Privacy Charter
Last updated: 14 September 2026. Effective for all UK clients and visitors of Corewisecorp Partners Ltd.
1. Who We Are & Data Controller
Corewisecorp ("we", "us", or "our") is the trading name of Corewisecorp Partners Ltd, a private limited company registered in England and Wales (Company Registration No. 14892011). Our registered office is located at 45 Charlotte Street, London W1T 1RR, United Kingdom.
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Corewisecorp acts as the Data Controller for personal data collected through this website, and as a Data Processor when handling operational inventory, customer invoices, and social profiles on behalf of our merchant clients.
2. Data We Collect
Depending on how you engage with our services, we may collect and process:
- Identity & Contact Data: Full name, business trade name, store URL, business email address, and UK telephone number submitted via consultation request forms.
- Operational & Commercial Data: Estimated monthly revenue, transaction volumes, software tooling stack (e.g. Shopify, Square, Xero, Clover), and current inventory parameters submitted via our ROI Calculator or during advisory onboarding.
- Technical & Telemetry Data: Internet protocol (IP) address, browser type and version, time zone setting, operating system, and browsing behaviour collected via privacy-conscious analytics.
- Client Customer Data (Processor Role): When providing website design, automated invoicing, or stock synchronization, we process customer transactional tokens and order records strictly under a written Data Processing Agreement (DPA).
How enquiry forms are handled: When you submit a consultation or contact form on this website, the details you enter are sent to our form-handling provider, Formspree, Inc. (based in the United States), which acts as our data processor and forwards them to us by email. This means your enquiry data is transferred outside the UK. We use it only to respond to your enquiry.
3. Lawful Basis for Processing under UK GDPR
Under Article 6 of the UK GDPR, we process your personal data based on:
- Contract Performance: Processing necessary to fulfill our service agreement or take requested steps prior to entering into a contract (e.g. conducting your free operations audit).
- Legitimate Interests: Processing necessary for our legitimate commercial interests (e.g. improving store performance, monitoring security, preventing fraud), provided your fundamental rights do not override these interests.
- Legal Obligation: Retaining financial transaction records to comply with UK HMRC statutory accounting requirements.
- Consent: Where you have provided clear, affirmative consent for non-essential cookies or direct marketing communications.
4. Service-Specific Data Handling
Social Media Management
Access to merchant accounts (Meta Business Suite, TikTok Ads, LinkedIn) is conducted via OAuth delegator tokens. We never store raw passwords or sensitive credentials on the frontend.
Automated Invoicing & Bookkeeping
Financial relays sync directly with FCA-authorized payment gateways (Stripe, Square UK) and HMRC Making Tax Digital (MTD) compliant software (Xero, QuickBooks). Payment card numbers never touch Corewisecorp servers.
Website Design & Headless E-commerce
Storefronts are built with HTTPS encryption by default. Customer sessions and cart pre-caching use privacy-first local storage with zero cross-site invasive tracking.
Multi-Channel Stock Management
Inventory telemetry (SKUs, quantities, warehouse locations) is synchronized via webhook triggers with deterministic encryption at rest and in transit.
5. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. Standard commercial engagement records are maintained for 6 years following contract conclusion in accordance with UK statutory limitation periods.
6. Your Rights Under UK Law
As a resident in the United Kingdom, you hold specific statutory rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you (Subject Access Request).
- Right to Rectification: Request correction of inaccurate or incomplete information.
- Right to Erasure: Request the deletion of your personal data where there is no good reason for us continuing to process it ("Right to be Forgotten").
- Right to Object & Restrict: Object to processing based on legitimate interests or direct marketing.
- Right to Data Portability: Request transfer of your data to yourself or another provider in a structured, machine-readable format.
7. Contact & Information Commissioner's Office (ICO)
To exercise any of your rights or raise questions regarding our privacy practices, please contact our Data Governance Officer:
Postal: Data Governance Officer, Corewisecorp Partners Ltd, 45 Charlotte Street, London W1T 1RR
Freephone: 0800 525 5478
You also have the right to make a complaint at any time to the UK Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (ico.org.uk).