Corelo

Legal

Privacy Policy

Effective date: 21 September 2026

Corelo AI Ltd ("Corelo," "we," "us," "our") is committed to protecting your privacy. This policy explains what personal data we collect, why we collect it, the legal basis we rely on, and how we handle it.

1. Who we are

Corelo AI Ltd is a company registered in England and Wales, company number 17302072. Our registered office is 124-128 City Road, London, EC1V 2NX.

If you have any questions about this policy or how we handle your data, contact us at [email protected].

2. What data we collect

If you visit our website, we collect basic analytics data (such as pages viewed, general location, and device type) using privacy-preserving, cookie-free analytics tools, and the details you submit through the booking form: your first name, surname, and email address.

If you become a client, we collect the contact details and business information needed to deliver our services, including anything shared with us while your service is being set up or run.

3. How we use your data, and our legal basis for each use

UK data protection law requires us to have a lawful basis for each way we use your personal data. These are:

  • Responding to enquiries and managing bookings: our legitimate interests in responding to people who contact us about our services.
  • Delivering our services and managing client relationships: performance of a contract with you, or steps taken at your request before entering one.
  • Keeping accounting and tax records: compliance with our legal obligations under UK company, accounting, and tax law.
  • Website analytics: our legitimate interests in understanding how our website is used. Our analytics are cookie-free and collect no more than the basic data described in section 2. You can object to this at any time (see section 9).
  • Loading the booking calendar: your consent, given through our cookie banner (see section 4). You can withdraw this consent at any time.

We do not use your data for any purpose beyond what is needed to run our business and serve our clients.

Automated decision-making: we do not make any solely automated decisions about you that have legal or similarly significant effects. A human is involved in every decision we make about the people we deal with.

4. Cookies and similar storage

Our website stores a small number of items on your device:

  • A consent preference, stored in your browser's local storage, that records your cookie choices so we do not ask you again. This is strictly necessary and does not require consent.
  • A Cloudflare security cookie (__cf_bm), set on every page to distinguish genuine visitors from automated bots and protect the site. It is strictly necessary, expires after around 30 minutes, and does not track you across other websites.
  • Booking calendar cookies, set by Google when our booking calendar loads. The calendar, and these cookies, only load after you give consent through our cookie banner.

Our analytics (a self-hosted instance of Umami running on our own infrastructure, and Cloudflare's server-side traffic analytics) are cookie-free and set nothing on your device.

You can withdraw your cookie consent at any time through the cookie preferences link on our website or by reopening the cookie banner, as well as through your browser settings. Withdrawing consent stops the booking calendar loading but does not affect the rest of the site.

5. Who we share your data with

We share personal data with a small number of trusted service providers who help us run Corelo and deliver our services, each bound by a data processing agreement or equivalent data protection terms:

  • Anthropic, for AI processing
  • Cloudflare, for website delivery, security, and privacy-preserving analytics
  • DigitalOcean, for hosting: our website, our self-hosted analytics, and client systems where we host a client's system for them
  • GitHub, for secure code storage
  • Google, for our business email (where enquiries and booking confirmations are received) and the booking calendar on our website

Our self-hosted analytics tool runs on our own infrastructure, so that analytics data is not shared with any analytics vendor.

We do not sell your data, and we do not share it with anyone else except where required by law.

6. Data accessed through connected third-party platforms

Where Corelo delivers a service that connects to a client's own third-party platforms, including Google Workspace, Microsoft 365, Xero, HubSpot, and other business tools the client already uses, Corelo accesses data from those platforms solely to provide the specific feature the client has requested (for example, reading a client's calendar to offer a caller appointment times that are genuinely free, writing a confirmed booking into it, or identifying unpaid invoices to chase).

Corelo accesses this data on its client's behalf and on its client's instructions, acting as the client's data processor. The client remains the controller of this data, and the client's own privacy policy governs how it is used. Corelo is not the controller of the data described in this section.

This data is processed via the Anthropic Claude API and is never used to create, train, or improve any machine learning or artificial intelligence model, beyond the specific processing required to deliver the requested feature to that client.

Where Google Workspace data is involved, Corelo's use of information received from Google Workspace scopes adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Corelo does not use data accessed through any connected third-party platform for advertising, for building databases beyond what is required to operate the client's system, or for any purpose other than delivering the client's requested automation. Full detail on Corelo's data handling practices, including its sub-processors and international transfer safeguards, is set out in Corelo's Data Processing Agreement, available to clients on request.

7. International transfers

Some of our service providers are based in the United States. Where we transfer personal data there, we use approved UK data protection safeguards, and we minimise the personal data involved wherever possible. Specifically:

  • Cloudflare, DigitalOcean, and GitHub are certified under the UK Extension to the EU-US Data Privacy Framework (the UK-US Data Bridge).
  • Our transfers to Anthropic are made under the International Data Transfer Addendum approved by the UK Information Commissioner.
  • Our transfers to Google are made under Google's data processing terms, which incorporate approved UK transfer safeguards.

8. How long we keep your data

We keep client data for as long as needed to deliver our services and meet our legal obligations, generally up to 6 years, in line with UK record-keeping requirements. Website enquiry data is kept only as long as needed to respond, unless it becomes part of an ongoing client relationship.

9. Your rights

Under UK data protection law, you have the right to:

  • ask us to confirm what data we hold about you and receive a copy of it
  • correct it if it is inaccurate
  • delete it where we are not required to keep it
  • restrict or object to certain uses, including any processing we carry out on the basis of our legitimate interests, such as website analytics
  • receive a copy in a portable format
  • withdraw your consent at any time, where we rely on consent (the booking calendar cookies), through the cookie preferences link on our website or by contacting us. Withdrawing consent does not affect the lawfulness of anything done before you withdrew it

To exercise any of these rights, contact [email protected].

10. How to make a complaint

If you are unhappy with how we have handled your personal data, please contact us first at [email protected] so we can try to resolve it. We will acknowledge your complaint within 30 days, keep you updated, and explain the outcome.

If you remain unhappy, you can also complain to the Information Commissioner's Office (ICO), the UK's independent regulator, at ico.org.uk or by calling 0303 123 1113.

11. Changes to this policy

We may update this policy from time to time. The effective date above shows when it was last revised.