Privacy Policy

How we handle personal data

Effective date:

1. Who Is Responsible for Your Data

This Privacy Policy explains how Kodex Compliance UG (haftungsbeschränkt) processes personal data through the public website, customer accounts, the Kodex Compliance platform, support, and related services. It is intended to provide the information required by Articles 13 and 14 of the General Data Protection Regulation.

When Kodex Compliance is the controller

Kodex Compliance is the controller for personal data used to run its own business. This includes website enquiries, account administration, authentication, billing, security monitoring, support, consented analytics, and the blog newsletter.

When Kodex Compliance is a processor

A customer organisation normally remains the controller for personal data that it uploads, generates, or connects within its workspace. This can include information about employees, students, suppliers, customers, or other individuals. Kodex Compliance processes that data on the customer’s documented instructions under the applicable Data Processing Agreement.

If your request concerns data placed in Kodex by a customer organisation, contact that organisation first. We will assist the organisation with the request as required by our processor duties.

Controller details

Kodex Compliance UG (haftungsbeschränkt)

Managing Director: Jeremiah Matador

Commercial Register: Amtsgericht Charlottenburg, HRB 289793

Berlin, Germany

Email: contact@kodex-compliance.com

Our primary application hosting, database, and configured artificial intelligence inference use European Union regions or European Union geographic routing. Some providers may process limited data outside the European Economic Area as described in Sections 6 and 7.

2. Data We Collect and Its Sources

Account and organisation data

  • Name, work email address, authentication identifiers, and account preferences
  • Organisation name, size, industry, region, role, and team membership
  • Subscription, billing status, and related customer support records

Customer workspace data

  • Questionnaire answers and project context
  • Uploaded evidence, policies, generated documents, and document metadata
  • Scan results, control findings, scores, remediation records, and frozen audit packs
  • Risk, supplier assessment, workforce assurance, and review records
  • Personal data contained in customer files or connected services, including special category data if a customer chooses to provide it

Connected service data

When an authorised user connects a service, Kodex accesses the selected repository, workspace, or account according to the granted permissions. Depending on the integration, this may include file names, repository metadata, security settings, policy documents, selected page or message content, and compliance signals. We do not ask customers to provide passwords, private keys, or secrets as evidence.

Technical, support, and security data

  • Internet Protocol address, browser, device, operating system, and request metadata
  • Authentication, audit, security, error, and performance events
  • Pages and features used when analytics consent has been granted
  • Messages and attachments sent to support or to the Koda compliance assistant

Payment data

Stripe processes payment card details. Kodex Compliance receives billing contact details, transaction references, subscription status, invoices, and limited payment metadata. We do not store full payment card numbers or card security codes.

Where the data comes from

We receive data directly from users, from their organisation’s administrators and team members, from services they choose to connect, from payment and authentication providers, and automatically from the device or browser used to access the service.

Required and optional data

Data needed to create an account, authenticate a user, provide a selected service, secure the platform, or meet a legal obligation is required. If it is not provided, the relevant account or feature may not work. Optional fields and optional integrations can be left blank or disconnected.

4. Customer Workspace Data

Customers decide the purpose and scope of compliance projects, which users receive access, which integrations are connected, and what evidence is submitted. Kodex uses workspace content to deliver the requested assessment, evidence management, reporting, and related support functions.

  • Workspace access is restricted by organisation, project assignment, and role permissions.
  • Customers should minimise personal data and use redacted or representative evidence where possible.
  • Customers must not upload secrets, passwords, private keys, or unrelated sensitive records.
  • Frozen exports and files downloaded by a customer are controlled by that customer after download.
  • The Data Processing Agreement contains the detailed instructions and processor obligations for customer workspace data.

See our Data Processing Agreement for further details.

5. Artificial Intelligence Processing

Artificial intelligence transparency

Kodex uses artificial intelligence to help classify evidence, evaluate controls, generate draft documents, and answer compliance questions. These functions support human compliance work. They do not certify compliance or provide legal advice.

Provider and information sent for inference

The current production service uses Amazon Bedrock to access Anthropic Claude models. Depending on the feature, a model may receive a user message, selected document excerpts, questionnaire answers, extracted compliance signals, and relevant control text. Kodex applies data minimisation and redaction controls before model calls, but submitted content may still contain personal data. We do not describe this content as anonymous unless it has actually been anonymised.

European Union geographic inference profiles may route processing among supported Amazon Web Services regions within the European Union. Amazon Bedrock retention depends on the model and account configuration. Kodex does not use customer content to train its own models. Amazon states that standard Bedrock customer content is not used to train base models. Current provider-specific handling is governed by our service configuration and contractual terms.

Connected systems and deep code scanning

The model does not independently sign in to customer systems. Kodex retrieves authorised data through its integration layer and sends only the content needed for the selected feature.

Deep code scanning is optional and must be selected for the scan. It reads a targeted set of security-relevant configuration files to extract structured compliance signals. Raw source content read by this deep scan is not persisted as scan evidence and is not sent to the model. Extracted signals and their provenance may be retained with the scan result.

Accuracy, human review, and legal effects

Artificial intelligence output can be incomplete or wrong. Kodex combines deterministic checks, model-assisted analysis, provenance records, and review workflows, but customers must review material findings before acting on them. A user may ask Kodex Compliance to review a disputed result by emailing contact@kodex-compliance.com. No fixed response time applies unless agreed in a separate service contract.

Kodex does not use its artificial intelligence features to make decisions about employment, education, credit, legal rights, or similarly significant matters on behalf of customers. Customers remain responsible for any decision they make using platform output.

See the Artificial Intelligence Transparency Notice for more detail.

6. Service Providers and Other Recipients

We use service providers where necessary to operate and secure the platform. We enter appropriate data protection terms where required. The services actually used can depend on the customer’s plan, enabled integrations, and consent choices.

ProviderPurposePrimary processing location or transfer position
Amazon Web Services EMEA SARL, Amazon Bedrock using Anthropic Claude modelsManaged artificial intelligence inferenceEuropean Union geographic inference regions
Supabase, Inc.Database, authentication, and file storageEuropean Union region
Render Services, Inc.Application hosting and deploymentFrankfurt, Germany
Upstash, Inc.Caching, rate limiting, and background job coordinationEuropean Union region
Stripe group companiesPayments, subscriptions, and fraud preventionEuropean Union and other countries under applicable safeguards
Resend, Inc.Transactional and newsletter email deliveryProcessing may include the United States under applicable safeguards
Functional Software, Inc., SentryError, performance, and security monitoringEuropean Union ingest region; limited global support processing may occur
Google Ireland Limited, Google AnalyticsConsented website analyticsEuropean Union and other countries under applicable safeguards
Cloudflare, Inc.Domain, network security, and traffic delivery servicesGlobal network under applicable safeguards

Data may also be disclosed to professional advisers, auditors, insurers, regulators, courts, law enforcement, or a party involved in a corporate transaction where there is a lawful basis. We do not sell personal data or disclose it for third-party behavioural advertising.

7. International Data Transfers

Primary application infrastructure is configured in the European Union. Some providers, support teams, network services, and connected integrations may process data outside the European Economic Area.

Where Chapter V of the General Data Protection Regulation applies, we rely on an adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful transfer mechanism. We assess supplementary measures where appropriate, including encryption, access restrictions, data minimisation, and regional configuration.

To request information about a transfer mechanism relevant to your data, email contact@kodex-compliance.com.

8. Retention and Deletion

We retain data only for the period needed for the stated purpose, contractual requirements, security, dispute handling, or applicable law. Current platform retention behavior includes the following.

Data typeCurrent retention approach
Account, organisation, project, scan, and review recordsFor the active customer relationship and until deleted, subject to legal and dispute-related retention needs
Document vault uploads, generated policies, and current evidence documentsAutomatically removed after 30 days under the current document retention job; customers should refresh evidence that remains needed
Evidence files with a specific expiry dateRemoved after the expiry date; legacy extracted text without an expiry is cleared by the scheduled purge, generally no later than 90 days
Frozen audit packs and audit reportsRetained as customer-requested records until deletion of the relevant record, workspace, or account, unless a legal requirement applies
Koda chat contentSent with the request needed to produce a response; Kodex does not currently maintain a separate persistent chat-history record. Operational artificial intelligence logs store call metadata, not message content
Integration credentialsUntil the integration is disconnected, the workspace is deleted, or the credential is replaced
Security, audit, and error recordsFor the period needed to protect the service, investigate events, and meet legal obligations; longer retention may apply to an active incident or claim
Invoices and accounting recordsFor the statutory period required by German tax and commercial law

Account deletion

An organisation owner can start account deletion from Settings. The workflow verifies the request and removes active account and associated organisation records. A deletion can affect other users in an organisation owned by that person, so the interface requires explicit confirmation. Records that must be retained by law are restricted and kept only for that purpose. Residual copies may remain in provider backups until the applicable backup cycle expires and are isolated from ordinary product access.

9. Your Rights

Subject to the conditions and exceptions in data protection law, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may also withdraw consent at any time and may object to direct marketing at any time.

  • Access the personal data we process about you and obtain information about that processing
  • Correct inaccurate or incomplete personal data
  • Request deletion where no lawful reason for continued retention applies
  • Restrict processing in the circumstances provided by law
  • Receive eligible data in a structured, commonly used, machine-readable format
  • Object to processing based on legitimate interests
  • Withdraw consent without affecting earlier lawful processing
  • Lodge a complaint with a competent supervisory authority

Send requests to contact@kodex-compliance.com. We may need to verify your identity. We respond without undue delay and normally within one month. If an extension is permitted for a complex request, we will explain this within the first month.

For data controlled by a Kodex customer, send the request to that customer. Kodex will support the customer in responding.

10. Security Measures

We use technical and organisational controls intended to protect personal data against accidental or unlawful loss, access, change, disclosure, or destruction. No online service can guarantee absolute security.

  • Encrypted transport using Transport Layer Security supported by our providers
  • Provider-managed encryption at rest for hosted databases and storage
  • AES-256-GCM application-level encryption for integration credentials and sensitive configuration before database storage
  • Organisation, project, and role-based access checks based on the authenticated session
  • Least-privilege scopes for supported integrations and the ability to disconnect them
  • Rate limiting, audit events, structured logging, error redaction, and security monitoring
  • Automated type checks, tests, dependency review, and security checks in the delivery pipeline
  • Incident response procedures and notification to authorities and affected individuals where legally required

Report a suspected vulnerability or security incident to contact@kodex-compliance.com. Please do not include live credentials or unnecessary personal data in the first message.

11. Cookies and Browser Storage

Necessary authentication and preference storage is used to provide the service requested by the user. Google Analytics measurement is optional. Google Consent Mode starts with analytics storage denied, and Kodex does not send a page-view event until analytics consent is granted. The Google tag script may load in denied mode before a user makes a choice. Advertising storage, advertising personalisation, and Google Signals remain disabled.

Name or categoryPurposeDuration
Supabase authentication cookies, including sb-<project-reference>-auth-token and chunked variantsSign-in, session refresh, and authenticated accessSession and refresh lifecycle set by the authentication service
kodex_cookie_consent, browser local storageStores the consent version and analytics choiceUntil cleared or replaced by a new consent version
Theme preference, browser local storageStores the selected appearance preferenceUntil changed or browser storage is cleared
_ga and _ga_*Google Analytics measurement after consentUp to two years, subject to Google configuration and browser controls

You can withdraw analytics consent at any time. The platform then updates Google Consent Mode and attempts to remove Google Analytics cookies from the current domain. Browser settings can also remove or block storage, but blocking necessary authentication storage can prevent sign-in.

12. Children and Student Data

Kodex accounts are intended for organisations and authorised adult users, not for children to create or use independently. Kodex does not knowingly offer direct consumer accounts to children under 16.

A school or another customer may process student or child data in a compliance project. In that situation, the customer is responsible for the lawful basis, transparency, access rules, and data minimisation. Kodex acts as processor and handles the data only under the customer’s instructions and the Data Processing Agreement. Customers should use redacted or representative evidence whenever identifiable student data is not necessary.

13. Changes to This Policy

We update this policy when our services, providers, data practices, or legal obligations materially change. The effective date at the top identifies the current version. Where a change materially affects registered users, we will provide an appropriate email or in-product notice. We will request new consent if the law requires it. Continued use is not treated as consent where valid consent is legally required.

14. Blog Newsletter

The Audit Room newsletter is optional and is sent on the basis of consent. Blog subscriptions use double opt-in. A person enters an email address and confirms it through a confirmation message before newsletter delivery begins.

We store the subscriber email, source, consent time, consent text version, and pseudonymous hashes of the confirmation Internet Protocol address and user-agent string as evidence of consent. These hashes are treated as personal data. Resend delivers the messages. Subscriber records remain until unsubscribe. Unconfirmed requests are deleted after 30 days.

Every newsletter contains an unsubscribe method. Confirmed unsubscribe requests remove the subscriber record, subject only to a minimal suppression record if needed to ensure no further messages are sent.

15. Contact and Complaints

For privacy questions, rights requests, or concerns, contact:

Privacy contact

Kodex Compliance UG (haftungsbeschränkt)

Berlin, Germany

contact@kodex-compliance.com

Until a Data Protection Officer is formally appointed, privacy enquiries are handled through the contact above. We review whether an appointment is required as the scale and nature of processing changes.

Supervisory authority

You may complain to the supervisory authority responsible for your usual residence, workplace, or the alleged infringement. The supervisory authority for our Berlin establishment is the Berlin Commissioner for Data Protection and Freedom of Information. See datenschutz-berlin.de.

Contents
TABLE OF CONTENTS