Privacy at A8 Core
How the commitments in our Privacy Policy work in practice inside a customer deployment. The binding notice is the Privacy Policy itself.
Last updated 23 July 2026 · Trust Center
The binding notice is our Privacy Policy. This page explains how those commitments work inside a deployment, for a reviewer who needs more than the notice provides. Where the two differ, the Privacy Policy governs.
1. Which document binds
Three documents, three jobs. The Privacy Policy is the binding notice for our own processing. The Data Processing Agreement governs processing we perform on a customer’s behalf. This page is explanatory and creates no rights.
2. Controller and processor
For data in a customer tenant we are a processor and the customer is the controller; where the customer is itself a processor, we are a subprocessor. For our own account administration, billing, security and aggregated telemetry we are a controller. Confusing the two is the most common source of a wrong answer in a vendor questionnaire, so it is worth stating twice.
3. Customer deployments
We do not determine why personal data in a tenant is processed, we do not sell personal data, and we do not use tenant data to train models that serve other customers. Support access to a tenant is authorized per data element with a stated purpose and is recorded like any other access — a support engineer opening a record is a caller, evaluated as one.
4. What we hold
The categories depend on the deployment, which is why they are issued as Exhibit A to the DPA rather than asserted here — a retirement custodian, a private-fund administrator and a digital-asset trustee do not process the same data. For our own controller-side processing the categories are in the Privacy Policy.
5. Rights requests in practice
The platform provides functions to access, correct, export and delete records so a controller can answer a request itself. If a request reaches us directly we do not respond to its substance: we refer the individual to the controller and tell the controller promptly. Where a controller cannot fulfil a request with platform functions, we assist on reasonable request.
6. Retention
Retention is configured per deployment, and deletion runs against that configuration. Backups are deleted on their ordinary expiry cycle rather than immediately, and we will tell you what that cycle is for your deployment.
An honest limitation. Records held in a system whose retention we do not control — a document-execution provider a customer has chosen, or an early evaluation record captured before provisioning — are deleted according to that system’s capabilities. Where a promise cannot be performed in full we name the limiting system instead of making the promise.
7. Children
Our websites and the platform are directed to financial institutions and their professional users, not to children, and we do not knowingly collect personal data from a child. Some account types — a custodial or minor beneficiary account — legitimately contain a minor’s data supplied by an adult account holder or plan sponsor. That data is processed for the controller under the DPA, is not used for marketing, and is subject to the same data-element authorization as any other record. If you believe a child’s data has reached us other than through that route, write to privacy@a8core.com and we will delete it.
8. Changes
Material changes to the binding notice are dated on the Privacy Policy. Changes to subprocessors follow the notice mechanism in clause 6 of the DPA — notices go to a named address you give us, so a change reaches your vendor-risk owner rather than waiting to be noticed on a web page.
Financial Infrastructure, Inc. is a technology provider and is not a bank, trust company, broker-dealer or investment adviser. Nothing on this page is legal, regulatory, tax or investment advice. Institutional Trust Company is a proposed trust entity seeking a South Dakota non-depository trust charter; it is not yet chartered and is not accepting accounts.
Questions about this document? Contact security@a8core.com or write to Financial Infrastructure, Inc., PO Box 1410, Menlo Park, California 94026-1410.