Last updated: June 8, 2026
This Data Protection and Security Policy describes how Corpshore Inc, trading as Corpshore US, protects the information entrusted to it by clients, candidates, and visitors. It reflects the standards we apply across our operations and the operations of the Corpshore group.
Our commitment
We treat data protection as a core operational requirement, not an afterthought. We handle personal and client data on a least-privilege basis, document how it is processed, and hold ourselves and our service providers to the standards described here.
Access control
Access to personal and client data is limited to people who need it to do their work. Access is granted by role, reviewed periodically, and revoked promptly when no longer required. Authentication controls protect the systems that hold data.
Protection in transit and at rest
We use encryption in transit for data moving between systems and apply appropriate protections to data at rest in the platforms we use. We segment access so that systems holding sensitive data are isolated from those that do not need it.
Regulatory frameworks
Depending on the engagement and the data involved, we align our handling with the frameworks that apply, including HIPAA for protected health information, PCI DSS for payment card data, and US state privacy laws such as the CCPA. For each engagement we agree in writing which requirements apply and which party is responsible for each control.
Service providers and subprocessors
Where we use service providers that process data on our behalf, we do so under contract terms that require appropriate security and limit processing to our instructions. We assess providers before onboarding and monitor them through the relationship.
Incident response
We maintain procedures to detect, contain, and respond to security incidents. Where an incident affects personal or client data, we act to limit harm, notify affected parties and authorities as required by law and contract, and review the cause to prevent recurrence.
Retention and disposal
We keep data only as long as needed for the purpose it was collected and to meet legal requirements, then delete or anonymize it. Disposal is carried out in a way that prevents recovery.
Contact
To ask about our data protection practices or to report a concern, contact Corpshore Inc at info@corpshore.us or 7901 4th St N, Ste 300, St. Petersburg, FL 33702, United States.
This document is a general policy of Corpshore Inc and is provided for information. It is not legal advice. For questions, contact info@corpshore.us.