Currity

Privacy

Last updated September 21, 2026

What we hold

Two kinds of thing. Account data is the email address and name of whoever signs in, handled by our authentication provider. Crew data is the names, roles, sites and certification dates you enter, plus any documents you upload.

Crew data is about your employees, not our users. You are the controller of it; we process it on your behalf.

What we do with it

Run the product: show you the board, work out what is expiring, and send the warning emails you asked for. That is the whole list.

We do not sell it, share it with other customers, or use it to train anything.

Keeping it separate

Every customer’s records are isolated at the database level, enforced by the database itself rather than by application code remembering to filter. A query that forgets its filter returns nothing rather than another company’s crew.

Who else touches it

The companies that run our infrastructure: hosting, the database, authentication, and the service that delivers email. Each sees only what it needs to do its job.

How long we keep it

For as long as your account is open. Delete a person and their record goes; close the account and we remove your data within 30 days, after giving you a chance to export it.

Backups are kept for a short window and then rotate out. A record deleted from the live database may persist in a backup until that window passes.

Your rights

Ask us for a copy of what we hold, a correction, or deletion, and we will do it. Email is the fastest route. There is no form to fill in.

Questions about any of this: hello@currity.com