Privacy Policy
CoreX respects individual privacy and values the confidence of its customers, employees, business partners, and others.
CoreX respects individual privacy and values the confidence of its customers, employees, business partners, and others.
Not only does CoreX strive to comply with the laws of the countries in which it does business when it collects, uses, and discloses Personal Data, but it also is committed to upholding the highest ethical standards in its business practices. This Privacy Policy (the “Policy”) sets forth the privacy principles CoreX follows with respect to transfers of Personal Data within and to the United States.
For purposes of this Policy, the following definitions shall apply:
When you choose to provide us with Personal Data about third-parties, we will only use this data for the specific reason for which you elect to provide it. It is your responsibility to ensure that when you disclose to CoreX. Personal Data of individuals other than yourself – such as your contacts, your users, or other third-parties – you abide by applicable privacy and data security laws, including informing users and third-parties that you are providing their Personal Data to CoreX, informing them of how it will be transferred, used, or processed, securing appropriate legal permissions and safeguards required for such disclosures, transfers and processing. If you choose to provide CoreX with a third-party’s Personal Data (such as name, email, and phone number), you represent that you have the third-party’s permission to do so. You also acknowledge that when we interact with such third-party individuals whose Personal Data you share with us, it is our duty to inform them that we obtained their Personal Data from you.
We use your Personal Data for the purposes outlined below:
On the basis of fulfilling our contract with you or entering into a contract with you on your request, in order to:
On the basis of your consent, in order to:
On the basis of legal obligations, we are obligated to, for instance, keep records for tax purposes or answer compelling orders and provide information to public authorities.
On the basis of our legitimate interest in the effective delivery of our products/services and communications to you as well as to our other customers and partners, in order to:
We will only process Sensitive Personal Information relating to you for specific purposes outlined above or in relevant product/services notices, because either: 1) You have given us your explicit consent to process such data; or 2) The processing is necessary to carry out our obligations under employment, social security or social protection law; 3) The processing is necessary for the establishment, exercise or defense of legal claims; or 4) You have made such data public.
On the basis of our legitimate interest, we and our third-party partners may combine the data we collect from you over time from our websites, products/services with data obtained from other sources. We combine your data with other sources to improve user experience on our websites and services we provide.
On the basis of legitimate interest, we process Personal Data for network and information security purposes. Pursuant to Recital (49) of the EU General Data Protection Regulation (“GDPR”), organizations have a recognized legitimate interest in collecting and processing Personal Data to the extent strictly necessary and proportionate for the purposes of ensuring network and information security. According to said Recital (49), network and information security means the ability of a network or of an information system to resist events, attacks, or unlawful or malicious actions that could compromise the availability, authenticity, integrity, and confidentiality of stored or transmitted data, or the security of the related services offered by, or accessible via those networks and systems. Both as an organization in our own right, and as a provider of services which may include hosted and managed computer emergency and security incident response services, it is in our legitimate interests as well as in our customers’, as laid down in Article 6(1)(f) of the GDPR, to collect and process Personal Data to the extent strictly necessary and proportionate for the purposes of ensuring the security of our own, and of our customers’ networks and information systems. This includes the development of threat intelligence resources aimed at maintaining and improving on an ongoing basis the ability of networks and systems to resist unlawful or malicious actions and other harmful events (“cyber-threats”). The Personal Data we process for said purposes includes, without limitation, network traffic data related to cyber-threats such as:
Depending on the context in which such data is collected, it may contain Personal Data concerning you or any other data subjects. However, in such cases, we will process the data concerned only to the extent strictly necessary and proportionate to the purposes of detecting, blocking, reporting (by removing any personally identifiable elements), and mitigating the cyber threats of concern to you, and to all organizations relying on our products/services to secure their networks and systems. When processing Personal Data in this context, we will not seek to identify a data subject unless strictly indispensable to the remediation of the cyber-threats concerned, or required by law.
If you believe that your Personal Data was unduly collected or is unduly processed by CoreX for such purposes, please refer to the “Your Privacy Rights” and “Contact Us” sections below. Please be aware that if it is determined that Personal Data concerning you is processed by CoreX because it is necessary for the detection, blocking, or mitigation of convicted cyber-threats, in line with GDPR Article 21(1), objection, rectification, or erasure requests may be rejected. It is our compelling legitimate interests to protect our organization and our customers from cyber threats, and therefore our interest may override your objection, rectification or erasure requests until you demonstrate the measures necessary to dissociate your Personal Data from any identified cyber-threat.
CoreX has a legitimate interest in promoting our commercial offerings and to optimize the delivery of communications to that effect to our customers and audiences that are most likely to find them relevant. We will therefore collect and process data to that end as explained below. However, where we are legally required to obtain your consent to provide you with certain marketing materials, and we will only provide you with such marketing materials where we have obtained such consent from you. If you do not want to continue receiving any marketing materials from us, you can click on the unsubscribe function in the communication or e-mail.
We do not sell, lease, rent or give away your Personal Data. We only disclose your Personal Data as described below, within CoreX, with our partners, with service providers that process data on our behalf and with public authorities, as required by applicable law. Processing is only undertaken for the purposes described in this Policy and the relevant product/services privacy notices. If we disclose your Personal Data, we require its recipients to comply with adequate privacy and confidentiality requirements, and security standards.
To make sure your Personal Data is secure, we communicate our privacy and security guidelines to CoreX employees and strictly enforce privacy safeguards within CoreX. CoreX secures your Personal Data, and the Personal Data of others on computer servers in a controlled, secure environment, protected from unauthorized access, use or disclosure. CoreX protects your information using technical, physical, and administrative security measures to reduce the risk of loss, misuse, unauthorized access, disclosure or modification of your information. Some of our safeguards include firewalls, data encryption, physical access controls, and administrative informational controls. While we have employed security technologies and procedures to assist safeguarding the information we collect from or about our users and their devices, no system or network can be guaranteed to be completely secure. However, no data transmission over the Internet can be guaranteed as 100% secure. As a result, while we strive to protect your information, we cannot ensure or warrant the security of any information you transmit to us or receive from us.
Some measures that we employ to protect your Personal Data include:
How long we retain or store your Personal Data: We will hold your Personal Data on our systems for the longest of the following periods:
For the sake of clarity in the event that CoreX is a data controller processing your Personal Data for our own purposes, your Personal Data will be deleted or de-identified when it is no longer needed for its originally stated processing purposes, or any additional compatible purpose for which CoreX may lawfully further process such data. Moreover, where CoreX is a data processor processing your Personal Data for the purposes and on the instructions of another data controller or data processor, we will comply with the time limits agreed with that other Controller or Processor unless we are compelled by applicable laws and regulations to delete such data sooner, or to retain it further.
Access to Personal Data: You can help ensure that your contact information and preferences are accurate, complete, and up to date by logging in to your account, and advising us of changes. For other Personal Data we hold, we will provide you with access for any purpose including to request that we correct the data if it is inaccurate or delete the data if CoreX is not required to retain it by law or for legitimate business purposes. We may decline to process requests that are frivolous/vexatious, jeopardize the privacy of others, are extremely impractical, or for which access is not otherwise required by local law. Access, correction, or deletion requests can be made per the Privacy Questions section below. Access, correction, or deletion requests can be made per the Privacy Questions section below.