Privacy policy
How personal data is handled in the CoreBit mobile app, on this website and by the CoreBit server software.
Last updated 29 September 2026
Who we are
CoreBit is made by EASE IT, Præstefælledvej 93, 2770 Kastrup, Denmark (CVR 45143317). You can reach us at ch@ease.dk.
EASE IT is the data controller for the data described on this page that reaches our own services: this website, the push notification relay, licence activation and purchases.
CoreBit itself is self-hosted. The CoreBit server your organisation runs, and the network data in it, is operated by your organisation, which is the data controller for that data. Questions about what your organisation's CoreBit server stores should go to your organisation's administrator.
In short
- The CoreBit app connects directly to your organisation's own CoreBit server. Your network data (devices, incidents, logs, metrics) is not sent to EASE IT.
- The app contains no advertising, no analytics, no crash-reporting service and no tracking, and we do not sell or share personal data for marketing.
- This website sets no cookies.
The CoreBit mobile app
Stored on your phone
The addresses of the CoreBit servers you have connected, an access key for each server, each server's certificate fingerprint and the name you gave your phone. This stays on your phone and is removed when you remove a server in the app or delete the app.
Sent to your organisation's CoreBit server
When you pair the app: the name you give the phone, its platform (iOS or Android) and a randomly generated key. After that: the requests you make in the app (for example viewing devices and incidents, acknowledging or assigning an incident, muting alarms) and, if you allow notifications, a push token. Your organisation's administrator must approve the phone before it can see anything, and can revoke it at any time.
Camera
The camera is used only to scan the pairing QR code. The image is processed on your phone and is never stored or sent anywhere.
Push notifications
If you allow notifications, the app gets a push token from Firebase Cloud Messaging (Google); on iOS, delivery goes through the Apple Push Notification service. Your organisation's CoreBit server sends the notification — its title and message, which can include device names, incident details and your organisation's site name, plus technical identifiers such as an incident or device ID and a server identifier — to our push relay (pushservice.corebit.network), which passes it to Firebase for delivery to your phone.
The relay does not store notification content or push tokens. They are handled in memory only to deliver the notification; the server identifier is used briefly to limit how many notifications a server can send. You can turn notifications off at any time in your phone's settings.
AI assistant
Questions you ask the assistant are sent to your organisation's CoreBit server. If your administrator has set up the AI assistant, the server sends the question together with relevant network data to the AI provider your administrator chose, under your organisation's agreement with that provider. Questions are not sent to EASE IT.
Deleting your data
The app has no separate user account. Remove a server in the app's Settings to delete its data from your phone. Your organisation's administrator can remove the phone and its push token from the CoreBit server.
This website (corebit.network)
The website sets no cookies and uses no advertising or third-party analytics. To count visits, we record the page visited, the referring website, the country (derived from your IP address), the type of device (desktop, mobile or tablet), whether the visitor is a bot, campaign tags in the link (utm parameters) and a visitor code that is calculated with a salt that changes every day, so a visitor cannot be recognised from one day to the next. Your IP address is not stored in these statistics.
To find the country, the website looks up your IP address with the ip-api.com service; the result is kept in the web server's memory only.
The pages load fonts from Google Fonts, so your browser connects to Google's servers, which receive your IP address. See Google's privacy policy for how Google handles this.
Like most websites, our web servers may keep standard access logs (including IP addresses) for a limited time, for security and troubleshooting.
The CoreBit server software
When a CoreBit server activates a licence or checks for updates, it contacts our licensing server with the licence key, an installation identifier derived from the machine and the CoreBit version.
Usage statistics are sent only if an administrator turns them on (they are off by default). They contain the CoreBit version, the licence type, the number of monitored devices and remote agents, the type of installation and anonymous performance averages. We also store the IP address the report came from and the country derived from it. Usage statistics never contain device names, device IP addresses, network topology or credentials.
Purchases
Payments are handled by Stripe. We never see or store card details.
For a purchase we store the name, email address, company name, address, country and VAT number you provide, the licence key and Stripe's payment reference. We use this to deliver and manage your licence, provide support and keep our accounts; purchases are recorded in our accounting system (Dinero, by Visma). Accounting records are kept for as long as Danish bookkeeping law requires (currently five years).
Legal basis
- Performing our agreement with you or your organisation: licences, purchases, updates and delivering push notifications.
- Legitimate interest: anonymous website statistics, security and preventing abuse.
- Consent: optional usage statistics and your phone's notification permission, which you can withdraw at any time.
- Legal obligation: accounting records.
Who else receives data
Stripe (payments), Google (Firebase Cloud Messaging and Google Fonts), Apple (push delivery on iOS), ip-api.com (country lookup for website statistics) and Visma Dinero (accounting). Some of these companies may process data outside the EU/EEA; where they do, the transfer relies on safeguards such as the EU Standard Contractual Clauses or the EU–US Data Privacy Framework.
Your rights
Under the GDPR you have the right to access, correct or delete your personal data, to restrict or object to its processing and to receive it in a portable format. To use these rights, email ch@ease.dk. For data held on your organisation's own CoreBit server, contact your organisation.
You can also complain to the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk).
Children
CoreBit is a tool for network professionals and is not directed at children under 16.
Changes
We may update this policy. The date at the top shows when it last changed.
Contact
EASE IT, Præstefælledvej 93, 2770 Kastrup, Denmark · CVR 45143317 · ch@ease.dk