This schedule applies where a studio uses ProcureCore to hold information about its own clients, colleagues or suppliers. It forms part of the ProcureCore Terms of Use and applies to every studio using ProcureCore. No separate signature is required.
In this schedule, “Workspace Content” means the records, files and information a studio enters into or uploads to its ProcureCore workspace. “We” and “us” mean Curated Design Limited.
1. Roles
Curated Design Limited acts as a processor in respect of Workspace Content, and the customer studio acts as the controller of that content.
We act as a controller in respect of account, subscription, support, security and service-operation data. That processing is described in the ProcureCore Privacy Policy and is not governed by this schedule.
Where these two overlap in a single request, we will say which capacity we are acting in.
2. Particulars of processing
Subject matter: provision of the ProcureCore procurement and studio-collaboration service.
Duration: for as long as the studio’s workspace exists, and until deletion completes under section 8.
Nature and purpose: hosting, storage, synchronisation between authorised devices, sharing with authorised workspace members, generation of exports and documents, client sign-off records, and — only where the studio enables it — submission of selected content to the optional AI assistant.
Types of personal data: names and contact details of the studio’s clients, colleagues and supplier contacts; project, placement and procurement records associated with named people; notes and correspondence entered by the studio; attachments uploaded by the studio; client sign-off records, including a signature image where one is drawn.
Categories of data subject: the studio’s clients; the studio’s own personnel and workspace members; contacts at the studio’s suppliers.
Special category data: none is requested or required. The studio must not enter special category data.
3. Instructions
We process Workspace Content only on the studio’s documented instructions, which comprise these terms, the Privacy Policy, and the studio’s use of the features of the service. We do not process Workspace Content for our own purposes.
Where we are required by law to process Workspace Content otherwise, we will inform the studio before doing so unless the law prohibits us from telling them.
If we consider an instruction to infringe data-protection law, we will tell the studio.
4. Confidentiality
Everyone we authorise to access Workspace Content is bound by an obligation of confidentiality, and by the restrictions in the User content and confidentiality section of the Terms.
5. Security
We implement appropriate technical and organisational measures, described in the Annex. The Annex states what exists rather than what is aspirational, and we will update it when the measures change.
6. Sub-processors
The studio authorises the following sub-processors for Workspace Content:
Supabase — authentication, database, file storage and functions holding Workspace Content. Always.
Anthropic — content submitted to the optional AI assistant. Only when the studio uses the AI assistant, and client names and notes only where the studio switches on “Include client & notes”, which is off by default.
Apple and RevenueCat are not sub-processors for Workspace Content. They process account and subscription data, where we are a controller.
We will give at least 30 days’ notice before adding or replacing a sub-processor, and the studio may object on reasonable data-protection grounds; if we cannot resolve the objection, the studio may terminate the affected subscription without penalty for the remainder of its term.
Each sub-processor is engaged under terms requiring protections materially equivalent to this schedule, and we remain liable for their performance. Supabase and Anthropic each publish their own sub-processor lists, and each commits to imposing materially equivalent obligations on the parties they engage.
7. Assistance
Taking into account the nature of the processing and the information available to us, we will:
- assist the studio in responding to requests from data subjects exercising their rights, including by providing the export and deletion tools built into the service;
- notify the studio without undue delay after becoming aware of a personal data breach affecting Workspace Content, with the information we hold at the time and further information as it becomes available;
- assist the studio with data protection impact assessments and prior consultation, to the extent the assessment concerns our processing.
Where a data subject contacts us directly about Workspace Content, we will not respond substantively on the studio’s behalf. We will tell the person that the studio controls the content, refer the matter, and assist the studio in responding.
8. Deletion and return
The studio may export its records using the tools in the service at any time during its subscription.
On deletion of a workspace or account, we delete the corresponding Workspace Content — records and uploaded files — from our systems.
We retain billing and subscription records after deletion because accounting and tax rules require it. Those records identify a workspace by an internal identifier and an opaque billing reference and contain no name or email address. They are controller data, not Workspace Content.
Before we make a change to the database that could affect existing records, we take a copy of it first, so the change can be undone if something goes wrong. That copy contains Workspace Content and is held securely by us, separately from the service. We delete it once the change it protected is confirmed to have worked, and we record the deletion. Because such a copy may exist for a short period, a workspace deleted very shortly before one was taken may still be present in it until it is deleted on that timetable.
There is no automated backup estate. No point-in-time recovery, no automated file backup, and therefore no restore capability. Studios should keep their own records using the export tools.
9. Audit and information
We will make available the information reasonably necessary to demonstrate compliance with this schedule, and will respond to a studio’s reasonable written questions about our processing.
A studio may audit our compliance no more than once in any twelve-month period, on at least 30 days’ notice, during business hours, without unreasonably disrupting the service, and at the studio’s own cost — except where an audit reveals a material breach of this schedule, in which case we bear the reasonable cost.
10. International transfers
Workspace Content is currently hosted in the European Economic Area. We will not host it outside the United Kingdom or the European Economic Area. Our sub-processors may process it, or support it, outside the UK. Where that is a restricted transfer under UK data-protection law, these are the safeguards we rely on:
Supabase (Supabase Pte. Ltd, Singapore) — EU Standard Contractual Clauses, Modules Two and Three, together with the UK Addendum, version B.1.0, incorporated into Supabase’s Data Processing Addendum.
Anthropic (Anthropic Ireland, Limited) — the UK International Data Transfer Addendum, version B.1.0, incorporated into Anthropic’s Data Processing Addendum.
You may request further information about these safeguards by emailing info@curateddesign.studio. Commercially sensitive parts may be redacted.
Annex — technical and organisational measures
Stated as at 2026-08-12. This is a description of what is in place, not a target.
- Encrypted connections (TLS) between the app and the service, and SSL enforced on database connections.
- Account authentication via Supabase, with Sign in with Apple supported.
- Row-level access controls enabled on all application tables.
- Private file storage; uploaded files are not publicly addressable.
- Role-based workspace permissions (owner, admin, member, viewer).
- Operational access restricted to what is necessary for support, security and maintenance.
- Deletion of account and workspace data through a dedicated server-side function, with a post-condition check and an orphaned-file detector.
- No point-in-time recovery and no automated backup. Recovery relies on a manual export taken before destructive changes. This is a known limitation and is recorded as such, rather than presented as a control.
You can also read the ProcureCore Terms of Use and the ProcureCore Privacy Policy, or visit ProcureCore Support.