PHYSICORE

Legal

Privacy Policy

Last updated: 25 June 2026

Key points

1. Controller and contact

The controller of personal data described in this policy is Physicore Limited, a company incorporated in England and Wales, with its registered office at 1 Kingdom Street, London W2 6BD, United Kingdom ('Physicore', 'we', 'us', 'our'). Physicore also operates from 200 Page Mill Road, Palo Alto, CA 94306, United States.

For privacy queries, requests to exercise rights, or to contact our data protection point of contact, write to partnerships@physicore.ai or to the registered office marked for the attention of the Data Protection Lead. Where we appoint a UK or EU representative, their contact details will be published here.

2. Scope

This policy applies to personal data we process in connection with:

This policy does not apply to processing carried out by our customers under their own licences, by our partners under their own controllership, or by third party services that you access independently of the Site.

3. Categories of personal data

The categories of personal data we process depend on how you interact with us.

4. Lawful bases

Under the UK GDPR and the EU GDPR, we rely on the following lawful bases:

5. Special category and biometric data

Real-world capture at Partner Sites may incidentally include identifiable footage of individuals, and in some configurations may include data capable of uniquely identifying a person (for example, full-face video or voice recordings). We treat this category of data with heightened controls:

6. Purposes of processing

7. Sharing and recipients

We share personal data only where necessary and under appropriate safeguards. Recipients fall into the following categories:

We do not sell personal data and do not share personal data for cross-context behavioural advertising.

8. International transfers

Physicore operates internationally. Personal data may be transferred to, stored in, or accessed from the United Kingdom, the United States, member states of the European Economic Area, and other jurisdictions where our processors or customers operate.

Where personal data is transferred outside the United Kingdom or the European Economic Area to a country not subject to an adequacy decision, we rely on one or more of the following mechanisms:

We carry out a transfer risk assessment for each transfer mechanism and apply supplementary measures (including encryption in transit and at rest, pseudonymisation and access controls) where the assessment requires them. A copy of the relevant safeguards is available on request to partnerships@physicore.ai.

9. Retention

We retain personal data only for as long as necessary for the purposes set out in this policy. Indicative retention periods are:

Where we are required to retain data for longer to comply with legal or regulatory obligations, we will do so for the minimum period required.

10. Security

We maintain a written information security programme aligned with recognised standards. Controls include role-based access, principle of least privilege, multi-factor authentication for administrative access, encryption of data in transit (TLS 1.2 or higher) and at rest, segregated environments for raw capture data and licensed datasets, secure software development practices, vendor risk management, vulnerability scanning, logging and monitoring, and a documented incident response plan including breach notification timelines that meet Article 33 and Article 34 UK GDPR.

11. Your rights (UK and EU)

Subject to applicable law, you have the right to:

To exercise any of these rights, contact partnerships@physicore.ai. We may need to verify your identity before responding. We will respond within one month, extendable by up to a further two months for complex requests, in accordance with Article 12 UK GDPR.

12. US state privacy rights

If you are a resident of California, Virginia, Colorado, Connecticut, Utah or any other US state granting equivalent rights, you may have the right to know what personal information we process about you, to request deletion or correction, to opt out of the sale or sharing of personal information, and to limit the use and disclosure of sensitive personal information.

Do Not Sell or Share My Personal Information. Physicore does not sell personal information and does not share personal information for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act as amended by the California Privacy Rights Act.

To exercise a US state privacy right, contact partnerships@physicore.ai. We will not discriminate against you for exercising any right. You may authorise an agent to act on your behalf; we will require proof of authorisation.

13. Children

The Site and our services are directed at business users. We do not knowingly process personal data of children under the age of 16. If you believe that a child's personal data has been processed in connection with our activities, contact partnerships@physicore.ai and we will take prompt steps to investigate and, where appropriate, delete the data.

14. Complaints

If you have a concern about how we process your personal data, please contact partnerships@physicore.ai so we can address it. You also have the right to lodge a complaint with a supervisory authority:

15. Changes to this policy

We may update this policy from time to time. The 'Last updated' date at the top of this page indicates when the most recent changes took effect. Where the changes are material, we will take reasonable steps to notify you, for example by a notice on the Site or by email where we hold your contact details.