Legal & Governance Framework
Chronological compliance timeline outlining security audits, data handling steps, and client rights for all CoreStackEngine engagements.
Privacy Policy
1.1 Data Controller. CoreStackEngine, located at Carrer de Colom, 6, 46002, València, Spain, acts as the data controller for all personal information collected through our web applications and services.
1.2 Data Collection. We collect only the minimum personal data necessary to deliver contracted services: name, email address, project specifications, and billing information. No biometric, health, or political data is processed.
1.3 Legal Basis. Data processing is conducted under Article 6(1)(b) of the GDPR — performance of a contract — and Article 6(1)(f) — legitimate interest in service improvement.
1.4 Data Retention. Personal data is retained for the duration of the service engagement plus 24 months. Project source code and deliverables are retained for 12 months post-delivery for warranty support.
1.5 Third-Party Sharing. Data is shared only with essential infrastructure providers (hosting, payment processing) under Data Processing Agreements compliant with GDPR Article 28. No data is sold or shared with marketing third parties.
1.6 International Transfers. All data is processed within the European Economic Area. Any transfer outside the EEA requires Standard Contractual Clauses (SCCs) approved by the European Commission.
Terms of Service
2.1 Scope of Engagement. CoreStackEngine provides web development, API engineering, security auditing, and cloud deployment services. All deliverables are defined in a signed Statement of Work (SOW) prior to project initiation.
2.2 Payment Terms. Invoicing follows a milestone-based structure: 40% upon SOW signing, 30% at midpoint delivery, and 30% upon final acceptance. All payments are due within 14 calendar days of invoice date.
2.3 Intellectual Property. Upon full payment, all source code, design assets, and documentation become the exclusive property of the client. CoreStackEngine retains the right to reference the project in portfolio materials unless otherwise agreed.
2.4 Service Level. CoreStackEngine guarantees 99.9% uptime for deployed applications under managed hosting plans. Support response time is guaranteed within 24 business hours for standard inquiries and 4 hours for critical outages.
2.5 Limitation of Liability. CoreStackEngine's total aggregate liability under any engagement shall not exceed the total fees paid by the client for the specific service giving rise to the claim. Consequential damages are excluded.
2.6 Termination. Either party may terminate with 30 days written notice. Work completed up to the termination date is billable. Source code for completed milestones is delivered regardless of termination.
Cookie Policy
3.1 Essential Cookies. CoreStackEngine uses strictly necessary cookies to maintain session state, preserve user preferences (including cookie consent), and ensure secure authentication flows. These cookies do not require consent under the ePrivacy Directive.
3.2 Analytics. We do not employ third-party analytics tracking, advertising pixels, or behavioral profiling cookies. All performance monitoring is conducted server-side using anonymized aggregate metrics.
3.3 Consent Mechanism. Upon first visit, a cookie consent banner is displayed. Acceptance is recorded in localStorage and persists for 365 days. Users may withdraw consent at any time by clearing browser storage or contacting [email protected].
3.4 Cookie Inventory. The only cookie-like mechanism in use is the cse_cookies_accepted localStorage key, which records your cookie consent preference. No session cookies, tracking cookies, or third-party cookies are set.
Refund & Reimbursement Policy
4.1 Pre-Development Cancellation. If a project is cancelled before development work commences (within 5 business days of SOW signing), a full refund of all payments made is issued within 10 business days.
4.2 Mid-Project Cancellation. For cancellations after development has begun, payment for completed milestones is non-refundable. The initial 40% deposit is non-refundable once architecture planning and discovery have been delivered.
4.3 Defective Deliverables. If deliverables materially fail to meet the specifications defined in the SOW, CoreStackEngine will remediate at no additional cost within 30 days. If remediation is not feasible, a pro-rata refund of the affected milestone is issued.
4.4 Dispute Resolution. Refund disputes are subject to a 30-day good-faith negotiation period. If unresolved, disputes are submitted to the competent courts of València, Spain, in accordance with Spanish consumer protection law.
4.5 Refund Processing. Approved refunds are processed via the original payment method within 14 business days. Stripe transaction fees are non-refundable and are deducted from the refund amount.
Your Data Rights Under GDPR
CoreStackEngine upholds all rights guaranteed by the General Data Protection Regulation (EU) 2016/679.
Right of Access
Request a complete copy of all personal data we hold about you, provided within 30 days.
Right to Erasure
Request deletion of your personal data, subject to legal retention obligations.
Right to Rectification
Request correction of inaccurate or incomplete personal data at any time.
Right to Portability
Receive your data in a structured, machine-readable format for transfer to another controller.
Right to Object
Object to processing based on legitimate interests, including profiling and direct marketing.
Right to Complain
File a complaint with the Spanish Data Protection Agency (AEPD) at aepd.es.
For legal inquiries, data requests, or GDPR-related questions:
TELEMETRY_DATA