Privacy
Privacy Policy

Effective Date: July 22, 2026

1. Introduction and Scope


Core Human Factors, Inc. (“Core,” “we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Notice explains how we collect, use, disclose, retain, and protect your personal information across all of our business activities, including our websites, mobile applications, research studies, consulting services, and other interactions with you.

This notice applies to personal information we collect from customers, research participants, prospective participants, employees, contractors, vendors, suppliers, website visitors, and job applicants. It also applies to information we collect offline (such as through phone calls, surveys, or in-person meetings) as well as online.

This Privacy Notice is designed to comply with all applicable privacy laws across every jurisdiction in which Core operates and collects personal information. Core applies the most protective standard available under any applicable law to all individuals whose personal information we process, regardless of where they reside. Where multiple laws apply, we follow the most restrictive requirements. Applicable frameworks include, without limitation,  all applicable U.S. federal and state privacy laws, including the California Consumer Privacy Act and California Privacy Rights Act (CCPA and CPRA), and the privacy statutes of Virginia, Colorado, Connecticut, Texas, Maryland, New Jersey, Delaware, Minnesota, Iowa, Indiana, Kentucky, Rhode Island, Nebraska, New Hampshire, Tennessee, Montana, Oregon, Florida, Utah, and all other states with enacted privacy legislation; the General Data Protection Regulation (GDPR) and applicable national implementing legislation; the UK GDPR and the Data Protection Act 2018; The Federal Act on Data Protection (nFADP, effective September 1, 2023) and its implementing ordinances; The Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec’s Act to Modernize Legislative Provisions Respecting the Protection of Personal Information (Law 25), and applicable provincial privacy legislation; The Protection of Privacy Law (5741-1981) as amended by Amendment 13 (effective August 14, 2025); and any applicable international and national privacy frameworks.

Washington State and Nevada Residents. If you are a resident of Washington State or Nevada, or if your consumer health data is collected in Washington State or Nevada, your consumer health data is also governed by Core’s separate Consumer Health Data Privacy Policy, available at Consumer Health Data Privacy Policy. That policy addresses your specific rights under Washington’s My Health My Data Act (RCW 19.373) and Nevada’s Consumer Health Data Privacy Law (NRS Chapter 603A). To the extent of any conflict between this Privacy Notice and the Consumer Health Data Privacy Policy, the Consumer Health Data Privacy Policy controls with respect to consumer health data.

Please note: If you are a participant in one of our research studies, your participation is also governed by a separate informed consent form or research protocol provided to you at the time of enrollment. To the extent there is any conflict between this Privacy Notice and a study-specific consent document, the consent document controls with respect to data collected in that study.

Back to Top

2. Categories of Personal Information We Collect



We collect various categories of personal information depending on how you interact with us. These categories include:

  • Other Information: Any other information you provide to us directly, such as through joining our research panel as a prospective study participant, surveys, feedback forms, or customer service interactions.
  • Identifiers: Name, email address, postal address, telephone number (landline and/or mobile), fax number, company name, job title, employee ID, username, and password.
  • Commercial Information (for business partners): Purchase and transaction history, billing information, payment method, and account status.
  • Financial Information (for business partners): Bank account information, credit history, and other financial details necessary for credit assessment.
  • Device and Network Information: IP addresses 
  • Location Information: General geographic location derived from IP address
  • Internet and Electronic Activity: Browsing and search history on our websites and apps, pages visited, links clicked, time and duration of visits, referring and exit pages, and interaction with our content and services.
  • Demographic Information: Age, gender, race, ethnicity, and other demographic details (collected only when you voluntarily provide this information).
  • Education and Professional Information: Educational background, work history, professional certifications, and skills.
  • Biometric Information: In limited research contexts, we may collect biometric data (such as fingerprints, voice recordings, or facial recognition data) only with explicit consent and in compliance with applicable law.
  • Sensory Information: Audio or video recordings of your interactions with us (where permitted by law and with notice).
  • Inferences and Derived Data: Inferences we draw from your personal information to create a profile reflecting your preferences, interests, or likely behavior.

Back to Top

3. Sources of Personal Information


We obtain personal information from a variety of sources:

  • Referral Programs: If you refer someone to us, we collect information about the person you refer (with both your and their permission).
  • Directly from You: Information you provide when you contact us, join our database as a prospective research participant, participate in a study, request services, complete surveys, apply for employment, or interact with our websites and applications.
  • Automated Collection: Information collected automatically through cookies, web beacons, pixel tags, and similar tracking technologies when you visit our websites or use our applications.
  • Third-Party Sources: Information obtained from business partners, vendors, data brokers, social media platforms, public records, conference attendees, and other third parties who provide contact or demographic information.
  • Service Providers and Partners: Information received from companies that perform services on our behalf, such as payment processors, analytics providers, and cloud storage vendors.
  • Affiliated Companies: Information shared among Core family of companies and affiliates for business purposes.
  • Public Sources: Information obtained from publicly available sources, including social media profiles, professional networks, and public databases.

Back to Top

4. Purposes for Processing Personal Information



We use personal information for the following purposes:

  • Service Delivery: Providing research services, consulting, training, and other services you request; fulfilling contracts; and responding to inquiries.
  • Billing and Payment: Processing payments, managing accounts, invoicing, and collecting fees.
  • Communication: Contacting you regarding your account, services, updates, and customer support.
  • Marketing and Advertising: Sending promotional materials, newsletters, and marketing communications (in accordance with your preferences and applicable law); measuring marketing effectiveness; and personalizing content.
  • Research and Analytics: Conducting internal research, analyzing usage patterns, improving our services, and developing new offerings.
  • Recruitment: Processing job applications and evaluating candidates for employment.
  • Compliance and Legal Obligations: Complying with laws, regulations, legal processes, and government requests; establishing, exercising, or defending legal claims.
  • Fraud Prevention and Security: Detecting, preventing, and addressing fraud, abuse, and security incidents; protecting against malicious, deceptive, or illegal activity.
  • Business Operations: Managing our business, including financial reporting, accounting, auditing, and internal administrative purposes.
  • Legitimate Business Interests: Pursuing legitimate business interests, including understanding customer needs, optimizing operations, and improving products and services.
  • Consent-Based Uses: Where you have provided explicit consent, we may use your information for additional purposes (such as specific marketing activities or research participation).

Core is the data controller of data collected as part of its business with its clients. It is also data controller of its database of potential research participants. 

In its role as human factors consultant and researcher, Core is a data processor on behalf of its client(s).  As a data processor, Core processes data as consistent with the directions of the controller and only as needed for the purpose of relationship. As data processor, Core may collect information for and on behalf of the data controller. Core applies principles of data minimization and will provide its clients with statistical reports (de-identified).  Processing including audio-visual recordings are handled as further described in the consent form related to a specific study.

Back to Top

5. Legal Bases for Processing 



We process personal information based on the following lawful bases:

  • Contract: Processing is necessary to perform a contract with you or to take steps at your request prior to entering into a contract.
  • Legal Obligation: Processing is required by applicable law, regulation, or court order.
  • Legitimate Interests: Processing is necessary for our legitimate business interests, provided that your interests and fundamental rights do not override these interests. Core’s legitimate interests include: operating and improving our research and consulting services; maintaining the security; and integrity of our systems and data; fraud prevention and detection; internal analytics and business reporting; managing our database of prospective research participants; and pursuing or defending legal claims. Where we rely on legitimate interests as a legal basis, you have the right to object to that processing.
  • Consent: You have given explicit consent to the processing for a specific purpose.
  • Vital Interests: Processing is necessary to protect the vital interests of you or another person.
  • Public Task: Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.

Processing of personal data occurs pursuant to core principles of lawfulness, good faith, proportionality, purpose limitation, accuracy, and storage limitation. 

For sensitive personal data (including health data, biometric data, genetic data, racial or ethnic origin, or gender specific information), we obtain explicit consent or rely on a recognized justification under applicable law. Core applies Privacy by Design and Privacy by Default principles to its processing activities.

Back to Top

6. Data Retention



We retain personal information only as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required by law. Specific retention periods vary by data category and purpose:

  • Customer and Service Information: Retained for the duration of the business relationship and for a minimum of 3โ€“7 years after the relationship ends (as required by tax and accounting regulations).
  • Financial Records: Retained for a minimum of 7 years to comply with tax and accounting requirements.
  • Employment and Recruitment Records: Retained in accordance with employment law requirements, typically 3โ€“7 years.
  • Marketing and Communications Data: Retained until you opt out or unsubscribe, unless a longer period is required by law.
  • Prospective Participant Database Information: Retained until you opt out or unsubscribe, unless a longer period is required by law.
  • Website Analytics and Tracking Data: Retained for up to 2 years, unless a longer period is necessary for legitimate business purposes.
  • Research Study Data: Retained in accordance with the informed consent document provided at the time of enrollment and applicable research regulations. Indicative retention periods by data type include:  (a) consent forms for a minimum of three (3) years after study completion; (b) audio and video recordings as stated in the consent form for the specific project, or if transferred to the client (which would then comply with the clientโ€™s privacy policy); (c) adverse event and pharmacovigilance records for a minimum of five (5) years, or longer as required by applicable law, regulatory guidance, or sponsor contract; and (d) anonymized or de-identified research data may be retained indefinitely.
  • Legal and Compliance Records: Retained as long as necessary to satisfy legal obligations, litigation holds, or other compliance requirements.

When information is no longer needed, we securely delete or anonymize it. However, we may retain aggregated or de-identified information indefinitely for analytical and business purposes.

Back to Top

7. Ethical Use of Artificial Intelligence




Core Human Factors, Inc. does not currently deploy artificial intelligence (AI) or machine learning systems as deliberate tools for analyzing, profiling, or making decisions about individuals. Core does not use your personal data to train AI models.

Some of the third-party platforms and tools we use to deliver our services โ€” such as transcription, translation, video conferencing, or data processing tools โ€” may incorporate AI or machine learning functionality within their underlying technology. Where this is the case, Core does not control the AI components of those tools, but we require all third-party providers to comply with applicable data protection law and to process personal data only as described in their data processing agreements with Core.

  • No Automated Decision-Making. Core does not make decisions about individuals that produce legal or similarly significant effects through automated means alone. All determinations affecting your rights or interests are made by Core personnel.

Should Core introduce deliberate AI-based processing of personal data in the future, we will update this Privacy Notice accordingly and, where required by applicable law, seek your consent or provide you with the opportunity to object before such processing begins.

Back to Top

8. Research Studies and Separate Consent



Core Human Factors, Inc. conducts human factors research, user studies, and other research activities. When you participate in a research study, the data you provide is subject to a separate informed consent document or research protocol that is provided to you at the time of enrollment.

Important Notice:

  • Separate Governance: Research study data is governed by the informed consent form and research protocol specific to that study, not solely by this general Privacy Notice.
  • Conflict Resolution: To the extent there is any conflict between this Privacy Notice and a study-specific consent document, the consent document controls with respect to data collected in that study.
  • Data Use and Sharing: The consent document will specify how your research data will be used, who may access it, how long it will be retained, and whether it will be shared with third parties or published.
  • Rights: Your rights regarding research data, including access, withdrawal, and deletion, will be addressed in the consent forms.

If you have questions about how your research data is handled, please refer to the consent document you signed or contact the principal investigator listed in that document.

Back to Top

9. Disclosure and Sharing of Personal Information



We may disclose personal information in the following circumstances:

9.1 Service Providers and Vendors

We share personal information with third-party service providers and vendors who perform services on our behalf, such as:

  • Cloud-based productivity and data processing platforms, including Microsoft 365, Microsoft Azure, and Google Workspace, which we use for business operations, data storage, collaboration, and processing activities
  • Payment processors and financial institutions
  • Marketing and analytics providers
  • Customer relationship management (CRM) systems
  • Human resources and recruitment firms
  • Legal and accounting advisors
  • Data security and compliance vendors

These vendors are contractually required to use personal information only for the purposes for which it was provided and to maintain appropriate security safeguards. Each of our primary cloud providers maintains its own data processing agreements and security certifications consistent with GDPR, UK GDPR, and other applicable data protection laws.

9.2 Affiliated Companies

We may share personal information with other companies within the Core family of companies for legitimate business purposes, including internal reporting, marketing, customer insights, and service optimization.

9.3 Business Partners and Joint Offerings

If we offer services jointly with a partner company, we may share personal information with that partner. We will notify you at the time of collection if your information will be shared. You should also review the partner’s privacy policy.

Core is a subsidiary of Rimkus Consulting Group, Inc. (โ€œRimkusโ€).  Rimkusโ€™s privacy notice is available on its website at rimkus.com.

9.4 Legal Requirements and Compliance

We may disclose personal information when required by law, court order, subpoena, or government request; when necessary to protect public safety or prevent harm; or when necessary to establish, exercise, or defend legal claims.

9.5 Business Transfers

In the event of a merger, acquisition, bankruptcy, or sale of assets, personal information may be transferred as part of that transaction. 

9.6 Your Consent

We may disclose personal information with your explicit consent for purposes you have authorized.

9.7 Aggregated and De-Identified Information

We may share aggregated or de-identified information that cannot reasonably be used to identify you with third parties for research, marketing, analytics, and other business purposes without restriction.

9.8 Third-Party Plug-Ins and Social Media

Our websites may include third-party plug-ins, widgets, and social media buttons. These third parties may collect information about your interactions with our sites even if you do not actively click on them. We recommend reviewing the privacy policies of these third parties.

Back to Top

10. International Data Transfers


Core operates globally and may transfer personal information to countries outside the country where it was collected. These countries may have different data protection laws than your country of residence.

10.1 Transfer Mechanisms

When transferring personal information internationally, we implement appropriate safeguards as required by applicable law, including one or more of the following recognized mechanisms as applicable:

  • Standard Contractual Clauses (SCCs): We use SCCs approved by the European Commission or the UK Information Commissioner’s Office (ICO) to govern transfers from the EU or UK to other countries. For transfers of personal data originating in Switzerland, we use SCCs recognized under Swiss law or other safeguards approved by the Swiss Federal Data Protection and Information Commissioner (FDPIC), as required by the nFADP.
  • Adequacy Decisions or Adequacy Determinations: Where available, we rely on adequacy decisions from the European Commission or the UK government, or adequacy determinations published by the FDPIC for Switzerland. For example, Israel, where Core maintains a subsidiary, benefits from an adequacy decision recognized under both EU and UK data protection law. 
  • Other Recognized Mechanisms: Where SCCs or adequacy decisions are not available or appropriate, we may rely on other lawful transfer mechanisms recognized under applicable law (such as derogations for specific situations under GDPR Article 49 or equivalent provisions under the nFADP).
  • Your Consent: Where required by law, we obtain your consent prior to transferring your information.

10.2 Recipient Responsibilities

Recipients of transferred personal information are contractually bound to use it only for the purposes for which it was originally provided and to maintain appropriate security safeguards consistent with this Privacy Notice.

ISO 27001 Certification. Core is part of a business enterprise that holds ISO 27001 certification (Information Security Management Systems). The ISO 27001-certified information security management system governing our enterprise provides an independently audited framework for the technical and organizational measures applied to personal data in transit and at rest and supports the security commitments made in our Standard Contractual Clauses and other transfer safeguards. Copies of the current ISO 27001 certificate are available upon request.

10.3 Your Rights

You have the right to request information about the mechanisms used to protect your data during international transfers. Please contact us using the details in Section 17 below.

Back to Top

11. Cookies and Tracking Technologies


11.1 What Are Cookies?

Cookies are small text files stored on your device that allow us to recognize you and remember your preferences. We use cookies and similar tracking technologies (including web beacons, pixel tags, and local storage) to enhance your experience, analyze usage, and deliver personalized content.

11.2 Types of Cookies We Use

  • Essential Cookies: Required for website functionality, security, and account management.
  • Performance Cookies: Help us analyze how users interact with our sites and identify areas for improvement.
  • Marketing Cookies: Used to deliver targeted advertising and measure campaign effectiveness.
  • Analytics Cookies: Collect data on website usage for internal reporting and analytics.

11.3 Your Cookie Choices

  • Browser Settings: Most web browsers allow you to control cookies through settings. You can choose to block all cookies, accept only certain types, or receive a warning before a cookie is stored. However, blocking cookies may limit functionality on our sites.
  • Opt-Out Links: We provide opt-out mechanisms for certain cookies, including analytics and marketing cookies. 

11.4 Third-Party Cookies

Third-party service providers (such as Google, social media platforms, and advertising networks) may place cookies on your device to deliver targeted content and measure advertising effectiveness. We recommend reviewing the privacy policies of these third parties to understand their cookie practices.

11.5 Web Beacons and Pixels

Web beacons (also known as pixel tags or clear GIFs) are tiny graphic images embedded in web pages or emails that allow us to track whether you have visited a page or opened an email. We use web beacons in conjunction with cookies to analyze usage patterns and measure marketing effectiveness.

11.6 Geofencing Prohibition

Core does not implement, use, or deploy geofencing technology around healthcare facilities or any other location for the purpose of identifying, tracking, or collecting consumer health data from individuals seeking in-person health care services or products. This prohibition is consistent with Core’s Consumer Health Data Privacy Policy and applies regardless of jurisdiction.

Back to Top

12. Data of Minors

12.1 Age Restrictions

Core’s websites and services are intended for users 18 years of age or older. We do not knowingly collect personal information from children under 18 without the consent of a parent or legal guardian.

12.2 Children Under 13 years of age (COPPA Compliance)

In compliance with the Children’s Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13. If we become aware that we have collected information from a child under 13 without verifiable parental consent, we will take reasonable steps to delete that information promptly.

12.3 Minors Ages 13 to17 years of age

For users ages 13โ€“17, we apply heightened privacy protections. We do not use information from minors for behavioral advertising, profiling, or other uses that could harm their privacy or safety without parental consent. We also limit the collection of sensitive personal information from minors.

12.4 Parental Rights

Parents or legal guardians of minors may request to review, correct, or delete personal information we hold about their child. Please contact us using the details in Section 17 below.

12.5 Research Studies with Minors

If we conduct research studies involving minors, we will obtain explicit informed consent from the minor’s parent or legal guardian, and we will comply with all applicable regulations, including the Common Rule (45 CFR 46) and institutional review board (IRB) requirements.

Back to Top

13. Data Security

13.1 Security Measures

Core takes data security seriously and has implemented technical, administrative, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, and destruction. These safeguards include:

  • Encryption: Sensitive data is encrypted in transit (using SSL/TLS) and at rest using industry-standard encryption protocols.
  • Access Controls: Access to personal information is restricted to authorized employees, contractors, and service providers who have a legitimate business need and are trained on privacy and security practices.
  • Authentication: We use multi-factor authentication and strong password requirements to protect accounts.
  • Network Security: We maintain firewalls, intrusion detection systems, and other network security measures.
  • Physical Security: We maintain physical security controls over facilities and equipment where personal information is stored.
  • Cloud Security: Personal information processed through cloud-based platforms (including Microsoft 365, Microsoft Azure, and Google Workspace) is subject to the security controls, certifications, and data processing agreements maintained by those providers, which include encryption, access controls, and compliance with applicable data protection laws.
  • Employee Training: All employees are trained on the importance of protecting privacy and on the proper handling of personal information.
  • Incident Response: We maintain an incident response plan to detect, investigate, and respond to data security incidents.

13.2 Limitations

While we implement comprehensive security measures, no system is 100% secure. We cannot guarantee that our safeguards will prevent every unauthorized attempt to access, use, or disclose personal information. If you believe your personal information has been compromised, please contact us immediately using the details in Section 17 below.

13.3 Data Breach Notification

In the event of a data breach involving personal information, we will notify affected individuals and regulatory authorities as required by applicable law, including CCPA/CPRA, GDPR, UK GDPR, PIPEDA, and other state privacy laws. Notifications will include details about the breach, the types of information affected, and steps you can take to protect yourself.

Back to Top

14. Your Privacy Rights

Your rights depend on where you live. The privacy rights available to you and the procedures for exercising them are determined by the laws of your jurisdiction. Individuals in California have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). Individuals in the European Union have rights under the General Data Protection Regulation (GDPR). Individuals in the United Kingdom have rights under the UK GDPR and the Data Protection Act 2018. Individuals in Switzerland have rights under the revised Federal Act on Data Protection (nFADP). Individuals in Canada have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and, in Quebec, under Law 25. Individuals in Israel have rights under the Israeli Privacy Protection Law and Amendment 13. Residents of Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and other U.S. states with comprehensive privacy laws have rights under those laws.

Not all rights listed in this Section apply to all individuals. Where a right is described as applying to residents of a specific jurisdiction, only residents of that jurisdiction may exercise that right under the applicable law. However, Core Human Factors, Inc. strives to extend privacy protections as broadly as possible, and individuals in any jurisdiction may contact us with privacy questions or concerns using the details in Section 17.

The table below provides a high-level overview of rights by jurisdiction. 

JurisdictionKey Rights Available
California (CCPA/CPRA)Know, access, delete, correct, opt-out of sale/sharing, limit sensitive data use, opt-out of ADMT, non-discrimination, data portability, authorized agentsCCPA: California Consumer Privacy ActCPRA: California Privacy Rights Act
EU (GDPR)Access, rectification, erasure, restriction, portability, object, withdraw consent, human review of automated decisions, lodge complaintEU GDPR: EU General Data Protection Regulation
UK (UK GDPR)Same as EU GDPR; complaint to ICOUK GDPR: UK General Data Protection Regulation 
Switzerland (nFADP)Access, rectification, erasure, restriction, portability, object, withdraw consent, lodge complaint with FDPICnFADP: New Federal Act on Data Protection
Canada (PIPEDA / Quebec Law 25)Access, correction, withdraw consent, complain to OPC; Quebec adds right to de-indexing and portabilityPIPEDA: Personal Information Protection and Electronic Documents ActQuebec Law 25: Quebec Law 25
IsraelAccess, correction, deletion, object to processing; complaint to Privacy Protection AuthorityIsrael: The Privacy Protection Authority
Virginia, Colorado, Connecticut, Texas, Oregon, MontanaAccess, correction, deletion, portability, opt-out of sale/targeted advertising/profiling; appeal rights; see ยง14.5VCDPA: Virginia Consumer Data Protection ActCPA: Colorado Privacy ActCTDPA: Connecticut Data Privacy Act TDPSA: Texas Data Privacy and Security ActOCPA: Oregon Consumer Privacy ActMCDPA: Montana Consumer Data Privacy Act 
All other jurisdictionsContact us โ€” we will respond to reasonable privacy requests to the extent required or permitted by applicable law

Additional information about each jurisdiction is at the bottom of this document.

Back to Top

15. Privacy Accountability Principles

Core Human Factors, Inc. is committed to the following privacy principles, which satisfy the requirements of accountability frameworks under applicable laws.

As applicable, Core engages in the following activities:

  • Privacy by Design and by Default: Core integrates data protection into the design of all systems, processes, and services from the outset. Default settings are configured to minimize data collection and processing to what is strictly necessary for the stated purpose. Users are not required to take additional steps to protect their privacy; the default is for data collection is the most privacy-protective.
  • Data Protection Impact Assessments (DPIAs): Where a processing activity is likely to pose a high risk to the rights and freedoms of individuals, particularly where new technologies are used, large-scale sensitive data is processed, or systematic monitoring occurs, Core conducts a DPIA before commencing that processing. If the DPIA identifies a residual high risk that cannot be mitigated, Core will consult with the appropriate authorities.
  • Breach Notification: In the event of a security breach that is likely to result in a high risk to the rights and freedoms of individuals, Core will notify the appropriate authorities and comply with all applicable laws and regulations as soon as possible (within approximately 72 hours where feasible). This includes notification of individuals where required.
  • Records of Processing Activities: Core maintains a record of its processing activities as applicable including the identity of the controller, the purpose of processing, categories of data subjects and personal data, recipients, retention periods, and cross-border transfer safeguards.

Core further adheres to the following principles:

Accountability: We are responsible for personal information in our possession and have designated a Privacy Officer to oversee our privacy practices and respond to privacy inquiries.

Identifying Purposes: We identify the purposes for collecting personal information at or before the time of collection.

Consent: We obtain your consent before collecting, using, or disclosing personal information, except where permitted or required by law.

Limiting Collection: We collect only the personal information necessary for identified purposes.

Limiting Use, Disclosure, and Retention: We use and disclose personal information only for identified purposes and retain it only as long as necessary.

Accuracy: We maintain personal information in an accurate, complete, and up-to-date manner.

Safeguards: We implement appropriate security safeguards to protect personal information.

Openness: We make information about our privacy practices readily available to individuals.

Individual Access: We provide individuals with access to personal information we hold about them and allow them to request corrections.

Challenging Compliance: We provide a process for individuals to challenge our compliance with these principles.

Privacy Officer Contact: [email protected].



Back to Top

16. CCPA/CPRA Specific Disclosures

16.1 Categories of Personal Information Collected

In the past 12 months, we have collected the following categories of personal information:

CategoryExamples
IdentifiersName, email, address, phone, username
Commercial InformationPurchase history, billing information
Financial InformationCredit card, bank account, credit history
Device/Network InformationIP address, device type, browser
Location InformationGeneral location, GPS coordinates (where permitted)
Internet/Electronic ActivityBrowsing history, search queries, interaction data
Demographic InformationAge, gender, race, ethnicity
Education/ProfessionalWork history, certifications, skills
Biometric InformationFingerprints, voice recordings (research only)
Sensory InformationAudio/video recordings (where permitted)
InferencesPreferences, interests, behavior profiles

16.2 Sources of Personal Information

We obtain personal information from:

  • You directly (through forms, applications, surveys)
  • Automated collection (cookies, analytics)
  • Third-party data providers and brokers
  • Service providers and business partners
  • Affiliated companies
  • Public records and social media
  • Referral programs

16.3 Business Purposes for Collection

We collect personal information for:

  • Providing services and fulfilling contracts
  • Billing and payment processing
  • Customer service and support
  • Marketing and advertising
  • Research and analytics
  • Recruitment and employment
  • Compliance and legal obligations
  • Fraud prevention and security
  • Business operations
  • Improving services and products

16.4 Categories of Third Parties with Whom Information Is Shared

In the past 12 months, we have disclosed personal information to:

  • Service providers (payment processors, analytics, hosting)
  • Business partners and affiliates
  • Marketing and advertising partners
  • Legal and accounting advisors
  • Government agencies (when required by law)
  • Other parties with your consent

16.5 Sale or Sharing of Personal Information

Core does not sell sensitive personal data under any circumstances

We may share non-sensitive personal information with third parties for purposes that could be considered ‘sale’ or ‘sharing’ under applicable law (such as cross-context behavioral advertising or targeted advertising). You have the right to opt out of such sharing at any time by contacting us using the details in Section 17.

We do not have actual knowledge that we sell or share the personal information of any individual under 16 years of age.

16.7 Sensitive Personal Information

We limit our use of sensitive personal information (such as precise geolocation, health information, or financial account numbers) to purposes necessary to provide services you request, as required to meet our obligations to our clients under client contract, or as otherwise permitted by law. You have the right to limit our use of sensitive personal information by submitting a request through the contact methods in Section 17 below.

Back to Top

17. Contact Details

If you have questions about this Privacy Notice, wish to exercise your privacy rights, or have concerns about our privacy practices, please contact us:

By Email:

[email protected]

By Mail:

Core Human Factors, Inc.

1 Belmont Avenue, Suite 704

Bala Cynwyd, Pennsylvania, 19004

USA

Privacy Officer / Data Protection Officer:

Attn: Privacy Officer

Email: [email protected]

For EU Residents (Representative):

Attn: Director

Rimkus Consulting UK Limited โ€“ Irish Branch (company registration number 910394) 

of Ground Floor, Lower Baggot Street, Dublin 2, D02P593, Ireland

Email: [email protected]

We will respond to your inquiry within 30 days of receipt. If your request is complex or requires additional information, we may need additional time to respond.

Back to Top

18. Policy Updates

We reserve the right to update this Privacy Notice at any time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes to this notice, we will notify you by:

  • Posting the updated notice on our website with a new effective date
  • Incorporating notice on general email communications
  • Requiring your consent (if required by applicable law)

Your continued use of our services following the posting of updates constitutes your acceptance of the updated Privacy Notice. We recommend reviewing this notice periodically to stay informed about how we protect your privacy.

We review and update this Privacy Notice at least once every 12 months to ensure it accurately reflects our current data practices and complies with applicable law, as required by the California Consumer Privacy Act (CCPA/CPRA) and consistent with best practice under GDPR and other applicable frameworks.

Back to Top

19. Additional Jurisdictional Information

19.1 CCPA/CPRA Rights (California Residents)

If you are a California resident, you have the following rights:

Right to Know: You have the right to request what personal information we have collected about you, including:

  • Categories of personal information collected
  • Sources of that information
  • Our business purposes for collection
  • Categories of third parties with whom we share information

Right to Delete: You have the right to request deletion of personal information we have collected from you, subject to certain exceptions (such as when information is necessary to complete a transaction or comply with law).

Right to Correct: You have the right to request correction of inaccurate personal information we maintain about you.

Right to Opt-Out of Sale or Sharing: You have the right to direct us not to sell or share your personal information with third parties for cross-context behavioral advertising. We do not currently sell personal information, but if we do in the future, you may opt out by clicking the “Do Not Sell or Share My Personal Information” link on our website: [INSERT LINK].

Right to Limit Use of Sensitive Personal Information: You have the right to limit our use of sensitive personal information (such as Social Security numbers, precise geolocation, or health information) to purposes necessary to provide services you request or as otherwise permitted by law.

Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights, including by denying services, charging different prices, or providing different quality of service.

How to Exercise Your Rights:

To exercise any of these rights, please submit a request through one of the following methods:

  • Email: [email protected]
  • Mail: Core Human Factors, Inc., 1 Belmont Ave., Suite 704, Bala Cynwyd, Pennsylvania 19004, USA.

Verification: We will verify your identity before processing your request. You may be asked to provide information such as your name, email address, and account details. If you cannot provide sufficient information to verify your identity, we may deny your request.

Authorized Agents: You may designate an authorized agent to submit requests on your behalf. The authorized agent must provide proof of authorization (such as a power of attorney) and may be required to verify their own identity.

Response Timeline: We will respond to your request within 45 days (or up to 90 days if the request is complex). We will provide information in a readily usable format.

19.2 GDPR Rights (EU Residents)

If you are located in the European Union, you have the following rights under GDPR:

Right of Access: You have the right to obtain confirmation of whether we are processing your personal information and to receive a copy of that information in a structured, commonly used, machine-readable format.

Right to Rectification: You have the right to correct inaccurate or incomplete personal information.

Right to Erasure (“Right to Be Forgotten”): You have the right to request deletion of your personal information in certain circumstances, such as when the information is no longer necessary for the purposes for which it was collected, or when you withdraw consent.

Right to Restrict Processing: You have the right to request that we restrict processing of your personal information in certain circumstances, such as when you contest the accuracy of the information or when processing is unlawful.

Right to Data Portability: You have the right to receive your personal information in a structured, commonly used, machine-readable format and to transmit that information to another controller.

Right to Object: You have the right to object to processing based on legitimate interests or for direct marketing purposes. If you object, we must stop processing unless we have a compelling legal basis to continue.

Rights Related to Automated Decision-Making: You have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal or similarly significant effects, unless you have consented or the decision is necessary for a contract. We do not make final decisions affecting you based solely on automated processing; a human reviews all significant decisions.

Right to Withdraw Consent: If we rely on your consent to process personal information, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.

How to Exercise Your Rights:

To exercise any of these rights, please contact us using the details in Section 17 below. We will respond within 30 days (or up to 90 days if the request is complex).

Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority:

  • EU: Contact your national data protection authority (e.g., CNIL in France, BfDI in Germany).
  • UK: Contact the Information Commissioner’s Office (ICO) at www.ico.org.uk or [email protected].

19.3 UK GDPR Rights (UK Residents)

If you are located in the United Kingdom, you have similar rights to those described above under GDPR, including the right to access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.

Right to Lodge a Complaint: You have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

19.4 PIPEDA Rights (Canadian Residents)

If you are a resident of Canada, you have the following rights under PIPEDA:

Right of Access: You have the right to request access to personal information we hold about you.

Right to Correction: You have the right to request correction of inaccurate or incomplete personal information.

Right to Withdraw Consent: You have the right to withdraw consent for the collection, use, or disclosure of personal information. However, withdrawal may prevent us from providing certain services to you.

Right to Complain: You have the right to file a complaint with the Office of the Privacy Commissioner of Canada if you believe we have violated your privacy rights.

How to Exercise Your Rights:

To exercise any of these rights, please contact our Privacy Officer using the details in Section 17 below. We will respond within 30 days (or up to 60 days if the request is complex).

Contact the Privacy Commissioner of Canada:

  • Website: www.priv.gc.ca
  • Phone: 1-800-282-1376
  • Mail: Office of the Privacy Commissioner of Canada, 30 Victoria Street, Gatineau, QC K1A 1H2

19.5 US State Privacy Rights (Virginia, Colorado, Connecticut, Texas, and Other States)

If you are a resident of Virginia, Colorado, Connecticut, Texas, or other U.S. states with privacy laws, you may have rights similar to those described above, including:

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to correct inaccurate information
  • Right to opt out of sale or sharing of personal information
  • Right to opt out of targeted advertising
  • Right to data portability
  • Right to non-discrimination for exercising your rights

How to Exercise Your Rights:

To exercise any of these rights, please contact us using the details in Section 17 below. We will respond within the timeframe required by your state’s law (typically 30โ€“45 days).

19.6 General Instructions for Exercising Rights

To submit a privacy request:

  1. Identify the Right: Clearly state which right you are exercising (e.g., “I request access to my personal information”).
  2. Provide Information: Include information to help us identify you, such as your name, email address, phone number, or account details.
  3. Specify Your Request: Provide specific details about the information you are requesting or the action you want us to take.
  4. Verify Your Identity: Be prepared to verify your identity through a process we will describe.

We will not charge a fee for most requests, but we may charge a reasonable fee if your request is manifestly unfounded or excessive. We will inform you of any fee before processing your request.

Last Updated: July 22, 2026

Back to top

Call on Core
We are here for you when you need us.
We are always happy to help.