How we handle personal data
Effective date:
Contents
- 1. Who Is Responsible for Your Data
- 2. Data We Collect and Its Sources
- 3. Purposes and Legal Bases
- 4. Customer Workspace Data
- 5. Artificial Intelligence Processing
- 6. Service Providers and Other Recipients
- 7. International Data Transfers
- 8. Retention and Deletion
- 9. Your Rights
- 10. Security Measures
- 11. Cookies and Browser Storage
- 12. Children and Student Data
- 13. Changes to This Policy
- 14. Blog Newsletter
- 15. Contact and Complaints
1. Who Is Responsible for Your Data
This Privacy Policy explains how Kodex Compliance UG (haftungsbeschränkt) processes personal data through the public website, customer accounts, the Kodex Compliance platform, support, and related services. It is intended to provide the information required by Articles 13 and 14 of the General Data Protection Regulation.
When Kodex Compliance is the controller
Kodex Compliance is the controller for personal data used to run its own business. This includes website enquiries, account administration, authentication, billing, security monitoring, support, consented analytics, and the blog newsletter.
When Kodex Compliance is a processor
A customer organisation normally remains the controller for personal data that it uploads, generates, or connects within its workspace. This can include information about employees, students, suppliers, customers, or other individuals. Kodex Compliance processes that data on the customer’s documented instructions under the applicable Data Processing Agreement.
If your request concerns data placed in Kodex by a customer organisation, contact that organisation first. We will assist the organisation with the request as required by our processor duties.
Controller details
Kodex Compliance UG (haftungsbeschränkt)
Managing Director: Jeremiah Matador
Commercial Register: Amtsgericht Charlottenburg, HRB 289793
Berlin, Germany
Email: contact@kodex-compliance.com
Our primary application hosting, database, and configured artificial intelligence inference use European Union regions or European Union geographic routing. Some providers may process limited data outside the European Economic Area as described in Sections 6 and 7.
2. Data We Collect and Its Sources
Account and organisation data
- Name, work email address, authentication identifiers, and account preferences
- Organisation name, size, industry, region, role, and team membership
- Subscription, billing status, and related customer support records
Customer workspace data
- Questionnaire answers and project context
- Uploaded evidence, policies, generated documents, and document metadata
- Scan results, control findings, scores, remediation records, and frozen audit packs
- Risk, supplier assessment, workforce assurance, and review records
- Personal data contained in customer files or connected services, including special category data if a customer chooses to provide it
Connected service data
When an authorised user connects a service, Kodex accesses the selected repository, workspace, or account according to the granted permissions. Depending on the integration, this may include file names, repository metadata, security settings, policy documents, selected page or message content, and compliance signals. We do not ask customers to provide passwords, private keys, or secrets as evidence.
Technical, support, and security data
- Internet Protocol address, browser, device, operating system, and request metadata
- Authentication, audit, security, error, and performance events
- Pages and features used when analytics consent has been granted
- Messages and attachments sent to support or to the Koda compliance assistant
Payment data
Stripe processes payment card details. Kodex Compliance receives billing contact details, transaction references, subscription status, invoices, and limited payment metadata. We do not store full payment card numbers or card security codes.
Where the data comes from
We receive data directly from users, from their organisation’s administrators and team members, from services they choose to connect, from payment and authentication providers, and automatically from the device or browser used to access the service.
Required and optional data
Data needed to create an account, authenticate a user, provide a selected service, secure the platform, or meet a legal obligation is required. If it is not provided, the relevant account or feature may not work. Optional fields and optional integrations can be left blank or disconnected.
3. Purposes and Legal Bases
| Purpose | Data | Legal basis |
|---|---|---|
| Create accounts, authenticate users, and provide contracted services | Account, organisation, project, and service data | Contract performance, Article 6(1)(b) |
| Process customer workspace content | Evidence, documents, questionnaires, integrations, and findings | Customer instructions under Article 28; the customer determines the applicable Article 6 and, where relevant, Article 9 basis |
| Provide support and manage the customer relationship | Contact, account, support, and service records | Contract performance and legitimate interests, Articles 6(1)(b) and 6(1)(f) |
| Protect the platform and investigate misuse or incidents | Authentication, Internet Protocol, audit, request, and error data | Legitimate interests and legal obligations, Articles 6(1)(f) and 6(1)(c) |
| Process payments and keep required records | Billing, invoice, subscription, and transaction data | Contract performance and legal obligations, Articles 6(1)(b) and 6(1)(c) |
| Measure website use with Google Analytics | Online identifiers and consented usage events | Consent, Article 6(1)(a), together with Section 25 TDDDG |
| Send The Audit Room newsletter | Email, consent record, and delivery data | Consent, Article 6(1)(a) |
| Establish, exercise, or defend legal claims and respond to authorities | Records relevant to the request or claim | Legal obligations and legitimate interests, Articles 6(1)(c) and 6(1)(f) |
Where we rely on legitimate interests, we consider the purpose, necessity, reasonable expectations, and impact on individuals. You may object as explained in Section 9. Where we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal.
4. Customer Workspace Data
Customers decide the purpose and scope of compliance projects, which users receive access, which integrations are connected, and what evidence is submitted. Kodex uses workspace content to deliver the requested assessment, evidence management, reporting, and related support functions.
- Workspace access is restricted by organisation, project assignment, and role permissions.
- Customers should minimise personal data and use redacted or representative evidence where possible.
- Customers must not upload secrets, passwords, private keys, or unrelated sensitive records.
- Frozen exports and files downloaded by a customer are controlled by that customer after download.
- The Data Processing Agreement contains the detailed instructions and processor obligations for customer workspace data.
See our Data Processing Agreement for further details.
5. Artificial Intelligence Processing
Artificial intelligence transparency
Kodex uses artificial intelligence to help classify evidence, evaluate controls, generate draft documents, and answer compliance questions. These functions support human compliance work. They do not certify compliance or provide legal advice.
Provider and information sent for inference
The current production service uses Amazon Bedrock to access Anthropic Claude models. Depending on the feature, a model may receive a user message, selected document excerpts, questionnaire answers, extracted compliance signals, and relevant control text. Kodex applies data minimisation and redaction controls before model calls, but submitted content may still contain personal data. We do not describe this content as anonymous unless it has actually been anonymised.
European Union geographic inference profiles may route processing among supported Amazon Web Services regions within the European Union. Amazon Bedrock retention depends on the model and account configuration. Kodex does not use customer content to train its own models. Amazon states that standard Bedrock customer content is not used to train base models. Current provider-specific handling is governed by our service configuration and contractual terms.
Connected systems and deep code scanning
The model does not independently sign in to customer systems. Kodex retrieves authorised data through its integration layer and sends only the content needed for the selected feature.
Deep code scanning is optional and must be selected for the scan. It reads a targeted set of security-relevant configuration files to extract structured compliance signals. Raw source content read by this deep scan is not persisted as scan evidence and is not sent to the model. Extracted signals and their provenance may be retained with the scan result.
Accuracy, human review, and legal effects
Artificial intelligence output can be incomplete or wrong. Kodex combines deterministic checks, model-assisted analysis, provenance records, and review workflows, but customers must review material findings before acting on them. A user may ask Kodex Compliance to review a disputed result by emailing contact@kodex-compliance.com. No fixed response time applies unless agreed in a separate service contract.
Kodex does not use its artificial intelligence features to make decisions about employment, education, credit, legal rights, or similarly significant matters on behalf of customers. Customers remain responsible for any decision they make using platform output.
See the Artificial Intelligence Transparency Notice for more detail.
6. Service Providers and Other Recipients
We use service providers where necessary to operate and secure the platform. We enter appropriate data protection terms where required. The services actually used can depend on the customer’s plan, enabled integrations, and consent choices.
| Provider | Purpose | Primary processing location or transfer position |
|---|---|---|
| Amazon Web Services EMEA SARL, Amazon Bedrock using Anthropic Claude models | Managed artificial intelligence inference | European Union geographic inference regions |
| Supabase, Inc. | Database, authentication, and file storage | European Union region |
| Render Services, Inc. | Application hosting and deployment | Frankfurt, Germany |
| Upstash, Inc. | Caching, rate limiting, and background job coordination | European Union region |
| Stripe group companies | Payments, subscriptions, and fraud prevention | European Union and other countries under applicable safeguards |
| Resend, Inc. | Transactional and newsletter email delivery | Processing may include the United States under applicable safeguards |
| Functional Software, Inc., Sentry | Error, performance, and security monitoring | European Union ingest region; limited global support processing may occur |
| Google Ireland Limited, Google Analytics | Consented website analytics | European Union and other countries under applicable safeguards |
| Cloudflare, Inc. | Domain, network security, and traffic delivery services | Global network under applicable safeguards |
Data may also be disclosed to professional advisers, auditors, insurers, regulators, courts, law enforcement, or a party involved in a corporate transaction where there is a lawful basis. We do not sell personal data or disclose it for third-party behavioural advertising.
7. International Data Transfers
Primary application infrastructure is configured in the European Union. Some providers, support teams, network services, and connected integrations may process data outside the European Economic Area.
Where Chapter V of the General Data Protection Regulation applies, we rely on an adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful transfer mechanism. We assess supplementary measures where appropriate, including encryption, access restrictions, data minimisation, and regional configuration.
To request information about a transfer mechanism relevant to your data, email contact@kodex-compliance.com.
8. Retention and Deletion
We retain data only for the period needed for the stated purpose, contractual requirements, security, dispute handling, or applicable law. Current platform retention behavior includes the following.
| Data type | Current retention approach |
|---|---|
| Account, organisation, project, scan, and review records | For the active customer relationship and until deleted, subject to legal and dispute-related retention needs |
| Document vault uploads, generated policies, and current evidence documents | Automatically removed after 30 days under the current document retention job; customers should refresh evidence that remains needed |
| Evidence files with a specific expiry date | Removed after the expiry date; legacy extracted text without an expiry is cleared by the scheduled purge, generally no later than 90 days |
| Frozen audit packs and audit reports | Retained as customer-requested records until deletion of the relevant record, workspace, or account, unless a legal requirement applies |
| Koda chat content | Sent with the request needed to produce a response; Kodex does not currently maintain a separate persistent chat-history record. Operational artificial intelligence logs store call metadata, not message content |
| Integration credentials | Until the integration is disconnected, the workspace is deleted, or the credential is replaced |
| Security, audit, and error records | For the period needed to protect the service, investigate events, and meet legal obligations; longer retention may apply to an active incident or claim |
| Invoices and accounting records | For the statutory period required by German tax and commercial law |
Account deletion
An organisation owner can start account deletion from Settings. The workflow verifies the request and removes active account and associated organisation records. A deletion can affect other users in an organisation owned by that person, so the interface requires explicit confirmation. Records that must be retained by law are restricted and kept only for that purpose. Residual copies may remain in provider backups until the applicable backup cycle expires and are isolated from ordinary product access.
9. Your Rights
Subject to the conditions and exceptions in data protection law, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may also withdraw consent at any time and may object to direct marketing at any time.
- Access the personal data we process about you and obtain information about that processing
- Correct inaccurate or incomplete personal data
- Request deletion where no lawful reason for continued retention applies
- Restrict processing in the circumstances provided by law
- Receive eligible data in a structured, commonly used, machine-readable format
- Object to processing based on legitimate interests
- Withdraw consent without affecting earlier lawful processing
- Lodge a complaint with a competent supervisory authority
Send requests to contact@kodex-compliance.com. We may need to verify your identity. We respond without undue delay and normally within one month. If an extension is permitted for a complex request, we will explain this within the first month.
For data controlled by a Kodex customer, send the request to that customer. Kodex will support the customer in responding.
10. Security Measures
We use technical and organisational controls intended to protect personal data against accidental or unlawful loss, access, change, disclosure, or destruction. No online service can guarantee absolute security.
- Encrypted transport using Transport Layer Security supported by our providers
- Provider-managed encryption at rest for hosted databases and storage
- AES-256-GCM application-level encryption for integration credentials and sensitive configuration before database storage
- Organisation, project, and role-based access checks based on the authenticated session
- Least-privilege scopes for supported integrations and the ability to disconnect them
- Rate limiting, audit events, structured logging, error redaction, and security monitoring
- Automated type checks, tests, dependency review, and security checks in the delivery pipeline
- Incident response procedures and notification to authorities and affected individuals where legally required
Report a suspected vulnerability or security incident to contact@kodex-compliance.com. Please do not include live credentials or unnecessary personal data in the first message.
12. Children and Student Data
Kodex accounts are intended for organisations and authorised adult users, not for children to create or use independently. Kodex does not knowingly offer direct consumer accounts to children under 16.
A school or another customer may process student or child data in a compliance project. In that situation, the customer is responsible for the lawful basis, transparency, access rules, and data minimisation. Kodex acts as processor and handles the data only under the customer’s instructions and the Data Processing Agreement. Customers should use redacted or representative evidence whenever identifiable student data is not necessary.
13. Changes to This Policy
We update this policy when our services, providers, data practices, or legal obligations materially change. The effective date at the top identifies the current version. Where a change materially affects registered users, we will provide an appropriate email or in-product notice. We will request new consent if the law requires it. Continued use is not treated as consent where valid consent is legally required.
15. Contact and Complaints
For privacy questions, rights requests, or concerns, contact:
Until a Data Protection Officer is formally appointed, privacy enquiries are handled through the contact above. We review whether an appointment is required as the scale and nature of processing changes.
Supervisory authority
You may complain to the supervisory authority responsible for your usual residence, workplace, or the alleged infringement. The supervisory authority for our Berlin establishment is the Berlin Commissioner for Data Protection and Freedom of Information. See datenschutz-berlin.de.