processing is based on consent.
  • Restrict or object to certain processing.
  • Receive a copy of your information in a portable, commonly used format.

To exercise these rights, contact us using the details in Section 23. We may need to verify your identity before responding.

16. GDPR Rights (EEA, UK & Switzerland)

If you are in the EEA, UK, or Switzerland, you may also lodge a complaint with your local data protection supervisory authority if you believe our processing violates applicable law. Our Data Protection Officer (or EU representative where applicable) can be reached at the contact details in Section 23, if applicable.

17. CCPA/CPRA Rights (California)

If you are a California resident, you have the right to:

  • Know the categories of personal information we have collected, used, disclosed, or sold/shared about you in the preceding 12 months.
  • Request deletion of personal information, subject to certain exceptions.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information — Curato does not sell or share personal information for cross-context behavioral advertising.
  • Limit the use of sensitive personal information — Curato does not intentionally collect sensitive personal information.
  • Not be discriminated against for exercising your privacy rights.

You may exercise these rights yourself or through an authorized agent. To exercise rights, contact us using the details in Section 23.

18. Marketing Communications

We may send service-related and promotional communications such as product updates, newsletters, educational resources, and event invitations. Where required by law, we send marketing communications only with your consent. You can unsubscribe any time using the link in our emails or by contacting us. Even after unsubscribing from marketing, we may still send important service-related messages (e.g., security notices, changes to terms or this Policy, and responses to inquiries).

19. Do Not Track & Global Privacy Control

Some browsers offer a "Do Not Track" (DNT) signal, and some jurisdictions recognize the Global Privacy Control ("GPC") signal. Curato currently does not respond to browser DNT signals. Where legally required, we honor GPC signals as a valid opt-out request to opt out of sale or sharing of personal information.

20. Third-Party Links

Our Platform may link to third-party websites or services. These operate independently of Curato and maintain their own privacy practices. We encourage you to review third parties' privacy policies before interacting with them. Curato is not responsible for the privacy practices, content, or security of third-party sites we do not control.

21. Children's Privacy

Curato is intended for businesses, founders, marketing professionals, and organizations, not for individuals under 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child without appropriate authorization, we will take steps to delete it. If you believe a child has provided information to us, please contact us.

22. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes to our services, technology, legal obligations, or business practices. When we make material changes, we will update the "Last updated" date and, where required, provide additional notice or obtain consent before changes take effect. Continued use of the Platform after changes constitutes acceptance of the revised Policy. Please review this Policy periodically.

23. Contact Us

If you have questions, concerns, or requests relating to this Privacy Policy or how your personal information is handled, contact us:

Curato, Inc.

Website: https://curato.ai

Email: partnerships@curato.ai

Business address: Moodadi House Kottapally, Chemmarathur, Vadakara, Kozhikode - 673104, Kerala

We will make reasonable efforts to respond to legitimate privacy requests within the timeframes required by applicable law. We may ask you to verify your identity before processing your request.

24. Our Privacy Principles

  • We are transparent: you should understand what we collect, why, and how it's used.
  • We collect responsibly: we only collect information necessary to operate, improve, secure the Platform, or deliver requested services.
  • We protect your information: we use industry-standard security practices and continually work to safeguard your data.
  • We respect your choices: when applicable, you can access, update, correct, or request deletion of your personal information.
  • We do not sell your personal information: we share information only where necessary to provide services, operate the Platform, or comply with the law.

Your trust matters. Every decision we make about data privacy is guided by a commitment to transparency, security, and responsible stewardship.

As Curato evolves, we will continue refining our privacy practices to reflect changes in technology, industry standards, and applicable law.