All policies

Data processing addendum

The binding terms under which Core Skill processes personal data on behalf of a customer organization: what is processed and why, the security measures applied, the sub-processors involved, breach notification, and what happens to the data at the end.

Effective 22/9/2026

No lawyer has reviewed this text

This addendum is written to match what the system actually does, and the technical annex is accurate. It has not been reviewed by a lawyer. Before Core Skill signs it with a customer, a qualified person must check it against Decree 13/2023/ND-CP, and against any foreign law that a particular customer is subject to.

This addendum applies whenever Core Skill processes personal data on behalf of a customer organization using CoreSkill. It forms part of the Terms of service and prevails over them on any question of personal data. Where a customer has signed a separate negotiated data processing agreement, that agreement prevails over this one.

The roles

Controller
The customer organization that creates a business. It decides who is a member, which department they belong to, which skills exist, and who may read them. It is responsible for having a lawful basis for the personal data it puts into the system.
Processor
Core Skill, registered at coreskill.app. It stores and delivers that data, and acts only on the controller's instructions. It does not decide what goes into a skill and does not use the content for any purpose of its own.
Data subject
The people whose data is processed: members of the business, and any identifiable person described inside a skill or an attached file.

Subject matter, duration, nature and purpose

Subject matter
Hosting the CoreSkill service for the controller, and delivering the controller's skills to the AI assistants of the people the controller has authorized.
Duration
For as long as the controller's business exists in the system, plus the short window described under Return and deletion below.
Nature of the processing
Collection, storage, organization, retrieval, transmission to authorized keys, logging of access, backup, and deletion. No analysis, no profiling, no model training.
Purpose
Operating the service, keeping it secure, and producing the access logs the controller relies on to supervise its own people.

Categories of data subject and of personal data

Category of data subjectPersonal data processed
Members of the businessName, email address, system and business role, department, free-text job title, membership status, language.
Key holdersKey name and prefix, a hash of the key, issue, expiry and revocation dates, and the member the key belongs to.
Anyone making an MCP callIP address, client user agent, tool called, status, duration, a summary of the call, and the member and department name recorded at the time.
People described inside contentWhatever the controller chooses to put into a skill or an attached file. Core Skill does not inspect this and cannot know in advance what it contains.

Instructions

  • Core Skill processes personal data only on the documented instructions of the controller. The Terms of service, this addendum, and the settings the controller configures in the product together constitute those instructions.
  • If Core Skill is required by law to process data beyond those instructions, it will inform the controller before doing so, unless the law forbids telling them.
  • If Core Skill believes an instruction breaches data protection law, it will say so and may refuse to carry it out.
  • Core Skill will not use the controller's content for its own purposes, and specifically will not use it for advertising, for analytics about the controller, or to train any AI model.

What Core Skill undertakes

  1. To apply the technical and organizational measures in Annex A below, and not to weaken them without an equivalent replacement.
  2. To ensure that everyone authorized to access personal data is bound by confidentiality and processes it only as needed for their work.
  3. To limit staff access to what is necessary, and to log administrative actions in an audit trail.
  4. To engage a sub-processor only as described under Sub-processors, and to impose equivalent obligations on it.
  5. To assist the controller in responding to requests from data subjects, and in meeting its own obligations on security, breach notification and impact assessments.
  6. To notify the controller without undue delay on becoming aware of a personal data breach, as described below.
  7. To delete or return the data at the end of the service, as described below.
  8. To make available the information the controller reasonably needs to demonstrate compliance, and to cooperate with an audit on the terms below.
  9. To notify the controller of any lawful request from an authority for its data, before disclosing anything, unless the law forbids telling them.

Sub-processors

The controller gives general authorization for the sub-processors below, each of which is necessary for the service to run. Core Skill remains fully liable to the controller for their acts and omissions.

Sub-processorPurposeLocation
DigitalOceanVirtual server and storage, on which the application and the database run.Singapore
CloudflareDNS, TLS at the edge, and protection against attack.Global edge network
GoogleOptional, only where the administrator enables it: sign-in with Google, and sending system email through Gmail.Global
Email providerOptional: delivering verification codes, password resets and invitations where SMTP is configured.As configured by the administrator

Core Skill will give the controller at least 30 days notice before adding or replacing a sub-processor. If the controller objects on reasonable data protection grounds within that period, the parties will discuss it in good faith, and if no solution is found the controller may terminate the affected service without penalty.

Transfer outside Vietnam

The server is in Singapore and Cloudflare operates a global network, so personal data is transferred outside Vietnam. Decree 13/2023/ND-CP requires the transferring party to prepare a cross-border transfer impact assessment dossier, keep it available for inspection, and notify the Ministry of Public Security. Core Skill prepares and maintains that dossier for the transfers listed above, and will provide the controller with a copy of the relevant parts on request so that the controller can complete its own filing.

Annex A: technical and organizational measures

MeasureHow it is implemented
Password storagebcrypt at cost 12. Plain-text passwords are never stored, never logged and never recoverable.
Key storageSHA-256 with a secret pepper, compared in constant time. The real key exists only in the response that creates it, for a few seconds.
Encryption of secretsAES-256-GCM for two-factor secrets and stored OAuth credentials, with a key held separately from the session signing key so that rotating one does not destroy the other.
Encryption of content at restOptional AES-256-GCM on skill bodies and attached files. It protects against a leaked backup, a stolen disk or a database read, and not against the operator of the server.
Encryption in transitHTTPS throughout, HSTS enabled, and the origin server accepts connections only from Cloudflare. Direct connections to its IP address are refused at the firewall.
Network isolationThe database publishes no port to the host and is reachable only by the application over a private network. Containers run as a non-root user with all capabilities dropped.
Access controlRole and department based, evaluated on every request. Resources outside a person's visibility answer as if they did not exist, so the system never confirms what it will not show.
Abuse resistanceRate limits on sign-in, password reset and both MCP endpoints. Malformed tokens are rejected before any database query is made.
Session controlTwo-factor authentication with single-use recovery codes. Changing or resetting a password revokes every session issued before that moment.
Logging and retentionEvery MCP call is logged, including refused ones. Logs are purged automatically after the configured retention period, 90 days by default. Administrative writes are recorded in a separate audit trail.
BackupDaily database dump, retained on a rolling 14 day window, held on the same infrastructure provider.

Personal data breach

  1. Core Skill will notify the controller without undue delay, and in any case within 24 hours of becoming aware of a breach affecting the controller's data.
  2. The notification will describe what happened, which categories of data and roughly how many people are affected, the likely consequences, and what is being done about it. Where that detail is not yet known, it will be sent in stages rather than held back.
  3. Core Skill will notify the Ministry of Public Security within 72 hours where Decree 13/2023/ND-CP requires it, and will assist the controller with any notification the controller must make itself.
  4. Core Skill will keep a record of breaches, their effects and the remedial action taken, and make it available to the controller on request.

Assisting with the rights of data subjects

Requests from data subjects are answered by the controller, because the controller decides. Where a data subject contacts Core Skill directly about data inside a business, Core Skill will not answer on the merits; it will pass the request to the controller within 72 hours and help it respond, including by providing an export or by carrying out a deletion the controller instructs.

Audit and evidence

  • Core Skill will provide the information reasonably needed to demonstrate compliance with this addendum, starting with this document and the product's own logs.
  • The controller may audit once in any twelve month period, on 30 days notice, at its own cost, and more often where an authority requires it or after a breach.
  • An audit must not disrupt the service, must not reach other customers' data, and the auditor must be bound by confidentiality.

Return and deletion at the end

  • The controller can export its data at any time while the service is running, including the MCP logs as CSV.
  • On termination, Core Skill will delete the controller's personal data within 30 days, unless the controller asks in writing for it to be returned first.
  • Deleting a business deletes its servers, skills, files, keys, members and logs immediately, and that action cannot be undone by anyone.
  • Copies inside routine backups age out on the 14 day cycle described in Annex A. They are not accessed during that time, and they are not restored except to recover the service as a whole.

Deletion is final, and export is the only preparation

There is no recycle bin and no undo. Once a business is deleted, Core Skill cannot bring back a skill, a member list or a log, because the record is gone rather than hidden. If there is any chance the content will be needed again, export it before you delete.

What the controller undertakes

  • To have a lawful basis for every piece of personal data it puts into the system, including anything inside a skill or an attached file.
  • To give its own people the information the law requires about how their data is used, including the fact that every MCP call is logged under their name.
  • To keep its member list current, and to remove or suspend people who leave so their keys stop working.
  • To issue instructions that comply with data protection law, and not to use the product to process sensitive personal data without the basis the law requires.
  • To answer its own data subjects, and to tell Core Skill promptly when it needs assistance to do so.

Liability and order of precedence

The limitation of liability in the Terms of service applies to this addendum as well, except where the law does not permit it to. If this addendum conflicts with the Terms of service on a question of personal data, this addendum prevails. If it conflicts with a separately negotiated agreement signed by both parties, that agreement prevails.

Accepting this addendum

This addendum takes effect automatically when a customer starts using CoreSkill to process personal data, and no signature is needed for it to bind both parties. A customer who needs a signed copy for its own compliance file should write to [email protected], and one will be issued naming the parties.

Contact

Anything to do with this addendum goes to [email protected], or by post to Core Skill, coreskill.app. Other matters go to [email protected]. This addendum is governed by the law of Core Skill and takes effect on 22/9/2026.