CoreVisor CoreVisor
🔒 LEGAL

Privacy Policy

Last updated: August 2026

1. Responsible party

CoreVisor — operated and technically backed by Sensando, with registered address at C.104B Mérida, Yucatán, México — is responsible for the collection, use and protection of the personal data described in this policy, in compliance with Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) and its regulations.

Privacy department: privacy@corevisor.io.

2. Personal data we collect

Depending on your relationship with CoreVisor, we may collect:

A. Site visitors and prospects. Identification and contact data you submit when requesting a demo or contacting us — name, role or rank, operation type and device volume — plus navigation and analytics data (section 6).

B. Customer organizations. Account administration data, billing and tax data (e.g. RFC / tax ID) and platform configuration.

C. Operational data processed through the platform. Telemetry and GPS, video streams, access control records (including biometrics), plate records, emergency call audio and transcriptions, WhatsApp messages and public social-feed signals. This data belongs to the customer organization and is processed strictly on its instructions.

3. Sensitive data — biometrics, video and voice

CoreVisor processes sensitive data in the course of its security functions: face snapshots and recognition vectors, fingerprint records from access terminals (Hikvision, ZKTeco and compatible devices), video feeds, plate records, and emergency call audio transcribed by EKO.

This data is used exclusively to verify identity, prevent impersonation, enforce access permissions and respond to security incidents. It is encrypted in transit and at rest, and is never sold or used for commercial profiling.

In these operations CoreVisor acts as data processor on behalf of the operating organization (the customer), which remains the responsible party toward its officers, employees and the public.

4. Purposes of processing

Primary purposes (necessary for the service): respond to your requests and prepare technical simulations; operate, maintain and secure the platform; run security and incident response; provide support; and comply with billing and contractual obligations.

Secondary purposes: send product updates, surveys and event invitations. You may opt out of secondary purposes at any time by writing to privacy@corevisor.io.

5. Third-party processors and transfers

To operate the platform, CoreVisor relies on essential service providers: cloud infrastructure (Google Cloud / AWS), WhatsApp automation through Meta's Official API, telemetry middleware (Flespi / Teltonika), and payment processors where applicable. Data is shared only as strictly necessary for the operation of the service and under confidentiality obligations.

CoreVisor does not sell, rent or trade your data — or the data of the people your operation serves — to marketing companies or unrelated third parties. Where providers are located abroad, transfers occur under appropriate legal safeguards.

6. Cookies and tracking technologies

Our website uses cookies and similar technologies, including Google Analytics 4 and Microsoft Clarity, to understand navigation (time on site, sections visited, referring pages) and improve your experience. You can disable cookies from your browser settings; the site remains functional.

7. Your rights (ARCO)

Under applicable data protection law you may exercise your rights of Access, Rectification, Cancellation and Opposition. Send your request to privacy@corevisor.io; we will respond within the statutory periods.

Note for end users: if your data is processed through a CoreVisor deployment (for example, as an officer, employee or citizen), please exercise your rights with the operating organization, which is the responsible party. CoreVisor acts as its processor.

8. Data retention

Prospect and contact data is kept while your request is active and for the legal terms that apply. Operational audit logs are retained per your service agreement and applicable custody-chain regulations. Video and call records follow the retention policy of the customer organization and applicable evidence rules. Biometric vectors are stored only while enrollment is active and are deleted upon cancellation.

9. Security measures

Encryption in transit and at rest (end-to-end encryption in cloud deployments), role-based access control, an immutable audit trail of every system action, and an air-gapped on-premise option where all data remains inside your closed network.

10. Changes to this policy

We may update this policy due to new legal requirements, product changes or business needs. The current version is always published on this page. Continued use of the site and the platform after publication of changes constitutes acceptance.

11. Contact

Privacy department: privacy@corevisor.io · General inquiries: hello@corevisor.io.