Privacy Policy (GDPR)

Last updated: 2026‑03‑16

1. Who we are (Controller)

Core51 (“we”, “us”) is the controller of personal data processed in connection with the Core51 website and Core51 mobile application. Contact: info@core-51.com.

2. What data we process

  • Account data: email address, password hash, profile fields (name, company, job title), Core ID.
  • Service data: message ciphertext and related metadata (timestamps, IDs, hashes/signatures). We do not aim to store message plaintext.
  • Attachments metadata: filename, MIME type, size, and encrypted file blobs in object storage.
  • Security/audit data: integrity hashes, key rotation records, and audit event logs.
  • Technical data: IP address, device and browser information (as needed for security and abuse prevention).

3. End‑to‑end encryption

Core51 is designed so message and file contents are encrypted on user devices. The server processes and stores encrypted data and necessary metadata for delivery and verification. For details, see Security.

4. Purposes and legal bases (GDPR Art. 6)

  • Provide the service (contract / pre‑contract steps).
  • Security and abuse prevention (legitimate interests).
  • Compliance and audits (legitimate interests / legal obligations where applicable).
  • Emails (verification, account notices) (contract / legitimate interests).

5. Sharing and processors

We use service providers (“processors”) to operate Core51. Typical categories include hosting/VPS providers, email delivery (SMTP), and object storage for encrypted attachments. We share only the data necessary to provide the service.

6. International transfers

Depending on where you and our providers are located, personal data may be processed outside the EEA/UK. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) and apply security measures.

7. Retention

We retain account and service data for as long as your account is active and as needed for service operation, security, and dispute resolution. Encrypted content may be retained until deleted or as described in product settings.

8. Your rights

Where GDPR applies, you may have the right to access, rectify, delete, restrict processing, object, and data portability. You may also withdraw consent where processing is based on consent.

9. Security

We apply technical and organizational measures to protect data, including encryption, access controls, and auditability features. No system is perfectly secure; as a beta service, Core51 may change quickly and may contain defects.

10. Contact and complaints

Contact us at info@core-51.com. If you are in the EEA/UK, you may also lodge a complaint with your local supervisory authority.