CoreShieldCoreShield AI

Last updated:

The Arabic version of this document is the authoritative legal text. This English translation is provided for convenience; in case of any discrepancy, the Arabic version prevails.

Privacy Policy

Data Controller: MainCore Technologies, Kingdom of Saudi Arabia Effective: 16 July 2026 Applicable regimes: Saudi PDPL (Royal Decree M/19), EU GDPR (2016/679), UK GDPR

1. Who we are

MainCore Technologies operates the CoreShield AI service. We are the data controller for personal data collected via our website, marketing activity, and customer accounts. For customer-uploaded content processed through the CoreShield Detect → Cloak → Send → Restore pipeline, we act as data processor under the DPA — see the DPA.

2. Data we collect

From website visitors: IP address and basic device/browser information, used to secure the Service. No web-analytics, advertising, or behavioural-tracking tooling is currently deployed, so we do not collect navigation analytics or advertising identifiers. See our Cookie Notice for the small set of strictly-necessary cookies we set.

From account holders: name, work email, phone (optional), employer, role, MFA secrets (hashed), audit trail of logins.

From customer-uploaded content (as processor): whatever the customer chooses to upload for Detect/Cloak processing. Original values sealed in the vault; only cloaked derivatives leave the customer's environment.

3. Why we collect it

4. Legal basis

5. Sharing

We do not sell personal data. We share only with sub-processors listed in the DPA Annex A, under written agreements that mirror this Privacy Policy and the DPA. Government disclosures happen only under a valid legal order, and we publish a transparency report annually.

6. Your rights (PDPL + GDPR)

You may:

Request via: info@maincore.sa. Response window: 30 days (extendable to 60 for complex requests, with notice).

7. Retention

8. Data residency & international transfers

Current pilot (synthetic data only). The CoreShield AI pilot is hosted on Microsoft Azure in the UAE North region and processes synthetic demonstration data only — zero real customer personal data.

Sovereign-residency commitment (dated). Real customer data will be hosted on infrastructure inside the Kingdom of Saudi Arabia. Licensed in-Kingdom cloud providers are currently under evaluation, including STC Cloud, and the final provider will be determined before any real data is processed. [OWNER DECISION: final in-Kingdom cloud provider] The migration to in-Kingdom infrastructure will be completed upon the first real customer contract, before any real customer personal data is processed. Until then, no real customer data is processed.

Other transfers. For any processing outside the in-Kingdom region, data transits only to the sub-processors listed in DPA Annex A, always under Standard Contractual Clauses (EU SCCs) or an equivalent PDPL-compliant safeguard. Under the Send verb, only cloaked text (tokenized placeholders, never original values) is transmitted to the external LLM provider.

9. Cookies

We set only a small number of strictly-necessary cookies (a language-preference cookie and a sign-in-presence cookie) plus authentication data in the browser's local storage. No analytics, advertising, or third-party tracking cookies are set, and there is currently no consent banner because none is required for strictly-necessary storage. Full details — name, purpose, and duration of each — are in our Cookie Notice.

10. Children

The Service is not directed to individuals under 18. We do not knowingly collect data from children.

11. Changes

Material changes are notified via email to account holders 30 days before taking effect.

12. Automated decision-making & profiling

CoreShield's detection and cloaking are rule-based: sensitive values are identified by pattern rules and named-entity-recognition models and replaced with tokens before any external processing. CoreShield does not make automated decisions that produce legal or similarly significant effects on any individual — it does not score, rank, profile, or make eligibility, credit, employment, or comparable determinations about data subjects. Documents may be flagged for human review against a customer-configured policy threshold; that review and any resulting action are carried out by the customer's own staff, not automatically by CoreShield. The only external AI (an LLM used for the Send verb) receives cloaked text only and returns text; it makes no decision about any identified person.

13. Providing your data: mandatory or optional

Whether personal data is required depends on the context:

14. Contact