Privacy
Privacy Notice
Last updated 25 August 2026. CoreFeld LLC, 425 Broadway Ave S #331, Rochester, Minnesota 55904, United States.
This notice covers three different things, and they are worth keeping separate because they carry different risks: the data this website collects, the data CoreFeld holds about the people it works with, and the data inside the systems CoreFeld builds and operates for clients.
The short version. This site sets no cookies and runs no analytics or advertising. CoreFeld does not sell, rent, or share personal data, and does not use client data to train machine-learning models. Where CoreFeld builds a system for a client, that system is normally deployed in the client's own cloud account, so the client's data never leaves their control.
1. This website
corefeld.com is a static site served from Cloudflare Pages. It sets no cookies, runs no analytics, and embeds no third-party trackers, advertising pixels, session recorders, or social widgets. The contact form loads Cloudflare Turnstile solely to prevent automated abuse. There is nothing here to opt out of.
Cloudflare, as the hosting and network provider, processes standard request data (IP address, user agent, requested URL, timestamp) to serve pages and to protect the site from abuse. That is a technical necessity of serving any website and is governed by Cloudflare's own privacy terms.
The contact form
If you use the contact form, CoreFeld receives what you type — typically your name, email address, organization, and message — together with the submission IP address, country, and browser user agent. Cloudflare Turnstile processes the request to block automated abuse. CoreFeld uses the submitted information to reply to you and the technical fields to protect and diagnose the form. It is not added to a marketing list, not sold, and not shared. Accepted enquiries are retained as ordinary business correspondence; rejected submissions are quarantined without email notification and deleted automatically after 30 days.
2. People CoreFeld works with
CoreFeld holds ordinary business-contact information for clients, prospective clients, references, and partners: name, employer, role, email, telephone, and the record of correspondence and work performed. This is held to deliver work, to answer questions about work already delivered, and to meet legal, tax, and contractual obligations.
CoreFeld does not build advertising profiles, does not enrich contact records from data brokers, and does not sell or rent contact information to anyone, ever.
3. Data inside systems CoreFeld builds or operates
This is the section a security reviewer is looking for.
CoreFeld's default deployment model is in the client's own environment, with source code delivered. Under that model, the client's data — including any personal data of the client's own users, students, members, or customers — resides in infrastructure the client owns and controls, encrypted with the client's own keys. CoreFeld operates no data centre and hosts no client data of its own.
What that means in practice
- CoreFeld acts as a processor (or, in an education context, as a school official under the client's direct control), never as an independent controller of the client's data.
- Client data is used only to provide the agreed service. It is never sold, shared, mined for insight, monetised, or used to train machine-learning models — CoreFeld's or anyone else's.
- Where a product includes AI features, those features run inside the client's environment on the client's compute wherever the design allows it, so no third-party model vendor receives client data.
- CoreFeld staff access client data only when performing support, under access the client grants and can revoke, and that access is recorded in an audit trail the client owns and CoreFeld cannot alter.
- All work is performed in the United States. There are no offshore staff, offshore subcontractors, or offshore support.
- No sub-processor receives client data without the client's prior written approval.
Payment card data
Where CoreFeld builds a system that takes payments, it is designed so that cardholder data never enters the software: payment pages are hosted by the client's own payment gateway, and in-person payments use point-to-point encrypted terminals settling to the client's own merchant account. CoreFeld's systems hold a gateway token and a transaction result, never a card number.
Health, student, and other regulated data
Where a client's data is subject to FERPA, HIPAA, GLBA, or similar regimes, CoreFeld executes the client's data-protection agreement and handles the data under it. CoreFeld does not process protected health information except under a signed business associate agreement.
4. Retention
Website enquiries and business correspondence are kept as long as the business relationship or a legal obligation requires, and deleted on request where no obligation prevents it. Data inside a client system is retained according to that client's own retention policy, which the client configures and can change; CoreFeld does not keep shadow copies.
5. Security
Least-privilege access, multi-factor authentication on everything administrative, no standing production credentials, encrypted transport and storage, dependency scanning on every change, and an append-only audit trail in the products CoreFeld builds. CoreFeld commissions independent penetration testing of delivered systems before go-live and annually thereafter, and provides the report to the client.
6. Your rights
You may ask what personal data CoreFeld holds about you, ask for it to be corrected, or ask for it to be deleted. Ask through the contact form and you will get a human answer, normally within five business days.
If the data in question sits inside a system CoreFeld operates for a client, the client is the controller and the request is theirs to decide; CoreFeld will forward it to them promptly and assist them in answering it.
7. Changes
If this notice changes materially, the date at the top changes and clients under contract are told directly rather than being expected to notice.
8. Contact
CoreFeld LLC
425 Broadway Ave S #331
Rochester, Minnesota 55904, United States
Contact · (507) 900-9300