How Core Enterprise collects, uses, and protects your data.
Last updated: August 24, 2026
Code FoundrySC (“Core Enterprise”, “we”, “us”, or “our”) operates the Core Enterprise platform — a unified IT management and monitoring service for internal IT teams and managed service providers (MSPs). This Privacy Policy explains what personal and operational data we collect through the platform, the website at app.core-enterprise.io (the “Site”), and related services (collectively, the “Service”), how we use it, and the choices you have.
By accessing or using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, you should not use the Service. This policy applies to platform administrators, end users provisioned within a tenant, and visitors to the Site. Where we act as a data processor on behalf of a customer organization, the customer is the controller of the data submitted to their tenant; this policy describes our handling as processor and our handling of any data where we act as controller.
Account & identity data. When an account is created through a paid subscription or invitation, we collect:
Billing data. Subscription and payment information collected through our payment provider (Base44 Payments / Wix Payments), including:
Operational & telemetry data. To deliver monitoring, patch, and asset management features, the Service processes data you or your agents submit about managed endpoints and networks:
Usage & device data. We automatically collect technical information about how the Service is accessed:
Correspondence data. Messages you send through contact forms, support requests, and email communications, including the content of those messages.
We process personal data for the following purposes:
For users in the European Economic Area, the United Kingdom, and Switzerland, we rely on the following legal bases under the GDPR:
Where we act as a processor on behalf of a customer controller, processing is governed by our agreement with that customer and documented instructions.
We do not sell personal data. We share information only as described here:
A current list of core sub-processor categories includes cloud hosting providers, payment processors, transactional email services, and error-monitoring tools. We will notify affected customers in advance of material changes to sub-processors where required by our agreements.
By default, app data and users are stored in the United States. Where supported by your plan, you may choose to store app data in European Union or United Kingdom clusters instead. Data residency controls where your data is stored, not where it is processed; when your app runs, requests may be handled by services in another region before the result is saved to your chosen region.
Where data is transferred from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or the Data Privacy Framework, and require our sub-processors to do the same. All vendors that receive personal information are bound by strict data-processing agreements. For the most up-to-date information on data privacy, including our DPA, please review our Terms of Service and Data Processing Agreement.
We retain data for as long as your account is active and as needed to provide the Service. Specifically:
You may request earlier deletion of your tenant data subject to legal retention obligations.
We implement industry-standard technical and organizational measures designed to protect your data:
Core Enterprise is SOC 2 Type II attested. This independent audit reviews how we protect data and systems; the full report is shared under NDA on request. We are also ISO 27001 certified, confirming a repeatable, audited process to protect data across people, processes, and technology.
No system is perfectly secure. While we work to protect your data, we cannot guarantee absolute security, and unauthorized access, interception, or alteration remains a possibility inherent to internet-based services.
We use cookies and similar technologies to operate the Service, keep you signed in, remember preferences, and understand usage. Categories include:
You can manage or disable non-essential cookies through your browser settings. Disabling essential cookies may prevent you from signing in or using the Service.
Depending on your jurisdiction, you may have the right to:
To exercise these rights, contact us through the details in Section 13. We will respond within the timeframe required by applicable law, generally within 30 days.
The Service is intended for business and professional use. We do not knowingly collect personal data from children under 16, and the Service is not offered to them. If you believe a minor has provided data to us, please contact us and we will take steps to delete it.
Messages sent by apps built on the platform use the base44-apps.com domain and its subdomains. Messages sent directly by Core Enterprise, such as account notifications or billing updates, use the base44.com domain. Always check that links in Core Enterprise emails point to these domains before clicking.
If you suspect a malicious or abusive app, or receive a message that you believe violates our policies, forward it to abuse@base44.com. This is the correct contact for security, misuse, and abuse reports. Do not send support or product questions to this address.
As a U.S.-based company, we comply with requirements issued by the U.S. Office of Foreign Assets Control (OFAC). The Service is not available in the following restricted countries and regions: Iran, North Korea, Syria, Cuba, the region of Crimea, the so-called Donetsk People’s Republic, and the so-called Luhansk People’s Republic. There are also substantial limitations on activity from the Russian Federation. Restricted-region domain extensions cannot be connected to the platform.
A legacy contact is a person you choose to receive ownership of your account if you pass away. To appoint a legacy contact, contact our support team with your legacy contact’s full name and email, and your full name exactly as it appears on valid identification. To transfer an account after the owner’s death, the legacy contact provides a death certificate and government-issued ID matching the name on record.
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date and, for material changes, provide notice through the Service or by email. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or wish to exercise your rights, contact us through the contact page at app.core-enterprise.io/contact, by email at compliance@base44.com, or by mail at Code FoundrySC, Attn: Privacy. To report abuse, use abuse@base44.com. Where we act as processor, please also coordinate with your tenant administrator, who may submit requests on behalf of your organization.