RoadTrip
Join a Trip

Legal

Curia Privacy Policy

Last updated: 27 June 2026

Curia operates business-to-business services connecting consumer brands, retailers, wholesalers, distributors, buyers and other industry participants. Our services include Curia, RoadTrip and other products, events, websites, digital platforms and services operated by companies within the Curia group.

This Privacy Policy explains how we collect, use, disclose and protect personal information.

1. About this Privacy Policy

This Privacy Policy applies to personal information relating to:

• customers and prospective customers

• brand and supplier contacts

• retail buyers and other retailer employees

• distributors, wholesalers and commercial partners

• event participants

• website and platform users

• partners, consultants and service providers

• people who contact us

• people whose professional contact information we obtain from business, public or third-party sources

• other business contacts

Our services are intended for business users and are not directed at children.

2. Who is responsible for your information?

The Curia company responsible for your personal information will normally be the Curia group company with which you interact or which provides the relevant service. This may include:

United Kingdom: CURIA Experiences (UK) Ltd, registered in Scotland, company number 892904. Registered address: 60 Tradeston Street, Glasgow, G5 8BH.

Where appropriate, Curia group companies may act as joint controllers or equivalent joint organisations responsible for personal information.

For privacy enquiries, please contact: hello@curia.co, or write to 60 Tradeston Street, Glasgow, G5 8BH.

3. Personal information we collect

The information we collect depends on how you interact with us. It may include:

Identity information:

• name

• job title

• employer

• professional role

• username or account identifier

Business contact information:

• business email address

• business telephone number

• company address

• LinkedIn profile

• other professional contact details

Company information linked to you:

• employer or business

• industry

• product categories

• geographic markets

• company size

• retailer, brand, supplier or partner type

Commercial information, where relevant to our relationship with you:

• bookings

• products and services purchased

• pricing

• payment status

• invoicing details

• event participation

• product categories

• buying responsibilities

• retailer interests

• commercial preferences

• past interactions with us

Product and brand information, for brand and supplier users:

• brand name

• product information

• product images

• pricing information

• distribution information

• product specifications

• samples submitted for events

• buyer-facing marketing information

Much of this information relates to companies rather than individuals and is therefore not personal information. However, it may become personal information where it is associated with an identifiable individual.

Buyer preferences, for retail buyers and similar users:

• categories you buy

• markets or territories you cover

• types of brands or products you are interested in

• buying preferences

• saved searches

• products viewed

• event participation

• engagement with brand or product opportunities

Communications. We may retain:

• emails

• enquiries

• meeting notes

• customer service communications

• survey responses

• feedback

• records of telephone or video conversations where appropriate

Website and technology information. When you use our websites or digital services we may collect:

• IP address

• browser type

• device information

• approximate location derived from IP address

• website usage

• pages viewed

• referral source

• links clicked

• session information

• cookie and similar technology identifiers

Marketing information. We may record:

• marketing preferences

• emails sent

• email opens or interactions where permitted

• links clicked

• event interests

• responses to campaigns

• unsubscribe requests

4. How we obtain information

We may collect personal information:

Directly from you, for example when you:

• register for a service

• book an Event

• complete a form

• create an account

• provide product information

• attend an Event

• communicate with us

• join a mailing list

• participate in a survey

• request information

From your organisation. Your employer or colleagues may provide information about you where relevant to our business relationship.

From retailers, brands and commercial partners. For example, a retailer may identify relevant category Buyers participating in a RoadTrip Event.

From publicly available professional sources, such as:

• company websites

• retailer websites

• professional directories

• trade associations

• conference or trade-event information

• press releases

• LinkedIn and similar professional networks

• other publicly available business sources

From commercial business-information providers. We may use reputable business-data providers to identify relevant professional contacts, organisations or business information.

From our existing business records, where we have previously interacted with you or your organisation.

Automatically. Certain information may be collected through cookies, analytics tools and similar technology when you interact with our websites, emails or digital platforms.

5. How we use personal information

We may use personal information to:

Provide our services, including to:

• manage bookings

• operate RoadTrip and other Events

• provide digital platforms

• manage customer accounts

• present brands and products to relevant Buyers

• facilitate commercial introductions

• provide event information

• provide customer support

Match brands, products and buyers. Our services are designed around relevance. We may use information about professional roles, categories, interests and previous engagement to help identify:

• products likely to be relevant to particular Buyers

• Retailers appropriate for particular brands

• Events relevant to brands or Buyers

• potential commercial relationships

Manage customer and retailer relationships, including:

• account management

• event planning

• communications

• invoicing

• feedback

• relationship management

Develop and improve our services. We may analyse activity to understand:

• which services are useful

• which products receive engagement

• how Events perform

• which categories are of interest

• how our websites and platforms are used

• how we can improve our products

Communicate with professional contacts. We may contact relevant business professionals about:

• Events

• retailer opportunities

• brand opportunities

• new services

• industry information

• commercial opportunities

• products or services we believe may be professionally relevant

We conduct such communications in accordance with applicable privacy and electronic-marketing laws.

Protect our business. We may process information to:

• prevent fraud

• maintain platform security

• enforce agreements

• protect our legal rights

• investigate misuse

• comply with legal requirements

Corporate administration, including:

• accounting

• taxation

• auditing

• insurance

• business planning

• corporate transactions

6. Our legal bases for using personal information

Where UK GDPR, EU GDPR or another law requiring a lawful basis applies, we rely on one or more of the following.

Contract. We process information where necessary to:

• enter into a contract

• provide contracted services

• administer a booking

• fulfil our obligations to a customer

Legitimate interests. We may process personal information where necessary for legitimate business interests and where those interests are not overridden by the rights and interests of the individual. These interests may include:

• operating a B2B brand and retailer network

• identifying relevant commercial contacts

• communicating relevant B2B opportunities

• organising Events

• facilitating introductions

• developing our business

• improving our services

• maintaining business relationships

• securing our systems

• preventing fraud

Where appropriate, we assess the necessity and proportionality of this processing.

Consent. We may rely on consent where required by law or where we choose to do so. Where processing is based on consent, you may withdraw that consent at any time.

Legal obligation. We may process personal information where required to comply with legal, taxation, regulatory or other obligations.

7. B2B marketing and professional outreach

As a B2B business, we may identify and contact people whose professional roles appear relevant to our services. This may include:

• retail buyers

• category managers

• procurement professionals

• brand founders

• sales directors

• export managers

• commercial directors

• distributors

• wholesalers

• brokers

• consultants

• other relevant business professionals

We may obtain professional contact details directly, through referrals, from publicly available sources or from reputable business-information providers.

We will only conduct direct marketing where permitted under the laws applicable to the recipient and the communication method used. Where required, we will obtain consent. Where applicable law permits B2B marketing on another legal basis, we may rely on that basis.

Marketing communications will identify us and provide a reasonable means of opting out. You can ask us to stop sending you marketing communications at any time.

You have an absolute right to object to the use of your personal information for direct marketing where UK or EU data-protection law applies. You can exercise this right by:

• using an unsubscribe link

• replying to an email requesting removal

• contacting hello@curia.co

We maintain suppression records where necessary to ensure that people who opt out are not inadvertently re-added to marketing campaigns.

8. Retail buyer information

Our services depend on connecting relevant brands with relevant professional Buyers.

Where you are a retail Buyer, we may process information concerning:

• your employer

• job title

• category responsibility

• geographic responsibility

• professional interests

• Event participation

• products or categories you have expressed interest in

We may use this information to improve the relevance of brands, products, Events and other opportunities presented to you.

We do not intend to disclose a Buyer’s personal contact information to brands for unrelated marketing purposes simply because the Buyer participated in an Event.

Where Buyer contact information is shared with a brand following genuine commercial engagement, it should only be used for appropriate business follow-up and in accordance with applicable law.

9. Who we share information with

We may share personal information with the following categories of recipient where reasonably necessary.

Companies within the Curia group, for:

• customer management

• Event delivery

• administration

• technology

• analytics

• finance

• marketing

• group management

Retailers and Buyers. Information about participating brands and their representatives may be shared with Retailers and Buyers as part of our services.

Brands and suppliers. Where appropriate, relevant Buyer or retailer information may be shared with brands or suppliers to facilitate legitimate commercial follow-up.

Service providers. We may use third parties for:

• website hosting

• cloud hosting

• CRM systems

• email

• marketing automation

• event management

• analytics

• payment processing

• accounting

• communications

• logistics

• IT support

• professional services

These organisations may process personal information on our behalf.

Professional advisers, including lawyers, accountants, auditors, insurers, tax advisers and financial advisers.

Authorities. We may disclose information where required by law, regulation, court order, law enforcement, tax authorities or regulatory bodies.

Corporate transactions. Information may be disclosed in connection with investment, financing, merger, acquisition, restructuring or the sale of a business or assets. Where appropriate, recipients will be subject to confidentiality obligations.

10. International transfers

Curia may operate internationally and our customers, Retailers, service providers and group companies may be located in different countries. As a result, personal information may be processed outside the country in which it was collected.

Where laws such as the UK GDPR or EU GDPR require safeguards for international transfers, we will use an appropriate lawful mechanism. This may include:

• an adequacy decision or regulation

• approved standard contractual clauses

• the UK International Data Transfer Agreement or UK Addendum

• another legally recognised safeguard

You may contact us for further information about safeguards relevant to your personal information.

11. Data retention

We keep personal information only for as long as reasonably necessary for the purposes for which it was collected and to satisfy legal, accounting and business requirements. Factors we consider include:

• the nature of our relationship

• whether an account remains active

• whether a professional contact remains relevant

• legal limitation periods

• taxation and accounting requirements

• contractual obligations

• potential disputes

• whether an individual has objected to marketing

Examples may include:

Customer and booking records: generally retained for up to seven years after the relevant financial year or relationship, subject to applicable legal requirements.

Marketing contacts: retained while the professional relationship or potential relevance remains current, with periodic review.

Marketing suppression records: may be retained for longer where necessary to honour an opt-out.

Event records: retained for as long as reasonably necessary for operational, relationship-management and legal purposes.

Website analytics: retained according to the settings of the relevant analytics service and our cookie practices.

Information that is no longer required will be deleted, anonymised or otherwise securely removed where appropriate.

12. Data security

We use reasonable technical and organisational safeguards designed to protect personal information. These may include:

• access controls

• account authentication

• secure cloud systems

• staff access restrictions

• security monitoring

• backups

• contractual controls with providers

• staff awareness and procedures

No electronic system can be guaranteed completely secure, but we take reasonable measures appropriate to the nature of the information we process.

13. Cookies and similar technologies

Our websites and digital services may use cookies and similar technologies. These may be used for:

• essential website functionality

• user preferences

• security

• analytics

• service improvement

• marketing attribution

• advertising where applicable

Where applicable law requires consent for non-essential cookies or similar technology, we will provide an appropriate consent mechanism.

More information may be provided through our Cookie Policy or cookie-preference tool.

14. Automated matching and AI

We may use automated tools, algorithms or artificial intelligence to improve the relevance of our services. For example, these tools may help:

• recommend Events

• match brands with retailers

• recommend products to Buyers

• categorise companies or products

• rank search results

• personalise content

Unless expressly stated otherwise, we do not use automated systems to make decisions that produce legal or similarly significant effects on individuals without appropriate human involvement.

15. Your rights — United Kingdom and European Economic Area

Where UK GDPR or EU GDPR applies, you may have rights including:

• access to your personal information

• correction of inaccurate information

• deletion in certain circumstances

• restriction of processing

• portability in certain circumstances

• objection to certain processing

• withdrawal of consent where consent is relied upon

You also have the right to object to direct marketing. Some rights depend on the circumstances and legal basis for processing.

To exercise your rights, contact hello@curia.co.

You may also complain to the relevant supervisory authority. In the United Kingdom this is the Information Commissioner’s Office.

16. Canada

Where Canadian privacy law applies, including the Personal Information Protection and Electronic Documents Act or applicable provincial privacy legislation, you may have rights concerning access to and correction of personal information and may challenge our compliance with applicable privacy requirements.

We will collect, use and disclose personal information in accordance with applicable Canadian privacy requirements.

Commercial electronic communications to Canadian recipients will also be handled in accordance with applicable Canadian anti-spam requirements.

Questions or complaints can be submitted to hello@curia.co.

17. United States privacy rights

Residents of certain US states may have additional rights under applicable state privacy legislation. Depending on the law and whether it applies to us, these rights may include:

• confirming whether we process your personal information

• accessing personal information

• correcting inaccurate information

• requesting deletion

• obtaining a portable copy of certain information

• opting out of certain sales, sharing, targeted advertising or profiling

• appealing certain privacy decisions

• receiving equal service when exercising privacy rights

We will honour applicable privacy rights where required by law. Requests may be submitted to hello@curia.co.

18. California privacy information

This section applies where the California Consumer Privacy Act, as amended, applies to our processing. California residents may have rights including:

• the right to know the categories and specific pieces of personal information collected

• the right to know the sources and purposes for which information is used

• the right to know categories of third parties to whom information is disclosed

• the right to delete certain information

• the right to correct inaccurate information

• the right to opt out of sale or sharing where applicable

• the right to limit certain uses of sensitive personal information where applicable

• the right not to receive discriminatory treatment for exercising applicable privacy rights

Curia’s core business model does not involve selling personal information for monetary consideration.

Some digital advertising or analytics arrangements may potentially be classified as “sharing” or “sale” under certain US privacy laws even where no money is exchanged. If we engage in activity that triggers an opt-out requirement, we will provide the legally required mechanism and honour recognised opt-out preference signals where required.

19. Information about other people

If you provide us with personal information about another person, you should ensure that you are permitted to provide it to us.

Where appropriate, you should make that person aware that their information may be provided to Curia and direct them to this Privacy Policy.

20. Links to third-party websites

Our websites or communications may contain links to websites operated by third parties. We are not responsible for the privacy practices of independent third-party websites. You should review their privacy information separately.

21. Changes to this Privacy Policy

We may update this Privacy Policy to reflect:

• changes to our services

• new products

• changes to our business

• legal developments

• changes in technology or data practices

The current version will be published on our website with its effective date. Where a change materially affects how we use personal information, we will take reasonable steps to bring the change to the attention of affected individuals where required.

22. Contact us

For privacy enquiries, requests or complaints, contact Curia Privacy:

Email: hello@curia.co

Address: 60 Tradeston Street, Glasgow, G5 8BH

Please include sufficient information for us to understand and respond to your request. We may need to verify your identity before responding to certain privacy-rights requests.

23. Supervisory and regulatory authorities

Depending on where you are located, you may have the right to contact your local privacy regulator. Relevant regulators may include:

United Kingdom: Information Commissioner’s Office.

Canada: Office of the Privacy Commissioner of Canada or the relevant provincial privacy authority.

United States: the relevant state privacy regulator or Attorney General where applicable.

Nothing in this Privacy Policy limits any rights you have under applicable privacy law.

Questions about these pages? Contact us at

hello@theroadtrip.co