The Arabic version of this document is the authoritative legal text. This English translation is provided for convenience; in case of any discrepancy, the Arabic version prevails.
Privacy Policy
Data Controller: MainCore Technologies, Kingdom of Saudi Arabia Effective: 16 July 2026 Applicable regimes: Saudi PDPL (Royal Decree M/19), EU GDPR (2016/679), UK GDPR
1. Who we are
MainCore Technologies operates the CoreShield AI service. We are the data controller for personal data collected via our website, marketing activity, and customer accounts. For customer-uploaded content processed through the CoreShield Detect → Cloak → Send → Restore pipeline, we act as data processor under the DPA — see the DPA.
2. Data we collect
From website visitors: IP address and basic device/browser information, used to secure the Service. No web-analytics, advertising, or behavioural-tracking tooling is currently deployed, so we do not collect navigation analytics or advertising identifiers. See our Cookie Notice for the small set of strictly-necessary cookies we set.
From account holders: name, work email, phone (optional), employer, role, MFA secrets (hashed), audit trail of logins.
From customer-uploaded content (as processor): whatever the customer chooses to upload for Detect/Cloak processing. Original values sealed in the vault; only cloaked derivatives leave the customer's environment.
3. Why we collect it
- Provide the Service: login, subscription management, support.
- Security: detect abuse, enforce rate limits, respond to incidents.
- Compliance: meet PDPL, NCA-ECC, SDAIA reporting obligations.
- Improve the product: aggregate usage patterns (never per-user targeted analytics without explicit consent).
4. Legal basis
- Performance of contract: account, subscription, support.
- Legitimate interest: security, fraud prevention.
- Consent: marketing emails, non-essential cookies. Withdrawable at any time via the settings page or by emailing
info@maincore.sa. - Legal obligation: audit-chain retention, tax records, PDPL data-subject requests.
5. Sharing
We do not sell personal data. We share only with sub-processors listed in the DPA Annex A, under written agreements that mirror this Privacy Policy and the DPA. Government disclosures happen only under a valid legal order, and we publish a transparency report annually.
6. Your rights (PDPL + GDPR)
You may:
- Access the personal data we hold about you (DSAR).
- Correct inaccurate data.
- Delete data ("right to be forgotten"), subject to legal retention.
- Object to processing based on legitimate interest.
- Withdraw consent for marketing at any time.
- Receive your data in machine-readable form ("portability").
- Lodge a complaint with SDAIA (KSA) or a supervisory authority (EU/UK).
Request via: info@maincore.sa. Response window: 30 days (extendable to 60 for complex requests, with notice).
7. Retention
- Account data: retained while the account is active + 12 months after termination for legal purposes.
- Audit chain: retained for 7 years per NCA-ECC and Saudi commercial code.
- Customer-uploaded content (processor role): deleted per customer instruction; default 30 days after subscription end.
- Marketing consent records: retained until withdrawn + 12 months.
8. Data residency & international transfers
Current pilot (synthetic data only). The CoreShield AI pilot is hosted on Microsoft Azure in the UAE North region and processes synthetic demonstration data only — zero real customer personal data.
Sovereign-residency commitment (dated). Real customer data will be hosted on infrastructure inside the Kingdom of Saudi Arabia. Licensed in-Kingdom cloud providers are currently under evaluation, including STC Cloud, and the final provider will be determined before any real data is processed. [OWNER DECISION: final in-Kingdom cloud provider] The migration to in-Kingdom infrastructure will be completed upon the first real customer contract, before any real customer personal data is processed. Until then, no real customer data is processed.
Other transfers. For any processing outside the in-Kingdom region, data transits only to the sub-processors listed in DPA Annex A, always under Standard Contractual Clauses (EU SCCs) or an equivalent PDPL-compliant safeguard. Under the Send verb, only cloaked text (tokenized placeholders, never original values) is transmitted to the external LLM provider.
9. Cookies
We set only a small number of strictly-necessary cookies (a language-preference cookie and a sign-in-presence cookie) plus authentication data in the browser's local storage. No analytics, advertising, or third-party tracking cookies are set, and there is currently no consent banner because none is required for strictly-necessary storage. Full details — name, purpose, and duration of each — are in our Cookie Notice.
10. Children
The Service is not directed to individuals under 18. We do not knowingly collect data from children.
11. Changes
Material changes are notified via email to account holders 30 days before taking effect.
12. Automated decision-making & profiling
CoreShield's detection and cloaking are rule-based: sensitive values are identified by pattern rules and named-entity-recognition models and replaced with tokens before any external processing. CoreShield does not make automated decisions that produce legal or similarly significant effects on any individual — it does not score, rank, profile, or make eligibility, credit, employment, or comparable determinations about data subjects. Documents may be flagged for human review against a customer-configured policy threshold; that review and any resulting action are carried out by the customer's own staff, not automatically by CoreShield. The only external AI (an LLM used for the Send verb) receives cloaked text only and returns text; it makes no decision about any identified person.
13. Providing your data: mandatory or optional
Whether personal data is required depends on the context:
- To create and use an account (required): full name, work email, employer/organization, and a password. Without these you cannot register or sign in.
- Optional account data: phone number (used only if you choose to provide it, e.g. for account recovery); multi-factor-authentication secrets (only if you enable MFA). Not providing these does not prevent you from using the Service, though declining MFA reduces your account's security.
- Security data collected automatically: when you use the website we process your IP address and basic device/browser information to protect the Service; this is necessary and cannot be switched off while you use the Service.
- Customer-uploaded content: you (the customer) decide entirely what content to upload for Detect/Cloak processing; providing it is optional and at your discretion.
14. Contact
- Privacy Officer: info@maincore.sa
- Data Protection Officer (EU representative): to be appointed before EU sales
- SDAIA complaint portal: https://sdaia.gov.sa/