CoreAccess ("CoreAccess", "we", "us") provides identity, membership, attendance and access-management software to organizations. This Privacy Policy explains what personal data we collect, why we collect it, and how we handle it.
1. Who is the data controller
When you sign up directly with CoreAccess, we act as the data controller for your account information. When your data is uploaded into CoreAccess by an organization (your gym, estate, school, employer, etc.), that organization is the data controller and we act as the data processor on their behalf.
2. Information we collect
Account information
- Name, email address, phone number, role.
- Hashed password (we never store passwords in plaintext).
- Organization name, industry, country and locations.
Membership & access data
- Membership records, plans, renewal dates, attendance, payments, credentials, photos.
- Device events (check-ins, scans) and audit logs.
Technical information
- IP address, browser, device, pages visited, and security events.
- Cookies strictly necessary for authentication and session security.
3. How we use your information
- Operate and improve the CoreAccess platform.
- Authenticate users and prevent fraud, abuse and unauthorized access.
- Process subscription payments and issue receipts.
- Send service notifications, transactional emails and security alerts.
- Comply with legal obligations, including tax, fraud-prevention and law-enforcement requests.
4. Legal basis
We rely on (a) performance of contract to deliver the service you sign up for, (b) legitimate interest to keep the service secure, and (c) consent where required by local law for optional features (e.g. marketing).
5. Sharing
We do not sell personal data. We share data only with:
- Sub-processors required to run the service (cloud hosting, email delivery, payment processors).
- Your organization, if you are added as a member or staff member.
- Authorities when required by law or to protect users and the public.
6. Data retention
Active account data is retained while the organization remains a customer. Soft-deleted records are kept for up to 90 days for recovery and audit before permanent deletion. Audit and financial records may be retained for up to 7 years to meet legal obligations.
7. Security
We use industry-standard controls including TLS encryption in transit, encryption at rest, row-level security, role-based access, daily backups, and continuous security monitoring.
8. Your rights
Subject to applicable law (NDPR, GDPR, etc.) you have the right to access, correct, export, restrict, or delete your personal data, and to lodge a complaint with your data protection authority. To exercise these rights, contact privacy@getcoreaccess.com.
9. International transfers
CoreAccess primarily processes data in regions selected by your organization. Where data is transferred internationally, we use appropriate safeguards such as standard contractual clauses.
10. Children
CoreAccess is not directed at children under 13. When a parent or school uploads a minor's record (e.g. a school plan), the organization is responsible for obtaining the necessary consent.
11. Changes
We may update this policy from time to time. Material changes will be announced in-app or by email at least 14 days before they take effect.
12. Contact
Questions or concerns? Email privacy@getcoreaccess.com (or support@getcoreaccess.com) or write to CoreAccess, 290A Ajose Adeogun Street, Victoria Island, Lagos, Nigeria. You can also reach us on +234 915 6409 379.