Corelayer procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ Corelayer is based in the United States , and the Site is primarily operated from there. This means that if you access the Site from outside the United States, your Personal Data may be transferred to, stored in, and processed in the United States or other countries where we or our service providers maintain operations.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ We retain Personal Data for as long as reasonably necessary to: Provide and operate the Site. Fulfill the purposes described in this Privacy Policy. Comply with our legal and regulatory obligations. Resolve disputes and enforce our agreements. When determining retention periods, we consider factors such as: The type and sensitivity of the Personal Data. The potential risk of harm from unauthorized use or disclosure. The purposes for which we collected the data and whether we can achieve those purposes through other means. Applicable legal, regulatory, tax, and accounting requirements. In some cases, we may retain Personal Data for longer periods if necessary to comply with legal obligations or for archiving purposes in the public interest, scientific or historical research, or statistical purposes, subject to appropriate safeguards. We may also retain information in an aggregated or de-identified form that does not identify you.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ We respect your right to request deletion of your Personal Data, subject to certain exceptions under applicable law. To request deletion of your Personal Data, please contact us at privacy@corelayer.com with the subject line “Data Deletion Request.” In your message, please provide enough information for us to: Verify your identity (and, where relevant, your relationship with a Corelayer customer). Identify the data you are asking us to delete. If your account or access is provided by your employer or another organization that is a Corelayer customer, we may need to coordinate with that organization before processing your request. We may request additional information to help verify your identity and protect your data from unauthorized deletion requests. Once we have verified your request, we will delete your Personal Data from our active systems within a reasonable period of time, subject to any legal or contractual obligations that require us to retain certain information (for example, for record-keeping, audit, or compliance purposes). Where required by law, we will also take reasonable steps to notify relevant service providers of your deletion request. Please note: We may retain certain information where we have an ongoing legitimate business need or legal obligation (for example, to detect fraud, maintain security, or enforce our agreements). Data that has been de-identified or aggregated may not be subject to deletion requirements, as it no longer identifies you.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Necessary to protect the rights, property, or safety of you, us, our users, or the public.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We disclose Personal Data to the categories of service providers and other parties listed below. Depending on the privacy laws that apply to you, some of these disclosures may be considered a “sale” or “sharing” of Personal Data. For more information, please refer to the “Tracking Tools and Opt-Out” section below. Service Providers. We share Personal Data with trusted third parties that provide services to us or perform functions on our behalf, such as: Hosting, cloud infrastructure, and technology providers. Customer relationship management and support tools. Email and communication service providers. Security, logging, and monitoring tools. Other vendors that help us operate, maintain, and improve the Site. These service providers are prohibited from using Personal Data for purposes other than providing services to us, unless otherwise permitted by law.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “This information is used to improve the Site and our marketing efforts. For example, we may use third-party analytics services such as Google Analytics. These providers may use their own Cookies to provide their services. You can control Cookies through your browser settings. Most browsers allow you to: Block Cookies. Delete existing Cookies. Receive a warning before a Cookie is stored. Please note that if you disable or delete Cookies, some features of the Site may not work as intended, and your experience may be less personalized. For more information about Cookies and how to manage them, you can visit resources such as www.allaboutcookies.org . If you are located in the European Union or the UK, you may also consult guidance from your local data protection authority.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ We may disclose any Personal Data we collect if we believe in good faith that disclosure is:” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Third Parties Vendors We may use analytics providers to analyze how you interact and engage with the Site, or third parties may help us provide you with customer support.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Analytics Partners. We work with analytics providers that help us understand how users find and use the Site, measure engagement, and improve our content and services. These providers may use cookies and similar technologies to collect information about your use of the Site and other websites over time. Parties You Authorize, Access, or Authenticate. We may disclose Personal Data to: Third parties you choose to connect or integrate with the Site. Social media platforms, if you interact with us or share content through those services. Other parties, with your consent or at your direction.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ If we are involved in a corporate transaction such as a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, your Personal Data may be transferred to the relevant third party as part of that transaction. We will use reasonable efforts to ensure that the receiving party honors this Privacy Policy or provides a comparable level of protection.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ The chart below describes the categories of Personal Data that we collect and have collected over the past 12 months when you visit or interact with the Site or communicate with us. Category of Personal Data Examples of Personal Data We Collect Categories of Third Parties With Whom We Share This Personal Data Contact Data First and last name; work email address; professional title; company/organization name; any information you choose to include when requesting a demo or contacting us. Service Providers; Analytics Partners; Parties You Authorize, Access or Authenticate Device / IP Data IP address; device identifier; browser type; operating system; language settings; approximate location based on IP address. Service Providers; Analytics Partners Web Analytics Data Pages or content viewed; referring URL or source; time and date of visits; clickstream data; interaction data (e.g., button clicks, scroll depth); non-identifiable request IDs. Service Providers; Analytics Partners Support & Communications Data Content of emails, messages, or other communications you send to us (including any personal information you choose to include); support correspondence and related metadata. Service Providers; Parties You Authorize, Access or Authenticate Other Identifying Information You Voluntarily Provide Any other identifying information you choose to provide in forms, surveys, feedback, or other interactions with us. Service Providers; Analytics Partners; Parties You Authorize, Access or Authenticate ” | Captured 2026-09-25Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.