Effective 14 August 2026
Privacy Policy
This Privacy Policy explains how Guildcores Pte. Ltd. handles personal data through the Guildcores website, the Guildcores project management and relationship platform, connected services, and related support.
Guildcores Pte. Ltd. is incorporated in Singapore and has its registered office at 68 Circular Road, #02-01, Singapore 049422. Privacy questions and requests can be sent to info@guildcores.com.
1. Our roles
Guildcores has different data protection roles depending on why data is processed.
- We act as a controller when we decide why and how to use account, security, support, website, billing, and business contact data.
- When an organisation uses Guildcores to manage its own projects, contacts, meetings, and documents, that organisation normally controls the customer content and Guildcores processes it on the organisation's instructions. Our Data Processing Addendum applies where it is incorporated into the customer agreement.
- Our own internal Guildcores workspace is controlled by Guildcores.
If your data was entered by a Guildcores customer, including as a contact, meeting participant, talent, brand representative, or counterparty, please contact that customer first. We will assist the customer with a valid request.
2. Personal data we handle
Account and profile data
We may handle a user's name, work email address, Google account identifier, profile image URL, uploaded avatar, job title, department, location, timezone, biography, phone number, professional links, language, role, and permission settings.
Users of the Guildcores instance sign in with Google. We receive the account information and authentication result needed to create and secure the session. The Guildcores instance does not offer public email signup or public password login.
Customer content
The service can hold information placed into projects, tasks, notes, updates, documents, notebooks, meetings, transcripts, contracts, invoices, reminders, interactions, and AI conversations. It can also hold uploaded files, images, voice recordings, voice transcripts, and source excerpts.
The relationship platform can hold names, work and personal contact details, organisations, professional profiles, relationship notes, relationship strength, work history, skills, introductions, and interaction history. Some of this information concerns people who do not have a Guildcores account.
Free text and uploaded material may contain sensitive information chosen by a customer or user. Customers should not submit sensitive data unless it is necessary, lawful, and covered by appropriate safeguards.
Connected services
An authorised administrator can connect services such as Google Drive and Google Calendar. We then receive the files, calendar details, account email, scopes, and service credentials needed to provide the requested connection. The service may also send selected project and task details to ClickUp when that connection is configured.
Optional Telegram features process the messages and identifiers needed for the configured team channel. They do not operate unless the relevant credentials are enabled.
Service, security, and support data
We process session and sign-in times, sign-in IP addresses, user agent information, request logs, feature permissions, activity records, AI approval records, errors, feedback, and support communications. The website contact form collects the sender's email address, message, and ordinary request metadata.
3. Where data comes from
We receive personal data:
- directly from users and website visitors;
- from the organisation that provides a user's account;
- from customer staff who enter or upload information about other people;
- from connected Google, ClickUp, and Telegram services when enabled;
- from documents, meeting notes, recordings, and messages processed at a customer's direction;
- from public professional sources when a user records that information in the service.
When we obtain personal data indirectly, the customer that supplied it remains responsible for giving any notice required for its own processing.
4. Why we use personal data
We process personal data to:
- provide, secure, maintain, and support the service;
- authenticate users and enforce permissions;
- organise projects, tasks, relationships, meetings, and documents;
- search, summarise, transcribe, classify, and extract requested information;
- generate proposals, drafts, reminders, and briefings;
- connect services selected by an administrator;
- detect abuse, investigate incidents, preserve evidence, and maintain audit records;
- respond to enquiries, rights requests, and contractual obligations;
- improve reliability using operational information that is reasonably necessary for the service;
- comply with law and protect legal rights.
Where applicable, our legal bases include performance of a contract, steps requested before entering a contract, legitimate interests in operating and protecting a business service, compliance with legal obligations, and consent where consent is required. A customer determines the legal basis for customer content it controls.
We do not sell personal data. We do not use customer content for targeted advertising.
5. AI processing
Guildcores uses the OpenAI API to provide chat, search assistance, document and image analysis, audio transcription, meeting detection, relationship suggestions, memory extraction, briefings, and drafting features. Depending on the feature, OpenAI may receive prompts, names, roles, document text, meeting content, contract text, images, audio, and relevant workspace context.
OpenAI states that, by default, it does not use API inputs or outputs to train or improve its models. OpenAI may retain API data according to the service and account configuration. We do not claim zero data retention unless it is separately confirmed for the relevant account and feature. See OpenAI's business data commitments and data processing terms.
AI output can be incomplete or wrong. Features that propose tasks or relationship facts present them for human approval before the proposed change is applied. The service records the proposal and the human decision. Customers must provide meaningful human review before using output for a decision that could materially affect a person. Guildcores must not be used to make employment, credit, housing, insurance, legal, medical, or similarly significant decisions solely by automated means.
6. Sharing and recipients
We disclose personal data only as needed to operate the service, follow a customer's instructions, comply with law, or protect rights. Recipients can include:
- hosting and infrastructure providers;
- OpenAI for enabled AI features;
- Google for sign-in, connected Drive and Calendar features, and configured email delivery;
- ClickUp and Telegram when a customer or administrator enables the relevant connection;
- professional advisers, auditors, and authorities where legally required;
- a successor in a lawful corporate transaction, subject to appropriate confidentiality.
Our current providers and their roles are listed on the Subprocessors page. We do not allow providers to use customer content for their own advertising.
7. International transfers
Guildcores is based in Singapore. The production application is hosted in Tokyo, Japan. Providers may process data in Japan, Singapore, the United States, and other countries identified in their service terms and subprocessor lists.
Where transfer rules apply, the customer agreement or transfer schedule must identify the data processing terms and transfer safeguard actually in force. European transfers may require the European Commission's Standard Contractual Clauses. United Kingdom transfers may require the UK International Data Transfer Addendum or International Data Transfer Agreement. Publishing or linking a standard document does not mean it has been executed for a particular account. A customer can contact us for the transfer mechanism relevant to its service.
8. Security
We use Google sign-in, role and feature permissions, restricted document visibility, encrypted network transport, activity records, AI decision records, backups, code review, automated tests, dependency review, and security scanning.
Most customer content is not yet encrypted by Guildcores at the individual database field level. Database rows and backups must therefore not be described as separately encrypted by the application. Access is restricted through infrastructure and application controls. This limitation and other current controls are described on the Security page.
No internet service is completely secure. Customers remain responsible for account administration, lawful content, connected service settings, and the devices used to access Guildcores.
9. Retention and deletion
We retain personal data only for as long as it is needed for the service, the customer relationship, security, dispute handling, or a legal obligation.
- Customer workspace data is kept during the service term. Following termination, the active workspace is scheduled for deletion within 30 days unless law or a written agreement requires longer retention.
- Server backup copies are retained for 14 days. Designated operational backup copies on an administrator-controlled device are retained for up to 30 days and then age out.
- Sign-in, access, change, and AI action records are retained for up to 400 days to support annual reviews, incident investigation, and accountability.
- Generated data export archives expire after 24 hours and can be downloaded once. Expired and collected archives are purged by a recurring job.
- Provider copies follow the provider's applicable retention terms and the account configuration.
Some deletion steps are operational rather than fully automated. We verify completion and restrict data from ordinary use while a deletion request is being processed. We may retain a limited record where required to establish, exercise, or defend legal claims.
10. Rights and requests
Depending on the law that applies, an individual may ask to:
- access personal data and information about recent use or disclosure;
- correct inaccurate or incomplete data;
- delete data;
- restrict or object to processing;
- withdraw consent where processing relies on consent;
- receive available data in a commonly used format;
- complain to a data protection authority.
Send a request to info@guildcores.com. Please identify the organisation or workspace involved and provide enough information for us to locate the record. We may verify identity and authority before responding. We aim to respond within 30 days, subject to lawful extensions, exceptions, and the rights of other people.
If a customer controls the data, we will refer the request to that customer or act on its documented instruction. A service administrator can prepare a structured export for an authorised request. Material protected by another person's rights, confidentiality, or a legal exception may be withheld or redacted.
11. Children
Guildcores is a business service and is not directed to children. Customers must not knowingly submit children's personal data unless the processing is lawful, necessary, and expressly agreed with Guildcores.
12. Changes
We may update this policy when the service, providers, or law changes. We will publish the new effective date here. We will give business customers at least 30 days' notice before a material change that reduces their data protection rights, unless an urgent legal or security reason requires faster action.
13. Contact
Guildcores Pte. Ltd. 68 Circular Road, #02-01 Singapore 049422 info@guildcores.com
This address is the public contact for privacy questions, rights requests, complaints, and communications to the Guildcores data protection function.