Skip to main content

Privacy Policy

Last updated: 2026-09-04

MspCoreX SRL ("we", "us", "the company"), a company registered in Romania, operates the MspCoreX platform — this website (mspcorex.com), the web application at app.mspcorex.com, the associated mobile applications, and the endpoint monitoring agents. This policy explains what personal data we collect, why, and the rights you have over it, in accordance with the EU General Data Protection Regulation (GDPR).

1. Two roles: controller and processor

For data about website visitors, prospects, and platform account holders, MspCoreX SRL acts as the data controller — this policy applies.

For data that our customers store inside the platform (their own clients' contacts, tickets, monitored devices), MspCoreX SRL acts as a data processor on the customer's behalf. That processing is governed by our Data Processing Addendum, and requests concerning it should be addressed to the organization that holds the account.

2. Data we collect

  • Account data: name, work email address, company, role, and an encrypted password (or your identity-provider reference if you sign in via SSO).
  • Contact and lead data: name, email, company, team size, and country when you request a trial, a demo, or contact us.
  • Billing data: company details, VAT number, and invoicing records for paid subscriptions.
  • Usage and technical data: actions performed in the application, device type, operating system, browser and application version, IP address, and server logs kept for security.
  • Support correspondence: messages and attachments you send our support team.

3. Purposes and legal bases

  • Providing the service (accounts, authentication, notifications, support) — performance of a contract (Art. 6(1)(b) GDPR).
  • Responding to trial, demo, and contact requests — steps taken at your request prior to a contract (Art. 6(1)(b)).
  • Security, fraud prevention, and service improvement — our legitimate interest (Art. 6(1)(f)).
  • Invoicing and accounting — legal obligation (Art. 6(1)(c)).
  • Marketing communications — only with your consent (Art. 6(1)(a)), which you can withdraw at any time.

4. Cookies

This website sets no advertising or third-party tracking cookies. We use only what is strictly necessary: a language-preference cookie, and — in the application — session and security (CSRF) cookies. Because we use no non-essential cookies, no consent banner is required. The full inventory — the one cookie, its attributes, and when it is set — is in our Cookie Policy.

5. Website analytics

We measure traffic to this website with Umami, which we run ourselves on our own infrastructure in the EU. The analytics data reaches no third party and stays on our servers. The request that produced it does not: this site is served through Cloudflare, which sees the connection before we do — it is named on our sub-processor register and described in our Cookie Policy. Umami itself sets no cookie and stores no identifier on your device: a visit is counted as a one-way hash of your IP address and browser user agent, salted and rotated daily, which cannot be reversed or linked to you across days. We keep page, referrer, country, and device type — never the IP address itself. The legal basis is our legitimate interest in understanding which pages are read (Art. 6(1)(f)); because no information is stored on or read from your device, no consent is required and no banner is shown. If your browser sends Do Not Track, nothing is recorded at all.

6. Data sharing

We do not sell personal data. We share it only with:

  • Infrastructure subprocessors strictly necessary to run the service. The operative list is the subprocessor register at /legal/subprocessors, which records each one's purpose, location, scope and transfer basis; material changes are announced 30 days in advance. We do not engage a subprocessor the register marks Platform without a written contract imposing data protection obligations no less protective than those of our Data Processing Addendum. One marked Tenant-selected processes data only where your organization connects it, ordinarily under its own account or key with that provider.
  • Competent authorities, where a legal obligation requires it.
  • Anyone else only with your explicit consent.

7. International transfers

Personal data is stored and processed within the European Union. Where a subprocessor processes data outside the EU/EEA, the transfer mechanism we rely on for that subprocessor — an adequacy decision, or Standard Contractual Clauses (SCCs) with supplementary measures — is recorded in the Transfer basis column of our subprocessor register at /legal/subprocessors. Where that column reads pending, the transfer impact assessment and the clauses for that subprocessor are still being finalised.

8. Data retention

  • Account data: for the life of the contract, then deleted within 90 days of termination.
  • Lead data: deleted no later than 24 months after our last contact, unless you become a customer.
  • Audit logs: up to 7 years, to meet security and compliance obligations.
  • Backups: rolling 30-day window, then overwritten.
  • Invoicing records: as required by Romanian fiscal law (currently 10 years).

9. Security

  • Encryption in transit (TLS) and at rest.
  • Passwords stored only as salted cryptographic hashes; MFA available on all accounts.
  • Per-tenant data isolation, session expiry, and full audit trails.
  • Access on a need-to-know basis, with regular access reviews.

The full list of technical and organizational measures is on our Security page.

10. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate data.
  • Erase your data ("right to be forgotten").
  • Port your data in a structured, machine-readable format.
  • Object to processing based on legitimate interest.
  • Restrict processing in certain circumstances.
  • Withdraw consent at any time, where processing is based on consent.

To exercise any of these rights, write to privacy@mspcorex.com. We respond within 30 days. You also have the right to lodge a complaint with a supervisory authority — in Romania, ANSPDCP (dataprotection.ro), or the authority of your country of residence.

11. Children

MspCoreX is a business-to-business platform and is not directed at individuals under 16. We do not knowingly collect data from children.

12. Changes to this policy

We may update this policy from time to time. The date at the top reflects the latest revision, and we notify account holders of material changes through the application before they take effect.

13. Contact

MspCoreX SRL
CUI 55420060 · Reg. Com. J2026049623008 · EUID ROONRC.J2026049623008
Aleea Sinaia nr. 6, Sector 2, Bucharest, Romania
Email: privacy@mspcorex.com
Web: www.mspcorex.com