PrivacyPolicy
Last updated: July 10, 2026
Overview & Scope
Chronos Core is a product of Ascension Consulting Team LLC dba ACT Solutions & Consulting ("ACT," "we," "us," or "our"). This Privacy Policy explains how we collect, use, share, and protect information in connection with this website (chronoscore.io) and the Chronos Core pre-launch waitlist, and it applies to visitors, waitlist signups, and anyone who contacts us through this site.
This policy is effective as of July 10, 2026. It is a complete, good-faith description of our current data practices, prepared for Chronos Core's pre-launch website. As the product moves toward general availability with logged-in customer accounts, we recommend — and intend to complete — a final legal review of this policy, and to publish an expanded, product-specific privacy policy covering in-product data before general availability.
Information We Collect
Personal data. When you join the waitlist, contact us, or request access to Chronos Core, we may collect your name, work email address, phone number, company name, job title or role, and the product family you're interested in.
Usage data. We automatically collect information about how you interact with this website, including pages visited, time spent, browser type, device information, and IP address.
Cookies. We use cookies and similar technologies to maintain your session and understand how the site is used. Session cookies are strictly necessary for site functionality; any additional analytics cookies are covered in "Cookies & Tracking" below.
Customer Data (once generally available). Chronos Core is a platform on which business customers will store their own operational data — records, documents, and other business information they upload or create in the product. For that data, we act as a data processor (or "service provider" under the CCPA/CPRA) on the customer's behalf, not as the controller — the customer decides what data to put in and who can see it, and we process it to provide the service. This website and its waitlist/contact functions, by contrast, are ones where we act as the controller of the information described in this policy.
Waitlist Signup Data
Chronos Core is currently in pre-launch. If you join the waitlist, we collect the fields you provide — email (required), and optionally your name, company, and role, plus which product family you're interested in — so we can reach out as access opens up and prioritize the modules you care about.
This is separate from a logged-in product account: Chronos Core does not yet have general public sign-up. Once the product itself is generally available with user accounts, a fuller privacy policy covering in-product data will be published, and this page will be updated to link to it.
How We Use Information
Service delivery. To respond to your inquiry, manage your place on the waitlist, and provide product updates relevant to the modules you expressed interest in.
Communication. To reply to inquiries, send waitlist and product updates, and provide support. You may opt out of non-essential communications at any time.
Improvement. To analyze usage patterns, diagnose technical issues, and improve the performance, security, and usability of this website.
Legal Bases for Processing
Where the GDPR or a similar law applies to our processing of your personal data, we rely on one or more of the following legal bases: Consent — for example, when you opt in to a specific communication; you may withdraw consent at any time without affecting processing that already occurred. Contract — to take steps you request before entering into an agreement with us (such as responding to an access request), and to perform an agreement as this product matures into a live service. Legitimate interests — to operate, secure, and improve this website and the waitlist/contact functions, and to communicate with prospective customers about a product they have asked to hear from us about, balanced against your rights and never overriding them. Legal obligation — where we must retain or disclose information to comply with the law.
Information Sharing
No selling. We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.
Service providers. We may share data with trusted third-party vendors who help us operate this website or process waitlist and contact submissions, under confidentiality obligations.
Legal requirements. We may disclose information when required by law, to enforce our site policies, or to protect our rights, property, or safety, or that of others.
Data Security
We use industry-standard measures to protect your information, including encryption in transit and at rest, and secure cloud infrastructure on Microsoft Azure, with access limited to authorized personnel.
Identity, access, and secrets. We use Microsoft Entra ID for identity and access management, an API gateway (Azure API Management) that mediates and rate-limits access to backend services rather than exposing them directly, and Azure Key Vault together with managed identities so application code authenticates to Azure services without handling raw credentials. Access follows a least-privilege model.
Tenant and account isolation. Chronos Core's platform layer — accounts, authentication, and access control — is protected by database-enforced row-level security, tested to fail closed (no tenant context returns zero rows; the wrong tenant's context also returns zero rows). Individual product modules layer application-level account scoping on top of this platform foundation, and we are extending database-enforced isolation module by module over time. We will always describe our isolation model accurately here rather than imply a stronger guarantee than what is built.
We do not claim SOC 2, ISO 27001, HIPAA, or FedRAMP certification at this time. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Data Retention
We retain personal data only as long as reasonably necessary for the purposes described in this policy. As our current, general retention posture — not a fixed guarantee, and subject to change as the product matures — waitlist and contact submissions are retained for up to 24 months from your last interaction with us, or until you ask us to delete your data, whichever comes first; website usage and log data is retained for up to 13 months for security and diagnostic purposes.
If you ask us to delete your data sooner, we will do so unless we are required or permitted by law to retain it longer (for example, to resolve a dispute or enforce our agreements).
Once Chronos Core reaches general availability with logged-in customer accounts, in-product Customer Data will be governed by a retention schedule tied to your subscription and contract, described in an updated version of this policy.
Subprocessors & Third-Party Services
This site and its backend services run on Microsoft Azure, including Azure Static Web Apps (site hosting), Azure API Management (the API gateway that mediates waitlist and contact requests), Azure Database for PostgreSQL (data storage), and Microsoft Entra ID (identity and access management) — collectively, our primary infrastructure subprocessor.
We may engage additional third-party service providers necessary to operate the waitlist and contact functions described above (for example, email delivery). Any such provider is bound by confidentiality and data-protection obligations consistent with this policy.
We maintain a current list of subprocessors and will update this section, or provide the list on request (see "Contact Us" below), as we formally engage additional processors ahead of general product availability.
International Data Transfers
This site and its backend infrastructure are hosted in United States Azure regions (Microsoft Azure East US 2). If you access this site from outside the United States, your information will be transferred to, stored, and processed in the United States, a jurisdiction whose data protection laws may differ from those of your home jurisdiction.
Where international transfer safeguards are required by law — for example under the GDPR — we rely on Microsoft's Standard Contractual Clauses and other transfer safeguards made available under its Online Services Terms and Data Protection Addendum for the underlying Azure infrastructure. Contact us using the details below for more information about the safeguards in place for a specific transfer.
Breach Notification
If we become aware of a security incident involving unauthorized access to your personal data, we will investigate promptly and, where legally required, notify affected individuals and/or the applicable regulator without undue delay and, in any case, within the timeframe required by applicable law (for example, the GDPR's 72-hour supervisory-authority notification standard, where it applies). Notification will describe, to the extent then known, the nature of the incident, the data involved, and the steps we are taking in response.
Children's Privacy
This website and the Chronos Core waitlist are intended for business professionals and are not directed at children. We do not knowingly collect personal data from anyone under 16 years of age. If we learn that we have inadvertently collected personal data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal data, please contact us using the details below.
Your Privacy Rights
Depending on where you live, you may have some or all of the following rights regarding your personal data: access (a copy of the personal data we hold about you); correction (of inaccurate or incomplete data); deletion (subject to legal retention requirements); portability (a copy of your data in a structured, commonly used, machine-readable format); objection and restriction (to certain processing, including processing based on legitimate interests); withdrawing consent at any time, where processing is based on consent; and, if you are in the EEA, UK, or Switzerland, lodging a complaint with your local data protection supervisory authority.
California residents (CCPA/CPRA) additionally have the right to know what personal information we collect, use, and disclose about you, to request deletion or correction of it, and to non-discrimination for exercising these rights. We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising as defined under the CPRA — there is currently no opt-out to exercise for either.
To exercise any of these rights, or to opt out of non-essential communications, contact us using the details in "Contact Us" below, or use the unsubscribe link in our emails. We will respond within the timeframe required by applicable law.
Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated "last updated" date. For material changes, we will provide additional notice where appropriate.
Contact Us
Chronos Core is a product of Ascension Consulting Team LLC dba ACT Solutions & Consulting, Houston, Texas, USA. If you have questions about this privacy policy or our data practices, or wish to exercise any of the rights described above, please reach us at contact@chronoscore.io or through the contact form on our About page: /about#contact.