GDPR Policy

Last Updated:

Thursday, March 6, 2025

Core Flow Intelligence ("we," "our," "us") is committed to safeguarding the privacy and security of personal data in compliance with the General Data Protection Regulation (GDPR). This policy outlines how we collect, use, store, and protect personal data and the rights of individuals under GDPR.

1. Scope

This policy applies to all personal data processed by Core Flow Intelligence, whether electronically, on paper, or through any other means. It covers data related to employees, customers, suppliers, and any other identifiable individuals


2. Data Controller

Core Flow Intelligence is the Data Controller, responsible for determining the purposes and means of processing personal data. For inquiries, please contact our Data Protection Officer (DPO):

πŸ“Core Flow Intelligence
20 S Charles St, Ste 403,
Baltimore, MD, USA
πŸ“§ DPO Contact Email: support@coreflowintelligence.ai

3. Principles of Data Protection

We adhere to the following principles when processing personal data:

  • Lawfulness, Fairness, and Transparency – Personal data is processed lawfully, fairly, and transparently.

  • Purpose Limitation – Data is collected for specific, explicit, and legitimate purposes.

  • Data Minimization – Data collection is limited to what is necessary for the intended purpose.

  • Accuracy – Personal data is accurate and kept up to date.

  • Storage Limitation – Data is stored only as long as necessary for its intended purpose.

  • Integrity and Confidentiality – Data is processed securely to prevent unauthorized access, loss, or destruction

4. Data Collection and Use

We collect and process personal data only for the following purposes::

  • To fulfill contractual obligations.

  • To comply with legal requirements.

  • To improve our products and services.

  • To communicate effectively with customers and stakeholders.


5. Legal Basis for Processing

We process personal data based on one or more of the following legal grounds:

  • Consent – The individual has given explicit consent.

  • Contractual Necessity – Processing is necessary to perform a contract.

  • Legal Obligation – Compliance with legal requirements.

  • Legitimate Interests – To pursue legitimate business interests, provided they do not override individual rights.


6. Data Subject Rights

Under GDPR, individuals have the following rights:

  • Right to Access – Request access to their personal data.

  • Right to Rectification – Request correction of inaccurate or incomplete data.

  • Right to Erasure – Request deletion of data, subject to certain conditions.

  • Right to Restriction – Restrict the processing of their data.

  • Right to Data Portability – Request transfer of their data to another organization.

  • Right to Object – Object to data processing in certain circumstances.

  • Right to Withdraw Consent – Withdraw consent at any time when processing is based on consent.

To exercise these rights, contact support@coreflowintelligence.ai.

7. Data Sharing and Transfers

We do not sell or rent personal data to third parties. However, data may be shared with.

  • Service providers under strict confidentiality agreements.

  • Regulatory authorities as required by law.

  • Third parties with explicit consent from the individual.


When transferring data outside the European Economic Area (EEA), we ensure adequate safeguards are in place to protect the data.

8. Data Security

We implement robust security measures to protect personal data against unauthorized access, alteration, disclosure, or destruction, including:

  • Encryption of sensitive data.

  • Regular security assessments and audits.

  • Access controls and authentication mechanisms.


9. Data Retention

Personal data is retained only as long as necessary to fulfill the purposes for which it was collected or as required by law. Upon expiry of the retention period, data is securely deleted or anonymized.

10. Limitation of Liability

In the event of a data breach, we will notify:

  • Affected individuals.

  • Relevant supervisory authorities within 72 hours, as required by GDPR


11. Changes to This Privacy Policy

We may update this policy periodically to reflect changes in regulations or business practices. The latest version will always be available on our website.

12. Contact Information

For any questions or concerns regarding this policy or your personal data, contact:

πŸ“§ General Support: support@coreflowintelligence.ai
πŸ“§ Product Support: support@echobase.ai

Core Flow Intelligence, 20 S Charles St, Ste 403, Baltimore MD, USA

Thank you for using Echobase.

The Echobase Team