| Document version | 1.2.0 |
|---|---|
| Published | 29 August 2026 |
| Effective date | 28 September 2026 |
| Last updated | 29 August 2026 |
This Privacy Policy explains how Boeni Industries AG processes personal data in connection with corelineos.com, Coreline OS, enquiries, business relationships and related communications. It complements the Coreline OS Terms of Service. It does not replace the Data Processing Addendum in the Terms, which governs personal data that we process on a customer's documented instructions.
1. Controller and contact
The controller for the processing described in this Privacy Policy is:
Boeni Industries AG
Sihleggstrasse 23
CH-8832 Wollerau
Switzerland
Commercial Register of the Canton of Schwyz: CHE-404.375.091
Email: hello@corelineos.com
We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP). Where the EU General Data Protection Regulation (GDPR) applies, we also process personal data in accordance with the GDPR.
2. Scope and roles
This Policy applies when you visit our website, contact us, register interest, act for a prospective or actual customer, use Coreline OS as an authorised user, or otherwise interact with us in a business context. It covers the customer-facing Coreline OS addresses below and the personal data processed through them:
| Service | Official address |
|---|---|
| Commercial website | https://corelineos.com and https://www.corelineos.com |
| Coreline OS Studio | https://studio.corelineos.com |
| Coreline OS API | https://api.corelineos.com |
| Coreline OS platform and tenant platform MCP | https://platform.corelineos.com |
| Coreline OS runtime MCP | https://mcp.corelineos.com |
Transactional messages may be sent from @mail.corelineos.com. No other domain or address is an official customer-facing Coreline OS service unless Boeni Industries AG communicates it through one of the addresses above or in a signed agreement.
Coreline OS is a business service. When a customer uploads, connects or otherwise makes personal data available in its workspace, that customer normally determines the purposes and means of processing. In that case, the customer is the controller (or a processor acting for its own controller) and Boeni Industries AG acts as processor under the Data Processing Addendum. Data subjects should direct requests about that customer data to the relevant customer first.
We act as an independent controller for our own account, contact, commercial, payment-administration, security, website and service-telemetry data, and for data that we otherwise process for our own business purposes.
3. Personal data we process
Depending on how you interact with us, we process the following categories of data.
| Context | Categories of data |
|---|---|
| Website visit | IP address, device and browser information, requested pages, referring pages, timestamps, language and cookie or consent preferences, plus security and diagnostic logs. |
| Enquiries and interest registration | Name, work email address, organisation, role, message, stated operational need, correspondence and records of our response. |
| Customer and authorised-user account | Name, work contact details, organisation, role, account identifier, authentication and access information, assigned permissions, account activity and support correspondence. |
| Service operation | Technical identifiers, audit and security events, configuration and usage information, capacity and consumption records, error reports and support information. Customer-provided workspace data is processed as described in section 2. |
| Commercial relationship | Contact and contract details, purchase and billing references, transaction status, invoices or receipts and tax-related information supplied by the merchant of record or payment provider. We do not store full payment-card details. |
| Communications | Communications with us, preferences, subscriptions or consents, and records needed to respond or demonstrate compliance. |
We receive data directly from you or the organisation you represent, from your use of our website or Service, from a customer workspace administrator, from a connected service enabled by the customer, and from payment or merchant-of-record providers in connection with a transaction.
4. Why we process personal data
We use personal data for the following purposes:
- providing, operating, securing, maintaining and supporting the website and Coreline OS;
- creating and administering accounts, authenticating users, managing access and preventing unauthorised use;
- responding to enquiries, evaluating interest in the Service, communicating about onboarding and maintaining a business relationship;
- providing customer support, diagnosing faults, maintaining audit trails and improving reliability, security and user experience;
- calculating usage, administering capacity, managing purchases and complying with accounting, tax, fraud-prevention and contractual obligations;
- sending service, security, administrative and transactional communications;
- improving our website and Service using aggregated, de-identified or appropriately limited analytics; and
- establishing, exercising or defending legal claims and complying with legal obligations or authority requests.
Under the FADP, we process personal data where the processing is lawful and does not unlawfully infringe personality rights, including where it is necessary for the purposes described above. Where the GDPR applies, the relevant legal basis is normally performance of a contract or steps requested before entering into a contract (Article 6(1)(b)), our legitimate interests in operating a secure and effective business service (Article 6(1)(f)), compliance with legal obligations (Article 6(1)(c)), or consent where we request it (Article 6(1)(a)). You may withdraw consent at any time for future processing; this does not affect processing already carried out lawfully.
We do not use personal data for solely automated decisions that produce legal effects concerning you or similarly significantly affect you, unless we have separately informed you and the processing is permitted by applicable law.
5. Cookies, analytics and similar technologies
We use necessary cookies and similar technologies to provide the website and Service securely, preserve your choices, enable essential functions and protect against abuse. These are required for the relevant service to work.
Optional analytics and marketing technologies are not activated unless you opt in through our cookie settings where consent is required. Analytics help us understand aggregate visits and interactions so that we can improve the website. Marketing technologies help us measure campaign attribution and performance. You can change or withdraw your choice at any time through Cookie settings in the website footer. Withdrawing consent does not affect processing carried out before withdrawal.
Browser settings may allow you to delete or block cookies. Blocking necessary technologies can impair the website or Service. The cookie settings interface provides the current categories and choices; we update it when technologies materially change.
6. Recipients and processors
We use carefully selected service providers to operate the website and Service. They may process personal data only for the purposes we instruct or as otherwise permitted by law and subject to appropriate contractual safeguards. Material providers currently include:
| Provider | Purpose | Processing location |
|---|---|---|
| Exoscale | Hosting, managed data services and infrastructure for Coreline OS. | Switzerland |
| Brevo | Transactional email delivery and operational email handling. | France / European Union |
| OpenAI and Anthropic | Model processing when a Coreline OS function requires it. | United States |
| Merchant of record / payment provider, currently Creem where offered | Hosted checkout, payment execution, taxes, invoices or receipts, refunds and payment disputes. | As stated in the provider's own privacy notice and transaction flow |
We may also disclose data to professional advisers, insurers, auditors, authorities, courts, counterparties in a corporate transaction, or other recipients where this is necessary for a legal obligation, a legitimate business purpose, or the establishment, exercise or defence of legal claims. We do not sell personal data.
7. International transfers
Coreline OS infrastructure is hosted in Switzerland. Some providers may process data in the European Union, the United States or another country. Where personal data is transferred to a country that does not provide an adequate level of protection under applicable law, we use the required safeguards, such as recognised standard contractual clauses with the adaptations required for Swiss law, or rely on another lawful transfer mechanism. You may request information about the relevant safeguards using the contact details in section 1, subject to confidentiality and legal restrictions.
The customer remains responsible for assessing and authorising any connected service or external recipient that it enables within its workspace.
8. Retention and deletion
We retain personal data only for as long as necessary for the purpose for which it was collected, to maintain the business relationship, meet legal retention duties, protect security, resolve disputes or establish, exercise or defend claims.
Retention periods depend on the data and context. For example, website security logs are retained for the period reasonably needed for operations and security; enquiry data is periodically reviewed and deleted or anonymised when no longer needed; and account, contract, usage and commercial records are retained for the term of the relationship and thereafter as required by law or legitimate record-keeping needs. Customer Data is retained and deleted under the customer's agreement and the Data Processing Addendum; absent a different contractual period, the Terms provide a 30-day post-termination export window.
Backups may retain data for a limited additional period before they are overwritten. We restrict any restoration of deleted data to legitimate disaster-recovery purposes.
9. Security
We use technical and organisational measures appropriate to the risk to protect personal data. These include, as appropriate, access controls, authentication, tenant segregation, encryption in transit, controlled operational access, logging, monitoring, vulnerability management, backup and recovery procedures. No internet service or data transmission can be completely secure. You are responsible for protecting your devices, credentials and any workspace access under your control.
10. Your rights
Subject to the conditions and limitations of applicable law, you may have the right to:
- request information about the personal data we process about you;
- request correction of inaccurate personal data;
- request deletion of personal data where there is no overriding retention or other lawful reason to process it;
- object to processing based on legitimate interests;
- request restriction of processing, where the GDPR applies;
- receive or request transmission of eligible data in a commonly used format, where applicable; and
- withdraw consent at any time for future processing.
To exercise a right, contact us at hello@corelineos.com. We may ask for information needed to verify your identity and will respond in accordance with applicable law. You may also lodge a complaint with the competent supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC). If the GDPR applies to the processing, you may also have the right to complain to the competent EEA supervisory authority.
11. Children
Coreline OS is intended for organisations and professional users. We do not knowingly seek or collect personal data directly from children. If you believe that a child has provided personal data to us, please contact us so that we can take appropriate action.
12. Changes to this Policy
We may update this Policy when our processing, providers, products or legal obligations change. We will publish the updated version with a revised date and, where required, provide additional notice through the website, Service or another appropriate channel.
13. Version history
| Version | Published | Effective | Change summary |
|---|---|---|---|
| 1.0.0 | 22 August 2026 | 22 August 2026 | Initial public Privacy Policy. |
| 1.1.0 | 22 August 2026 | 21 September 2026 | Version alignment with Terms v1.1.0; no material change to this Privacy Policy. |
| 1.2.0 | 29 August 2026 | 28 September 2026 | Version alignment with Terms v1.2.0; no material change to this Privacy Policy. |