Legal

Privacy policy

This policy explains what personal data Protocore processes, why we process it, and the rights you have. Last updated August 2026.

Who we are

Protocore provides a governance, risk and compliance platform to organisations and consultancies. For website visitors and for account holders, Protocore acts as data controller. For content that customers upload into their workspaces, Protocore acts as data processor on the customer's instructions under a data processing agreement.

Data we process

  • Account data: name, work email, workspace membership and role.
  • Authentication data: password hashes, multi-factor enrolment and sign-in events.
  • Usage and security logs: IP address, timestamps and actions taken in the platform.
  • Enquiry data: the details you send us when requesting a demo or support.
  • Customer content: the records a customer chooses to store in their workspace.

Why we process it

  • To provide and secure the platform (performance of a contract).
  • To prevent abuse, detect incidents and maintain audit trails (legitimate interests).
  • To respond to enquiries you initiate (legitimate interests or consent).
  • To meet legal and regulatory record-keeping obligations (legal obligation).

Sharing and sub-processors

We use a small number of vetted providers for hosting, database services, email delivery and intelligent assistance. Each is bound by contract to process data only as instructed. We do not sell personal data and we do not allow customer workspace content to be used to train third-party models.

International transfers

Data is hosted in the European Union. Where a provider processes data outside the EEA, the transfer relies on an adequacy decision or on Standard Contractual Clauses with additional safeguards.

Retention

Account and workspace data is retained for the life of the contract and then deleted or returned according to the agreement. Security and audit logs are retained for a defined period to support investigations. Enquiry correspondence is deleted when it is no longer needed.

Security

We apply encryption in transit and at rest, enforced multi-factor authentication, role-based and row-level access control, least-privilege service credentials, logging and regular review. See the security page for detail.

Your rights

Subject to conditions, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. If Protocore processes your data on behalf of a customer, we will refer your request to that customer. You may also complain to your national data protection authority.

Cookies

The platform uses strictly necessary cookies and local storage for authentication, session management and security. We do not use advertising cookies.

Contact

For any privacy question or to exercise a right, email privacy@protocore.pro.