Privacy Policy
Last updated: 24 June 2026
RCORE ("RCORE", "we", "us", or "our") operates the website rcore.io and provides AI-powered messaging and automation services, including services delivered over WhatsApp through the WhatsApp Business Platform (the "Services").
This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the rights you have. We are committed to handling your data transparently and in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR).
1. Who we are
RCORE is the data controller responsible for your personal data.
- Controller: RCORE Mariusz Rokicki (sole trader)
- Address: Konarskiego 22/67, 01-355 Warszawa, Poland
- NIP: 6562253206
- Contact: hello (at) rcore.io
If you have any questions about this Policy or how we handle your data, contact us at hello (at) rcore.io.
2. Data we collect
2.1 Information you provide
- Contact details you submit through forms on rcore.io, such as your name, email address, company, and the content of your enquiry.
2.2 Information from messaging (WhatsApp and other channels)
When you communicate with us (or with a business using our Services) over WhatsApp or another messaging channel, we process:
- Your phone number and WhatsApp profile name;
- The content of the messages you send and receive (text, images, documents, and other media);
- Message metadata, such as timestamps and delivery or read status.
2.3 Information collected automatically
When you visit rcore.io, we may collect technical data such as your IP address, browser type, device information, and pages viewed, through cookies and similar technologies.
3. How we use your data and our legal bases
- To provide and operate the Services, including sending and receiving messages
- Performance of a contract
- To respond to enquiries you send us
- Performance of a contract / legitimate interests
- To deliver business automation and AI-assisted replies
- Performance of a contract / legitimate interests
- To send you messages you have opted in to receive
- Consent
- To maintain security, prevent fraud, and improve the Services
- Legitimate interests
- To comply with legal obligations
- Legal obligation
You can withdraw consent at any time where we rely on it; this does not affect processing carried out before withdrawal.
4. Automated processing and AI
Our Services use automated systems, including artificial intelligence, to process and respond to messages, route conversations, and provide business automation features. These systems are designed to support predictable, business-related outcomes such as answering queries, handling requests, and providing information. We do not use your message content to make decisions producing legal or similarly significant effects about you without a lawful basis and appropriate safeguards.
5. Who we share your data with
- Meta Platforms: as the operator of the WhatsApp Business Platform, Meta processes messages exchanged over WhatsApp. Your use of WhatsApp is also subject to Meta's and WhatsApp's own privacy policies.
- Service providers (sub-processors): we use trusted third parties for hosting, infrastructure, and analytics. They may access personal data only as needed to perform services for us and under appropriate confidentiality and data protection obligations.
- Legal authorities: where required by law or to protect our rights, users, or the public.
We do not sell your personal data.
6. International transfers
Some recipients, including Meta, may be located outside the European Economic Area (EEA). Where we transfer personal data outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision or Data Privacy Framework certification.
7. Data retention
We keep personal data only for as long as necessary for the purposes described in this Policy, or as required to comply with our legal obligations, resolve disputes, and enforce our agreements. When data is no longer needed, we delete or anonymize it.
8. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten");
- Restrict or object to certain processing;
- Data portability: receive your data in a structured, machine-readable format;
- Withdraw consent where processing is based on consent;
- Lodge a complaint with your local data protection supervisory authority.
To exercise any of these rights, email hello (at) rcore.io.
9. Data deletion
You can request deletion of your personal data at any time by emailing hello (at) rcore.io. See our Data Deletion Instructions for full details. We will action verified requests within 30 days, subject to any legal retention obligations.
10. Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, misuse, or alteration. No method of transmission or storage is completely secure, but we work to safeguard your information using industry-standard practices.
11. Children
Our Services are not directed at children under 16 (or the age of digital consent in your country), and we do not knowingly collect their data. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to this Policy
We may update this Privacy Policy from time to time. The updated version will be indicated by a revised "Last updated" date and is effective as soon as it is posted at rcore.io. We encourage you to review it periodically.
13. Contact
Questions about this Policy or your data? Email hello (at) rcore.io.