Skip to content
See Corei on your own data in a 45–60 minute demo.
Corei
Legal

Privacy Notice

How Corei handles information across the platform, Corei AI, and the integrations our customers connect.

Last updated: June 22, 2026Effective: June 22, 2026

Informational only. This page is maintained by Corei and provided as general information about how the product operates. It is not legal advice and may be superseded by a signed agreement between Corei and your organization. For tailored terms, contact us.

Section 01

Scope of this notice

This Privacy Notice explains how Corei ("Corei", "we", "us") collects, uses, shares, and protects information when you visit our marketing site, request a demo, or use the Corei platform (the "Service") as a customer, prospective customer, or end user of a customer's tenant.

When Corei processes data that belongs to a managed service provider ("MSP") customer or their downstream clients, we act as a processor on behalf of that customer (the "Controller"). Customers are responsible for providing notice to their own end users and for the lawful basis on which Corei processes that data.

Section 02

Information we collect

We collect the following categories of information:

  • Account & contact data. Name, business email, company, role, and similar information you provide when creating an account, booking a demo, or contacting us.
  • Authentication data. Hashed credentials, session tokens, multi-factor enrollment metadata, and single sign-on identifiers (e.g., Microsoft Entra ID, Google Workspace).
  • Customer operational data. Tickets, time entries, agreements, configurations, opportunities, invoices, assets, and related records that you or your connected systems (e.g., ConnectWise PSA, HubSpot, Microsoft Teams, Axcient, Hook Security) send to the Service.
  • Usage & telemetry. Pages viewed, features used, latency, error traces, IP address, browser type, and similar diagnostic information generated as you use the Service.
  • Corei AI interactions. Prompts, instructions, and outputs exchanged with our AI assistant ("Corei"), along with the operational context the assistant relied on to respond.
  • Billing data. Plan, seat count, token usage, and payment metadata processed by our payment provider. Corei does not store full payment card numbers.

Section 03

How we use information

We use the information described above to:

  • Provide, operate, secure, and improve the Service.
  • Authenticate users and enforce tenant isolation and access controls.
  • Sync data with the integrations you authorize and surface it back inside Corei.
  • Power Corei AI features — including triage, briefings, pre-proposals, and inventory recommendations — grounded in your authorized data.
  • Generate aggregated, de-identified analytics about platform performance and reliability.
  • Respond to support requests, send service notifications, and provide product information you request.
  • Detect, investigate, and prevent fraud, abuse, and security incidents.
  • Comply with our legal, regulatory, and contractual obligations.

Section 04

AI processing and model training

Corei uses a combination of first-party models and third-party AI providers (such as commercial large language model APIs) to generate responses. When you interact with Corei, the relevant prompts and grounded context are transmitted to those providers under contractual terms that prohibit them from using customer content to train their public foundation models.

We do not use your customer operational data to train public or shared models. We may use aggregated, de-identified usage signals to evaluate and improve our own retrieval, ranking, and safety systems.

Section 05

How we share information

We share information only as described below:

  • Subprocessors. Vetted vendors that host infrastructure, deliver email, process payments, provide AI inference, or support analytics and error monitoring. A current list is available on request.
  • Integrations you authorize. When you connect a third-party system (e.g., ConnectWise, HubSpot, Microsoft Teams), data flows to and from that system under your direction and its provider's terms.
  • Your organization. Administrators in your tenant can access usage and content produced by users in that tenant, subject to their internal policies.
  • Legal & safety. Where required to comply with law, enforce our agreements, or protect the rights, property, or safety of Corei, our customers, or others.
  • Corporate transactions. In connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.

We do not sell personal information and do not share it for cross-context behavioral advertising.

Section 06

Retention

We retain customer operational data for as long as your subscription is active and you direct us to store it. After termination, customer content is deleted from active systems within 30 days and from encrypted backups within 90 days, except where retention is required by law.

Account, billing, and audit log records are retained for the period required for tax, legal, and security purposes, typically up to seven (7) years.

Section 07

Security

Corei maintains administrative, technical, and physical safeguards designed to protect your information, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256) for customer data.
  • Tenant isolation at the database and application layer.
  • Role-based access controls, least-privilege provisioning, and audit logging for administrative actions.
  • Mandatory SSO and MFA options for customer administrators.
  • Continuous vulnerability scanning, dependency monitoring, and a coordinated disclosure process.

No system is perfectly secure. If you believe your account has been compromised, contact us immediately at the address below.

Section 08

Your rights and choices

Depending on where you reside, you may have rights to:

  • Access, correct, or delete personal information we hold about you.
  • Restrict or object to certain processing.
  • Request a portable copy of your information.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with a supervisory authority.

If you are an end user of an MSP customer's tenant, please direct privacy requests to that customer first; we will assist them in responding. To exercise rights directly with Corei, contact us using the details below.

Section 09

International data transfers

Corei operates primarily in the United States. Where we transfer personal information from the European Economic Area, United Kingdom, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms, together with supplementary measures where required.

Section 10

Cookies and similar technologies

Corei uses a small number of strictly necessary cookies to keep you signed in and to remember your tenant selection, as well as first-party analytics cookies to understand product usage. We do not use cookies for third-party advertising. You can control cookies through your browser; disabling strictly necessary cookies may prevent the Service from functioning.

Section 11

Children

The Service is intended for use by businesses and is not directed to children under 16. We do not knowingly collect personal information from children.

Section 12

Changes to this notice

We may update this notice from time to time. Material changes will be communicated through the Service or by email to account administrators. The "Last updated" date at the top of this page reflects the most recent revision.

Section 13

How to contact us

Questions about this notice or our privacy practices can be sent to privacy@coreiplatform.com or through our contact page.

Corei — Privacy Office

Email: privacy@coreiplatform.com

For requests under GDPR, UK GDPR, CCPA/CPRA, or similar laws, please include enough information for us to verify your identity and locate your records.