Compliance
GDPR and CCPA privacy rights at Corei
Corei is built so that privacy requests are answered with records, not guesses. Submit a request below, review the compliance program behind it, or change your cookie choices at any time.
Who is responsible
Controller and processor roles
Corei as processor
For tickets, time entries, agreements, assets, and other operational records inside a customer's tenant, the MSP is the controller (or business) and Corei is the processor (or service provider). We act only on that customer's documented instructions and assist them in answering their own clients' requests.
Corei as controller
For our own marketing site, demo requests, pilot applications, account administration, and billing contacts, Corei is the controller. Requests about that information come straight to us and we answer them directly.
If you are an end user of an MSP that uses Corei, start with that MSP. Send us the request anyway if you are unsure — we will route it and tell you who holds the record.
Your rights
What you can ask for
GDPR and UK GDPR
Right of access
Confirmation of whether we process your data and a copy of it, with the purposes and recipients.
Rectification
Correction of inaccurate data and completion of incomplete data.
Erasure
Deletion where data is no longer necessary, consent is withdrawn, or processing is unlawful.
Restriction & objection
Pause processing while a dispute is resolved, or object to processing based on legitimate interests.
Portability
A machine-readable export (JSON or CSV) of the data you provided to us.
Automated decisions
Corei never makes solely automated decisions with legal or similar significant effect. A person approves.
CCPA and CPRA (California)
Right to know
The categories and specific pieces of personal information collected, the sources, purposes, and any disclosures.
Right to delete
Deletion of personal information we collected from you, subject to legal exceptions.
Right to correct
Correction of inaccurate personal information we maintain about you.
Opt out of sale/sharing
We do not sell personal information and do not share it for cross-context behavioral advertising — so there is nothing to opt out of. You can still submit a request on record.
Limit sensitive information
We do not use or disclose sensitive personal information beyond the purposes permitted under CPRA.
Non-discrimination
Exercising a privacy right never changes your pricing, service level, or support.
| Law | Acknowledgement | Completion |
|---|---|---|
| GDPR / UK GDPR | Without undue delay | Within 1 month (extendable by 2 months for complex requests) |
| CCPA / CPRA | Within 10 business days | Within 45 days (extendable once by 45 days) |
We verify identity before acting on a request, and we may ask for information that lets us match you to a record. An authorized agent may submit on your behalf with written permission.
Lawful basis
Why we process personal data
Contract
Providing the platform, authentication, support, and billing to customers.
Legitimate interests
Securing the service, preventing abuse, and improving reliability with aggregated signals.
Consent
Analytics cookies and optional marketing email. Withdrawable at any time.
Legal obligation
Tax, accounting, and lawful requests we are required to answer.
Compliance program
How we operationalize GDPR and CCPA
Data Processing Addendum
A DPA with GDPR Article 28 processor terms, sub-processor commitments, security measures, and breach notification is available for every customer on request.
International transfers
EU/UK/Swiss transfers rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, with transfer impact assessments where required.
Data minimization by design
Corei syncs only the records a customer authorizes, keeps tenants isolated at the database layer, and never uses customer data to train public models.
Records of processing
We maintain processing records, a sub-processor register, retention schedules, and DPIA support for customers who need it.
Breach response
Documented incident response with notification to affected controllers without undue delay and within 72 hours of confirmation.
Consent management
Analytics cookies are off until a visitor allows them, choices are stored with a timestamp, and permission can be withdrawn from any page.
Corei is aligned to SOC 2 controls and working toward a Type II attestation. See Security for tenant isolation, MFA, IP restrictions, and conditional access, and the Privacy Notice for full detail on collection, retention, and sub-processors.
Submit a request
Data subject and consumer requests
Send the request here and it lands in our privacy queue with a timestamp. We acknowledge it, verify your identity, and tell you exactly what we hold and what we did. You can also email privacy@coreiplatform.com.
- Access a copy of my personal information
- Portable export of my personal information
- Correct inaccurate personal information
- Delete my personal information
- Opt out of sale/sharing or targeted advertising
- Restrict or object to processing
Exercising a privacy right never affects your pricing, service level, or support.