CoreITsm is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, and protect your data when you use our enterprise IT service management platform. We act as both a data controller and processor depending on the context, and we comply with global data protection regulations including GDPR, CCPA, HIPAA, and LGPD.
When you register for an account, we collect:
Legal Basis: Contract necessity for service delivery; Consent for optional features
We automatically collect information about your use of our platform:
Legal Basis: Legitimate interest for service improvement and security; Contract necessity for service delivery
As an enterprise platform, we process customer data on behalf of our customers:
Legal Basis: We act as data processor based on customer instructions; Contract necessity
We collect communications data for service delivery:
Legal Basis: Consent for marketing; Contract necessity for support communications
Provide, maintain, and improve our ITSM platform and related services
Ensure platform security, prevent fraud, and comply with legal obligations
Analyze usage patterns, develop new features, and enhance user experience
Respond to support requests, send important notifications, and provide customer service
We implement enterprise-grade security measures:
For customers subject to GDPR or other data protection laws, we execute Data Processing Agreements (DPAs) that clearly define our responsibilities as a data processor. Our DPAs include:
We retain personal data only as long as necessary for the purposes outlined in this policy, unless a longer retention period is required or permitted by law. Our retention periods include:
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Account Information | Until account deletion | Contract necessity |
| Service Usage Data | 2 years (analytics), 7 years (financial) | Legitimate interest, Legal obligation |
| Support Communications | 3 years after closure | Contract necessity, Legal obligation |
| Marketing Data | Until consent withdrawal | Consent |
We maintain comprehensive breach detection and response procedures:
Notify supervisory authority within 72 hours of becoming aware of a breach that poses risk to individuals' rights and freedoms. Notify affected individuals without undue delay for high-risk breaches.
Notify affected California residents in the event of a breach of unencrypted personal information that compromises security, confidentiality, or integrity.
Notify affected individuals, the Department of Health and Human Services, and sometimes the media within 60 days of a breach of unsecured PHI.
Our breach notifications include:
Response Time: 30 days (GDPR), 45 days (CCPA)
Exceptions: Legal obligations, public interest, contractual requirements
Format: CSV, JSON, XML, or other structured format
CCPA: Opt-out of sale/sharing of personal information
To exercise your rights, please contact us at privacy@coreitsm.com. We will:
CoreITsm is a global platform and your data may be transferred to and processed in countries outside your own. We ensure appropriate safeguards are in place for international data transfers, including:
Our primary data hosting locations include:
We may share your information with trusted third-party service providers who help us operate our platform. All subprocessors undergo rigorous security and privacy assessments.
Cloud hosting, database services, and content delivery networks
Authentication providers, security monitoring, and threat detection
Usage analytics and performance monitoring tools
Customer support platforms and communication tools
Payment processing and billing services
We maintain a comprehensive subprocessor management program including:
Our platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information immediately.
Parents or guardians may:
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the way we operate our business. We will notify you of any material changes by:
We maintain a version history of our privacy policy including:
If you have questions about this Privacy Policy or how we handle your data, please contact us:
Support:
Info@coreitsm.xyz
Technical support and account assistance
Mailing Address:
Rua Dr Antonio Jose de Almeida Nº2 9ºF 2780-089 Oeiras Portugal
Response Times:
We will respond to privacy inquiries within 5 business days and complete requests within legally required timeframes.
European residents have enhanced rights under the General Data Protection Regulation (GDPR), including rights to access, rectification, erasure, restriction of processing, data portability, and objection. Our GDPR compliance includes:
California residents have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know, delete, and opt-out of the sale of personal information. Our CCPA/CPRA compliance includes:
Brazilian residents have rights under the Lei Geral de Proteção de Dados (LGPD), including rights to access, correct, delete, and port their personal data. Our LGPD compliance includes:
Canadian residents have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA), including rights to access, correct, and withdraw consent for personal information. Our PIPEDA compliance includes:
For customers processing Protected Health Information (PHI), we provide HIPAA-compliant services including:
We maintain a comprehensive privacy compliance program including:
We align our practices with leading industry standards and frameworks:
Note: We are aligned with these certification requirements and follow their guidelines for security and privacy practices.
We maintain comprehensive audit and reporting capabilities: