Legal

Privacy Policy

Effective date: 1 July 2026  ·  Last updated: 1 July 2026
Applies to: core.ssdbtech.com and all CORE platform services
Controller: SSDB Tech Services, Inc., Texas, USA

This Privacy Policy explains how SSDB Tech Services, Inc. ("SSDB Tech", "we", "us", "our") collects, processes, stores, and protects personal data when you use CORE — our AI-powered enterprise software generation platform available at core.ssdbtech.com. We are committed to transparency, data minimisation, and your rights under applicable privacy laws worldwide.

1. Who we are and how to contact us

SSDB Tech Services, Inc. is a corporation incorporated under the laws of the State of Texas, United States. CORE is a software product of SSDB Tech, accessible at core.ssdbtech.com.

For all privacy-related enquiries, requests, and complaints, contact our Privacy Team:

Email: privacy@ssdbtech.com

Website: core.ssdbtech.com

We respond to all privacy requests within 30 days, and within 72 hours for urgent data breach reports.

2. Scope of this policy

This Privacy Policy applies exclusively to the CORE platform at core.ssdbtech.com. It governs the processing of personal data of:

  • Individuals who register for or access a CORE account on behalf of a business organisation
  • Authorised users within customer organisations who use CORE to generate software specifications and applications
  • Visitors to core.ssdbtech.com who browse our website without creating an account

This policy does not apply to ssdbtech.com or any other SSDB Tech services, which are governed by their own separate policies. CORE is a business-to-business platform intended for use by professionals aged 18 and over acting in a commercial capacity. We do not knowingly collect data from individuals under the age of 18 and do not offer CORE to consumers for personal, household, or family use.

3. What data we collect and why

3.1 Account and identity data

When you access CORE via Microsoft Single Sign-On (SSO), your identity provider authenticates you. We receive confirmation of successful authentication only — we do not store your Microsoft password, Microsoft profile data, or organisational directory information. The data we associate with your CORE account is limited to:

  • Your work email address (used as your CORE identifier and for platform communications)
  • Account access timestamps and session metadata (for security and audit purposes)
  • Your organisation's subscription tier and access permissions

As CORE expands to support additional authentication methods, this section will be updated to reflect any additional data collected through those methods.

3.2 Project and input data

When you use CORE to generate software, you may provide:

  • Text descriptions of business requirements, processes, and systems
  • Uploaded documents, including requirements specifications, database schemas, architecture documents, and similar technical artefacts
  • Answers to structured questions within the CORE guided workflow
  • Feedback and edits to AI-generated outputs during the review stages

This data is used solely to process your request and generate your software specification or application. It is not shared with other CORE customers, not used to train our AI models or any third-party AI models, and not used for any purpose beyond delivering the CORE service to you.

3.3 Usage and technical data

We automatically collect limited technical information when you use CORE, including:

  • IP address (used for security, fraud prevention, and approximate geographic region identification for data routing compliance)
  • Browser type and version, operating system, and device type
  • Pages visited within core.ssdbtech.com, session duration, and navigation patterns
  • Error logs and platform performance data

This data is collected using industry-standard analytics tools. Where analytics data is used, it is processed in aggregated or anonymised form for the purpose of improving CORE's functionality and reliability.

3.4 Communications data

If you contact us via email or our contact form, we retain the content of that communication and your contact details in order to respond to you and maintain a record of our correspondence.

4. Legal bases for processing (applicable to EEA, UK, and similar jurisdictions)

For users in the European Economic Area (EEA), United Kingdom, and other jurisdictions that require a documented legal basis for processing personal data, we rely on the following:

  • Performance of a contract — Processing your account data, project data, and authentication data is necessary to provide CORE to you under our terms of service
  • Legitimate interests — Processing usage and security data to maintain the integrity, performance, and security of CORE, where those interests are not overridden by your fundamental rights
  • Legal obligation — Retaining certain records where required by applicable law, including tax, accounting, and regulatory obligations
  • Consent — Where we send optional marketing or product update communications, subject to your opt-in

5. AI processing and third-party AI sub-processors

Important: CORE uses third-party AI models via API to process your inputs and generate software outputs. Your data is transmitted to these AI providers solely to fulfil your request. We do not disclose the identity of specific AI providers on this page in order to protect our platform architecture, but we maintain a current list of AI sub-processors which is available to enterprise customers on request at privacy@ssdbtech.com.

Our commitments regarding AI processing are as follows:

  • No AI training on your data: We have executed Data Processing Agreements with each AI sub-processor we use. Under those agreements, your inputs and uploaded data are contractually prohibited from being used to train, fine-tune, or improve any AI model — whether belonging to us or to the AI provider.
  • Session isolation: Each CORE session is processed independently. Your data is never pooled with other customers' data, and outputs generated for you are never influenced by other customers' inputs.
  • Purpose limitation: AI sub-processors receive only the minimum data necessary to generate your requested output. They are contractually restricted from processing your data for any other purpose.
  • Data transfer safeguards: Transfers to AI sub-processors located outside your jurisdiction are protected by appropriate legal mechanisms, including Standard Contractual Clauses where applicable.

You can request the full list of current AI sub-processors and copies of the relevant Data Processing Agreements by contacting privacy@ssdbtech.com.

6. Data storage, retention, and deletion

6.1 Where your data is stored

CORE's infrastructure is hosted in the United States. For customers in the European Economic Area and United Kingdom, we route and store project data in EU-region infrastructure to comply with GDPR data residency requirements. Your IP address at point of login is used to determine the applicable data routing region.

6.2 Retention periods

  • Project data (uploaded documents, inputs, generated outputs): Retained for 30 days from creation, then permanently and irreversibly deleted from all systems including backups
  • Account data (email address, subscription data, access logs): Retained for the duration of your active subscription plus 90 days, then deleted unless retention is required by law
  • Communications data: Retained for 3 years from the date of last correspondence
  • Security and audit logs: Retained for 12 months for security monitoring purposes
  • Analytics data: Processed in anonymised or aggregated form; not subject to individual retention periods

6.3 User-initiated deletion

You may request permanent deletion of your project data at any time before the automatic 30-day deletion by submitting a deletion request through your CORE account dashboard or by emailing privacy@ssdbtech.com. Deletion requests are executed within 72 hours and confirmed to you by email. Deleted data cannot be recovered.

7. Data sharing and disclosure

We do not sell, rent, or trade your personal data. We share data only in the following limited circumstances:

  • AI sub-processors: As described in Section 5, solely for the purpose of generating your requested outputs
  • Infrastructure and hosting providers: Cloud hosting, content delivery, and security providers who process data on our behalf under data processing agreements
  • Analytics providers: For aggregated, anonymised website analytics only
  • Legal compliance: Where we are required by applicable law, court order, or government authority to disclose data. Where legally permitted, we will notify you before complying
  • Protection of rights: Where disclosure is necessary to protect the rights, property, or safety of SSDB Tech, our users, or the public
  • Business transfers: In the event of a merger, acquisition, or sale of all or substantially all of SSDB Tech's assets, personal data may be transferred to the acquiring entity, subject to equivalent privacy protections

8. Your privacy rights

Depending on your jurisdiction, you have the following rights. We honour all of these rights regardless of your location, subject to applicable legal limitations:

  • Right to access — Request a copy of the personal data we hold about you
  • Right to rectification — Request correction of inaccurate or incomplete data
  • Right to erasure — Request deletion of your personal data ("right to be forgotten")
  • Right to restrict processing — Request that we limit how we use your data
  • Right to data portability — Receive your data in a structured, machine-readable format
  • Right to object — Object to processing based on legitimate interests or for direct marketing
  • Right to withdraw consent — Withdraw any consent given at any time without affecting lawfulness of prior processing
  • Right not to be subject to automated decisions — CORE does not make automated decisions that produce legal or similarly significant effects about individuals

To exercise any right, email privacy@ssdbtech.com. We respond within 30 days. We may request identity verification before processing your request.

9. Jurisdiction-specific provisions

European Economic Area & UK (GDPR / UK GDPR)

SSDB Tech acts as data controller. Enterprise customers may request a Data Processing Agreement (DPA / Article 28 GDPR) at privacy@ssdbtech.com. Transfers to the US are protected by Standard Contractual Clauses (SCCs). You may lodge a complaint with your national supervisory authority (e.g. ICO in the UK).

California, USA (CCPA / CPRA)

We do not sell or share personal information for cross-context behavioural advertising. California residents have the right to know, delete, correct, and opt out of sale. We do not discriminate against users who exercise CCPA rights. Contact privacy@ssdbtech.com to exercise rights.

India (DPDP Act 2023)

SSDB Tech processes personal data of Indian data principals in accordance with the Digital Personal Data Protection Act 2023. You have rights to access, correct, and erase your data, and to nominate a representative. Contact privacy@ssdbtech.com to exercise rights or raise a grievance.

Brazil (LGPD)

Processing of personal data of Brazilian data subjects is conducted in accordance with the Lei Geral de Proteção de Dados. You have the right to confirmation of processing, access, correction, anonymisation, portability, deletion, and information about sharing. Contact privacy@ssdbtech.com.

Canada (PIPEDA / Law 25)

Personal data is collected with consent and used only for identified purposes. You have the right to access and correct your data and to withdraw consent. Quebec residents have additional rights under Law 25. Contact privacy@ssdbtech.com.

Australia (Privacy Act 1988)

SSDB Tech complies with the Australian Privacy Principles (APPs). You have the right to access and correct personal information we hold. Cross-border transfers are conducted with appropriate protections. Contact privacy@ssdbtech.com or raise a complaint with the OAIC.

UAE & Saudi Arabia (PDPL / DIFC / ADGM)

We process personal data of users in UAE and Saudi Arabia in compliance with applicable data protection frameworks including the Saudi Personal Data Protection Law (PDPL) and applicable UAE free zone regulations. Contact privacy@ssdbtech.com.

Other jurisdictions

We apply the standards of this policy globally. Where local law provides additional rights or protections, we will comply with those obligations. If you are uncertain about your rights in your jurisdiction, contact us at privacy@ssdbtech.com.

10. EU/UK Data Processing Agreement

Enterprise customers whose organisations are established in the EEA or UK and who process personal data through CORE are entitled to a Data Processing Agreement (DPA) as required by GDPR Article 28. The DPA will: identify SSDB Tech as data processor acting on your instructions; document the subject matter, nature, and purpose of processing; set out your and our respective obligations; and incorporate Standard Contractual Clauses for onward data transfers. To request a DPA, contact privacy@ssdbtech.com.

11. Cookies and tracking

CORE uses Google Analytics to collect anonymised, aggregated usage data to understand how the platform is used and to improve its functionality. Google Analytics may set cookies on your device. You can opt out by installing the Google Analytics Opt-out Browser Add-on.

We do not use advertising cookies, cross-site tracking cookies, or any cookies for behavioural profiling. The only cookies placed by CORE are those strictly necessary for platform functionality (session management, authentication state) and the Google Analytics measurement cookie described above.

12. Security of your data

We implement technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.2 or higher), encryption at rest (AES-256), access controls based on least privilege, and regular security assessments. For full details of our security measures, see our Security Policy.

In the event of a personal data breach that creates a risk to your rights and freedoms, we will notify you and relevant supervisory authorities within the timeframes required by applicable law (72 hours for GDPR; promptly for other jurisdictions).

13. Children's data

CORE is a professional enterprise software platform intended exclusively for use by business professionals aged 18 and over, accessing CORE on behalf of their employing organisation. We do not knowingly collect personal data from individuals under the age of 18. If you believe we have inadvertently collected data from a minor, contact privacy@ssdbtech.com immediately and we will delete the data without delay.

14. Changes to this policy

We may update this Privacy Policy to reflect changes in our practices, legal obligations, or the CORE platform. When we make material changes, we will: update the "Last updated" date at the top of this page; notify active users by email at least 30 days before the change takes effect (for material changes); and, where required by law, seek fresh consent. Your continued use of CORE after the effective date of a revised policy constitutes acceptance of the revised terms. If you do not agree, you may request deletion of your account and data by contacting privacy@ssdbtech.com.

Privacy contacts

General privacy enquiries & rights requests: privacy@ssdbtech.com

Data breach reports: privacy@ssdbtech.com (mark subject: URGENT — Data Breach)

EU/UK DPA requests: privacy@ssdbtech.com

Website: core.ssdbtech.com

SSDB Tech Services, Inc.  ·  Incorporated in Texas, USA  ·  Response time: 30 days standard, 72 hours for urgent breach reports