# Privacy policy draft
HOLISTICCORE Information Technology Services processes account details, project briefs, uploaded references, payment evidence, generated artifacts, service communications, audit events, and technical logs to provide and secure the service.
## Contact
Privacy questions and deletion requests: support@holisticcoreit.com
## Purposes
- create and secure accounts;
- generate, preview, customize, and deliver projects;
- verify payments and provide support;
- prevent abuse and investigate incidents;
- comply with legal and accounting obligations.
## Sharing
Data may be processed by contracted hosting, storage, email, monitoring, payment, and AI providers only as needed to operate the service. Project text sent to an AI provider must not contain secrets or unnecessary personal data.
## Retention
Temporary previews should expire automatically. Abandoned projects and uploads should follow the documented retention schedule. Payment and contractual records may be retained for legal and accounting requirements. Backups expire according to the operations policy.
## Security and rights
The service uses access controls, encrypted transport, audit logging, backups, and restricted workers. Users may request access, correction, export, or deletion where applicable. Some records may be retained when required by law or to resolve disputes.
This draft requires review for compliance with the Philippine Data Privacy Act and the actual providers selected for production.
## First-party usage analytics
For signed-in Client accounts, the service records the application page or controller action visited, the visit date, visit count, and first and most recent visit time. This information is used to understand feature adoption, improve navigation, prioritize product work, provide support, and protect service reliability. The analytics do not record form contents, passwords, private messages, uploaded file contents, or URL query strings. Access is restricted to authorized platform administrators.
## Account-device security
For Client account protection, the service stores a one-way digest of a random browser device token, the binding time, and limited request metadata (IP address and browser user agent) when a device or email change is submitted. The raw device token remains in an encrypted, HTTP-only browser cookie. Authorized administrators review account change requests; request records are retained for security and audit purposes.
## Account device security records
For account security and fraud prevention, the service records the latest authenticated browser and operating-system signature, a masked internal device identifier, the latest IP address, and last-seen time. These records are visible only to authorized Admin users and are not used to store form contents or browsing query parameters.
## First-party visitor analytics
The service records successful HTML page visits for guests and signed-in users to understand traffic and feature use. Records include an anonymous random browser identifier for guests, the signed-in account for authenticated users, the user category (Guest, Client, or Admin), the page/controller action, normalized path without query strings, date, count, and first and latest visit times. Form contents, passwords, private messages, uploads, URL query strings, and security/MFA pages are excluded. Guest identifiers do not contain names, email addresses, or raw IP addresses. Access is restricted to authorized Admin users.
HC
Help & Messages
Choose who you want to contact
Hi! I am Core, the AI Guide. Ask me about services, how the platform works, or which solution may fit your business.
Checking free question balance...
AI guidance may be imperfect. Do not share sensitive information.
Open a project, service, or deployment request to start a private conversation.