Who this policy covers
This policy explains how GEOCORE OS LTD (registration in progress), Vincent Gardens, NW2 7RP, United Kingdom ("GeoCore", "we", "us") handles personal information in its UK-first business software, website, demo requests and related communications. It is written for organisations and professionals aged 18 or over. GEOCORE OS LTD is intended to be the operating legal entity; its registration is in progress.
Customers remain responsible for the information they place in their workspaces and for giving notices or obtaining permissions required for their own use of GeoCore.
Information we process
We process account and profile details, workspace and business details, customer records, project and quotation information, documents and photos uploaded by authorised users, support communications, subscription and invoice metadata, and technical/security records.
We may also process demo or contact-request details, marketing preferences and consent/source records, campaign attribution where consent permits persistent storage, copyright-report information, and information submitted to configured AI features.
- Account and access data: names, email addresses, roles, password-derived security data and verification records.
- Workspace data: business, customer, project, quote, document and operational information entered by a customer.
- Commercial and communications data: plan, payment-provider references, invoices, marketing choices, delivery and suppression records.
- Technical data: browser/storage choices, IP- and security-related logs, device and service telemetry needed to operate and protect the service.
Why we use information
We use information to provide and administer GeoCore, authenticate users, operate workspaces, respond to requests, provide support, maintain security, prevent fraud or abuse, process subscriptions, meet legal obligations and improve our service.
For optional analytics or marketing technologies, we rely on the choices made through our consent controls where required. Marketing email is separately controlled by marketing preferences and unsubscribe/suppression records. Necessary verification, password, security, invitation, billing and service messages are not marketing messages.
Legal bases and rights
Where UK data-protection law applies, processing may be necessary for a contract, our legitimate interests in operating and protecting a B2B service, compliance with legal obligations, or consent where that is the appropriate basis. The precise basis can depend on the context and the relationship with the individual.
Individuals may have rights to request access, correction, deletion, restriction, objection, portability or withdrawal of consent. Workspace owners can use available export and deletion controls; users may contact privacy@geocore.one for help. Individuals may also complain to the UK Information Commissioner's Office. This policy does not state an ICO registration number.
Retention, export and deletion
Workspace owners can request a tenant-scoped export and request workspace deletion. A deletion request starts a 30-day recovery period during which the owner may cancel it. Final purge is an internal, authorised process and occurs only after eligibility; it is not initiated directly by a workspace owner.
Ordinary workspace information may be deleted or anonymised after the recovery window. Billing/accounting, security/audit, suppression, deletion/copyright evidence and backup copies can have different retention characteristics where necessary. We do not promise that every category is erased exactly 30 days after a request.
Processors, international processing and contact
We use service providers to operate the service. The current verified subprocessor information is published in our Subprocessor Information page and may change as services are configured. Provider processing may occur outside the UK; the applicable safeguards and contractual arrangements depend on the provider and circumstances and remain subject to legal review.
Configured AI features may send the submitted request and information needed for that feature to the configured server-side AI provider. Provider credentials remain server-side. We do not promise a provider's retention, training or processing location unless separately confirmed. Contact privacy@geocore.one with privacy questions.
