Privacy Notice
Last updated: 1 October 2026
This notice explains how FSMCore handles personal data. FSMCore is run by Felikss Veilands, trading as FSMCore, Apartment 205, Richmond Court, Mount Kennett Place, Dock Road, Limerick, V94 K316, Ireland. Contact: support@fsmcore.com.
Two roles
- For the data companies put into FSMCore (their clients, sites, jobs, staff, subcontractors, time, documents, files), the company is the controller and we are its processor. We handle that data only on the company's instructions, under our Data Processing Agreement. If you are a client or worker of a company that uses FSMCore, please contact that company about your data; we will help them answer you.
- For our own customer relationship (who signs up, who uses the service, billing, support, security), we are the controller. The rest of this notice covers that.
What we collect and why
| Data | Why | Legal basis |
|---|---|---|
| Name, email, password (stored hashed), two-factor settings, company name and address | Create and run your account | Contract |
| Which company you belong to, your role | Give the right access; show activity to your company's admins | Contract; legitimate interest (security) |
| IP address, browser type, server and security logs, the change history (audit log) inside your company | Keep the service secure, find faults, stop abuse | Legitimate interest |
| Plan, subscription status, invoices and receipts from Paddle (we do not see your full card details) | Billing and our own tax records | Contract; legal obligation |
| Emails you send to support | Help you | Contract; legitimate interest |
| Service emails (trial reminders, deletion warnings, security notices) | Required to run the account | Contract |
We do not sell personal data, do not use advertising or tracking cookies, and do not use analytics services. We do not use customer data to train AI models.
Cookies
FSMCore uses only cookies needed for it to work: a session cookie that keeps you signed in, a security token (XSRF-TOKEN) that protects forms, and, only if you tick "Remember me" when signing in, a cookie that keeps you signed in on that device. They do not track you across sites, so no consent banner is needed. When you open the checkout, Paddle loads its own script and may set its own cookies; see Paddle's privacy notice.
Who we share data with
Only the service providers listed on our Sub-processors page, each under a written agreement, and only what they need: hosting and backups in the EU, email delivery, and payments (Paddle, who acts as an independent controller for payment data as Merchant of Record). We may disclose data if the law requires it.
If your company turns on AI features with its own AI provider key, content is sent to the provider your company chose, under your company's own agreement with that provider.
Where data is stored
The service and its database run on servers in Germany (EU). Files and backups are stored in the EU. Some providers (for example the server management tool) are based outside the EEA; where they receive personal data, the transfer is covered by Standard Contractual Clauses or an adequacy decision (such as the EU-US Data Privacy Framework or the UK adequacy decision).
How long we keep it
- Account and company data: while the company has an active trial or subscription.
- After a trial or subscription ends: the company is locked and all its data is permanently deleted 30 days later, unless the company subscribes again or deletes it sooner from the lock page.
- Backups: backups are kept to recover data after a failure or a mistake and expire on a fixed schedule, so deleted data can remain in backups for up to about 7 months before it is gone for good. They are never used to bring back a deleted company or for anything else.
- Billing records: kept for 6 years, as Irish tax law requires.
- Security logs: kept only as long as needed to investigate problems.
Security
Data is encrypted in transit (HTTPS), and uploaded files and backups are encrypted at rest. Each company's data is kept separate in the application and checked by automated tests. Two-factor sign-in is available. Daily backups are stored with a separate provider from the main server.
Your rights
You have the right to access, correct, delete, restrict or object to the use of your personal data, and to receive it in a portable format. Admins can export all company data from inside FSMCore. To use your rights, email support@fsmcore.com. We answer within one month.
You can also complain to the Data Protection Commission in Ireland (dataprotection.ie).
Changes
We will post changes here and email account admins and owners about important changes before they take effect.