Privacy Policy

1. Introduction
CoreOS (“CoreOS”, “we”, “us”, or “our”) is an AI-powered commercial intelligence platform developed by CSM, an Irish company based in the European Union. CoreOS helps business owners, founders, and leadership teams consolidate operational, financial, marketing, and sales data from connected platforms and analyse that data using AI-driven tools and agents to support informed strategic decision-making. We are committed to protecting your privacy and handling your personal data in a transparent, lawful, and secure manner, in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Irish data protection laws. This Privacy Policy explains:
- What data we collect
- How and why we use it
- The legal bases for processing
- How data is stored and protected
- Your rights under GDPR

2. Data Controller
For the purposes of GDPR, the data controller is:
CSM
Registered in Ireland
63 Woodside, Rathfarnham, Dublin 14
Email: [hello@coreos.ai or similar]If you have any questions about this policy or how we handle data, you can contact us using the details above.

3. Scope of This Policy
This Privacy Policy applies to:
- The CoreOS website
- The CoreOS platform and related services
- Any communications or interactions you have with CoreOS
- It does not apply to third-party websites, platforms, or services that you may connect to CoreOS. Those services are governed by their own privacy policies.

4. Data We Collect
4.1 Personal Data You Provide Directly
We may collect personal data when you:
- Visit our website
- Create an account
- Request a demo or contact us
- Use the CoreOS platform
- Communicate with us
This may include:
- Name
- Email address
- Company name
- Job title or role
- Contact details
- Account credentials
- Communications with us
4.2 Business and Platform Data
When you use CoreOS, you may connect third-party platforms (such as analytics, finance, CRM, marketing, or sales tools).Depending on your configuration and consent, CoreOS may process:
- Aggregated business performance data
- Operational, financial, marketing, and sales metrics
- Reports, dashboards, and performance indicators
- Strategic inputs provided by users
- This data may include personal data if such data exists within the connected platforms. CoreOS processes this data solely in accordance with your instructions and permissions.
4.3 Automatically Collected Data
When you visit our website or use the platform, we may automatically collect:
- IP address
- Device and browser type
- Operating system
- Usage data and interaction logs
- Referring URLs
- Date and time of access
This data is used for security, performance monitoring, analytics, and service improvement.

5. Legal Bases for Processing
Under GDPR, we process personal data only where a lawful basis applies. These include:
Consent – where you have explicitly agreed to data processing (e.g. cookies, platform connections)
Contractual necessity – to provide the CoreOS services you request
Legitimate interests – to operate, secure, and improve our services (balanced against your rights)
Legal obligation – to comply with applicable laws and regulationsYou may withdraw consent at any time where processing is based on consent.

6. How We Use Your Data
We use personal data to:
- Provide and operate the CoreOS platform
- Connect and synchronise authorised third-party data sources
- Generate AI-driven insights, analysis, and recommendationsImprove platform functionality and user experience
- Communicate with you regarding your account or inquiries
- Ensure platform security and prevent misuse
- Meet legal and regulatory obligations
- CoreOS does not sell personal data.

7. AI and Automated Processing
CoreOS uses AI models and automated systems to analyse data and generate insights.Important clarifications:
- AI outputs are generated based on the data you authorise and provide
- CoreOS does not make legally binding decisions on your behalf
- AI-generated recommendations are intended to support, not replace, human decision-making
- We do not use your private business data to train public or external AI models
- Where required by law, you have the right to request human review of automated processing.

8. Data Sharing and Processors
We may share personal data with trusted third parties who act as data processors, including:
- Cloud hosting providers
- Infrastructure and security providers
- Analytics and monitoring servicesCustomer support tools
All processors are bound by contractual obligations to:
- Process data only on our instructions
- Maintain appropriate security measures
- Comply with GDPR requirements
We do not share data with third parties for advertising purposes.

9. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:
- EU Standard Contractual Clauses (SCCs)
- Transfers to jurisdictions deemed adequate by the European Commission

10. Data Retention
We retain personal data only for as long as necessary to:
- Provide our servicesFulfil contractual obligations
- Comply with legal requirements
- Resolve disputes and enforce agreements
- When data is no longer required, it is securely deleted or anonymised.

11. Security Measures
We implement appropriate technical and organisational measures to protect personal data, including:
- Encryption in transit and at rest
- Access controls and authentication
- Secure infrastructure and monitoring
- Regular security reviews
- No system is completely secure, but we take reasonable steps to protect your data.

12. Your Rights Under GDPR
As an EU data subject, you have the right to:
- Access your personal dataRectify inaccurate data
- Request erasure (“right to be forgotten”)
- Restrict or object to processing
- Data portability
- Withdraw consent at any timeLodge a complaint with the Data Protection Commission (Ireland)
- Requests can be made by contacting us at [hello@coreos.ai].

13. Cookies and Tracking
We use cookies and similar technologies on our website. For details, please see our Cookie Policy and Cookie Settings, where you can manage your preferences.

14. Changes to This Policy
We may update this Privacy Policy from time to time. Any material changes will be communicated via the website or directly where appropriate.The “Last updated” date will always reflect the current version.

15. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact:
Email: hello@core-os-ai