Legal

Privacy Policy

How KORE1st handles account data, business workspace data, custom domain data, customer-owned database information, cookies, security, retention, and data rights.

Effective date: July 6, 2026

1. Overview

This Privacy Policy explains how KORE1st (KEY OPERATIONS & RESOURCE ENGINE) collects, uses, stores, shares, and protects information when you visit our website, create an account, subscribe to the platform, upload files, create image/video annotations, use a mapped domain, connect a customer-owned database, configure customer-managed cloud storage, or use our business management services.

For data entered by a customer into its workspace, the customer is generally responsible for deciding what data is collected and how it is used. KORE1st processes that data to provide the platform, support, security, backups, integrations, and related services.

2. Information We Collect

  • Account and registration details such as name, business name, email, mobile number, company code, state, password, and verification status.
  • Subscription and billing details such as plan, renewal status, invoices, payment references, tax details, and support history.
  • Business and company data such as company profiles, users, roles, permissions, CRM records, vouchers, inventory records, HRMS records, approvals, notifications, reports, templates, files, image/video annotations, and settings.
  • Custom domain information such as domain name, DNS status, SSL status, verification records, and related technical metadata.
  • Customer-owned database details such as database host, port, database name, username, access status, connection metadata, and support logs. Passwords or secrets are handled with protective controls where storage is required.
  • Customer-managed cloud storage details such as provider type, bucket or container name, region, endpoint, access status, connection metadata, CORS status, and support logs. Credentials or secrets are handled with protective controls where storage is required.
  • Uploaded file and media metadata such as file name, type, size, upload time, owner, storage location, annotation metadata, review notes, and related operational references.
  • Usage and technical data such as IP address, browser, device, operating system, pages visited, login events, API activity, error logs, security events, cookies, and similar diagnostics.
  • Communications such as support requests, emails, notices, feedback, and account messages.

3. How We Use Information

  • To create, verify, operate, secure, and support customer subscriptions.
  • To provide CRM, sales, inventory, HRMS, approvals, notifications, reports, templates, and related ERP functionality.
  • To support multiple companies under a customer subscription.
  • To configure custom domain mapping, SSL, workspace routing, and access controls.
  • To connect, monitor, and troubleshoot approved customer-owned database environments.
  • To store, retrieve, secure, process, and troubleshoot uploaded files, media, annotations, and approved customer-managed cloud storage environments.
  • To send service emails, verification emails, operational alerts, renewal notices, security notices, and support responses.
  • To prevent fraud, abuse, unauthorized access, service disruption, and security incidents.
  • To comply with legal, regulatory, tax, accounting, security, dispute, and enforcement obligations.
  • To improve product reliability, performance, user experience, and platform features.

4. Legal Basis and Consent

Where required by applicable law, we rely on consent, contract performance, legitimate business interests, legal obligations, or other permitted grounds to process personal data. You may withdraw consent where consent is the applicable basis, subject to legal, contractual, and technical limitations.

5. Customer Workspace Data

Customers may upload or process personal data of their customers, employees, vendors, leads, users, or other individuals. The subscribing customer is responsible for providing notices, obtaining consents, honoring rights requests, setting retention periods, and ensuring lawful processing for such data.

KORE1st processes customer workspace data only to provide, secure, support, and improve the service, or as required by law or authorized instructions.

6. Sharing and Service Providers

We may share information with trusted service providers that help us deliver hosting, email, notifications, analytics, storage, security, payments, support, domain, SSL, infrastructure, and communication services. These providers are expected to process information only for authorized purposes.

We may also disclose information when required by law, court order, regulator, law enforcement request, security investigation, business transfer, or to protect rights, safety, and service integrity.

7. Custom Domain, Database, Storage, and Media Privacy

When a customer uses a custom domain, visitors and users may interact with the platform through that domain. The customer is responsible for domain ownership, DNS accuracy, lawful branding, and user notices shown on its own domain.

When a customer uses a customer-owned database, the customer remains responsible for database hosting, access control, backups, encryption, audit logs, residency, and compliance for that environment. KORE1st may process technical metadata and credentials as needed to provide the service.

When a customer uses customer-managed cloud storage, the customer remains responsible for storage provider account ownership, bucket/container permissions, region, retention, deletion rules, backups, encryption, access control, and compliance for that environment.

When users upload images, videos, or files and create annotations, the customer remains responsible for ensuring that the uploaded content and annotation notes are lawful, accurate, authorized, and shared only with appropriate users.

8. Cookies and Similar Technologies

We may use cookies, session storage, CSRF tokens, local storage, analytics identifiers, and similar technologies to keep users signed in, protect accounts, remember preferences, measure usage, and improve the service. Browser settings may allow you to block or delete cookies, but some features may stop working.

9. Data Retention

We retain information for as long as needed to provide the service, maintain subscriptions, comply with legal and accounting obligations, resolve disputes, enforce agreements, support backups, and protect security. Customer workspace data, uploaded files, media, and annotations may remain in backups for a limited period after deletion according to backup cycles and technical constraints.

10. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect data, including access controls, authentication, logging, encryption where appropriate, backups, and security monitoring. No internet-based service, customer-managed database environment, or customer-managed cloud storage environment can be guaranteed to be completely secure.

11. International Transfers and Data Location

Data may be processed in locations where we, our infrastructure providers, or our service providers operate, subject to applicable law and contractual safeguards. If a customer-owned database or customer-managed cloud storage provider is used, data location may depend on the customer's selected database or storage environment.

12. Children's Data

The platform is intended for business use and is not directed to children. Customers must not knowingly use the service to collect children's personal data unless they have a lawful basis and all required notices, consents, and safeguards.

13. Your Rights and Choices

Depending on applicable law, individuals may have rights to access, correct, update, delete, restrict, object, withdraw consent, or request information about personal data. Workspace users should contact their business account owner for workspace data requests. Requests related to data controlled by KORE1st can be sent to contact@yugtechno.com.

14. Data Breach and Incident Notices

If we become aware of a security incident affecting personal data, we will take reasonable steps to investigate, contain, and notify affected customers or authorities where required by applicable law. Customers using customer-owned databases or customer-managed cloud storage must also maintain their own incident response process for that infrastructure.

15. Changes to This Policy

We may update this Privacy Policy to reflect product, legal, security, infrastructure, or operational changes. Updates will be posted on this page with a revised effective date. Continued use of the service after updates means you acknowledge the updated policy.

16. Contact

For privacy questions, data requests, grievance requests, custom domain privacy concerns, uploaded file or annotation concerns, customer-managed cloud storage questions, or customer-owned database security questions, contact us at contact@yugtechno.com.