Zum Hauptinhalt springen
Core Industry
ProcessProjectsAbout
PortalStart a Project
Legal

Privacy Policy

In accordance with GDPR (EU) 2016/679 — Last updated: April 2026

1. Controller (Art. 4 No. 7 GDPR)

Responsible for data processing on this website:

Isam Al-Ani · Core IndustryMax Schwarze Weg 27A, 46236 BottropE-Mail: info@coreindustry.deTel.: +49 2041 3894257

2. Overview of data processed

Data categories processed:

  • Master data (name, company name)
  • Contact data (email address, phone number)
  • Content data (messages from forms, support chat)
  • Usage data (pages visited, dwell time, click paths)
  • Meta/communication data (IP address, browser, device, timestamp)
  • Newsletter data (email address on sign-up)
  • For AI telephony: call metadata, AI transcriptions (via third-party provider)

Purposes: Website operation, processing enquiries, contract fulfilment, customer support, invoicing, web analytics (consent only).

3. Legal bases (Art. 6 GDPR)

  • Art. 6 para. 1 lit. a GDPR — Consent (e.g. analytics cookies, newsletter)
  • Art. 6 para. 1 lit. b GDPR — Contract performance (all software projects, AI telephony)
  • Art. 6 para. 1 lit. c GDPR — Legal obligation (invoice retention, accounting)
  • Art. 6 para. 1 lit. f GDPR — Legitimate interest (server logs, security, anti-spam)

4. Data collection when visiting the website

Server log files (Netlify)

When you visit our website, your browser automatically transmits information to the web server (Netlify, Inc.): IP address, browser type/version, operating system, referrer URL, requested page and time. This data is technically required to deliver the website. Legal basis: Art. 6 para. 1 lit. f GDPR. Retention: max. 30 days.

5. Cookies and cookie consent

This website uses cookies. Technically necessary cookies do not require consent. All other cookies are only loaded after your explicit consent via the cookie banner.

Necessary cookies (always active)

NamePurposeDuration
portal_sessionAdmin/client portal authenticationSession
ci_cookie_consentStores your cookie consent1 year
ci_support_sessionSupport chat session ID (localStorage)Persistent (local)

Analytics cookies (consent only)

NameProviderDuration
_gaGoogle Analytics2 years
_ga_*Google Analytics2 years
_clsk, _clckMicrosoft Clarity1 year / session

You may withdraw your consent at any time by clearing your browser's localStorage or contacting us at info@coreindustry.de.

6. Google Analytics 4 (consent only)

This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics sets cookies (_ga, _ga_*) and transfers usage data to Google servers (potentially in the USA, secured by the EU-US Data Privacy Framework and Standard Contractual Clauses under Art. 46 GDPR). IP anonymisation is enabled.

Legal basis: Art. 6 para. 1 lit. a GDPR (consent). Loaded only after consent via cookie banner.

Permanent opt-out: tools.google.com/dlpage/gaoptout

7. Microsoft Clarity (consent only)

This website uses Microsoft Clarity, a behavioural analytics service by Microsoft Corporation. We use Clarity to improve website usability — no advertising, no profiling, no cross-site tracking.

Clarity collects anonymised usage data (click/scroll behaviour, session recordings in anonymised form) on Microsoft servers (USA). Sensitive input fields are automatically masked.

Tracked conversion events

  • lead_saved — Lead submission in Corie chat completed
  • contact_form_submitted — Contact form submitted
  • newsletter_signup — Newsletter signup successful
  • support_requested — Support request escalated via Corie
  • corie_chat_opened — Corie chat opened for first time in session
  • corie_image_requested — Design preview requested

Legal basis: Art. 6 para. 1 lit. a GDPR (consent). Retention: 13 months (Microsoft standard). Data processing agreement concluded under Art. 28 GDPR.

Microsoft privacy policy: privacy.microsoft.com

8. Contact (form, email, phone, WhatsApp)

When you contact us, the transmitted data (name, email, message content) is stored to process your enquiry. Legal basis: Art. 6 para. 1 lit. b GDPR or Art. 6 para. 1 lit. f GDPR.

WhatsApp: When contacting us via WhatsApp, Meta Platforms Ireland Ltd.'s privacy policy applies. Do not transmit sensitive data via WhatsApp.

Retention: Enquiries are deleted after full resolution, unless statutory retention obligations apply (10 years).

9. Live support chat

When you use the chat, the following data is processed and stored in Google Firebase (Firestore):

  • Your self-provided name (free text)
  • Message content of the conversation
  • Message timestamps
  • The page viewed at the start of the chat
  • A randomly generated session ID (UUID, stored locally in browser)

The IP address is stored as a SHA-256 hash for spam prevention for max. 24 hours and then automatically deleted.

Legal basis: Art. 6 para. 1 lit. b and f GDPR.

Chat histories are automatically deleted after 90 days.

10. Newsletter

Your email address is stored in Google Firebase (Firestore) upon sign-up. Legal basis: Art. 6 para. 1 lit. a GDPR (consent).

Unsubscribe: You can unsubscribe at any time by email to info@coreindustry.de. Your data will be deleted immediately.

11. AI phone assistant (service)

Core Industry offers AI-powered phone assistants for businesses. Data processed:

  • Call metadata (timestamp, phone number, call duration)
  • AI-generated transcriptions of call content
  • Appointment data (name, requested date)
  • Transfer information (when handed over to staff)

Callers are informed at the start of the call that they are speaking to an AI assistant. Core Industry acts as data processor (Art. 28 GDPR).

12. Corie AI assistant (website chatbot)

Messages you send to Corie are forwarded to the OpenRouter API (OpenRouter, Inc., San Francisco, CA, USA) for processing. OpenRouter provides multiple AI language models from various providers, including Google Gemini 2.0 Flash and others. Core Industry automatically selects the available best-performing model.

No conversation content is stored permanently. IP addresses are stored only as SHA-256 hashes for rate limiting, for a maximum of 24 hours, then automatically deleted. The usage limit is 20 messages per IP address per day.

Corie responses are purely informational and do not constitute legally binding offers or professional advice.

Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in automated initial information). Data transfer to the USA: secured by Standard Contractual Clauses (SCC) under Art. 46 GDPR and the EU-US Data Privacy Framework.

13. Fonts

This website uses fonts that are downloaded during the build process via Next.js and served directly from our web server (Netlify). No data is transmitted to Google servers when the page is loaded.

14. Hosting (Netlify)

This website is hosted by Netlify, Inc., 44 Montgomery Street, Suite 300, San Francisco, CA 94104, USA. Server logs are processed on Netlify servers. Data transfer to the USA is secured by Standard Contractual Clauses (Art. 46 GDPR).

Netlify privacy policy: netlify.com/privacy

15. Google Firebase (database, auth, storage)

This website uses Google Firebase (Google Ireland Limited, Dublin) for:

  • Firebase Authentication: Authentication of admin and client accounts
  • Cloud Firestore: Storage of client profiles, projects, contracts, invoices, newsletter addresses, support chat histories, usage quotas
  • Firebase Storage: Storage of blog images (publicly accessible)

Secured by the EU-US Data Privacy Framework and Standard Contractual Clauses (Art. 46 GDPR).

Firebase privacy policy: firebase.google.com/support/privacy

16. External services (social media, WhatsApp)

Meta Platforms Ireland Ltd. (WhatsApp, Instagram)

Merrion Road, Dublin 4, Ireland. When contacting us via WhatsApp/Instagram, Meta's privacy policy applies. Meta privacy policy

LinkedIn Ireland Unlimited Company

Wilton Plaza, Dublin 2, Ireland. LinkedIn privacy policy

17. Your rights (Art. 15–22 GDPR)

  • Right of access (Art. 15) — What data we hold about you
  • Right to rectification (Art. 16) — Correction of inaccurate data
  • Right to erasure (Art. 17) — "Right to be forgotten"
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20) — Data in machine-readable format
  • Right to object (Art. 21) — Against processing based on legitimate interests
  • Withdrawal of consent (Art. 7 para. 3) — At any time with future effect

Submit requests to: info@coreindustry.de

Right to lodge a complaint: Supervisory authority for NRW: Landesbeauftragte für Datenschutz und Informationsfreiheit NRW, Kavalleriestraße 2–4, 40213 Düsseldorf, ldi.nrw.de

18. Data security

Core Industry implements technical and organisational measures: SSL/TLS encryption (HTTPS), access restriction to authorised persons, hashed IP addresses for rate limiting, server-side validation of all inputs, regular security reviews.

Last updated: April 2026

Future-proof digital solutions for the international B2B market. SaaS, Apps, Web & AI.

+49 2041 3894257
WhatsApp

Services

  • AI Phone Agent
  • SaaS Development
  • AI Lab & Agents
  • Customer Portals
  • Premium Websites
  • iOS & Android Apps
  • Windows Software
  • SEO Optimisation

Company

  • About
  • Process
  • Projects
  • Core
  • Get a quote
  • Software
  • Contact
  • Blog

Legal

  • Imprint
  • Privacy
  • AGB
  • Accessibility

Newsletter — 5% Off

Instant discount code for your first project

⭐ Happy with our work?

A quick review helps others find us — thank you!

Rate on Trustpilot

© 2026 Core Industry. All rights reserved.

Made in Germany
Start a Project