Skip to content
CorpshoreUS

Legal

Data Protection and Security Policy

Last updated: June 8, 2026

This Data Protection and Security Policy describes how Corpshore Inc, trading as Corpshore US, protects the information entrusted to it by clients, candidates, and visitors. It reflects the standards we apply across our operations and the operations of the Corpshore group.

Our commitment

We treat data protection as a core operational requirement, not an afterthought. We handle personal and client data on a least-privilege basis, document how it is processed, and hold ourselves and our service providers to the standards described here.

Access control

Access to personal and client data is limited to people who need it to do their work. Access is granted by role, reviewed periodically, and revoked promptly when no longer required. Authentication controls protect the systems that hold data.

Protection in transit and at rest

We use encryption in transit for data moving between systems and apply appropriate protections to data at rest in the platforms we use. We segment access so that systems holding sensitive data are isolated from those that do not need it.

Regulatory frameworks

Depending on the engagement and the data involved, we align our handling with the frameworks that apply, including HIPAA for protected health information, PCI DSS for payment card data, and US state privacy laws such as the CCPA. For each engagement we agree in writing which requirements apply and which party is responsible for each control.

Service providers and subprocessors

Where we use service providers that process data on our behalf, we do so under contract terms that require appropriate security and limit processing to our instructions. We assess providers before onboarding and monitor them through the relationship.

Incident response

We maintain procedures to detect, contain, and respond to security incidents. Where an incident affects personal or client data, we act to limit harm, notify affected parties and authorities as required by law and contract, and review the cause to prevent recurrence.

Retention and disposal

We keep data only as long as needed for the purpose it was collected and to meet legal requirements, then delete or anonymize it. Disposal is carried out in a way that prevents recovery.

Contact

To ask about our data protection practices or to report a concern, contact Corpshore Inc at info@corpshore.us or 7901 4th St N, Ste 300, St. Petersburg, FL 33702, United States.

This document is a general policy of Corpshore Inc and is provided for information. It is not legal advice. For questions, contact info@corpshore.us.