Legal / Privacy Statement

Privacy Statement

Version 2.0  ·  Effective September 9, 2026  ·  Replaces the previous User Privacy Statement

What personal data Coretas handles, why, who we share it with, and how to exercise your rights.

This statement explains how Coretas, Inc. ("Coretas", "we", "us") handles personal data. It covers our website at coretas.ai and the Coretas platform.

"Personal data" means information relating to an identified or identifiable individual.

Two things are worth separating up front, because they are treated differently in law and in this statement:

1. Who we are

Coretas, Inc., a Delaware corporation, 509 Madison Avenue, Room 404, New York, NY 10022. Contact info@coretas.ai for any privacy question, including to exercise your rights.

If you are in the European Economic Area or the United Kingdom and want to raise a data protection question, write to the same address and mark it for the attention of our data protection contact.

2. Personal data we collect about you

You give us

We collect automatically

We receive from your connected accounts

When you connect Google Ads or Meta Ads, we receive the identity of the authorising user and the accounts you select, along with advertising performance and configuration data. Advertising data is mostly not personal data, but it can contain it, for example in audience names or campaign metadata that you have chosen. See section 6.

We do not knowingly collect special category personal data, and you must not upload it. We do not collect data from children.

3. Why we use it, and our legal basis

PurposeLegal basis
Creating and running your account, providing the platform, supportPerformance of a contract
Billing, collecting payment, tax and accounting recordsContract, and legal obligation
Security, fraud prevention, abuse investigation, service logsLegitimate interests in protecting the service
Improving the platform using aggregated and de-identified usage dataLegitimate interests in improving our product
Product and service emails you need to receive as a customerContract
Marketing emails and outreach to prospective customersConsent where required, otherwise legitimate interests in business-to-business marketing
Non-essential analytics cookiesConsent
Responding to legal requests and defending legal claimsLegal obligation, and legitimate interests

You can object to processing based on legitimate interests, and you can withdraw consent at any time, by emailing info@coretas.ai. Every marketing email carries an unsubscribe link.

4. AI processing

To generate analysis, recommendations, media plans, campaign components and Copilot answers, we send relevant parts of your advertising data to OpenAI, acting as our processor. OpenAI is listed under Subprocessors.

Your data is context, not training material. Your advertising data is supplied to the model as context for your own request, so that the output reflects your account rather than a generic benchmark. Under OpenAI's published API data policy, data sent through its API is not used to train or improve OpenAI's models unless the customer opts in, and we do not opt in. OpenAI may retain API inputs and outputs for up to 30 days for abuse monitoring before deleting them, unless it is legally required to retain them for longer.

Long-term memory. As you use the platform, Coretas builds and keeps a working context for your account from your data, your previous questions and the plans and campaigns you have worked on, so that later analysis and recommendations are better tuned to how you operate. That context is held inside Coretas, is specific to your account, is never used to produce output for another customer, and is deleted with the rest of your data as described in section 8.

We may change which model providers we use, and the models we use, at any time and without prior notice. The current list is always the one published under Subprocessors.

Coretas does not use AI to make automated decisions about individuals that produce legal effects for them or similarly significantly affect them. Changes to your advertising accounts are approved by a person at your company before they take effect. See the AI and Automation Policy.

5. Who we share it with

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

6. Customer data we process for you

Where we process personal data contained in your advertising accounts, we act as a processor on your instruction and you act as the controller. In that role we:

Our Data Processing Addendum, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, is available on request from info@coretas.ai.

7. International transfers

Coretas is a US company. We and our subprocessors process personal data in the United States, the European Union and the United Kingdom. Where you are located, where you connect your advertising accounts from, and which features you use will determine which of those locations your data passes through, and data may be transferred between them.

If you are in the European Economic Area, the United Kingdom or Switzerland, your personal data may therefore be transferred to, stored in and processed in the United States and in other countries whose data protection laws may differ from those of your own country.

Where we transfer personal data out of the EEA, the United Kingdom or Switzerland to a country that has not been recognised as providing an adequate level of protection, we put a lawful transfer mechanism in place. Depending on the recipient and the transfer, that will be the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or the UK Addendum to those Clauses, the Swiss addendum, an adequacy decision, or another mechanism permitted by applicable law, in each case together with any additional technical, organisational and contractual safeguards we consider appropriate. You can request details of the mechanism relied on for a particular transfer, including a copy of the relevant clauses, from info@coretas.ai.

We may change our hosting locations, our subprocessors and the transfer mechanisms we rely on at any time and without prior notice, provided a lawful basis for the transfer remains in place.

8. How long we keep it

DataRetention
Account and contact dataFor the life of the account, then 12 months after closure
Customer advertising data30 day export window after access ends, then deleted or de-identified within 90 days
Billing and tax recordsAs required by law, normally 7 years
Security and access logs12 months
Marketing contact dataUntil you unsubscribe or object, then a suppression record only
Support correspondence12 months

These periods are our current practice and we may change any of them at any time and without prior notice, subject to any minimum retention the law requires and any longer period we need in order to comply with a legal obligation, resolve a dispute or enforce our agreements. Where we no longer need personal data we delete it or de-identify it so that it can no longer be linked to you.

9. Security

We use access controls, encryption in transit and at rest, restricted administrative access, logging, and vendor review appropriate to the data we handle. Advertising platform access tokens are stored encrypted and their use is logged. Access to customer data is limited to personnel who need it to do their job, and is subject to confidentiality obligations.

No system is perfectly secure. If a breach affects your personal data we will notify you and any regulator as required by law, without undue delay. Report a suspected problem to info@coretas.ai.

The platform runs on Amazon Web Services, which provides our application hosting and data storage. Data is encrypted in transit using TLS and encrypted at rest by the storage services we use. Administrative access is limited to named personnel, is protected by multi-factor authentication, and is logged.

Our security measures develop over time and we may change them at any time and without prior notice, provided the level of protection remains appropriate to the data. For a security questionnaire or a fuller description of our controls, email info@coretas.ai.

10. Your rights

Depending on where you are, you may have the right to access your personal data, correct it, delete it, restrict or object to its processing, receive it in a portable format, withdraw consent, and lodge a complaint with a data protection authority.

If you are in California, you also have the right to know what we collect, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell personal data or share it for cross-context behavioural advertising, so there is nothing to opt out of on that front.

Exercise any of these by emailing info@coretas.ai. We respond within one month, and will tell you if we need longer. We may need to verify your identity first.

If the personal data sits inside a Coretas customer's advertising account, that customer is the controller and we will refer your request to them.

11. Cookies

See the Cookie Notice for what we set, why, and how to refuse it.

12. Changes

We may update this statement at any time. Unless the law requires otherwise, a change takes effect as soon as we post it here, without prior notice to you, and the version on this page is the version that applies. Where a change materially reduces the protection given to personal data we already hold about you, we will give notice by email or in-product notice before it takes effect. Prior versions are available on request from info@coretas.ai.

13. Complaints

Email info@coretas.ai first. Most privacy questions we can resolve the same week. If you are not satisfied you may complain to your local data protection authority, and on request we will give you its contact details.