CURAM IRELAND GOVERNANCE, PRIVACY & COMPLIANCE FRAMEWORK
Effective Date: 04 September 2026
1. Introduction
This Governance, Privacy & Compliance Framework sets out Curam's legal, regulatory and ethical standards in Ireland across:
- Platform operations
- Data protection
- Safeguarding
- AI oversight
- Equality and human rights
- Modern slavery and human trafficking prevention
This document applies to:
- CURAMIOIRELAND LTD (company number 778233), 7/8 Mount Street Upper, Dublin 2, D02 FT59, Ireland
PART A – MASTER PRIVACY POLICY
A.1 Data Controller Position
CURAMIOIRELAND LTD acts as data controller in respect of:
- Platform operations
- Communications
- Monitoring systems
- Safeguarding review
- Payment systems
Carers and clients may act as independent data controllers for records held outside the Curam platform.
A.2 Categories of Data Collected
We may process:
- Identity and contact details
- Payment and invoicing data
- Care documentation and care notes
- Health information
- Garda vetting disclosures (and equivalent overseas background checks, such as UK DBS certificates, where relevant)
- PPS numbers
- Platform activity logs
- Emails (inbound and outbound)
- WhatsApp and SMS messages (where used to communicate with Curam)
- Telephone recordings
- In-platform audio and video recordings
- Safeguarding records
A.3 Monitoring, Recording & AI Systems
Curam uses artificial intelligence, automated monitoring tools and human oversight to support:
- Safeguarding
- Fraud prevention
- Risk detection
- Regulatory compliance
- Quality assurance
- Operational efficiency
- Matching of carers and clients (analysing profiles, care requirements, experience, qualifications, availability and location to suggest suitable matches)
- AI-assisted profile content tools (suggesting improvements to carer profile text, which carers must review and confirm as accurate before publication)
The following may be recorded and analysed:
- All in-platform audio/video calls
- All inbound and outbound telephone calls
- All inbound and outbound emails
- WhatsApp and SMS messages (where used to communicate with Curam)
- Platform messaging
- Care notes
- Activity logs
AI systems may flag potential risks for human review.
AI does not replace human judgment and does not guarantee detection of misconduct.
Where required by law, users will be clearly informed when they are interacting with an AI system.
Users may request human review of significant automated decisions.
AI-generated matches and suggestions assist users' searches only; the decision to engage a carer always remains with the client, and significant decisions about accounts — including carer approval and account removal — always involve review by a member of the Curam team.
A.4 Lawful Bases
Processing relies on:
- Contract
- Legitimate interests
- Legal obligations
- Health and social care provision
- Safeguarding duties
- Vital interests
- Explicit consent (where required)
A.5 Data Sharing
Information may be shared with:
- Other users where necessary
- The HSE, Tusla and other statutory agencies
- An Garda Síochána and other law enforcement
- Approved service providers
- Professional advisers
All processors operate under contractual data protection safeguards.
A.5a Anonymised Data
Curam may anonymise and aggregate certain healthcare data generated by the platform or the Curam apps, applying anonymisation standards consistent with European Data Protection Board and Data Protection Commission guidance so that no individual can be identified or re-identified from the data. Curam may share this anonymised, aggregated data with carefully selected research and development partners for the purposes of improving care outcomes and advancing health and social care research. Any user can opt out of anonymised data sharing at any time via their account settings (where available) or by emailing client@curamcare.ie. Once data has been anonymised it is no longer personal data and may be retained indefinitely.
A.6 Retention
Indicative retention periods:
- Financial records: 7 years
- Account data: 6 years after closure
- Call recordings (telephone and in-platform audio/video): up to 30 days, after which they are deleted unless retention is required for an active safeguarding investigation, complaint, insurance claim or legal obligation
- Identity documentation: retained per legal requirement
- Safeguarding records: retained according to regulatory necessity
Anonymised data may be retained indefinitely.
A.7 Your Rights
You have rights under the EU General Data Protection Regulation including:
- Access
- Rectification
- Erasure
- Restriction
- Objection
- Data portability
- Rights relating to automated decision-making
Complaints may be made to the Data Protection Commission (www.dataprotection.ie).
Contact: client@curamcare.ie
PART B – CARER PRIVACY NOTICE
Applies to carers using the Curam platform.
Curam processes carer data to:
- Verify eligibility
- Maintain profiles
- Facilitate bookings
- Process payments
- Monitor safeguarding
- Prevent fraud
- Ensure compliance
Carer communications may be recorded and analysed using AI-assisted tools with human oversight.
Self-employed carers remain independent data controllers for any care records maintained outside the Curam platform.
PART C – CLIENT PRIVACY NOTICE
Applies to clients and care recipients.
Curam processes client data to:
- Provide platform access
- Match carers
- Facilitate payments
- Maintain safeguarding
- Comply with legal duties
Health information is processed under health and safeguarding lawful bases.
Where the care notes feature is used, care notes and any attached photographs are created by the carer at the client's request (with the care recipient's permission where they are a different person). Clients may grant friends and family members access to care notes via the Curam client app; access should only be granted to people the client and care recipient are content to see this information. The Curam team has oversight of care notes for safeguarding and quality purposes. Care notes are not shared with other third parties except as set out in this Framework (for example with law enforcement in exceptional cases).
Care notes are distinct from care plans. A care plan is a document which a carer may prepare for their client as good practice, whether to do so is a matter for the carer and their client.
PART D – SAFEGUARDING POLICY
Curam operates with regard to:
- The HSE's national safeguarding policies for adults at risk of abuse
- The Assisted Decision-Making (Capacity) Act 2015
- Children First Act 2015 (where relevant)
AI-assisted systems support safeguarding review.
All safeguarding concerns must be reported immediately.
Emergency: 112 or 999
An Garda Síochána (non-emergency): contact your local Garda station
HSE Safeguarding and Protection Teams: www.hse.ie/safeguarding
Tusla (children): www.tusla.ie
Senior Safeguarding Lead: Gemma Stokes
Deputy Safeguarding Lead: Jessica Huntley
PART E – MODERN SLAVERY & HUMAN TRAFFICKING
Curam operates a zero-tolerance approach to modern slavery and human trafficking.
Risk areas include:
- Recruitment
- Supply chain
- International contractors
Mitigation measures:
- Right-to-work checks
- Ethical recruitment
- Supplier due diligence
- Training
- Whistleblowing protections
This statement reflects the Curam group's zero-tolerance approach, issued at group level under the (UK) Modern Slavery Act 2015 and applied in Ireland having regard to the Criminal Law (Human Trafficking) Acts 2008 and 2013.
PART F – EQUALITY, DIVERSITY & INCLUSION
Curam operates in accordance with the Employment Equality Acts 1998–2015 and the Equal Status Acts 2000–2018.
We prohibit discrimination on the grounds of gender, civil status, family status, sexual orientation, religion, age, disability, race or membership of the Traveller community.
Harassment, victimisation or discriminatory behaviour may result in disciplinary action or removal from the platform.
PART G – AI ETHICS & OVERSIGHT
Curam uses AI responsibly and proportionately.
AI systems:
- Support safeguarding
- Support fraud detection
- Support compliance
- Operate with human oversight
- Are reviewed periodically
Curam complies with applicable transparency obligations under the EU Artificial Intelligence Act.
Curam remains accountable for all operational decisions.
Approval
This Governance, Privacy & Compliance Framework is approved by the Board of Directors of CURAMIOIRELAND LTD.
Signed:
Patrick Wallace
Director
CURAMIOIRELAND LTD
Date: 04 September 2026