Privacy Policy

How we protect your commercial account data and privacy.

Privacy & Data Policy

Last Updated: July 4, 2026

Entity: Core Durability, LLC ("Company", "we", "us", or "our")

Platform: Legionella Compliance SaaS Platform ("Service", "Platform")

This Privacy Policy explains how Core Durability, LLC acts as a Data Controller to collect, use, and protect the account and billing information necessary to operate our Business-to-Business (B2B) Platform.

1. Information We Collect

1.1 Account & Authentication Data

To provision your access to the Platform, we collect names, professional email addresses, job titles, and hashed passwords of authorized personnel.

1.2 Billing & Commercial Data

We collect payment method details and billing addresses. Payment processing is managed via our secure third-party payment processor (e.g., Stripe). We do not store raw credit card numbers on our servers.

1.3 Security & Audit Logs

To maintain the forensic integrity of the platform and enforce our legal agreements, we log IP addresses, browser User-Agent strings, and timestamps for all login events and Terms of Service (ToS) agreement executions.

1.4 Platform Analytics Data

We collect anonymized, aggregated behavioral telemetry about how users interact with the Platform (e.g., page views, feature usage, workflow completion rates) using Vercel Analytics. This data does not include personally identifiable information and is used solely to improve the Platform's user experience and reliability.

1.5 Push Notification Tokens

If you opt-in to browser-based push notifications for compliance alerts, we store a browser push subscription token in our database. This token is a technical device identifier used solely to deliver real-time alerts to your browser. You may revoke push notification permissions at any time via your browser settings, which will automatically invalidate and remove your token from our systems.

2. How We Use Your Information

We process this data under the legal basis of fulfilling our contractual obligations to you and for our legitimate business interests, specifically to:

  • Administer your account, process subscription billing, and provide customer support.
  • Secure the Platform against unauthorized access and maintain immutable audit trails of legal consent.
  • Analyze generalized, aggregated platform usage to improve our commercial offerings.

3. Data Sharing and Disclosure

We do not sell your personal data. We share data only with the following named sub-processors and parties:

  • Stripe: Payment processing and subscription billing management. Your payment method details are transmitted to and stored by Stripe. We do not store raw card numbers.
  • Supabase: Cloud database and authentication infrastructure. All facility compliance data, user account records, and audit logs are stored on Supabase-managed servers.
  • Vercel: Cloud hosting and anonymized behavioral analytics. Vercel hosts the Platform and receives anonymized page-view telemetry via Vercel Analytics.
  • Resend: Transactional email delivery. Your name and email address are transmitted to Resend solely to deliver team invitation emails and compliance alert escalation notifications. No facility health or compliance data is included in these transmissions.
  • Legal & Compliance Requirements: If compelled by a court order, subpoena, or government request.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, subject to confidentiality obligations.

4. Data Retention and Storage Limitation

We enforce strict data retention schedules to comply with global privacy laws:

  • Account & Billing Data: Retained for the duration of your active subscription, plus up to seven (7) years following termination to satisfy tax, accounting, and legal requirements.
  • Routine Security Logs: General access and IP logs used for routine troubleshooting are retained for ninety (90) days before being automatically purged.
  • Contractual Audit Logs: IP addresses and timestamps linked specifically to the execution of legal agreements (e.g., ToS clickwraps) are retained for seven (7) years following the termination of your account to align with civil statutes of limitations for contract disputes. If retained longer for generalized analytics, they will be irreversibly anonymized.

5. Your Privacy Rights

Depending on your jurisdiction (such as California under the CPRA, or the EU under the GDPR), you may have the right to request access to, correction of, or deletion of your personal account data. To exercise these rights, please contact our legal department. Note that fulfilling deletion requests for active accounts will necessitate the termination of your subscription, as we cannot provide the Service without basic account data.

6. Changes to this Policy

We may update this Privacy Policy periodically. For material changes, we will require you to affirmatively agree to the new Privacy Policy via an in-app interstitial screen before continuing to use the Platform.

7. Contact Us

For questions regarding this Privacy Policy or your data, please contact:
Core Durability, LLC
legal@coredurability.com
Washington, D.C.