Skip to Content

Data Privacy & Security

Our approach is guided by the principle of Security and Privacy by Design

At a glance


At Korefocus, data privacy and security are not optional — they are built into every layer of our technology and operations. We are committed to safeguarding your information and ensuring the reliable performance of our solutions.

  • Privacy by Design: Clients retain full ownership and control of their data.
  • No model training on client data: Your data is never used to train or improve AI models.
  • Dedicated tenant per client: Each environment operates in complete isolation for maximum confidentiality.
  • Flexible deployment: Cloud-hosted or on-premise, depending on your security and governance requirements.
  • Microsoft Azure foundation: Hosted in EU datacenters with Microsoft Entra ID for SSO and MFA.
  • Strict access management: Role-based controls, auditable connection logs, and enforced MFA protect every access point.
  • Client-in-the-Loop authentication: Access sessions can be validated or terminated directly by the client, ensuring continuous visibility and control over data interactions.
  • Data purge on demand: Clients can permanently delete all data and logs from Korefocus environments at any time, ensuring full control and GDPR-compliant data lifecycle management.
  • Layered safeguards: Physical, administrative, and technical measures prevent unauthorized access and preserve system integrity.
  • GDPR alignment: Supported by a comprehensive Data Processing Agreement and clearly defined controller/processor roles.

Data Usage and Privacy


  • Client-exclusive data use: all client data processed through Korefocus solutions remain the sole property of the client.
  • No model training on client data: Korefocus and third-party models does not use, share, or repurpose client data for training or improving its own or third-party models. 
  • Strict data isolation with dedicated tenant: Each client environment operates in a dedicated and secure context, ensuring full separation from other deployments.
  • Data purge on demand: Clients can permanently delete all data and logs from Korefocus environments at any time, ensuring full control and GDPR-compliant data lifecycle management.
  • Confidentiality commitment: All data handling strictly complies with contractual agreements, GDPR requirements, and the highest confidentiality standards.

Data Security


Korefocus ensures the highest standards of data protection and confidentiality throughout its infrastructure.

  • Encryption: All client data is encrypted in transit using TLS and at rest using AES-256, ensuring comprehensive protection across all Korefocus environments.
  • Hosting environment: Data is hosted exclusively on Microsoft Azure servers located within the European Union (Western Europe region), ensuring compliance with EU data residency requirements.
  • Physical and operational security: Azure data centers operate under strict access control, continuous monitoring, and 24/7 on-site supervision.
  • Compliance: Azure infrastructure supporting Korefocus services is independently audited and certified for major international standards, including SOC 2 Type 2, ISO/IEC 27001, and HITRUST CSF.
  • Confidentiality commitment: All measures are designed to ensure that client information remains fully protected, private, and under the client’s sole control.

Hosting and Authentication


  • The Korefocus solution is fully hosted on Microsoft Azure, benefiting from Azure’s global-grade reliability and compliance.
  • All client data is exclusively stored on Microsoft Azure Cloudno local storage is used in Korefocus-managed cloud deployments.
  • Authentication relies on Microsoft Entra ID (formerly Azure Active Directory), with Single Sign-On (SSO) for Microsoft 365, Multi-factor authentication (MFA) available on demand (enforced for privileged access).
  • Each Korefocus team member benefits from a single, named user account protected by a secure password with Multi-factor authentication (MFA).

Infrastructure and Access Control


  • Access to services is strictly controlled and limited to authorized personnel only — the list of authorized users is defined in agreement with the client.
  • Multi-factor authentication (MFA) is implemented throughout the infrastructure to minimize intrusion risks.
  • Can be implemented upon request (free of charge):
    • Client-in-the-Loop Authentication process for session-based access, further enhancing control and transparency
    • Comprehensive connection log can also be implemented on client's demand, allowing consultation by the client at any time, providing detailed information on all data access, consultations, and modifications.

Deployment options

  • Flexible architecture: Korefocus solutions can be deployed either in the cloud or on-premise, depending on client preferences and IT infrastructure.
  • Confidentiality by design: On-premise deployment is available for clients who require maximum data protection and confidentiality, ensuring all AI workflows and data remain within their own secure environment.
  • Regulatory compliance: Deployment mode can be aligned with internal governance policies, data residency requirements, and industry-specific compliance standards.
  • Full control: Clients maintain complete ownership of their data, configurations, and access rights, while still benefiting from the full power of Korefocus AI solutions.

Data Governance: Roles & Responsibilities


Clients remain the owners and controllers of their dataKorefocus acts solely as the data processor.


1. Definitions (European Commission):

  • The Data Controller determines the purposes and means of personal data processing — deciding why and how the data is used.
  • The Data Processor handles personal data only on behalf of the controller and under their instructions.

Source: European Commission – What is a data controller or data processor?


2. Accountability and compliance

  • Korefocus is not responsible for the legal compliance of client-hosted data.
  • Instruction-bound processing, Korefocus processes and stores data solely on the documented instructions of the client and for defined purposes, with no secondary use or sale. 
  • Korefocus is acting exclusively as a data processor. Where helpful, Korefocus can provide AI-powered discovery to help clients map and identify potential personal data within their environments.


  • The client remains solely responsible for evaluating and ensuring the compliance of all data processed within the Korefocus environment.


3. Incident Notification

  • Notify without undue delay (≤24h) after becoming aware of a personal data breach.
  • Include nature/scope, likely consequences, measures taken, and a contact point.
  • Provide updates, cooperate on GDPR Articles 33/34, and log notifications.
  • Notices sent by email to designated contacts.