Privacy Policy
Current as of July 28, 2026
This Policy explains how CoreTV LLC collects, uses, discloses, protects, retains, and responds to requests concerning personal information.
1. Overview & Scope
This Privacy Policy applies to all personal data collected by CoreTV LLC (trading as CORE) through our website, client portal, CORE shop, booking system, estimate builder, email communications, and any other service or product we offer. It applies to clients, prospective clients, visitors, contractors, and anyone else who interacts with CORE.
This Policy is a notice, not a request for blanket consent. CORE relies on the processing basis that applies to the activity—such as performing a contract or requested pre-contract step, operating and securing the service, complying with law, pursuing a permitted legitimate interest, or obtaining consent. Where consent is required, CORE requests it in the relevant interface or interaction.
2. Information We Collect
Identity & Contact Data: name, email address, phone number, company name, and mailing address provided during account registration, checkout, or contact form submission.
Account Data: login credentials (hashed password), account preferences, client portal activity, project history, and communications with CORE staff.
Billing & Payment Data: billing name, billing address, permitted payment-method references, last four digits, card type, transaction IDs, invoice data, and risk or authorization metadata. Full card numbers are collected and hosted by the configured PCI-compliant payment processor and are not stored in CORE's application database.
Technical & Usage Data: IP address and request-security metadata received when the service is accessed; browser and operating-system family; pages, referral source, session and interaction data; and first-party or provider identifiers. Optional analytics, advertising, and pseudonymous browser-signal collection follows the consent and privacy-signal controls described in the Cookie Policy.
Communications: emails, support tickets, chat transcripts, and other correspondence you send to CORE.
Project & Content Data: files, images, text, brand assets, and other materials you upload or share with CORE in the course of a project.
Domain & Broker Data: requested domain names, registrant contact details, WHOIS or registry information, broker inquiry details, seller communications, proposed purchase terms, escrow or transfer status, and related domain administration records.
3. Business Discovery & Public-Record Lead Intelligence
Authorized CORE staff may use a live Google Maps/Places finder and other lawful public sources, such as official business websites, government or professional registries, and public business directories, to identify and evaluate prospective business customers. Source facts may include a business name, public business address and phone number, published website or social profile, map coordinates, business status, ratings, Google Place ID, and the source provider or URL. Where supported, CORE also records when a source was observed or verified so staff can distinguish sourced facts from internal notes or analysis.
Google receives the ZIP code, business category, radius, and related technical data needed to answer a finder request. Google-derived business details are displayed live with required attribution and are never durably stored by CORE. CORE retains only the exempt Google Place ID plus its own discovery, review, suppression, provenance, and CRM-link state. If staff creates a CRM shell after a fresh live review, the shell contains the Place ID and CORE workflow metadata only—not the Google name, address, phone, website, coordinates, rating, or business-status fields—and must be enriched from an independent permitted source. Use of live results is also subject to the Google Maps/Google Earth Additional Terms of Service and the Google Privacy Policy.
Public-source information can be incomplete, outdated, or incorrect. Staff must review the displayed source and verify material contact details before relying on them. These lead-discovery tools do not infer or guess personal email addresses or personal phone numbers, access private or restricted data, or automatically call, text, or email a prospect. Any later outreach is a separate, human-authorized action and must use a lawfully published business channel or information supplied directly to CORE.
CORE checks active global do-not-call and suppression records using available business identifiers and phone numbers. A suppressed result is not eligible for import through the finder, and staff must not use it for outreach. CORE may retain the minimum identifier and suppression history reasonably needed to honor an opt-out and prevent renewed contact.
4. How We Use Your Information
To deliver and administer services: process orders, manage subscriptions, bill for services, fulfill project work, provide hosting, and maintain your client portal.
To communicate: send transactional emails (receipts, invoices, project updates, password resets), respond to support requests, and send account notifications.
Marketing communications: CORE sends promotional email only with consent or another lawful basis applicable to email and the recipient. CORE sends promotional SMS, automated or artificial/prerecorded voice, or automated cross-channel follow-up only with the affirmative consent or other specific authorization required for that technology, purpose, and jurisdiction. An existing relationship or published business contact is not by itself treated as consent where the channel or law requires affirmative permission. CORE respects channel-specific consent, suppression, quiet-hour, do-not-call, STOP/unsubscribe, and revocation records and provides the opt-out method required for the message.
Analytics & improvement: analyze usage patterns to improve our website, shop, and services. We use aggregated, anonymized data for this purpose where possible.
Domain services: check domain availability, register or transfer domains through the configured registrar, configure DNS, administer renewals, contact domain owners or marketplaces for broker requests, coordinate escrow or transfer steps, and maintain records needed for registrars, registries, and dispute processes.
Legal compliance: retain records required by tax, accounting, or other applicable law; respond to lawful requests from authorities.
5. Data Storage & Infrastructure
CORE uses configured cloud, database, hosting, content-delivery, and storage providers. Current core providers can include Supabase, Vercel, Railway, and Cloudflare, while AWS or another provider may be used for a particular storage or client configuration. Processing locations depend on the provider, feature, and project settings and are primarily in the United States unless the order or provider configuration says otherwise.
CORE uses transport encryption for supported connections and provider-managed encryption at rest where available, together with credential, session, access-control, monitoring, backup, and recovery safeguards appropriate to the service. Specific algorithms, token lifetimes, regions, and backup schedules can vary by provider and configuration.
We apply role- and assignment-based access controls. Authorized personnel may access only the records needed for their role, client ownership, project participation, support, security, or other approved purpose. Privileged and auditable actions are logged according to the configured system; CORE does not claim that every ordinary read generates a separate immutable event.
6. Third-Party Service Providers
We share personal data with service providers only as needed for enabled functions. Depending on configuration, provider categories include payment and tax, database and authentication, hosting and delivery, DNS and domains, email, voice and messaging, AI and transcription, embeddings or search, rate limiting, error monitoring, analytics and advertising, source control, storage, and client-selected integrations. The DPA identifies representative core and optional providers and the accepted order can identify project-specific providers.
For domain registration, transfer, renewal, and brokered acquisition requests, we may share necessary contact, billing, domain, and transaction information with the configured registrar, applicable registries, escrow providers, domain marketplaces, the current registrant or representative, and other parties needed to complete or attempt the transaction.
Providers process information under the applicable contract, instructions, and service terms. CORE uses data-protection terms where required and evaluates providers proportionate to the data and function, but a provider may independently process limited account, abuse-prevention, billing, or legal-compliance information under its own terms.
CORE does not sell personal information for monetary consideration. Optional advertising, remarketing, conversion, or cross-context activity described in the Cookie Policy may be treated by an applicable statute as a sale, sharing, targeted advertising, or profiling even without a monetary payment. CORE subjects that activity to its consent and privacy-signal controls and honors any covered opt-out right.
7. Billing Information Retention
Billing records — including invoices, payment amounts, transaction IDs, and billing metadata — are retained for category-specific periods based on tax and accounting rules, applicable limitation periods, fraud prevention, payment disputes, legal holds, and other documented business or legal needs. They are not treated as subject to a blanket indefinite-retention requirement.
Billing contact details, permitted payment-method references, last-four digits, invoices, and transaction metadata follow category-specific retention based on the account, tax and accounting rules, limitation periods, fraud prevention, disputes, legal holds, and processor requirements. Full payment-card numbers are not stored in CORE's application database.
After a verified deletion request, CORE deletes, de-identifies, restricts, or retains each billing category according to the applicable purpose and lawful exception. Some records may need to remain identifiable to establish authorization, satisfy accounting or tax duties, prevent fraud, or resolve a dispute.
8. Cookies & Tracking Technologies
We use strictly necessary cookies and first-party storage to operate security, authentication, preferences, carts, drafts, and requested sessions. Optional analytics, advertising, personalization, and pseudonymous browser-signal processing begins only as described in the Cookie Policy and the active consent or privacy-signal state.
When enabled, Google Analytics, Google Tag Manager, advertising tags, or a project-specific measurement provider may receive page, campaign, device, and interaction information for measurement or advertising under its own terms. Such data may be pseudonymous rather than fully anonymous.
Error, performance, and privacy-filtered reliability monitoring is separate from optional advertising. The feature-specific sections below describe its categories, masking, and purpose.
9. Account Data
When you create a CORE account, we collect and store your profile information, preferences, project history, communication logs, and any documents associated with your engagements. This data is accessible to you in the CORE client portal.
If CORE creates a portal account during onboarding, the invite and account controls identify the authorized account. Personal data is not treated as property; rights and access are governed by applicable law, the account role, the controlling agreement, and the Privacy Policy. Documents and export tools are available only where the applicable service and permissions expose them.
10. Data Deletion Requests
You may request deletion of personal data where the applicable law or CORE's voluntary process provides that option. Email legal@coretv.co with the subject line 'Data Deletion Request' and include the email address associated with your account. CORE verifies requests and may retain information covered by a lawful exception, legal hold, suppression duty, or security need.
CORE acknowledges and responds to a verified request within the period required by the law that applies to the request or, for a voluntary request, within the operational schedule communicated during intake. CORE will confirm the completed action or explain any permitted exception, extension, verification need, or appeal path.
11. Account Data Deletion Process
For a verified request, CORE identifies the eligible record categories and may deactivate access; delete, de-identify, export, or restrict profile, communication, and project records; notify relevant processors; and preserve only categories covered by a lawful exception, legal hold, security need, contract, or unresolved dispute.
A privacy request does not require cancellation of an unrelated service. Account closure or deletion of data necessary to deliver an active service may require resolution of authority, billing, domain, project, export, or transition steps, but CORE will process other eligible categories without using the active service as a blanket reason to deny the request.
Residual copies may remain temporarily in encrypted backups until they age out under the applicable backup lifecycle. CORE restricts restoration and ordinary use of data that is pending deletion, subject to security, disaster-recovery, legal-hold, and other lawful exceptions.
12. Data Security
We implement safeguards appropriate to the service and risk, including supported transport encryption, provider-managed or application-level encryption for configured protected data at rest, access controls, monitoring, dependency and configuration review, backup or recovery measures where included, and role-appropriate staff security practices.
Despite these measures, no system is completely secure. If a data incident triggers a notification duty, CORE will notify affected people and authorities without unreasonable delay and within the period required by the law that applies after CORE has made the necessary determination.
13. Data Retention
We retain personal data for as long as reasonably needed for the service or interaction, account continuity, security, tax and accounting duties, dispute resolution, legal claims, suppression obligations, and other documented business or legal purposes. After account closure, data is deleted, de-identified, or restricted according to its category, configured lifecycle, unresolved obligations, and any legal hold; not every category follows the same deadline.
Domain registration, transfer, broker, escrow, renewal, and dispute-related records may be retained longer where registrar, registry, ICANN, accounting, fraud prevention, or legal obligations require it.
14. Your Privacy Rights
Depending on your jurisdiction, you may have rights including: access to your personal data; correction of inaccurate data; deletion of your data (subject to legal retention requirements); data portability (receiving a copy of your data in a machine-readable format); objection to processing; and withdrawal of consent.
Florida residents and other U.S. consumers may have additional rights when a state law applies to CORE and the processing. EU/UK data-protection law may apply when its territorial-scope rules are met, such as when services are offered to or behavior is monitored in the covered territory; residence alone does not decide applicability. To submit a request, contact legal@coretv.co.
15. Children's Privacy
CORE services are not directed to children under 13 or any higher minimum age that applies to the relevant service and jurisdiction, and CORE does not knowingly collect children's personal data in a manner requiring parental authorization. If you believe a child submitted personal data, contact legal@coretv.co so CORE can investigate and take the action required by applicable law.
16. Changes to This Policy
We may update this Privacy Policy as products, providers, or legal requirements change. The 'Current as of' date identifies the published version. CORE provides additional notice or obtains fresh consent when the applicable law, contract, or nature of a material change requires it; this notice does not turn continued use into consent where the law requires an affirmative choice.
17. Voice, Recordings & Biometric Identifiers
CORE's voice services may process telephone or browser audio, synthesized speech, voicemail, transcripts, captions, routing events, and call metadata. Recording or transcription begins only after the notice and consent required for the interaction, including all-party consent where applicable.
CORE uses this information to operate the requested call, route or transfer it, provide captions or transcripts, prepare a summary, create a requested lead, booking, estimate, or support record, investigate quality or security issues, bill metered usage, and resolve disputes. Access is restricted to authorized personnel and linked records.
CORE does not create a voiceprint to identify a person by default. If a separately scoped feature would derive a biometric voice identifier for authentication or identification, CORE will provide a specific notice, obtain any legally required written consent, publish the purpose and retention schedule, and offer any alternative required by law before enabling it.
Voice data is retained according to the service, consent, account, dispute, security, and legal requirements that apply, then deleted or de-identified where reasonably feasible. Submit a verified request to legal@coretv.co. Clients operating CORE voice features remain responsible for their own caller notices and lawful instructions; CORE remains responsible for obligations that apply directly to CORE.
18. AI Processing & Model Training
CORE's service architecture uses artificial-intelligence systems to deliver its features. Client data and end-user data submitted to or generated by CORE may be processed through this AI architecture solely to provide, operate, and support the services requested by the Client.
CORE uses configured model, transcription, speech, embedding, or search APIs, which can include Anthropic, OpenAI, ElevenLabs, Deepgram, Voyage, Pinecone, or another provider selected for the feature. CORE does not authorize private client, applicant, or end-user content for public-foundation-model training. Provider retention and model-improvement treatment follow the applicable service plan and terms, so CORE does not make a blanket no-retention promise for every provider.
CORE does not authorize private client or applicant content for training a public foundation model. Model providers may retain limited information for abuse prevention or service operation under their enterprise terms. A client-specific fine-tuning or training project requires a separate written scope, risk review, and any consent required by law.
19. Florida Digital Bill of Rights & State Privacy Rights
CoreTV LLC is a Florida limited liability company. The Florida Digital Bill of Rights and other state privacy statutes apply only when their definitions, revenue or processing thresholds, territorial rules, and exemptions are met. CORE does not claim that the FDBR applies merely because CORE is organized in Florida. Where a law grants a right for a covered interaction, CORE will honor it to the extent required.
Subject to identity verification and the rights, thresholds, and exceptions of the applicable process, you may request access, correction, or deletion of covered personal data. Billing, tax, voice, domain, consent, security, suppression, acceptance, and dispute records may be retained in identifiable, restricted, or de-identified form for a documented service, compliance, security, claim, or legally permitted purpose.
To exercise a right or use CORE's voluntary privacy-request process, email legal@coretv.co identifying the request and the email address associated with your account. CORE will verify and respond within the timeframe the applicable process requires. If CORE declines a request in whole or in part, it will explain the basis and any appeal method required by law.
20. Contact
For privacy questions, access requests, or complaints: legal@coretv.co. CoreTV LLC is registered in the State of Florida, United States.
21. Browser identity, device signals & session linking
CORE uses a first-party visitor or device identifier to keep an estimate, cart, application draft, chat, and other in-progress work available in the same browser. For signed-in users, device observations may also support account security and continuity. For unauthenticated visitors, additional pseudonymous browser-signal collection is enabled only after non-essential personalization consent.
Those signals may include coarse screen size and pixel ratio, color depth, time zone, language, browser and operating-system family, device capability buckets, and cryptographic hashes derived from user-agent, canvas, and WebGL characteristics. CORE also receives IP address and network information from ordinary web requests. Stable raw browser attributes are protected or transformed server-side. Similarity between a device or network and another record is treated only as a possible match for review—not proof that two people are the same.
If a visitor later verifies a phone number or email address, or signs in to an account, CORE may link that confirmed identity to earlier CORE sessions, leads, estimates, chats, calls, bookings, or requests so the person can resume work and staff can avoid duplicate or disconnected records. We do not use this feature to identify an unrelated person from a fingerprint alone.
Separately, an inbound caller number asserted by the telephony provider may be compared with a stored number to suggest a possible lead or client association and reconnect a recent linked browser session. Caller ID is not treated as verified identity on its own; account-changing or sensitive actions remain subject to the platform's separate authentication, authorization, and approval controls.
22. Calls, chats & conversation intelligence
When enabled and lawfully noticed, CORE processes call audio, chat content, live transcription, voicemail, call metadata, routing and transfer events, and staff notes. We may create summaries and limited inferences such as topic, urgency, sentiment, purchase intent, support risk, or recommended next action. These records may be linked to a lead, client, estimate, proposal, project, support ticket, request, or booking.
Recording or transcription begins only after the notice and consent required for the interaction. Ordinary call audio is not used to establish a biometric identity unless CORE separately discloses that purpose and obtains any consent the law requires. A person may request an available non-recorded or non-voice channel.
Conversation classifications help route work and assist staff; they may be incorrect and are not used by themselves to make a binding price, legal, employment, cancellation, or other significant decision. Authorized staff review material actions under the role and assignment controls described in this Policy.
23. Remote-assist & co-browsing data
A remote-assist session may process the current CORE page path or field context, invitation and guide or form-assistance consent events, navigation or highlight commands, limited prefill values, revocation, timestamps, and staff identity. The platform records this information to deliver the session, enforce its configured CORE portal page and field allowlist, investigate misuse, and maintain an audit trail.
Remote control is opt-in and time-limited. The participant chooses the offered interaction mode and can revoke it at any time. Sensitive credentials, payment-card inputs, authentication codes, signatures, legal acceptances, and final approval controls are outside the permitted command set. CORE does not activate hidden continuous screen control through this feature.
24. Estimates, proposals, automation & analytics
CORE processes estimate and cart selections, outcome answers, budgets, deadlines, uploaded files and source URLs, scope assumptions, architecture and dependency nodes, timeline choices, proposal comments, approvals, payment-choice state, and interaction events such as opening or comparing a proposal, viewing a section, inviting a collaborator, asking a question, or downloading an artifact. We use this information to prepare requested services, extract a structured intake draft and source references, explain pricing, detect missing scope, calculate first-touch, last-touch, or position-based attribution, provide authorized staff with deal-health or risk signals, and offer relevant assistance.
An intake extraction, citation, architecture fact, dependency, cost explanation, attribution result, or proposal-activity inference may be incomplete or incorrect. Submitted files or URLs may be parsed by configured extraction, search, or AI providers for the requested workflow. Use the designated credential or delegated-access channel for secrets; do not place passwords, authentication codes, private keys, or payment-card data in a general intake, proposal comment, or AI prompt.
Lifecycle and follow-up tools may use consent status, channel, recent interactions, stage, scheduling, objections, and stop conditions to select and time an approved email, SMS, call, or task. Frequency caps, suppression records, and human-review policies limit these workflows. You may opt out of marketing communications using the method in the message; service and security notices may still be sent.
25. Applications, onboarding & certifications
For applicants and team members, CORE may process application answers, work history, resume and cover-letter files, location and time zone, referral information, draft progress, reminder consent, interview or review status, optional voice-introduction audio and transcript, learning results, capability evidence, certification records, and staff date of birth. When the documented applicant self-identification program is lawfully enabled, CORE may also collect voluntary race or ethnicity, gender, protected-veteran, and disability responses on a separate questionnaire. Reviewers may add job-related notes and decisions. Date of birth supports authorized personnel administration and birthday reminders.
Candidate-recovery tools may process the current missing-evidence list, estimated time to finish, reminder schedule and channel, last activity, expiration, and opt-out state. Learning tools may map role requirements, prerequisites, submitted evidence, practice results, assigned content, progress, and authorized work signals to suggest a training path. These records support recruiting administration and staff development and remain subject to the access, human-review, and retention controls described here.
The voluntary questionnaire is disabled by default and is enabled only after a super-admin records the current compliance attestation for a documented, counsel-reviewed affirmative-action program. The responses are requested solely to administer and evaluate efforts intended to benefit individuals with disabilities, protected veterans, and other underrepresented groups; are confidential and stored outside the application record; are unavailable to ordinary application reviewers; and are excluded from AI, conversation scores, ranking, interviewing, and hiring or engagement decisions. Refusal does not affect the application or cause adverse treatment. Individual responses are retained for 730 days by default and then deleted through the governed retention job unless a documented legal requirement or legal hold changes that deadline. Aggregate compliance reporting suppresses groups with fewer than five responses and is purpose-logged. The questionnaire is not an accommodation request; accommodation intake is handled separately and should include only the information reasonably needed to respond.
Optional voice introductions have a text alternative and are retained only for the application or review purpose and the applicable retention period. A certification-passport link currently displays the holder's public profile identity and all active credentials included by that passport configuration; the link or an underlying credential may expire or be revoked. CORE does not sell applicant data and does not use a conversation score or AI-generated recommendation as the sole basis for a final employment or engagement decision.
26. Client-success signals, relationship links & decision history
CORE may create daily or event-driven service-health and client-success indicators from project and milestone progress, ticket and escalation history, satisfaction feedback, outstanding requests, billing or delinquency status, and the age of unresolved work. The resulting status, score, risk factors, and recommended actions are visible only to authorized account staff and, where designed for the client, as a limited client-facing status.
Project workspaces may process blueprint versions and assignments; tasks, milestones, dependencies, readiness requirements, verification or waiver records; deliverable and request decisions; comments, mentions, collaborator invitations; portal history; and configured infrastructure or vendor-usage measurements and thresholds. Staff workspaces may process assignment, ownership, availability, queue, workload, escalation, and claim history to route authorized work. A universal search may process a query and matching record identifiers within the searcher's existing permissions; search does not expand access to the underlying record.
CORE may also store direct or proposed relationships among leads, accounts, estimates, quotes, projects, requests, communications, and other records, together with a confidence level, supporting evidence, confirmer, visibility, and append-only decision or approval history. These inferred or proposed links can be incorrect and are reviewed or corrected through the applicable workflow. They do not by themselves determine eligibility, price, a service credit, employment, cancellation, or another legal or similarly significant effect.
27. Issue reports & security diagnostics
When you prepare or submit an issue report, CORE may collect your message, the page and attempted route, reference or error identifier, date and time, referrer, browser and version, operating system, device type, viewport and screen dimensions, language, time zone, user agent, a diagnostic hash, and any screenshot or file you choose to capture or upload. A screenshot can be stored before final submission so you can preview it. An abandoned pending upload remains subject to the issue-report storage cleanup and security process. The request IP may be used transiently for rate limiting and security but is deliberately omitted from the stored issue-report record.
CORE uses diagnostics to reproduce and fix errors, detect duplicate or abusive reports, secure the service, and maintain incident history. Do not include passwords, payment details, private keys, health information, or other unnecessary sensitive data in a report or screenshot. Rate-limit, blocklist, and abuse events may be retained to defend the platform and enforce this Policy.
28. Reliability monitoring & privacy-filtered replay
CORE uses error, performance, and reliability monitoring to diagnose failures and protect the service. Depending on configuration and sampling, this can include route, timing, browser, device, network, error stack, interaction breadcrumb, and a privacy-filtered session replay. The monitoring configuration masks text and inputs, blocks media, and removes known personal fields before transmission, but do not enter unnecessary sensitive information into an error-producing field.
Reliability monitoring is operated separately from optional advertising tags and is used for service security and fault diagnosis. Monitoring providers act under their applicable service terms and receive only the information configured for the diagnostic purpose.
29. Security screening & rights-request case data
For public intake, booking, chat, estimate, cart, newsletter, application, upload, and issue-report workflows, CORE may transiently compare the request IP address or network and submitted email domain against administrator-managed security rules, allowed-domain exceptions, and a maintained disposable-email-domain dataset. Signed-in authentication may be evaluated against an IP or network deny rule, but a later change to the disposable-domain dataset is not used by itself to lock an existing account. A rule match is a security signal, not proof of identity, fraud, or misconduct.
Security configuration may contain exact IP addresses, CIDR network ranges, blocked email domains, allowed-domain exceptions, rule status, reason, creator, and timestamps. Denied public requests receive a generic response so the rule cannot be enumerated. CORE limits administrative audit summaries to information such as configuration action, actor, time, and list counts and does not place the raw denied value in that audit summary. CORE may retain a protected deny rule or separate security evidence for as long as reasonably necessary to prevent abuse, investigate an incident, comply with law, or resolve a documented false-positive review.
A privacy-rights case may contain the requester's contact information, request type and scope, identity or authority verification, affected accounts and record categories, jurisdiction information supplied for the request, deadlines and extensions, communications, searches performed, decisions, appeal status, fulfillment evidence, legal holds, and an audit history. CORE uses that information to authenticate the requester, coordinate the response, prevent unauthorized disclosure or deletion, demonstrate compliance, and enforce applicable rights. Request records are retained only for the period reasonably necessary for those purposes and applicable limitation or recordkeeping periods.
30. Processing bases, privacy rights & appeals
Depending on the activity and applicable law, CORE processes personal information to perform a contract or take requested pre-contract steps, operate and secure the service, comply with law, pursue legitimate business interests that do not override applicable rights, or act on consent. Consent can be withdrawn for future processing, but withdrawal does not make earlier lawful processing invalid.
Where an applicable privacy law grants a right, you may request access, correction, deletion, or portability; opt out of covered targeted advertising, sale, sharing, or qualifying profiling; limit certain sensitive-data uses; or appeal a denied request. CORE may verify identity and authority, preserve data subject to a legal hold or permitted exception, and respond within the legally applicable period. Rights depend on the law's scope and thresholds; this Policy does not claim that every statute applies to every interaction.
Download this document
Save a PDF copy for your records.