Get in Touch
Legal

Privacy Policy

Last updated: July 1, 2025

At Hezcore, your privacy matters. This policy explains what data we collect, why we collect it, how we protect it, and your rights.

1. Information We Collect

Information You Provide Directly

  • Name, email address, and company name submitted via contact or enquiry forms
  • Newsletter subscriptions (email address)
  • Project briefs, files, and communications shared during service delivery
  • Account registration details if you create a client account

Information Collected Automatically

  • IP address and browser type
  • Pages visited and time spent on our website
  • Referring URLs
  • Device type and operating system

2. Cookies

Our website uses cookies — small text files placed on your device — to improve functionality and analyse traffic. We use the following types:

  • Essential cookies: Required for the website to function. Cannot be disabled.
  • Analytics cookies: Help us understand how visitors interact with our site.
  • Marketing cookies: Used to show relevant ads or measure campaign performance. Only set with your consent.

You can manage your cookie preferences at any time. See our Cookie Policy for full details.

3. Analytics

We use analytics tools to understand how visitors use our website. This data is aggregated and anonymised where possible and does not directly identify you as an individual.

Analytics data helps us improve page performance, identify user flow issues, and make informed decisions about our content. You may opt out by enabling a Do Not Track header, using a browser extension, or adjusting cookie preferences.

4. AI Processing

Some of our services use artificial intelligence to process data you provide — for example, to power AI chatbots, generate automation workflows, or analyse business data as part of a managed service.

Data processed by AI tools is handled in accordance with the data processing agreements of the underlying AI providers (e.g., OpenAI, Anthropic). We do not use your business data to train general-purpose AI models. Where AI processing involves personal data, we ensure appropriate safeguards are in place.

5. Customer Account Data

If you have a client account with Hezcore, we store information necessary to manage your subscription and deliver services, including your contact details, billing address, service history, and support communications. This data is stored securely and is not shared with third parties except as required to deliver your services.

6. Payment Information

Hezcore does not store, access, or process your payment card information. All payments are securely handled by Paddle, our Merchant of Record. Paddle collects and processes your payment details in accordance with PCI DSS standards and their own privacy policy.

We only receive confirmation of successful payment and a Paddle-generated transaction reference. We do not receive your card number, CVV, or bank account details.

7. Usage Data

When you use a Hezcore-built product or managed service, we may collect usage data such as feature interactions, automation run counts, API call volumes, and error logs. This data is used to maintain service quality, optimise performance, troubleshoot issues, and inform future feature development.

8. Log Files

Our web servers and hosting infrastructure automatically record log files that include IP addresses, browser types, referring pages, date/time stamps, and error codes. Log files are retained for a limited period for security and diagnostic purposes and are not used to identify individual users except where required to investigate a security incident.

9. Third-Party Services

We use a number of trusted third-party services to operate our business. These may include:

  • Paddle — payment processing and subscription management
  • Google Analytics / analytics providers — website analytics
  • Calendly — appointment scheduling
  • Email service providers — transactional and marketing emails
  • Cloud hosting providers — infrastructure for our website and client projects
  • AI providers (e.g., OpenAI) — powering automation and AI features

Each provider is selected for their commitment to security and privacy. We do not sell your personal data to any third party.

10. Security Measures

We implement industry-standard technical and organisational measures to protect your personal data. These include:

  • HTTPS encryption for all data in transit
  • Access controls limiting who can view personal data internally
  • Regular security reviews of infrastructure and dependencies
  • Secure password storage using modern hashing algorithms

While we take every reasonable precaution, no method of transmission over the internet is 100% secure. We will notify affected individuals and relevant authorities of any data breach in accordance with applicable law.

11. Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law:

  • Contact form submissions: up to 2 years
  • Client account data: duration of the relationship plus 5 years
  • Payment records: as required by financial regulations (typically 7 years)
  • Analytics data: retained in aggregated form per provider settings
  • Log files: up to 90 days

You may request deletion of your personal data at any time (see Section 12).

12. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you
  • Right to rectification: Request correction of inaccurate data
  • Right to erasure: Request deletion of your personal data
  • Right to restrict processing: Ask us to limit how we use your data
  • Right to data portability: Receive your data in a structured, machine-readable format
  • Right to object: Object to processing based on legitimate interests or for direct marketing
  • Right to withdraw consent: Withdraw any previously given consent at any time

To exercise any of these rights, contact us at support@hezcore.com. We will respond within 30 days.

13. International Data Transfers

Hezcore is based in Trinidad and Tobago and serves clients worldwide. Your data may be processed on servers located in various countries. When transferring personal data internationally, we ensure appropriate safeguards are in place, such as using providers who comply with GDPR standard contractual clauses or equivalent data protection frameworks.

14. Children's Privacy

Our services are intended for businesses and individuals aged 18 and over. We do not knowingly collect personal data from children under the age of 13. If you believe a child has provided us with personal data, please contact us immediately and we will delete it.

15. Policy Updates

We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal obligations. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email.

Continued use of our services after an update constitutes acceptance of the revised policy.

16. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:

Hezcore

Trinidad and Tobago

Email: support@hezcore.com

Website: https://hezcore.com