NewCura is committed to protecting privacy and supporting our healthcare partners’ compliance with the General Data Protection Regulation (GDPR) across the European Union and the United Kingdom.
Our technology is designed using a privacy‑first, non‑persistent data model that minimizes risk, simplifies compliance, and ensures patient data remains under the control of the healthcare organization at all times.
Our GDPR Role
Under GDPR (Regulation (EU) 2016/679), NewCura acts solely as a Data Processor.
• Our customers (healthcare organizations) act as Data Controllers
• We process personal data only on documented instructions from the controller
• We do not determine the purpose or means of processing
No Data Storage or Retention
NewCura does not store, host, retain, or back up personal or patient data.
All personal data:
• Remains entirely within the healthcare organization’s systems
• Is governed by the healthcare organization’s retention and deletion policies
• Is never copied, archived, or persisted by NewCura
This architecture significantly reduces data protection risk and supports GDPR principles of data minimization and storage limitation.
How We Process Data
Any access to personal data by NewCura is:
• Strictly limited to what is necessary to provide contracted services
• Performed only under customer instruction
• Used for no independent purpose such as analytics, marketing, profiling, or AI training
NewCura does not use customer data to train models, create benchmarks, or develop secondary products.
Security Measures
NewCura implements appropriate technical and organizational measures to protect personal data during authorized access, including:
• Encryption of data in transit
• Role‑based access controls
• Strong authentication
• Secure endpoint protection
• Operational and security logging (excluding personal data content)
These controls are designed to protect confidentiality, integrity, and availability in accordance with Article 32 GDPR.
Data Subject Rights
Under GDPR, individuals have rights including access, correction, deletion, restriction, and objection.
As a data processor, NewCura:
• Does not respond directly to data subject requests
• Forwards any requests received to the healthcare organization without delay
• Provides reasonable technical assistance when requested by the controller
All data subject rights are managed by the healthcare organization as Data Controller.
Personal Data Breaches
In the event of a suspected or confirmed personal data breach involving access under our control, NewCura will:
• Notify the healthcare organization without undue delay
• Provide relevant information to support the controller’s assessment and regulatory obligations
Regulatory and individual notifications are the responsibility of the Data Controller.
Sub‑Processors
NewCura does not engage sub‑processors that access or process personal data without prior authorization from the healthcare organization.
Any approved sub‑processors are contractually bound to data protection obligations consistent with Article 28 GDPR.
International Data Transfers
NewCura does not transfer personal data outside the European Union or United Kingdom.
Because all data remains within the healthcare organization’s environment, no cross‑border data transfers are performed by NewCura.
GDPR Documentation
Healthcare partners may request the following GDPR documentation:
• EU‑Wide GDPR Processor Statement
• Article 28 Data Processing Agreement (DPA)
• GDPR Compliance Pack (Statement, DPA summary, and FAQ)
These materials are available upon request.
Contact
For GDPR or privacy‑related inquiries, please contact:
Email: privacy@newcura.com
Plain‑English Summary
NewCura does not store your data.
Your data stays in your environment.
You remain in control at all times.
This privacy‑first approach helps healthcare organizations reduce risk, accelerate procurement, and confidently meet GDPR obligations across the EU.