CompliCore Privacy Policy
Effective Date: [EFFECTIVE DATE] Last Updated: [EFFECTIVE DATE] Version: 2.1
This Privacy Policy describes how [COMPLICORE LEGAL ENTITY NAME] ("CompliCore," "we," "us," or "our") collects, uses, stores, and shares information when you use our building-compliance software platform, websites, mobile/PWA applications, and related services (collectively, the "Service").
CompliCore is a business-to-business service for building owners and property managers in the District of Columbia, Maryland, and Virginia. By using the Service, you agree to the collection and use of information as described here. If you do not agree, do not use the Service.
Contact: privacy@compli-core.com · [COMPLICORE LEGAL ENTITY NAME], [MAILING ADDRESS]
1. Scope
This Policy covers:
- The CompliCore web application — dashboard, building and asset management, compliance tracking, CapEx planning, vendor dispatch, and billing;
- Our public marketing website, including its contact form;
- Email, SMS, and push notifications we send in connection with the Service;
- Live-chat support on our website and in the app, provided by a third-party chat provider (tawk.to); and
- The in-product AI support assistant and Help Center.
This Policy does not cover the practices of third-party contractors, inspectors, or vendors you engage through or alongside the Service. Those are independent businesses with their own privacy practices.
Where we process personal data on behalf of a business customer, that processing is also governed by our Data Processing Addendum, which controls over this Policy in the event of a conflict.
2. Information We Collect
2.1 Information You Provide Directly
Account and profile information. When you register we collect your full name, email address, password (stored by our authentication provider in hashed form — we never store plaintext passwords), a U.S. mobile phone number, your company name (optional), and your notification preferences.
The mobile number is required to create an account, and SMS delivery is not. We ask for it so that a time-critical compliance alert has a second delivery channel if email fails, and because account-recovery and abuse-prevention depend on it. You can turn SMS off in Settings and keep using the Service normally; turning it off does not delete the number from your profile, but you can clear or change it there at any time.
Google Sign-In. If you register or sign in with Google, we receive your name, email address, and basic profile information from your Google account, as permitted by your Google settings.
Team and invitation information. When an Owner or Admin invites teammates, we collect the invitee's email address, the assigned role (Owner, Admin, Manager, Viewer), and the identity of the inviting member. Invitation links contain a single-use token; we store only a cryptographic hash of that token, never the token itself.
Building and portfolio information. Building names, street addresses in DC/MD/VA, gross floor area, property type, ownership type, and internal identifiers you assign.
Compliance and equipment information. Details about safety-critical equipment — elevators, boilers, fire-protection systems, backflow preventers, energy-benchmarking data — including state registration numbers, inspection dates, due dates, and compliance status.
Financial and job records. Inspection and service records you enter or that the Service generates, including estimated, quoted, and final costs, budgets, and estimated fine or liability exposure.
Documents you upload. Inspection certificates, invoices, permits, and similar documents. These may contain names, signatures, contact details, and pricing information relating to you or third parties, such as the contractors who issued them.
Vendor contact information. Names, email addresses, and phone numbers of contractors and inspectors you enter or select for outreach. See Section 2.5.
Communications with us. Information you provide in support requests, feedback, or through our marketing-site contact form (name, email, company, message), which is delivered to us by Web3Forms. If you use the live-chat widget, we and tawk.to collect the chat transcript and anything you choose to share in it.
Questions you ask the AI support assistant. When you use the in-product support assistant, we process the text of your question and the recent conversation history in order to generate an answer. See Section 4.
2.2 Information Collected Automatically
Authentication and session data. Tokens from our authentication provider, stored in your browser to keep you signed in. Strictly necessary for the Service to function.
Push notification tokens. If you enable push notifications, we store a device-specific Firebase Cloud Messaging token so we can deliver notifications to your device.
Device and log data. Standard technical information — IP address, browser type, operating system, pages accessed, timestamps — collected through server logs and our hosting infrastructure for security, debugging, rate limiting, and operations.
Local storage / offline data. As a progressive web app, the Service caches application assets and stores display preferences (such as light/dark theme) in your browser's local storage.
Live-chat widget data. When a page containing the tawk.to chat widget loads, tawk.to automatically collects technical information about your visit — IP address, approximate location derived from it, browser and device type, and pages viewed — and sets cookies and local-storage entries to keep your chat session continuous. This happens whether or not you open a chat.
We do not use third-party advertising trackers, advertising cookies, or cross-site tracking. Apart from the visit information collected by the live-chat widget, we do not use third-party analytics tools. See our Cookie and Tracking Notice.
2.3 Information from Public Records and Government Sources
A core function of the Service is monitoring public government compliance records, including the Maryland Division of Labor elevator and boiler/pressure-vessel records, District of Columbia datasets, and DC BEPS data. From these sources we collect equipment registration numbers, equipment type and location, certificate expiration dates, inspection dates and statuses, and — where the source publishes them — the name of the building or its listed owner and a site telephone number.
We hold these records for entire jurisdictions, not only for buildings in customer portfolios. Rather than query a government system building-by-building, we periodically obtain the underlying dataset — by downloading a published file, by public-records request, or through a government API — and store a structured index of it. That index currently covers Maryland statewide and is refreshed on a schedule. When you add a building, we look it up in that index; the index existed before you did, and it contains records for buildings that belong to people who are not our customers and have never used the Service.
We use this index for two purposes. The first is to populate and refresh the compliance calendar for our customers' buildings. The second is to identify businesses that may want to become customers — for example, to find buildings with equipment whose certificates appear to have lapsed, so we can contact the owner or manager about the Service. This is ordinary business-to-business prospecting from public government records. If you are a building owner or site contact who appears in one of these public records and you do not want us to contact you or to retain your details, write to privacy@compli-core.com and we will suppress you; see Section 2.5.
These records are created and maintained by government agencies, which may publish on a delay and may disclaim accuracy — a record may show equipment as overdue that has in fact been re-certified, or as active when it no longer exists. See Section 12. We maintain internal standards governing how we obtain, verify, and use public records, including a rule that registry data is re-downloaded before use rather than served from a stale copy. Business customers may request a summary at privacy@compli-core.com.
2.4 Information from Third-Party Directories and Vendor Websites
When you use the vendor-suggestion feature, we retrieve publicly listed business information — business name, phone, website, rating, review count, address — about local contractors from the Google Places API.
Business directories rarely publish an email address. Where a listing gives us the vendor's own website, our server may visit that website and read its publicly served pages — the homepage and up to two likely contact pages — to find a published contact email, preferring addresses the business has explicitly published for contact (such as mailto: links and role addresses like info@ or service@). We read only what the site serves publicly to any visitor; we do not log in, submit forms, or bypass any access control, and we do not collect anything from those pages other than a contact email address.
We cache directory and discovery results for approximately 30 days to reduce repeat lookups, so a given vendor's site is visited at most about once a month per area rather than once per request.
2.5 Information About People Who Are Not Our Users
Some people whose information we hold never signed up for CompliCore. There are two different situations, and they matter because they determine who is answerable for the data.
(a) Data a customer gave us or asked us to fetch — our customer decides, we act on instructions.
- Vendors and inspectors — contact details entered by a customer, retrieved from a public business directory, or found on the vendor's own website (Section 2.4), so that a customer can request a quote. Where a Vendor is a sole proprietor, their business contact details may also be personal information.
- Invitees — a person's email address is stored when a customer invites them, before they accept or decline.
- People named in uploaded documents — for example, the inspector who signed a certificate.
For this category, our customer is the controller and CompliCore is the processor: we hold it because a customer put it there or asked us to look it up, and we use it only to provide the Service to that customer.
(b) Data we collected ourselves from public government records — we decide, so we are answerable.
The jurisdiction-wide registry index described in Section 2.3 includes building and owner names and site telephone numbers that no customer asked us to collect. For that data, CompliCore is the controller, not a processor. We do not attempt to shift responsibility for it onto anyone else.
In either case, if you are one of these people: write to privacy@compli-core.com and you may ask us what we hold about you, ask us to correct it, ask us to delete it, and ask us to stop contacting you. For category (b) we will act on the request ourselves. For category (a) we will act ourselves where we can, and otherwise route the request to the customer responsible and tell you we have done so. A request to stop contact is honoured platform-wide — it suppresses you from outreach initiated by any customer, not just the one who contacted you. We will never sell your details and we will never add you to a marketing list.
3. How We Use Information
We use the information we collect to:
- Create and administer your account, portfolio, and team;
- Track compliance deadlines and generate the compliance calendar for your buildings;
- Send compliance alerts and reminders by email, SMS, and push notification, according to your preferences;
- Suggest local vendors and, at your direction, send service-request emails to vendors you select;
- Generate AI-assisted content and answer support questions (Section 4);
- Process subscription payments and manage billing through Stripe;
- Provide customer support and respond to inquiries;
- Secure the Service, prevent fraud and abuse, enforce rate limits, and debug problems;
- Comply with legal obligations; and
- Improve and develop the Service, including through aggregated or de-identified data that does not identify you.
We do not sell personal data, we do not process personal data for targeted advertising, and we do not use personal data to make solely automated decisions that produce legal or similarly significant effects about an individual.
4. Artificial Intelligence Features
Four features use large language models provided by Google (Gemini API):
| Feature | What is sent to the model | Your control |
|---|---|---|
| Vendor outreach drafting | Building name and address, equipment details, service type, and summarized inspection history (dates, costs, overdue status) | You review and may edit every draft before anything is sent |
| Invoice and document extraction (OCR) | The uploaded document file itself | Only runs when you upload a document and request parsing |
| Building health profiles (Pro) | Equipment and inspection-history data for one building | Only runs when you request a profile |
| AI support assistant | Your question, recent conversation history, and relevant sections of our Help Center articles | Only runs when you ask it something. Do not paste confidential information into it that is not needed to answer your question |
We send only the data needed for the specific feature. We do not send account credentials or payment information to any AI provider.
We do not use Customer Data to train our own models. We transmit this data to Google's Gemini API on a paid basis; under Google's terms for the paid API, Google does not use data submitted through the API to train or improve its models.
AI-generated output may contain errors. It is a convenience, not professional, engineering, or legal advice. See our AI Transparency Notice and Terms of Service §6.4–6.5.
5. How We Share Information
We share personal information only as described below. We do not sell personal information to anyone, and we do not share it with third parties for their own marketing.
5.1 Service Providers (Processors)
We use service providers that process data on our behalf under contractual restrictions. The current list — provider, purpose, data involved, and location — is maintained at Subprocessors and forms part of this Policy.
We may add, replace, or remove providers as the Service evolves. Before a new or replacement provider that processes personal data begins processing, we will update that list; business customers may subscribe to notifications of changes as described in the Data Processing Addendum.
5.2 Vendors and Contractors — At Your Direction
When you use the dispatch feature to request quotes, we send the email you approved to the vendors you selected. That email typically includes the building name and address, the equipment and service needed, relevant inspection history, and your reply contact information. Once delivered, that information is in the vendor's hands and subject to the vendor's own practices.
5.3 Within Your Organization
Members of your portfolio team can see portfolio data — buildings, assets, logs, alerts — and basic teammate profile information (name, email, role), consistent with their assigned role. The portfolio Owner controls membership. Your team's administrators can see your activity in the portfolio.
5.4 CompliCore Personnel
A small number of CompliCore personnel hold administrative access to the systems that run the Service. We would rather say this plainly than imply that no human at CompliCore can ever see your data.
- Access is limited to what the job requires — to operate and secure the Service, to investigate a fault or a suspected abuse, to comply with law, and to respond to a support request you have raised.
- We do not read your documents, inspection records, or support conversations for any other reason, and we do not use them to build marketing lists or to inform sales outreach to you.
- The platform-administration surface is separate from customer accounts. It governs configuration — which government data sources are indexed, how their columns map to equipment types, and the published penalty schedules used to estimate exposure. Because those settings determine what appears in your compliance calendar, every administrative action is written to an append-only audit log that no one, including us, can edit or delete through the application.
- Personnel with such access are bound by confidentiality obligations.
5.5 Legal, Safety, and Corporate Events
We may disclose information: (a) to comply with law, regulation, subpoena, or lawful government request; (b) to enforce our Terms of Service; (c) to protect the rights, safety, or property of CompliCore, our users, or others; or (d) in connection with a merger, acquisition, financing, or sale of assets, in which case this Policy continues to apply to previously collected data until a successor policy takes effect with notice to you.
Where we receive a government request for a business customer's data, we will notify that customer before disclosing, unless legally prohibited.
5.6 Aggregated and De-Identified Data
We may use and share aggregated or de-identified information — for example, regional compliance-lapse statistics — that cannot reasonably be used to identify you or any individual. We maintain the measures needed to keep that information de-identified, and we commit not to attempt to re-identify it.
6. SMS / Text Messaging
By providing your mobile number at registration and enabling SMS notifications, you consent to receive transactional and account-related text messages from CompliCore — compliance alerts, deadline warnings, and service notifications. Consent to receive texts is not a condition of purchasing any good or service, and the Service is fully usable with SMS disabled.
- Message frequency varies based on your buildings' compliance activity.
- Message and data rates may apply, per your carrier plan.
- Reply STOP to cancel at any time, or disable SMS notifications in Settings. Reply HELP or contact support@compli-core.com for help.
- Carriers are not liable for delayed or undelivered messages.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties, except for our SMS delivery provider (Twilio) solely as necessary to deliver the messages you requested.
Full program terms are in our SMS Terms.
7. Push Notifications
If you opt in to push notifications, your browser or device generates a delivery token that we store with your account. You can revoke push permission at any time through your browser or device settings, or in the app's notification settings. We deactivate stored tokens that become invalid.
8. Cookies and Local Storage
We use strictly necessary and functional browser storage only — no advertising or cross-site-tracking cookies. Full details, including each cookie's purpose, are in our Cookie and Tracking Notice. In summary: authentication tokens, your theme preference, PWA caching, Stripe's payment-security cookies on Stripe's own pages, and the tawk.to chat-session cookies.
We do not respond differently to browser "Do Not Track" signals, because we do not track users across third-party sites. Because we do not sell personal data or engage in targeted advertising, universal opt-out signals such as Global Privacy Control do not change how we process your data; we honor them where required by law.
9. Data Retention
We retain personal information for as long as your account is active and as needed to provide the Service. Thereafter we retain it only as necessary to comply with legal, tax, and accounting obligations; resolve disputes and enforce agreements; and maintain security and audit logs for a limited period.
| Category | Retention |
|---|---|
| Account and profile data | Life of the account, then deleted or de-identified within 90 days of verified deletion |
| Compliance records, inspection logs, uploaded documents | Until you delete them or your account is deleted; exportable for 30 days after termination |
| Billing records | As required by tax and accounting law (generally 7 years) |
| Security and access logs | Limited period for security and audit purposes |
| Support chat transcripts | As long as reasonably needed for support and recordkeeping; deletable on request |
| Cached vendor-directory data | Expires automatically after approximately 30 days |
| Public-registry index (Section 2.3) | Held for as long as we operate in that jurisdiction, and replaced wholesale on each refresh — a record dropped by the issuing agency is removed from our index at the next refresh. Not tied to any account |
| Platform-administration audit log | Retained for security and accountability; append-only and not deletable through the application |
| Backups | Purged on a rolling basis; deleted data may persist in backups briefly after deletion from live systems |
The table above is our retention schedule. We maintain a more detailed internal retention and deletion policy covering operational records; business customers may request a copy at privacy@compli-core.com.
10. Security
We use commercially reasonable technical and organizational safeguards, including:
- Encryption in transit (TLS) for all connections, and encryption at rest provided by our cloud infrastructure;
- Password hashing and authentication managed by Firebase Authentication;
- Tenant isolation — database security rules restrict every read to members of the owning portfolio, and all writes flow through authenticated server-side APIs that verify portfolio ownership;
- Role-based access control within each portfolio;
- Secrets management for API credentials; signed webhooks and shared-secret authentication between internal systems;
- Rate limiting on authentication and other sensitive endpoints; and
- Recipient caps and validation on outbound email features to prevent abuse.
More detail is in our Security Overview. No system is perfectly secure. You are responsible for maintaining the confidentiality of your credentials and for the access you grant to team members. To report a vulnerability, see our Vulnerability Disclosure Policy.
11. Your Privacy Rights
11.1 Rights we extend to everyone
Regardless of where you live or whether any privacy statute applies to you, you may:
- Access the personal information in your account — most is visible directly in Settings and your dashboard;
- Correct your profile information;
- Export your compliance data in a portable format;
- Adjust notification preferences at any time; and
- Request deletion of your account by contacting privacy@compli-core.com.
We extend these rights to all users, including those outside the District of Columbia, Maryland, and Virginia, and including individuals whom state privacy statutes do not cover. We will not discriminate against you for exercising them.
11.2 A note on which laws actually apply
We want to be accurate rather than impressive here.
Maryland (MODPA). The Maryland Online Data Privacy Act took effect 1 October 2025 and applies to processing from 1 April 2026. It applies to businesses that control or process the personal data of at least 35,000 Maryland consumers in a calendar year, or that derive more than 20% of gross revenue from selling personal data while processing the data of at least 10,000 Maryland consumers. CompliCore is well below these thresholds. Separately, MODPA's definition of "consumer" excludes individuals acting in a commercial or employment context — which describes nearly everyone who uses a business compliance platform. So MODPA likely does not apply to most of our processing today.
Virginia (VCDPA). The VCDPA contains a similar exclusion for individuals acting in a commercial or employment context, and similar volume thresholds.
District of Columbia. D.C. has no comprehensive consumer privacy statute. We comply with D.C.'s data-security and breach-notification requirements and the D.C. Consumer Protection Procedures Act.
What this means for you: we grant the substantive rights in Section 11.1 anyway. If and when MODPA, the VCDPA, or another statute does apply to our processing of your data, you additionally have that statute's rights — to confirm and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and significant-effect profiling. We do not sell personal data, do not engage in targeted advertising, and do not perform such profiling, so those opt-outs have nothing to operate on.
We apply MODPA's data-minimization standard as a design rule for account and portfolio data: we collect only what is reasonably necessary to provide the Service you requested. We state one honest exception rather than let the claim over-reach. The public-registry index in Section 2.3 is deliberately broader than any individual customer's needs — it covers a whole jurisdiction because that is what makes an instant lookup possible when you add a building, and because we use it to find businesses that may want the Service. The records in it are ones the government has already published or released, we hold no more fields than the source provides, and anyone in it can have their details suppressed on request under Section 2.5.
11.3 Exercising rights and appeals
Submit requests to privacy@compli-core.com with the subject "Privacy Request." We will verify your identity, typically by confirming control of the account email, and respond within 45 days, extendable once by a further 45 days where reasonably necessary, with notice to you. Authorized agents may submit requests with proof of authorization.
If we decline a request, you may appeal by replying to our decision or emailing privacy@compli-core.com with the subject "Privacy Appeal." We will respond to appeals within 60 days. If your appeal is denied, you may contact your state Attorney General: Maryland, Virginia, or the D.C. Office of the Attorney General.
If you are a business customer's end user, teammate, or a Vendor, see Section 2.5 — we may need to route your request to the customer who controls the data.
12. Public Records Accuracy
Compliance statuses shown in the Service are derived in part from government registries that the issuing agencies may update on a delay and for which they disclaim accuracy. Information about your buildings appearing in those public records is not created by CompliCore, and we cannot correct it. If you believe a government record is inaccurate, contact the issuing agency; we will re-synchronize on our regular schedule or on your request.
13. Data Breach Notification
If we discover a breach of security affecting personal information, we will investigate, contain it, and notify affected individuals and — where required — regulators and consumer reporting agencies, in the most expedient time possible and without unreasonable delay, and in accordance with:
- the Maryland Personal Information Protection Act (Md. Code, Com. Law § 14-3504) — notice to affected individuals no later than 45 days after discovery, with notice to the Maryland Attorney General before notice to individuals;
- the D.C. Security Breach Protection Amendment Act; and
- Virginia Code § 18.2-186.6.
Where we process personal data on behalf of a business customer, we will notify that customer without undue delay, and in any event within 72 hours of becoming aware of a breach affecting their data, so they can meet their own obligations. See the Data Processing Addendum §8. We maintain a documented internal incident response and breach notification plan; business customers may request a summary at privacy@compli-core.com.
14. Children's Privacy
The Service is a business tool intended for users 18 years of age or older. We do not knowingly collect personal information from children under 13, or from any minor. If you believe a child has provided us personal information, contact privacy@compli-core.com and we will delete it.
15. Data Location
We store and process your account, building, compliance, and document data in the United States, in cloud regions operated by our infrastructure providers. If you access the Service from outside the U.S., you understand your information will be transferred to and processed in the U.S.
One exception, stated because it is real: our transactional email provider is a European company that hosts in the European Union. When we send you a compliance alert, send a teammate an invitation, or send a quote request to a vendor at your direction, the recipient's email address and the content of that message are processed in the EU in order to deliver it. Nothing else leaves the United States — not your documents, your inspection records, your building data, or your payment details.
We do not currently offer data residency in any other region, and we do not offer a way to opt out of this while still receiving email from the Service.
16. Changes to This Policy
We may update this Policy. We will post the revised version with a new "Last Updated" date and, for material changes, notify you by email or in-app notice before the changes take effect. Continued use after the effective date constitutes acceptance.
17. Contact Us
[COMPLICORE LEGAL ENTITY NAME] [MAILING ADDRESS]
- Privacy questions and requests: privacy@compli-core.com
- General support: support@compli-core.com
- Legal notices: legal@compli-core.com
- Security vulnerabilities: see our Vulnerability Disclosure Policy
Change log
| Version | Date | Summary |
|---|---|---|
| 2.1 | [EFFECTIVE DATE] | Section 2.3 now discloses that we hold jurisdiction-wide indexes of public registry data — including building and owner names and site telephone numbers for buildings that are not our customers' — and that we use them both to run the compliance calendar and to identify businesses that may want the Service, with a route to be suppressed. Section 2.4 describes how we look for a vendor's published contact email on the vendor's own website. Section 2.5 distinguishes data we hold on a customer's instructions from data we collected ourselves and are directly answerable for. New Section 5.4 explains CompliCore personnel access and the append-only administrative audit log. Retention schedule extended. Section 11.2 states the one place our data-minimization practice does not reach. Section 2.1 confirms the mobile number is required while SMS is optional. Section 15 corrected: transactional email is processed in the European Union, not the United States. |
| 2.0 | — | Added the AI support assistant and Web3Forms; new §2.5 on non-user data subjects; subprocessor list moved to a standalone page; §11 rewritten to state statutory applicability accurately; retention schedule tabulated; §13 given specific statutory deadlines. Not published as a final release. |
| 1.0 | — | Initial version. |