Legal · Privacy policy

Privacy policy.

Last updated · July 2026

This Privacy Policy describes how CoreDesk handles personal data at hccoredesk.com. CoreDesk is operated by HC Core Tech, based in Almere, Netherlands (KvK registration pending), which acts as the data controller for the purposes described here. Personal data is processed lawfully, transparently, and only for the purposes described below, in accordance with the EU General Data Protection Regulation (GDPR) and Dutch data-protection law.

This policy governs the CoreDesk product only. Separate privacy terms apply to HC Core Tech consulting engagements conducted through hccoretech.com.
01

Data controller

For personal data processed in connection with account creation, billing, and general use of CoreDesk, HC Core Tech is the data controller. In respect of the personal data that Users enter into their own workspaces, HC Core Tech acts as a data processor on the User's behalf; that relationship is governed by the separate Data Processing Agreement.

Contact for privacy questions: hello@hccoredesk.com (backup: hc@hccoretech.com).

02

Personal data CoreDesk collects

Depending on how the User interacts with the platform, CoreDesk collects the following categories of data:

  • Account data— name, business name, email address, contact details, and the sign-in credentials required to access the workspace.
  • Workspace content — client records, emails, meeting notes, financial records, drafts, and any other content the User creates or imports into the workspace.
  • Usage and log data — sign-in events, feature usage, error logs, IP address, browser type, and system information required for operating and securing the platform.
  • Billing data — invoice records and payment reference numbers. Payment details themselves (card numbers, bank account details) are processed by third-party payment providers and are not stored by CoreDesk.
04

Where data is hosted

All CoreDesk workspace data is hosted in the European Union. The primary infrastructure runs on Hetzner Cloud in Helsinki, Finland. Each active workspace uses a dedicated Postgres database. Backups are also stored within the EU. Workspace data is not transferred to jurisdictions outside the European Economic Area without adequate safeguards in place (see Section 6 on international transfers).

05

Sub-processors

CoreDesk relies on a small number of trusted third-party providers to operate the platform. Current sub-processors include:

  • Hetzner Online GmbH (Germany, EU) — infrastructure hosting.
  • Anthropic PBC (United States) — large-language-model processing for AI drafting and triage features, with EU data-residency routing where available.
  • OpenAI L.L.C. (United States) — where the User has explicitly enabled OpenAI-powered features, model processing for drafting and triage.
  • Microsoft Ireland Operations Limited (Ireland, EU) — email and calendar integration (Microsoft Graph) where the User connects a Microsoft 365 account.
  • Google Ireland Limited (Ireland, EU) — where the User connects Google Workspace / Google Meet for meetings.
  • Stripe Payments Europe Limited (Ireland, EU) — payment processing.
  • Vercel Inc. (United States, EU regional deployments where selectable) — hosting for the public marketing surface at hccoredesk.com.

The full authoritative list is maintained in the Data Processing Agreement. Users are notified at least thirty (30) days before any new sub-processor is added.

06

International transfers

Where personal data is transferred outside the European Economic Area (for example, to AI-model providers based in the United States), such transfers are covered by the European Commission's Standard Contractual Clauses (2021/914), supplementary technical measures such as at-rest encryption, and, where the recipient participates, the EU-US Data Privacy Framework.

07

AI processing

When the User invokes AI-assisted features, relevant workspace content is transmitted to the AI provider selected for that feature. AI requests are routed through providers that contractually agree not to use User content to train their general foundation models and that offer EU data-residency options where available.

Nothing sends, publishes, or acts across the workspace on the User's behalf without explicit User approval. This approval-first governance model is documented in the audit trail and can be reviewed at any time from within the workspace.

08

Data retention

Workspace data is retained for the duration of the User's active subscription. Upon termination, the workspace is preserved for ninety (90) days as a safety buffer during which the User may still request an export. After that period, the workspace and its content are deleted.

Certain records must be retained for longer periods to comply with Dutch legal obligations: invoices and financial records are retained for seven (7) years, as required by the Dutch Fiscal Code. Log data required for security or audit purposes is retained for up to twelve (12) months.

09

Data-subject rights

Data subjects (Users, and where applicable the individuals whose data appears within a User's workspace) have the following rights under GDPR: access, rectification, erasure, restriction of processing, portability, and objection to processing. Where processing is based on consent, that consent may be withdrawn at any time.

Requests may be made by writing to hello@hccoredesk.com, with hc@hccoretech.com as a backup. Verified requests are responded to within thirty (30) days. Requests concerning data held on behalf of a User (workspace content) are forwarded to that User for handling and may be answered by them directly under the terms of the Data Processing Agreement.

Data subjects may also lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with their local supervisory authority in another EU member state.

10

Cookies and tracking

The CoreDesk platform uses only strictly necessary cookies required for authenticated sessions and security. No advertising cookies, no third-party analytics that identify individual visitors, and no cross-site trackers are used on hccoredesk.com.

11

Security and breach notification

CoreDesk applies industry-standard security measures including encryption at rest and in transit, per-workspace database isolation, access-control auditing, and regular backups. Security measures are described in more detail in the Data Processing Agreement.

In the event of a personal data breach affecting a User's data, the affected User will be notified within twenty-four (24) hours of CoreDesk becoming aware of the breach, and the competent supervisory authority will be notified as required by GDPR Article 33.
12

Children

CoreDesk is not directed to children under the age of sixteen (16). CoreDesk does not knowingly collect personal data from children. If a User believes such data has been provided in error, they should contact hello@hccoredesk.com (or hc@hccoretech.com) so it may be promptly deleted.

13

Changes to this policy

This Privacy Policy may be updated from time to time. Material changes are communicated by email to Users at least thirty (30) days before they take effect. The “Last updated” date at the top of this page always reflects the current version.

Terms of servicePrivacy policyData processing