CORE
Enterprise
Legal

Privacy Policy

How Core Enterprise collects, uses, and protects your data.

Last updated: August 24, 2026

1. Introduction

Code FoundrySC (“Core Enterprise”, “we”, “us”, or “our”) operates the Core Enterprise platform — a unified IT management and monitoring service for internal IT teams and managed service providers (MSPs). This Privacy Policy explains what personal and operational data we collect through the platform, the website at app.core-enterprise.io (the “Site”), and related services (collectively, the “Service”), how we use it, and the choices you have.

By accessing or using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, you should not use the Service. This policy applies to platform administrators, end users provisioned within a tenant, and visitors to the Site. Where we act as a data processor on behalf of a customer organization, the customer is the controller of the data submitted to their tenant; this policy describes our handling as processor and our handling of any data where we act as controller.

2. Information We Collect

Account & identity data. When an account is created through a paid subscription or invitation, we collect:

  • Full name, email address, and role assigned within your tenant.
  • Authentication records, including login timestamps and (where used) OAuth identifiers from single sign-on providers.
  • Tenant organization details you provide, such as organization name, industry, and contact email.

Billing data. Subscription and payment information collected through our payment provider (Base44 Payments / Wix Payments), including:

  • Plan selected, billing cycle, renewal dates, and subscription status.
  • Billing name, address, and transaction identifiers. Card numbers and full payment credentials are handled entirely by the payment provider and never touch our servers.

Operational & telemetry data. To deliver monitoring, patch, and asset management features, the Service processes data you or your agents submit about managed endpoints and networks:

  • Device hostnames, operating systems, IP addresses, hardware identifiers (serial numbers, IMEIs), and agent versions.
  • Status, performance, and health telemetry (uptime, throughput, latency, resource utilization).
  • Patch, vulnerability, software inventory, backup, and compliance records you import or that agents report.
  • Support tickets, comments, scripts, and knowledge base articles you create within your tenant.

Usage & device data. We automatically collect technical information about how the Service is accessed:

  • IP address, browser type, operating system, referring URLs, and approximate location derived from IP.
  • Pages and features viewed, click patterns, and session duration (usage analytics).
  • Audit log entries recording actions performed by users within your tenant (actor, action, resource, timestamp).

Correspondence data. Messages you send through contact forms, support requests, and email communications, including the content of those messages.

3. How We Use Your Information

We process personal data for the following purposes:

  • Provisioning & access: to create and administer tenant accounts, authenticate users, and enforce role-based access control and tenant isolation.
  • Service delivery: to operate monitoring, ticketing, patch, compliance, and reporting features, and to display the data you submit back to authorized users in your tenant.
  • Billing & subscriptions: to process payments, manage renewals and cancellations, and reconcile subscription entitlements.
  • Security & integrity: to detect, prevent, and respond to fraud, abuse, unauthorized access, and security incidents affecting the Service.
  • Support & communication: to respond to your inquiries, provide technical support, and send service notices, billing alerts, and policy updates.
  • Improvement: to analyze usage trends, diagnose errors, and improve the performance, reliability, and features of the Service.
  • Legal compliance: to meet legal obligations and to enforce our Terms of Service and acceptable use policies.

4. Legal Bases for Processing (GDPR)

For users in the European Economic Area, the United Kingdom, and Switzerland, we rely on the following legal bases under the GDPR:

  • Contract: processing necessary to provide the Service you subscribed to and to fulfill our contractual obligations.
  • Legal obligation: processing to comply with applicable laws, tax, and record-keeping requirements.
  • Legitimate interests: processing for security, fraud prevention, service improvement, and analytics, where balanced against your rights.
  • Consent: for optional analytics, marketing, and non-essential cookies, where you have given affirmative consent. You may withdraw consent at any time.

Where we act as a processor on behalf of a customer controller, processing is governed by our agreement with that customer and documented instructions.

5. Data Sharing & Sub-Processors

We do not sell personal data. We share information only as described here:

  • Within your tenant: data you submit is visible to authorized users in the same tenant and to platform administrators acting on behalf of your organization.
  • Service providers: we engage trusted sub-processors to host infrastructure, process payments, deliver email, and provide analytics. Each is bound by confidentiality and data-protection obligations.
  • Legal & safety: where required by law, court order, or to protect the rights, property, or safety of Core Enterprise, our users, or the public.
  • Business transfers: in connection with a merger, acquisition, or asset sale, information may be transferred subject to the protections in this policy.

A current list of core sub-processor categories includes cloud hosting providers, payment processors, transactional email services, and error-monitoring tools. We will notify affected customers in advance of material changes to sub-processors where required by our agreements.

6. International Data Transfers & Data Residency

By default, app data and users are stored in the United States. Where supported by your plan, you may choose to store app data in European Union or United Kingdom clusters instead. Data residency controls where your data is stored, not where it is processed; when your app runs, requests may be handled by services in another region before the result is saved to your chosen region.

Where data is transferred from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or the Data Privacy Framework, and require our sub-processors to do the same. All vendors that receive personal information are bound by strict data-processing agreements. For the most up-to-date information on data privacy, including our DPA, please review our Terms of Service and Data Processing Agreement.

7. Data Retention

We retain data for as long as your account is active and as needed to provide the Service. Specifically:

  • Active tenants: operational and telemetry data is retained for the life of the subscription.
  • After cancellation: tenant data is scheduled for deletion within 90 days of subscription termination, except where retention is required for legal, accounting, or billing purposes.
  • Audit logs: retained per your plan and applicable compliance requirements, typically 1–7 years.
  • Billing records: retained as required by tax and financial regulations.

You may request earlier deletion of your tenant data subject to legal retention obligations.

8. Security Measures

We implement industry-standard technical and organizational measures designed to protect your data:

  • Encryption in transit (TLS) and at rest for stored data.
  • Tenant isolation enforced through row-level access controls so users in one tenant cannot access another tenant’s data.
  • Role-based access control limiting actions to authorized roles within each tenant.
  • Regular security reviews, least-privilege internal access, and audit logging of administrative actions.
  • Incident response procedures intended to identify, contain, and notify affected parties of security incidents.

Core Enterprise is SOC 2 Type II attested. This independent audit reviews how we protect data and systems; the full report is shared under NDA on request. We are also ISO 27001 certified, confirming a repeatable, audited process to protect data across people, processes, and technology.

No system is perfectly secure. While we work to protect your data, we cannot guarantee absolute security, and unauthorized access, interception, or alteration remains a possibility inherent to internet-based services.

9. Cookies & Tracking Technologies

We use cookies and similar technologies to operate the Service, keep you signed in, remember preferences, and understand usage. Categories include:

  • Essential: required for authentication and core functionality; cannot be disabled.
  • Functional: remember settings such as layout and display preferences.
  • Analytics: help us understand how the Service is used so we can improve it.

You can manage or disable non-essential cookies through your browser settings. Disabling essential cookies may prevent you from signing in or using the Service.

10. Your Privacy Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Rectify inaccurate or incomplete data.
  • Erase your personal data (the “right to be forgotten”), subject to legal exceptions.
  • Restrict or object to certain processing activities.
  • Portability: receive your data in a structured, machine-readable format and transmit it to another controller.
  • Withdraw consent at any time where processing relied on consent.
  • Lodge a complaint with your supervisory data-protection authority.

To exercise these rights, contact us through the details in Section 13. We will respond within the timeframe required by applicable law, generally within 30 days.

11. Children’s Privacy

The Service is intended for business and professional use. We do not knowingly collect personal data from children under 16, and the Service is not offered to them. If you believe a minor has provided data to us, please contact us and we will take steps to delete it.

12. Recognizing Legitimate Core Enterprise Emails

Messages sent by apps built on the platform use the base44-apps.com domain and its subdomains. Messages sent directly by Core Enterprise, such as account notifications or billing updates, use the base44.com domain. Always check that links in Core Enterprise emails point to these domains before clicking.

13. Reporting Abuse & Misuse

If you suspect a malicious or abusive app, or receive a message that you believe violates our policies, forward it to abuse@base44.com. This is the correct contact for security, misuse, and abuse reports. Do not send support or product questions to this address.

14. Your Data Choices & Controls

  • Access your data: to request a copy of the personal data we hold, email compliance@base44.com from the email associated with your account.
  • Delete your app data: from your app dashboard, go to Settings → App Settings → Danger Zone and delete your app. Deleted apps remain recoverable for 30 days.
  • Delete your account: follow the account deletion guide or contact support to permanently delete your account.
  • GDPR rights: access, rectify, erase, restrict, object, data portability, and withdraw consent — contact compliance@base44.com.

15. Country & Region Availability

As a U.S.-based company, we comply with requirements issued by the U.S. Office of Foreign Assets Control (OFAC). The Service is not available in the following restricted countries and regions: Iran, North Korea, Syria, Cuba, the region of Crimea, the so-called Donetsk People’s Republic, and the so-called Luhansk People’s Republic. There are also substantial limitations on activity from the Russian Federation. Restricted-region domain extensions cannot be connected to the platform.

16. Legacy Contacts

A legacy contact is a person you choose to receive ownership of your account if you pass away. To appoint a legacy contact, contact our support team with your legacy contact’s full name and email, and your full name exactly as it appears on valid identification. To transfer an account after the owner’s death, the legacy contact provides a death certificate and government-issued ID matching the name on record.

17. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date and, for material changes, provide notice through the Service or by email. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

18. Contacting Us

If you have questions about this Privacy Policy or wish to exercise your rights, contact us through the contact page at app.core-enterprise.io/contact, by email at compliance@base44.com, or by mail at Code FoundrySC, Attn: Privacy. To report abuse, use abuse@base44.com. Where we act as processor, please also coordinate with your tenant administrator, who may submit requests on behalf of your organization.