Privacy Policy
This policy explains what personal data Corpshore AI collects, why we process it, the legal bases we rely on, how we protect and transfer it, and the rights available to you under the laws of the regions where we operate.
1. About this policy and who we are
Corpshore AI is a division of Corpshore Solutions Corporation (together, "Corpshore", "we", "us", or "our"). Corpshore AI provides AI data services, including data collection, data annotation and labeling, reinforcement learning from human feedback, speech and audio dataset production, robotics and embodied AI data, red-teaming and model evaluation, and related consulting. This policy applies to personal data we process through our website at corpshore.ai, through business enquiries and communications, and in the course of operating our business.
We operate delivery hubs across more than twelve countries. Personal data described in this policy may therefore be processed by Corpshore teams and approved service providers in several regions. Where we act on behalf of a client to process personal data contained in datasets, we generally act as a processor or service provider under the client's instructions, and the client's own privacy notice and our executed data processing agreement govern that processing. This policy describes our own processing as a controller or business, for example when you contact us, browse our website, or apply to work with us.
This document is provided for information and does not constitute legal advice. It is written to describe our practices and our alignment with the privacy and data protection frameworks summarized below. Nothing in this policy is an unqualified guarantee; the final and binding terms of any engagement are set out in the executed agreement between the client and Corpshore Solutions Corporation, including any data processing agreement, standard contractual clauses, or service schedule attached to that agreement.
2. Our roles: controller, processor, business, and service provider
Data protection law distinguishes between the party that decides why and how personal data is processed and the party that processes personal data on another party's instructions. Under the European Union and United Kingdom General Data Protection Regulation frameworks, these roles are called controller and processor. Under the California Consumer Privacy Act as amended by the California Privacy Rights Act, comparable roles are called business and service provider or contractor. Under Canadian and Australian law, similar concepts of the responsible organization and its agents apply.
When you interact with our website, submit an enquiry, subscribe to updates, or apply for a role, Corpshore is the controller or business for that personal data and decides the purposes and means of processing it. When we process personal data that a client includes within a dataset or provides to us for annotation, collection, evaluation, or other services, Corpshore generally acts as a processor or service provider and processes that data only on the documented instructions of the client, as recorded in the executed data processing agreement.
Where this policy refers to your rights, those rights primarily concern personal data for which Corpshore is the controller or business. If your personal data appears within a client dataset for which we are a processor, you should generally direct your request to the relevant client as controller, and we will support that client in responding as required by our agreement and by law.
3. Personal data we collect
We collect the information you choose to provide through our website forms and direct communications. This typically includes your name, business email address, telephone number where you provide it, employer or company name, job title, country or region, and the content of the enquiry, message, or project description you send us. If you apply to work with Corpshore, we also collect the information in your application, such as your curriculum vitae, work history, language skills, and any details you elect to share during assessment.
We collect standard technical and usage data when you visit our website. This includes your internet protocol address, approximate location inferred from that address, browser type and version, device and operating system information, referring pages, the pages you view, and the dates and times of access. We collect this data through server logs and, where you consent, through cookies and similar technologies described below.
We do not intentionally collect special categories of personal data, such as data revealing racial or ethnic origin, political opinions, religious beliefs, health, biometric identifiers, or sexual orientation, through our website. Please do not submit such information through our enquiry forms. Where a client engagement requires processing of special categories of data within a dataset, that processing is governed by the executed agreement and by additional safeguards agreed in writing.
4. Sources of the personal data we hold
Most of the personal data we hold about you comes directly from you, for example when you complete a form, send an email, book a call, or apply for a role. Some technical data is generated automatically when you use our website, as described in the section on cookies and tracking.
In limited cases we obtain business contact information from third-party sources, such as professional networking platforms, publicly available business directories, event registration lists where you have agreed to share your details, or referrals from mutual contacts. Where we obtain your details from such sources, we process them for legitimate business development purposes and honor any objection or opt-out you communicate to us. Where required by law, we provide notice at the point of first contact and identify the source on request.
5. Purposes for which we process personal data
We process enquiry and contact data to respond to your questions, to scope and discuss potential engagements, to prepare proposals and statements of work, and to manage our relationship with you and the organization you represent. We process this data because it is necessary to take steps at your request and to pursue our legitimate interest in operating and developing our business.
We process website and technical data to operate, secure, and maintain our website, to understand how visitors use it, to measure the effectiveness of our content, and to detect and prevent fraud, abuse, and security incidents. We process recruitment data to assess applications, to communicate with candidates, and to administer our hiring and onboarding processes.
We process data to comply with legal, regulatory, tax, and accounting obligations, to establish, exercise, or defend legal claims, and to enforce our agreements. Where we wish to send you marketing communications about our services, we do so in accordance with the consent and opt-out rules described in the sections on Canadian and other communications law, and you can withdraw your consent or unsubscribe at any time.
6. Lawful bases for processing under EU and UK law
Under the European Union General Data Protection Regulation and the United Kingdom General Data Protection Regulation, we process personal data only where we have a lawful basis to do so. We rely on the following bases. First, performance of a contract or taking steps at your request before entering a contract, for example when we respond to your enquiry or negotiate an engagement. Second, our legitimate interests in operating, securing, and growing our business, provided those interests are not overridden by your interests or fundamental rights. Third, compliance with a legal obligation to which we are subject. Fourth, your consent, for example for certain cookies and for some marketing communications, which you may withdraw at any time.
Where we rely on legitimate interests, we carry out a balancing assessment to confirm that our interests do not override your rights and freedoms, and we can provide information about that assessment on request. Where we rely on consent, withdrawing your consent does not affect the lawfulness of processing carried out before the withdrawal. Where processing of any special category data is ever required, we identify an additional condition under Article 9 of the applicable Regulation before proceeding.
7. Cookies, analytics, and similar technologies
Our website uses cookies and similar technologies to operate the site, to remember your preferences, and, where you consent, to measure and analyze usage. Strictly necessary cookies are required for the site to function and do not require consent. Analytics and other non-essential cookies are set only where you have given consent through our cookie banner or an equivalent control, in line with the ePrivacy rules that apply in the European Economic Area and the United Kingdom and with consent expectations in other regions.
You can manage cookies through the controls we provide and through your browser settings. Most browsers allow you to block or delete cookies, and you can withdraw analytics consent at any time. Some features of the website may not function correctly if you block certain cookies. Where we use third-party analytics providers, those providers act as our processors and are contractually restricted from using the data for their own purposes.
We honor recognized opt-out preference signals where required by law. In particular, for residents of United States states that provide this right, we treat a Global Privacy Control browser signal as a valid request to opt out of the sale or sharing of personal information and of targeted advertising, to the extent such activities occur.
8. How we share personal data and our subprocessors
We do not sell personal data for money, and we do not share personal data for cross-context behavioral advertising in a way that would require an opt-out under United States state law, except to the limited extent that use of analytics or advertising cookies might be interpreted as such, in which case we provide the opt-out described above. We share personal data only as described in this policy.
We share personal data with service providers and subprocessors that support our operations, such as website hosting, cloud infrastructure, customer relationship management, email and communications, analytics, scheduling, and security providers. These providers process personal data only on our instructions and under contractual terms that require appropriate confidentiality and security safeguards. A current list of subprocessors used for client engagements is available on request, and our data processing agreements provide for advance notice of material subprocessor changes where required.
We may also share personal data with professional advisers such as lawyers, auditors, and insurers, with regulators, courts, and law enforcement where required by law, and with a successor entity in connection with a merger, acquisition, financing, or reorganization, subject to appropriate confidentiality protections. Within the Corpshore group, we share personal data among Corpshore Solutions Corporation and its divisions and hubs for the purposes described in this policy and under intra-group agreements.
9. International transfers and data residency
Corpshore operates delivery hubs across more than twelve countries and works with clients and providers in multiple regions. As a result, personal data may be transferred to, stored in, or accessed from countries other than the one in which you are located, including countries that may not provide the same level of data protection as your home jurisdiction. We take steps to protect personal data whenever it is transferred internationally.
For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards, principally the European Commission Standard Contractual Clauses, the United Kingdom International Data Transfer Agreement or Addendum, and the Swiss addendum where relevant. We combine these clauses with a transfer risk assessment and, where needed, supplementary technical and organizational measures. For transfers subject to Canadian and Australian law, we use comparable contractual and accountability measures so that a comparable level of protection accompanies the data.
Where a client requires that its data remain in a specific country or region, we can agree data residency and access controls in the executed agreement, including restrictions on the hubs and personnel that may access the data. Absent such a requirement, we select processing locations based on service needs, security, and applicable law. You can request more information about the safeguards we apply to a specific transfer by contacting us at info@corpshore.ai.
10. Data retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including to respond to your enquiry, to manage our relationship, to meet legal, tax, and accounting obligations, and to establish, exercise, or defend legal claims. Retention periods vary according to the type of data and the applicable legal requirements.
As a general guide, we retain enquiry and contact data for the duration of our discussions and for a reasonable period afterward to maintain the business relationship and our records, unless you ask us to delete it earlier and we have no overriding legal reason to keep it. We retain recruitment data for the assessment period and, where you agree, for a limited period afterward to consider you for future roles. We retain data required for financial and legal compliance for the periods prescribed by applicable law.
When personal data is no longer required, we delete it or anonymize it so that it can no longer be associated with you. Where deletion is not immediately feasible, for example because data is held in secure backups, we isolate the data from further processing until deletion is possible.
11. How we protect personal data
We maintain technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, and destruction. These measures include access controls based on the principle of least privilege, role-based permissions, encryption of personal data in transit and, where appropriate, at rest, network and endpoint security controls, logging and monitoring, secure development practices, vendor security review, and staff training and confidentiality obligations.
For client engagements, we agree additional security measures in the executed agreement and can support recognized control frameworks and independent assessments as described in our Trust Center. No method of transmission or storage is completely secure, and we cannot provide an unqualified guarantee of security. We work to maintain a level of security appropriate to the risk and to improve our controls over time. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately at info@corpshore.ai.
12. United States: CCPA, CPRA, and other state privacy laws
If you are a resident of California, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you rights over your personal information. These include the right to know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients; the right to access a copy of your personal information; the right to delete personal information subject to exceptions; the right to correct inaccurate personal information; and the right to opt out of the sale or sharing of personal information and to limit the use of sensitive personal information. We do not sell personal information for money and honor opt-out preference signals as described above. We do not discriminate against you for exercising these rights.
Residents of other United States states that have enacted comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as those laws take effect, have comparable rights to access, correct, delete, and obtain a portable copy of personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Where these laws apply, we provide the same core rights and appeal mechanisms that they require, and we respond within the statutory timeframes.
Certain United States sector-specific laws may apply to particular data or clients, such as the Health Insurance Portability and Accountability Act for protected health information, the Gramm-Leach-Bliley Act for certain financial data, the Family Educational Rights and Privacy Act for education records, and the Children's Online Privacy Protection Act for data about children under thirteen. We do not seek to collect data governed by these laws through our website. Where a client engagement involves such data, the required protections and any business associate or comparable terms are set out in the executed agreement.
To exercise your United States privacy rights, contact us at info@corpshore.ai. We will verify your request using the information we hold and respond within the timeframes required by the applicable law. You may use an authorized agent to submit a request where the law permits, subject to verification.
13. Canada: PIPEDA, Quebec Law 25, and CASL
For personal data subject to Canadian federal law, we align our practices with the Personal Information Protection and Electronic Documents Act and its fair information principles, including accountability, identifying purposes, consent, limiting collection, limiting use and disclosure, accuracy, safeguards, openness, individual access, and the ability to challenge compliance. We collect, use, and disclose personal information for purposes that a reasonable person would consider appropriate in the circumstances, and we obtain consent where required.
For personal data of individuals in Quebec, we align our practices with the Act respecting the protection of personal information in the private sector as amended by Law 25. This includes providing transparency about our practices, obtaining consent where required, supporting rights of access, correction, and, where applicable, portability and de-indexing, conducting privacy impact assessments for certain transfers and projects, and reporting confidentiality incidents that present a risk of serious injury. Corpshore Solutions Corporation designates a person responsible for the protection of personal information, reachable at info@corpshore.ai.
For commercial electronic messages sent to recipients in Canada, we align with Canada's Anti-Spam Legislation. We send marketing electronic messages only with the recipient's express or implied consent as defined by that law, we identify ourselves clearly, and we include a functioning unsubscribe mechanism in each message. You can withdraw consent at any time, and we will action unsubscribe requests promptly.
14. European Union and United Kingdom: your GDPR rights
If you are in the European Economic Area or the United Kingdom, you have rights under the applicable General Data Protection Regulation in relation to personal data for which we are the controller. These include the right to be informed about our processing; the right of access to your personal data; the right to rectification of inaccurate or incomplete data; the right to erasure in certain circumstances; the right to restrict processing; the right to data portability where processing is based on consent or contract and carried out by automated means; the right to object to processing based on legitimate interests and to direct marketing; and rights in relation to automated decision-making and profiling.
Where our processing is based on your consent, you have the right to withdraw that consent at any time. You also have the right to lodge a complaint with a supervisory authority. In the United Kingdom this is the Information Commissioner's Office, and in the European Economic Area it is the data protection authority of your country of residence, place of work, or the place of the alleged infringement. We would appreciate the chance to address your concerns before you approach a supervisory authority, so we encourage you to contact us first.
To exercise any of these rights, contact us at info@corpshore.ai. We will respond without undue delay and within one month, subject to any extension permitted for complex or numerous requests, in which case we will inform you of the extension and the reasons. We may need to verify your identity before acting on a request. There is normally no fee, although we may charge a reasonable fee or decline to act where a request is manifestly unfounded or excessive, as permitted by law.
15. Australia: the Privacy Act 1988 and the Australian Privacy Principles
For personal information subject to Australian law, we align our practices with the Privacy Act 1988 and the Australian Privacy Principles. We are open about how we manage personal information, we collect personal information only where it is reasonably necessary for our functions and by lawful and fair means, and we notify individuals of the matters set out in the Australian Privacy Principles at or before the time of collection where practicable.
We use and disclose personal information for the purposes for which it was collected and for related purposes that an individual would reasonably expect, or as otherwise permitted by law. We take reasonable steps to keep personal information accurate, up to date, and secure, and to destroy or de-identify it when it is no longer needed. Individuals may request access to and correction of their personal information, and we respond in accordance with the Australian Privacy Principles.
Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles the information consistently with the Australian Privacy Principles, or we rely on another permitted basis for the disclosure. Where a notifiable data breach occurs under the Notifiable Data Breaches scheme, we notify affected individuals and the Office of the Australian Information Commissioner as required.
16. International principles: UN and OECD
Beyond specific national and regional laws, we seek to align our practices with widely recognized international privacy principles. We recognize privacy as a human right reflected in international instruments, including Article 12 of the Universal Declaration of Human Rights and Article 17 of the International Covenant on Civil and Political Rights, and we treat the responsible handling of personal data as an element of respecting that right across the regions where we operate.
We also align our practices with the Organisation for Economic Co-operation and Development Guidelines on the Protection of Privacy and Transborder Flows of Personal Data. These principles include collection limitation, data quality, purpose specification, use limitation, security safeguards, openness, individual participation, and accountability. Applying a consistent set of principles across our hubs helps us provide a comparable level of protection wherever your personal data is processed, even where local requirements differ.
17. How to exercise your rights
You can exercise your rights, ask questions about this policy, or raise a concern by contacting us at info@corpshore.ai. Please tell us which right you wish to exercise, the region in which you are located or resident, and enough information for us to identify your records. We may ask you for additional details to verify your identity before we act on your request, so that we do not disclose or change personal data on the basis of an unverified request.
We respond within the timeframes set by the law that applies to your request. Where a law permits an authorized agent to act on your behalf, we will accept requests from an agent subject to reasonable verification of the agent's authority. If we are unable to fulfill a request in full, we will explain why to the extent the law allows, and we will tell you about any right to appeal our decision or to complain to a supervisory or regulatory authority.
If your personal data appears within a dataset that we process on behalf of a client, we generally act as a processor or service provider for that data. In that case we will, where appropriate, direct your request to the relevant client as controller and support that client in responding, as required by our agreement and by law.
18. Children's data
Our website and services are directed to businesses and are not intended for children. We do not knowingly collect personal data from children through our website. If you believe that a child has provided us with personal data through our website, please contact us at info@corpshore.ai and we will take reasonable steps to delete it.
Where a client engagement involves data relating to minors, that processing is subject to the executed agreement and to any additional legal requirements that apply, including applicable age thresholds for consent under the relevant regional laws and, in the United States, the Children's Online Privacy Protection Act. We do not use our website to collect such data.
19. Automated decision-making and profiling
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing of your personal data in the course of operating our website or handling your enquiries. Where we use analytics or automated tools, a human remains involved in decisions that affect our relationship with you.
Where any client engagement involves automated processing or profiling within a dataset, the roles, safeguards, and any rights of individuals to obtain human intervention, to express a point of view, and to contest a decision are addressed in the executed agreement and under the applicable law, including the relevant provisions of the General Data Protection Regulation and comparable regional rules. If regional law gives you a right to information about, or to object to, automated decision-making that we carry out as a controller, you may exercise that right by contacting us.
20. Data breach notification
We maintain procedures to detect, investigate, contain, and respond to personal data breaches. If a breach affecting personal data for which we are the controller is likely to result in a risk to individuals, we notify the relevant supervisory or regulatory authority and, where required, affected individuals, within the timeframes set by the applicable law. Under the General Data Protection Regulation this generally means notifying the competent authority without undue delay and, where feasible, within seventy-two hours of becoming aware of a qualifying breach.
Where we act as a processor or service provider for a client, we notify the client without undue delay after becoming aware of a personal data breach affecting that client's data, and we support the client in meeting its own notification obligations, as set out in the executed data processing agreement. We keep records of breaches and our response as required by law.
21. Third-party links and services
Our website may contain links to third-party websites, platforms, and services that we do not control, such as scheduling tools, social media pages, and partner sites. This policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy notices of any third-party service before providing personal data to it.
22. Changes to this policy
We may update this policy from time to time to reflect changes in our practices, our services, or the law. When we make material changes, we will update the date shown at the top of this policy and, where appropriate, provide additional notice. We encourage you to review this policy periodically. Your continued use of our website after an update takes effect indicates that you are aware of the current version.
23. Contact and data protection contact
If you have questions about this policy or our privacy practices, or if you wish to exercise a right, please contact us at info@corpshore.ai. You can address correspondence to the data protection contact of Corpshore Solutions Corporation at that email address, and we will route your request to the appropriate team.
For personal data subject to Quebec's Law 25, the same contact acts as the person responsible for the protection of personal information. For enquiries from the European Economic Area, the United Kingdom, Canada, Australia, or the United States, please indicate your region so that we can apply the correct process. This policy is provided for information and does not constitute legal advice, and the binding terms of any engagement are governed by the executed agreement with Corpshore Solutions Corporation.
Questions about this policy? Contact info@corpshore.ai. This document is provided for information and does not constitute legal advice; final terms are governed by your executed agreement with Corpshore Solutions Corporation.