Policy summary
Personal Data processed for the following purposes and using the following services:
- Advertising
- LinkedIn Ads
Personal Data: Trackers; Usage Data
- LinkedIn conversion tracking (LinkedIn Insight Tag)
Personal Data: device information; Trackers; Usage Data
- Outbrain
Personal Data: Trackers; various types of Data as specified in the privacy policy of the service
- Analytics
- Google Analytics 4
Personal Data: number of Users; session statistics; Trackers; Usage Data
- Building and running this Website
- WordPress (self-hosted)
Personal Data: email address; first name; last name
- Contacting the User
- Contact form
Personal Data: email address; first name; last name; Usage Data
- Displaying content from external platforms
- Google Fonts
Personal Data: Trackers; Usage Data
- Spam and bots protection
- Google reCAPTCHA
Personal Data: answers to questions; clicks; scroll position; Trackers; Usage Data
- Traffic optimisation and distribution
- Cloudflare
Personal Data: Trackers; various types of Data as specified in the privacy policy of the service
Information on opting out of interest-based advertising
Users may learn more on how to generally opt out of interest-based advertising within the dedicated section of the Cookie Policy.
Contact information
- ControllerData Controller
Curaleaf International Pharma Sagl
Via Trevani, 1, 6600 – Locarno, Svizzera
Controller contact email: pharma@curaleafint.com
Controller’s Data Protection Officer contact: data.protection@curaleafint.com
Full policy
Data Controller
Curaleaf International Pharma Sagl
Via Trevani, 1, 6600 – Locarno, Svizzera
Controller contact email: pharma@curaleafint.com
Controller’s Data Protection Officer contact: data.protection@curaleafint.com
Types of Data collected
This Website collects, by itself or through third parties: Trackers; Usage Data; number of Users; session statistics; answers to questions; clicks; scroll position; first name; last name; email address; device information; session duration; scroll-to-page interactions; country; time zone; interaction events; diagnostic events; page events; custom events.
Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the Data collection.
Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using this Website.
All Data requested by this Website is not mandatory, but failure to provide this Data may make it impossible for this Website to provide its services. Any use of Cookies – or of other tracking tools — by this Website or by the owners of third-party services used by this Website serves the purpose of providing the Service required by the User, in addition to any other purposes described in the present document and in the Cookie Policy.
Mode and place of processing the Data
Methods of processing
The Controller takes appropriate security measures to prevent unauthorised access, disclosure, modification, or unauthorised destruction of the Data.
The Data processing is carried out using computers and/or IT enabled tools, following organisational procedures and modes strictly related to the purposes indicated. In addition to the Controller, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Website (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Controller. The updated list of these parties may be requested from the Controller at any time.
Place
The Data is processed at the Controller’s operating offices and in any other places where the parties involved in the processing are located.
Depending on the User’s location, data transfers may involve transferring the User’s Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the processing of Personal Data.
Retention time
Personal Data shall be processed and stored for as long as required by the purpose they have been collected for.
The purposes of processing
The Data concerning the User is collected only to the extent necessary, relevant and adequate for the purposes for which it is processed, to allow the Controller to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following: Traffic optimisation and distribution, Analytics, Displaying content from external platforms, Spam and bots protection, Advertising, Contacting the User, Building and running this Website.
For specific information about the Personal Data used for each purpose, the User may refer to the section “Detailed information on the processing of Personal Data”.
Detailed information on the processing of Personal Data
Personal Data is collected for the following purposes and using the following services:
- Advertising
This type of service allows User Data to be utilised for advertising communication purposes. These communications are displayed in the form of banners and other advertisements on this Website, possibly based on User interests.
This does not mean that all Personal Data are used for this purpose. Information and conditions of use are shown below.
Some of the services listed below may use Trackers to identify Users or they may use the behavioural retargeting technique, i.e. displaying ads tailored to the User’s interests and behaviour, including those detected outside this Website.
For more information, please check the privacy policies of the relevant services.
LinkedIn Ads (LinkedIn Corporation)
LinkedIn Ads is an advertising service provided by LinkedIn Corporation.
Personal Data processed: Trackers; Usage Data.
Place of processing: United States – Privacy Policy.
LinkedIn conversion tracking (LinkedIn Insight Tag) (LinkedIn Corporation)
LinkedIn conversion tracking (LinkedIn Insight Tag) is an analytics and behavioural targeting service provided by LinkedIn Corporation that connects data from the LinkedIn advertising network with actions performed on this Website. The LinkedIn Insight Tag tracks conversions that can be attributed to LinkedIn ads and enables to target groups of Users on the base of their past use of this Website.
Personal Data processed: device information; Trackers; Usage Data.
Place of processing: United States – Privacy Policy.
Outbrain (Outbrain UK)
Outbrain is an advertising service provided by Outbrain UK.
Personal Data processed: Trackers; various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy.
- Analytics
The services contained in this section enable the Controller to monitor and analyse web traffic and can be used to keep track of User behaviour.
Google Analytics 4 (Google LLC)
Google Analytics 4 is a web analysis service provided by Google LLC or by Google Ireland Limited, depending on how the Controller manages the Data processing, (“Google”). Google utilizes the Data collected to track and examine the use of this Website, to prepare reports on its activities and share them with other Google services. Google may use the Data collected to contextualize and personalize the ads of its own advertising network. In Google Analytics 4, IP addresses are used at collection time and then discarded before Data is logged in any data center or server. Users can learn more by consulting Google’s official documentation.
In order to understand Google’s use of Data, consult their partner policy and their Business Data page.
Personal Data processed: number of Users; session statistics; Trackers; Usage Data.
Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.
Monday.com
Monday.com CRM is used by the Controller to manage relationships with Healthcare Professionals (HCPs) by centralizing contact information, tracking interactions, and coordinating communication activities. The system serves as a secure, cloud-based platform for collecting and processing HCP key parameters necessary for professional relationship management and service delivery.
Categories of Personal Data Processed: professional identification data (name, workplace, position), contact details (email address, phone number, professional address), interaction history (communication logs, meeting notes, follow-up activities), behavioral data (engagement patterns, preferences for communication methods). Please note that certain training-related information from LearnDash LMS Plugin (e.g., enrolment, progress, completion) may be passed into Monday.com to support CRM workflows.
Monday.com implements industry-standard security measures including data encryption in transit and at rest, secure data storage, access controls, and regular security audits. The platform is GDPR compliant and provides data subjects with rights to access, deletion, and data portability as required by European data protection law. The system also adheres to CCPA requirements for California residents.
- Building and running this Website
Key components of this Website are built and run directly by the Controller by making use of the software listed below.
WordPress (self-hosted) (this Website)
This Website is built and run by the Controller via a CMS software (Content Management System) called WordPress.
Personal Data processed: email address; first name; last name.
LearnDash LMS Plugin
LearnDash LMS is a WordPress plugin used to create, manage, and deliver online courses to learners. The plugin processes personal data to track course progress, assess learning outcomes, manage enrollments, and facilitate communication between course administrators and learners.
Categories of Personal Data Processed: user ID and account details (to associate progress with a specific learner), course enrolments, course progress and completion status, assessment and quiz responses, time spent or video progress. Please note that certain training-related information from LearnDash LMS Plugin (e.g., enrolment, progress, completion) may be passed into Monday.com to support CRM workflows.
LearnDash is fully GDPR compliant and hooks into WordPress’s built-in privacy tools. The plugin supports data subject rights through WordPress’s native export and erase personal data functionality (found under the TOOLS menu). Importantly, the LearnDash LMS plugin itself does not collect, store, or process data beyond what is necessary for course delivery and management on the self-hosted WordPress installation.
- Contacting the User
Contact form
By filling in the contact form with their Data, the User authorises this Website to use these details to reply to requests for information, quotes or any other kind of request as indicated by the form’s header.
Personal Data processed: email address; first name; last name; Usage Data.
- Displaying content from external platforms
This type of service allows you to view content hosted on external platforms directly from the pages of this Website and interact with them. Such services are often referred to as widgets, which are small elements placed on a website or app. They provide specific information or perform a particular function and often allow for user interaction.
This type of service might still collect web traffic data for the pages where the service is installed, even when Users do not use it.
Google Fonts (Google LLC)
Google Fonts is a typeface visualisation service provided by Google LLC or by Google Ireland Limited, depending on how the Controller manages the Data processing, that allows this Website to incorporate content of this kind on its pages.
Personal Data processed: Trackers; Usage Data.
Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.
- Spam and bots protection
This type of service analyses the traffic of this Website, potentially containing Users’ Personal Data, with the purpose of filtering it from unwanted parts of traffic, messages and content that are recognised as spam or protecting it from malicious bots activities.
Google reCAPTCHA (Google LLC)
Google reCAPTCHA is a SPAM protection service provided by Google LLC or by Google Ireland Limited, depending on how the Controller manages the Data processing. The use of reCAPTCHA is subject to the Google privacy policy and terms of use.
In order to understand Google’s use of Data, consult their partner policy and their Business Data page.
Personal Data processed: answers to questions; clicks; scroll position; Trackers; Usage Data.
Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.
- Traffic optimisation and distribution
This type of service allows this Website to distribute their content using servers located across different countries and to optimise their performance.
Which Personal Data are processed depends on the characteristics and the way these services are implemented. Their function is to filter communications between this Website and the User’s browser.
Considering the widespread distribution of this system, it is difficult to determine the locations to which the contents that may contain Personal Information of the User are transferred.
Cloudflare (Cloudflare, Inc.)
Cloudflare is a traffic optimisation and distribution service provided by Cloudflare Inc. The way Cloudflare is integrated means that it filters all the traffic through this Website, i.e., communication between this Website and the User’s browser, while also allowing analytical data from this Website to be collected.
Personal Data processed: Trackers; various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy.
Cookie Policy
This Website uses Trackers. To learn more, Users may consult the Cookie Policy.
Further Information for Users in the European Union
This section applies to all Users in the European Union, according to the General Data Protection Regulation (the “GDPR”), and, for such Users, supersedes any other possibly divergent or conflicting information contained in the privacy policy. Further details regarding the categories of Data processed, the purposes of processing, the categories of recipients of the Personal Data, if any, and further information about Personal Data can be found in the section titled “Detailed information on the processing of Personal Data” within this document.
Legal basis of processing
The Controller may process Personal Data relating to Users if one of the following applies:
- Users have given their consent for one or more specific purposes.
- provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
- processing is necessary for compliance with a legal obligation to which the Controller is subject;
- processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Controller;
- processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party.
For example, the Controller relies on contract necessity where processing is required to provide requested services or take steps prior to entering into a contract; on legitimate interests where processing is required to operate, secure, and improve the Website and related services; on consent where processing is based on optional features, cookies, or marketing activities; and on legal obligations where processing is required to comply with applicable law.
Further information about retention time
Personal Data shall be processed and stored for as long as required by the purpose they have been collected for.
Therefore:
- Personal Data collected for purposes related to the performance of a contract between the Controller and the User shall be retained until such contract has been fully performed.
- Personal Data collected for the purposes of the Controller’s legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by the Controller within the relevant sections of this document or by contacting the Controller.
The Controller may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Controller may be obliged to retain Personal Data for a longer period whenever required to fulfil a legal obligation or upon order of an authority. If you are a customer or supplier, we will retain your personal data while our relationship is active and for a period of up to six years after it ends.
Once the retention period expires, Personal Data shall be deleted.
Who we share your personal data with
We may share your personal data with trusted third parties and internal stakeholders, but only where necessary and lawful. The categories of recipients include the following:
- Affiliated Companies within the Curaleaf Group
We may share your personal data with other entities within the Curaleaf corporate group. This may occur for internal administrative purposes, regulatory compliance, business continuity, or group-level marketing activities, where legally permitted. These transfers are governed by intragroup agreements that ensure appropriate safeguards and alignment with applicable data protection laws.
- Service Providers and Processors
We engage third-party service providers to support our operations and deliver services on our behalf. These may include payment processors, IT support providers, customer service platforms, delivery partners, event organisers, cloud hosting providers, and marketing agencies. These third parties act as data processors under our instructions and are contractually required to process your personal data only for specified purposes and with appropriate security measures in place.
- Public Authorities and Legal Disclosures
Where required by law, we may disclose your personal data to public authorities, law enforcement bodies, courts, regulatory agencies, or other government institutions. This may occur to comply with legal obligations, support investigations, satisfy public health requirements, or respond to binding requests.
We may also disclose your data to legal counsel or external advisers when necessary to establish, exercise, or defend legal claims, resolve disputes, enforce our terms and conditions, or protect the rights and safety of our users or staff.
- Business Transfers
If Curaleaf undergoes a reorganisation, acquisition, merger, or sale of assets, your personal data may be transferred to the acquiring entity or involved third parties as part of the transaction. In such cases, we will ensure that any transfer complies with applicable data protection laws and that appropriate confidentiality obligations are upheld.
- Exclusion for Messaging Data
Any data collected in connection with messaging opt-in (such as SMS subscriptions) will not be shared with third parties, unless required to fulfil the messaging service. Consent-related information for messaging purposes will be kept confidential and used strictly in accordance with your preferences.
How We Protect Your Data
We implement appropriate technical and organisational measures to safeguard your personal data and protect it against accidental loss, unlawful access, destruction, alteration, or unauthorised disclosure.
The data we collect is stored on secure IT systems operated either by Controller or verified third-party service providers who are contractually required to maintain appropriate levels of security and confidentiality. These systems may include access control tools, encryption at rest and in transit, multi-factor authentication, regular security patching, and monitored server environments.
Although we take reasonable steps to protect your information once we receive it, please be aware that transmission over the internet, including email, cannot be guaranteed to be completely secure. We therefore advise that you avoid sending sensitive or confidential data via unencrypted email unless necessary.
Once your data is received, we apply strict access controls and internal security policies to prevent unauthorised access and to ensure that only authorised personnel with a legitimate business need can process your data.
We regularly review our information security practices and update them in line with legal requirements, industry standards, and technological advancements.
The rights of Users based on the General Data Protection Regulation (GDPR)
Users may exercise certain rights regarding their Data processed by the Controller.
In particular, Users have the right to do the following, to the extent permitted by law:
- Withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
- Object to processing of their Data. Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent.
- Access their Data. Users have the right to learn if Data is being processed by the Controller, obtain disclosure regarding certain aspects of the processing and obtain a copy of the Data undergoing processing.
- Verify and seek rectification. Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.
- Restrict the processing of their Data. Users have the right to restrict the processing of their Data. In this case, the Controller will not process their Data for any purpose other than storing it.
- Have their Personal Data deleted or otherwise removed. Users have the right to obtain the erasure of their Data from the Controller.
- Receive their Data and have it transferred to another controller. Users have the right to receive their Data in a structured, commonly used and machine readable format and, if technically feasible, to have it transmitted to another controller without any hindrance.
- Lodge a complaint. Users have the right to bring a claim before their competent data protection authority.
Users are also entitled to learn about the legal basis of Data transfers to a country outside the European Union or to any international organisation governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by the Controller to safeguard their Data.
If any such transfer takes place, Users can find out more by checking the relevant sections of this document or enquire with the Controller using the information provided in the contact section.
Details about the right to object to processing
Where Personal Data is processed for a public interest, in the exercise of an official authority vested in the Controller or for the purposes of the legitimate interests pursued by the Controller, Users may object to such processing by providing a ground related to their particular situation to justify the objection.
Users must know that, however, should their Personal Data be processed for direct marketing purposes, they can object to that processing at any time, free of charge and without providing any justification. Where the User objects to processing for direct marketing purposes, the Personal Data will no longer be processed for such purposes. To learn whether the Controller is processing Personal Data for direct marketing purposes, Users may refer to the relevant sections of this document.
How to exercise these rights
Any requests to exercise User rights can be directed to the Controller through the contact details provided in this document. Such requests are free of charge and will be answered by the Controller as early as possible and always within one month, providing Users with the information required by law. Any rectification or erasure of Personal Data or restriction of processing will be communicated by the Controller to each recipient, if any, to whom the Personal Data has been disclosed unless this proves impossible or involves disproportionate effort. At the Users’ request, the Controller will inform them about those recipients.
Further information for Users in Switzerland
This section applies to Users in Switzerland, and, for such Users, supersedes any other possibly divergent or conflicting information contained in the privacy policy.
Further details regarding the categories of Data processed, the purposes of processing, the categories of recipients of the personal data, if any, the retention period and further information about Personal Data can be found in the section titled “Detailed information on the processing of Personal Data” within this document.
The rights of Users according to the Swiss Federal Act on Data Protection
Users may exercise certain rights regarding their Data within the limits of law, including the following:
- right of access to Personal Data;
- right to object to the processing of their Personal Data (which also allows Users to demand that processing of Personal Data be restricted, Personal Data be deleted or destroyed, specific disclosures of Personal Data to third parties be prohibited);
- right to receive their Personal Data and have it transferred to another controller (data portability);
- right to ask for incorrect Personal Data to be corrected.
How to exercise these rights
Any requests to exercise User rights can be directed to the Controller through the contact details provided in this document. Such requests are free of charge and will be answered by the Controller as early as possible, providing Users with the information required by law.
Transfers of personal data outside the United Kingdom (UK), Switzerland and the European Economic Area (EEA)
We operate internationally and may transfer your personal data to countries outside the United Kingdom (UK), Switzerland, and the European Economic Area (EEA). This may occur where:
- it is necessary to fulfil a contract with you;
- we are under a legal obligation to do so;
- we have a legitimate business interest to support global operations.
Where personal data is transferred to countries that do not offer the same level of protection as required under the UK GDPR, EU GDPR, or Swiss data protection law, we take steps to ensure that your personal data is adequately protected.
This may include:
- entering into standard contractual clauses (SCCs) approved by the European Commission or UK Information Commissioner;
- relying on adequacy decisions issued by the European Commission, the UK Secretary of State, or the Swiss Federal Council;
- implementing appropriate supplementary measures, such as encryption, access restrictions, and audit controls.
Example: Internal Management Functions in the United States
Currently, Curaleaf has a key data transfer arrangement that involves the access or processing of personal data by members of its senior management, compliance, audit, and oversight teams who are based in the United States. While Curaleaf is headquartered in the United Kingdom:
Certain employees located in the United States may access personal data for operational or oversight purposes.
Some personal data may be stored or maintained on servers based in the United States, subject to appropriate contractual and technical safeguards.
We ensure that all such transfers are governed by valid transfer mechanisms and regularly review them to ensure ongoing compliance.
Complaints
If you have any concerns about how we handle your personal data or are dissatisfied with our response to a privacy-related query, you can contact us directly using the details provided in the “Contact Information” section of this notice. We are committed to addressing your concerns in a prompt and transparent manner.
You also have the right to lodge a complaint with the data protection authority in the country where you reside, work, or believe a data protection breach has occurred. This includes authorities such as:
- The Information Commissioner’s Office (ICO) in the United Kingdom
- The Federal Data Protection and Information Commissioner (FDPIC) in Switzerland
- The national data protection authorities within EU Member States, such as the CNIL in France, the BfDI in Germany, or the GPDP in Italy
Please note that most supervisory authorities will expect you to raise the issue with us first before they will consider handling the matter independently.
Additional information about Data collection and processing
Legal action
The User’s Personal Data may be used for legal purposes by the Controller in Court or in the stages leading to possible legal action arising from improper use of this Website or the related Services.
The User declares to be aware that the Controller may be required to reveal personal data upon request of public authorities.
Additional information about User’s Personal Data
In addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual information concerning particular Services or the collection and processing of Personal Data upon request.
System logs and maintenance
For operation and maintenance purposes, this Website and any third-party services may collect files that record interaction with this Website (System logs) or use other Personal Data (such as the IP Address) for this purpose.
Information not contained in this policy
More details concerning the collection or processing of Personal Data may be requested from the Controller at any time. Please see the contact information at the beginning of this document.
Changes to this privacy policy
The Controller reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within this Website and/or – as far as technically and legally feasible – sending a notice to Users via any contact information available to the Controller. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.
Should the changes affect processing activities performed on the basis of the User’s consent, the Controller shall collect new consent from the User, where required.
Definitions and legal references
Personal Data (or Data)
Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.
Usage Data
Information collected automatically through this Website (or third-party services employed in this Website), which can include: the IP addresses or domain names of the computers utilised by the Users who use this Website, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilised to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilised by the User, the various time details per visit (e.g., the time spent on each page within the Website) and the details about the path followed within the Website with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment.
User
The individual using this Website who, unless otherwise specified, coincides with the Data Subject.
Data Subject
The natural person to whom the Personal Data refers.
Data Processor (or Processor)
The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller, as described in this privacy policy.
Data Controller (or Controller)
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of this Website. The Data Controller, unless otherwise specified, is the Controller of this Website.
This Website
The means by which the Personal Data of the User is collected and processed.
Service
The service provided by this Website as described in the relative terms (if available) and on this site/Website.
European Union (or EU)
Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.
Cookie
Cookies are Trackers consisting of small sets of data stored in the User’s browser.
Tracker
Tracker indicates any technology – e.g Cookies, unique identifiers, web beacons, embedded scripts, e-tags – that enables the tracking of Users, for example by accessing or storing information on the User’s device.
Legal information
This privacy statement has been prepared based on provisions of multiple legislations.
This privacy policy relates solely to this Website, if not stated otherwise within this document.
iubenda hosts this content and only collects the Personal Data strictly necessary for it to be provided.
Cookie Policy of www.curaleafeducation.com
This document informs Users about the technologies that help this Website to achieve the purposes described below. Such technologies allow the Controller to access and store information (for example by using a Cookie) or use resources (for example by running a script) on a User’s device as they interact with this Website.
For simplicity, all such technologies are defined as “Trackers” within this document – unless there is a reason to differentiate.
For example, while Cookies can be used on both web and mobile browsers, it would be inaccurate to talk about Cookies in the context of mobile apps as they are a browser-based Tracker. For this reason, within this document, the term Cookies is only used where it is specifically meant to indicate that particular type of Tracker.
Some of the purposes for which Trackers are used may also require the User’s consent, depending on the applicable law. Whenever consent is given, it can be freely withdrawn at any time following the instructions provided in this document.
This Website uses Trackers managed directly by the Controller (so-called “first-party” Trackers) and Trackers that enable services provided by a third-party (so-called “third-party” Trackers). Unless otherwise specified within this document, third-party providers may access the Trackers managed by them.
The validity and expiration periods of Cookies and other similar Trackers may vary depending on the lifetime set by the Controller or the relevant provider. Some of them expire upon termination of the User’s browsing session.
In addition to what’s specified in the descriptions within each of the categories below, Users may find more precise and updated information regarding lifetime specification as well as any other relevant information – such as the presence of other Trackers – in the linked privacy policies of the respective third-party providers or by contacting the Controller.
How this Website uses Trackers
Necessary
This Website uses so-called “technical” Cookies and other similar Trackers to carry out activities that are strictly necessary for the operation or delivery of the Service.
Trackers managed by third parties
- Cloudflare (Cloudflare, Inc.)
Cloudflare is a traffic optimisation and distribution service provided by Cloudflare Inc. The way Cloudflare is integrated means that it filters all the traffic through this Website, i.e., communication between this Website and the User’s browser, while also allowing analytical data from this Website to be collected.
Personal Data processed: Trackers and various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy.
Trackers duration:
- _cfuvid: indefinite
- cf_clearance: 30 minutes
- Google reCAPTCHA (Google LLC)
Google reCAPTCHA is a SPAM protection service provided by Google LLC or by Google Ireland Limited, depending on how the Controller manages the Data processing. The use of reCAPTCHA is subject to the Google privacy policy and terms of use.
In order to understand Google’s use of Data, consult their partner policy and their Business Data page.
Personal Data processed: answers to questions, clicks, scroll position, Trackers and Usage Data.
Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.
Trackers duration:
- _GRECAPTCHA: duration of the session
- rc::a: indefinite
- rc::b: duration of the session
- rc::c: duration of the session
- rc::f: indefinite
Experience
This Website uses Trackers to improve the quality of the user experience and enable interactions with external content, networks and platforms.
Trackers managed by third parties
- Google Fonts (Google LLC)
Google Fonts is a typeface visualisation service provided by Google LLC or by Google Ireland Limited, depending on how the Controller manages the Data processing, that allows this Website to incorporate content of this kind on its pages.
Personal Data processed: Trackers and Usage Data.
Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.
Measurement
This Website uses Trackers to measure traffic and analyze User behavior to improve the Service.
Trackers managed by third parties
- Google Analytics 4 (Google LLC)
Google Analytics 4 is a web analysis service provided by Google LLC or by Google Ireland Limited, depending on how the Controller manages the Data processing, (“Google”). Google utilizes the Data collected to track and examine the use of this Website, to prepare reports on its activities and share them with other Google services. Google may use the Data collected to contextualize and personalize the ads of its own advertising network. In Google Analytics 4, IP addresses are used at collection time and then discarded before Data is logged in any data center or server. Users can learn more by consulting Google’s official documentation.
In order to understand Google’s use of Data, consult their partner policy and their Business Data page.
Personal Data processed: number of Users, session statistics, Trackers and Usage Data.
Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.
Trackers duration:
- _ga: 2 years
- _ga_*: 2 years
Marketing
This Website uses Trackers to deliver personalised ads or marketing content, and to measure their performance.
Trackers managed by third parties
- LinkedIn Ads (LinkedIn Corporation)
LinkedIn Ads is an advertising service provided by LinkedIn Corporation.
Personal Data processed: Trackers and Usage Data.
Place of processing: United States – Privacy Policy.
Trackers duration:
- GAID: indefinite
- IDFA: indefinite
- UserMatchHistory: 1 month
- _gcl_*: 3 months
- _guid: 3 months
- aam_uuid: 1 month
- li_fat_id: 1 month
- li_giant: 7 days
- li_sugr: 3 months
- lms_ads: 1 month
- oribi_cookie_test: duration of the session
- oribi_session: 2 hours
- oribi_user_guid: 7 months
- LinkedIn conversion tracking (LinkedIn Insight Tag) (LinkedIn Corporation)
LinkedIn conversion tracking (LinkedIn Insight Tag) is an analytics and behavioural targeting service provided by LinkedIn Corporation that connects data from the LinkedIn advertising network with actions performed on this Website. The LinkedIn Insight Tag tracks conversions that can be attributed to LinkedIn ads and enables to target groups of Users on the base of their past use of this Website.
Personal Data processed: device information, Trackers and Usage Data.
Place of processing: United States – Privacy Policy.
Trackers duration:
- AnalyticsSyncHistory: 1 month
- JSESSIONID: duration of the session
- UserMatchHistory: 1 month
- bcookie: 1 year
- bscookie: 1 year
- lang: duration of the session
- li_gc: 7 months
- lidc: 1 day
- lms_ads: 1 month
- lms_analytics: 1 month
- sdui_ver: 1 day
- Outbrain (Outbrain UK)
Outbrain is an advertising service provided by Outbrain UK.
Personal Data processed: Trackers and various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy.
Trackers duration:
- FPtrust: indefinite
- OB-AD-BLOCKER-STAT: indefinite
- OB-AD-BLOCKER-WL-STAT: indefinite
- OB-CCPA: indefinite
- OB-CLDT: indefinite
- OB-CNSNT-2: indefinite
- OB-FD-TO: indefinite
- OB-FDE: indefinite
- OB-FREQUENCY: indefinite
- OB-SKELETON-STRUCT: indefinite
- OB-SYNC: indefinite
- OB-SYNC-TTL: indefinite
- OB-TPCS: indefinite
- OB-USER-TOKEN: indefinite
- OB-USER-TOKEN-CREATION: indefinite
- OB-lastPageViewInfo: indefinite
- OB:LSU: indefinite
- auid: 3 months
- dicbo_id: 7 days
- ob-monitor-obm-ImageError: indefinite
- ob-monitor-obm-MCDPRetriesError: indefinite
- ob-monitor-obm-PixelLoadingError: indefinite
- ob-test: indefinite
- obuid: 3 months
- optout: 2 years
- ref-{}: 1 minute
- sync: 7 days
- thirdparty: 1 hour
- token: indefinite
- uids: 3 months
- zoptout: 2 years
- zpb: 1 day
- zpbid: 1 day
- zuid: 3 months
How to manage preferences on this Website
Users can set or update their preferences via the relevant privacy choices panel available on this Website.
With regard to any third-party Trackers, Users can manage their preferences via the related link (where provided), by using the means indicated in the third party’s privacy policy, or by contacting the third party.
How to control or delete Cookies and similar technologies via your device settings
Users may use their own browser settings to:
- See what Cookies or other similar technologies have been set on the device;
- Block Cookies or similar technologies;
- Clear Cookies or similar technologies from the browser.
The browser settings, however, do not allow granular control of consent by category.
Users can, for example, find information about how to manage Cookies in the most commonly used browsers at the following addresses:
Users may also manage certain categories of Trackers used on mobile apps through relevant device settings such as the device advertising settings for mobile devices, or tracking settings in general (Users may open the device settings and look for the relevant setting).
How to opt out of interest-based advertising
Notwithstanding the above, Users may follow the instructions provided by YourOnlineChoices (EU), the Network Advertising Initiative (US) and the Digital Advertising Alliance (US), DAAC (Canada), DDAI (Japan) or other similar services. Such initiatives allow Users to select their tracking preferences for most of the advertising tools. The Controller thus recommends that Users make use of these resources in addition to the information provided in this document.
The Digital Advertising Alliance offers an Website called AppChoices that helps Users to control interest-based advertising on mobile apps.
Consequences of denying consent
Users are free to decide whether or not to grant consent. However, please note that Trackers help this Website to provide a better experience and advanced functionalities to Users (in line with the purposes outlined in this document). Therefore, in the absence of the User’s consent, the Controller may be unable to provide related features.
Controller and Data Controller
Curaleaf International Pharma Sagl
Via Trevani, 1, 6600 – Locarno, Svizzera
Controller contact email: pharma@curaleafint.com
Controller’s Data Protection Officer contact: data.protection@curaleafint.com
Given the objective complexity surrounding tracking technologies, Users are encouraged to contact the Controller should they wish to receive any further information on the use of such technologies by this Website.
Definitions and legal references
Personal Data (or Data)
Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.
Usage Data
Information collected automatically through this Website (or third-party services employed in this Website), which can include: the IP addresses or domain names of the computers utilised by the Users who use this Website, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilised to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilised by the User, the various time details per visit (e.g., the time spent on each page within the Website) and the details about the path followed within the Website with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment.
User
The individual using this Website who, unless otherwise specified, coincides with the Data Subject.
Data Subject
The natural person to whom the Personal Data refers.
Data Processor (or Processor)
The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller, as described in this privacy policy.
Data Controller (or Controller)
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of this Website. The Data Controller, unless otherwise specified, is the Controller of this Website.
This Website
The means by which the Personal Data of the User is collected and processed.
Service
The service provided by this Website as described in the relative terms (if available) and on this site/Website.
European Union (or EU)
Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.
Cookie
Cookies are Trackers consisting of small sets of data stored in the User’s browser.
Tracker
Tracker indicates any technology – e.g Cookies, unique identifiers, web beacons, embedded scripts, e-tags – that enables the tracking of Users, for example by accessing or storing information on the User’s device.
Legal information
This privacy statement has been prepared based on provisions of multiple legislations.
This privacy policy relates solely to this Website, if not stated otherwise within this document.