Effective: 2026 · Company: RiRo Technologies Inc., doing business as Control Core.
At Control Core, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, products, and services.
1. Our Deployment Model and Data Sovereignty
Control Core is strictly a 100% Customer-Hosted, On-Premises, or Private Virtual Private Cloud (VPC) solution; there is no Software-as-a-Service (SaaS) component. Zero metadata or payload telemetry ever exits the private network boundary.
2. Information We Collect
Because our product operates within your infrastructure, the data we collect is strictly limited.
Personal Information: We collect contact information (name, email address, phone number), company information, account credentials, and billing information.
Usage & Analytics Data: Subject to your consent, we collect log data for transaction monitoring and licensing enforcement without any organization data. We also collect device information and analytics data on errors without including any organization data.
Policy and Access Management Data: We do not collect user roles, permissions, access policies, or audit logs, except under specific Managed Service or Hybrid cloud models where explicitly granted.
3. How We Use Your Information
We use your information to provide and maintain our services, improve and personalize the user experience, process transactions, send administrative information, provide customer support, enforce our policies, and comply with legal obligations.
4. Data Storage and Security
We implement robust measures to protect the limited data we handle and the systems we help manage:
Encryption and Key Management: All sensitive data is encrypted using industry-standard algorithms at rest and in transit. Encryption keys are managed securely and rotated regularly, and in Managed Service models, you have the option to manage your own encryption keys.
Data Isolation and Access Control: Access to our systems is strictly limited and controlled through multi-factor authentication and role-based access control. Each customer’s data is logically isolated to prevent unauthorized access. Control Core staff cannot access your data without your explicit permission, which is typically only granted for specific support issues and is time-limited.
Auditing and Monitoring: All access attempts and activities by our personnel are logged and auditable. We provide comprehensive audit logs of all system access and regular third-party security audits are conducted on our infrastructure.
Backups and Disaster Recovery: Regular encrypted backups are performed and stored in geographically separate locations. We maintain a robust disaster recovery plan which is tested regularly.
Data Deletion: When you delete data, it is immediately made inaccessible and securely erased according to industry standards.
5. Specific Provisions for Deployment Models
On-Premise: You maintain full control over your data, while we provide software updates, security patches, and guidance on best practices for securing your data.
Managed Service: We may host and manage the infrastructure, but you retain full control over your data, can configure access policies, and manage encryption keys if desired.
6. Data Sharing and Disclosure
We do not sell your personal information.
Third-Party Service Providers: We may engage third-party service providers (e.g., cloud infrastructure providers) to assist in providing our services. These providers are contractually obligated to maintain confidentiality and security, and do not have direct access to your unencrypted data.
Legal Compliance: We may disclose data to comply with legal obligations, providing only the minimum amount necessary, and will notify you unless legally prohibited.
7. Compliance, DPAs, and International Transfers
We comply with applicable data protection laws, including PIPEDA and GDPR. If we transfer data internationally, we ensure appropriate safeguards are in place to protect your information. For our enterprise customers, we offer Data Processing Agreements (DPAs) that comply with GDPR and other relevant regulations.
8. Your Rights, Choices, and Data Retention
Depending on your location, you have the right to access your personal information, correct inaccurate data, delete your data, object to or restrict processing, and request data portability. To exercise these rights, please contact us at support@controlcore.io. We retain your data only for as long as necessary to provide our services and comply with legal obligations. For on-premise solutions, data retention is entirely controlled by you.
9. Children’s Privacy
Our services are not intended for children under 13, and we do not knowingly collect data from children under 13.
10. Changes to This Policy
We may update this policy from time to time. We will notify you of any significant changes by posting the new policy on our website. If you have any questions, please contact us at support@controlcore.io.