Would you like to try the Codenica application in your company?
Create a free business account and see how the software works in practice.
Codenica's Privacy Policy sets out how we process data relating to people who use the website, accounts and services and separates our responsibilities from the Customer's responsibility for Customer Data. It describes data sources, purposes and legal bases of processing, security, individual rights and integrations.

This Privacy Policy explains how Codenica processes personal data in connection with the Codenica website, accounts, contact with the Codenica team and use of the Codenica system. We want to clearly distinguish two groups of data: data for which Codenica acts as the Data Controller and Customer Data that the Customer enters into the system as part of its own business activities.
For Customer Data stored in Codenica Cloud, the Customer generally determines the purposes and means of processing, while Codenica acts as a Data Processor under the agreement and the Customer's documented instructions. The detailed rules for this processing should also be set out in a Data Processing Agreement or another document governing the processing of personal data.
With Codenica On-Premise, the system is installed in the Customer's infrastructure. In the ordinary operation of the application, data remains in the Customer's environment and is not sent to Codenica. This may be different if the Customer configures an external integration or gives Codenica access needed for support or a specific administrative task.
This Privacy Policy does not replace the Codenica Software Terms of Use, the agreement with the Customer, the Data Processing Agreement or the Cookies Policy. Each of these documents governs a different part of our relationship.
This Policy applies when you visit the Codenica website, contact us, create an account, use the Cloud version, order a Service, use support or provide us with data in connection with our cooperation. It also covers technical information related to the operation of the website and the security of the Services.
This Policy does not describe in detail the rules under which the Customer, as Data Controller, processes data about its employees, customers, contractors or other people in the system. In that context, the Customer should determine the legal basis, data scope, retention period and information obligations toward those people. Codenica provides technical support as the system provider and Data Processor.
The scope of data depends on how you use Codenica. We may process identification and contact details, login data, account information, contract and billing information, the content of messages sent to us and information needed to handle tickets and support requests.
When you use the website or Services, technical data may be generated, such as an IP address, session identifiers, browser and device information, security events and logs needed to diagnose errors and protect the system. Optional analytics data is activated according to the consent settings described in the Cookies Policy.
Customer Data may include information about employees, customers, devices, software, licences, documents, tickets, tasks, attachments and data from scanning and monitoring features. The Customer decides what information to enter into the system and for what purpose it will use it.
Data that is not needed for a defined purpose should not be entered into the system. This applies in particular to special categories of personal data, such as health data, political opinions, religious beliefs or biometric data, unless the Customer has an appropriate legal basis and expressly needs such a function.
Codenica is the Data Controller for personal data connected with operating the website, managing its own accounts, contact, sales, billing, support, the security of its own Services and communications with us. In this context, Codenica independently determines the purposes and means of processing.
The Customer is the Data Controller for Customer Data that it enters into Codenica Cloud or its own On-Premise installation. Codenica processes that data on the Customer's behalf and according to its documented instructions, to the extent necessary to provide, maintain and secure the system. The details should be set out in a Data Processing Agreement that meets the requirements of Article 28 of the GDPR.
With On-Premise, the Customer is responsible for its infrastructure, server access, administrator accounts, backups and system settings. Codenica does not receive Customer Data as part of the ordinary operation of the installation. Service access may be provided only within the scope agreed with the Customer and needed for a specific support task.
We use data for which Codenica is the Data Controller to create and manage accounts, enter into and perform agreements, provide Services, handle payments and billing, conduct correspondence, provide support, maintain security and detect misuse and errors.
The legal basis may be the performance of an agreement or steps taken before entering into one, compliance with a legal obligation, Codenica's legitimate interest or consent, depending on the specific purpose and applicable law. If processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
We process Customer Data primarily to activate the system features selected by the Customer, store and display the information entered, handle tickets, perform scanning or monitoring according to the configuration, synchronise selected integrations and maintain and secure the Service.
Codenica does not make decisions concerning users that produce legal or similarly significant effects solely on the basis of automated processing.
Codenica Cloud and Codenica On-Premise are two ways of using the same system. The main difference is where the application runs and where data is stored.
Codenica Cloud. The application runs on Microsoft Azure infrastructure. In this model, Customer Data is stored and processed in the Cloud environment within the scope resulting from the system configuration, the agreement and the selected features. Microsoft Azure and other necessary technical providers may process data only to the extent needed to provide, maintain and secure the Service, in accordance with the applicable data protection arrangements.
Codenica On-Premise. The application, database, files and Agent data run and are stored in the Customer's infrastructure. With a local application address, a local Agent connection, a local data source and the appropriate configuration, the system can operate without an Internet connection. External SMTP, IMAP, OAuth, Google, Microsoft or other integrations are optional and work only when configured by the Customer.
Customer Data remains the Customer's data. Codenica does not sell, rent or trade Customer Data. We do not use it for advertising, creating advertising profiles, selling databases or training general-purpose AI models. If the Customer enables an external integration, the data exchange results from that configuration and is limited to the operation of the selected feature.
Data for which Codenica is the Data Controller may be shared with providers that help us operate the website and Services, manage infrastructure, provide security, process payments, send communications or respond to support requests. They receive only the data needed for the specific task and are required to maintain confidentiality and apply appropriate safeguards.
In the Cloud version, data may be processed by Microsoft Azure and other Sub-processors necessary for the Service to operate. Their current list, service scope, locations and transfer mechanism should be set out in Sub-processor documentation and the agreement with the Customer. We do not share Customer Data with advertising companies or data brokers.
Data may be disclosed to an authorised authority or court when required by applicable law, a final judgment or a binding request. In that case, we limit the disclosure to what the law requires, unless the law prevents us from informing the Customer or the relevant Data Subject.
If the Customer enables an integration with Google, Microsoft, an email provider, a calendar provider or another service, data may be sent to that service according to the permissions and settings selected by the Customer. The operation of that service is also governed by its own privacy policy.
We apply technical and organisational measures appropriate to the risk, the nature of the data and the deployment model. These may include access controls, separation of permissions, infrastructure protection, event logging, updates, operational procedures and measures for detecting and limiting unauthorised access. The measures depend on whether the system runs in the Cloud or in the Customer's On-Premise infrastructure.
In the Cloud, the security of Azure infrastructure is complemented by application safeguards and the Customer's account configuration. With On-Premise, the security of the network, servers, operating system, backups and physical access primarily depends on the Customer. No system removes every risk, which is why strong passwords, limited permissions and an up-to-date runtime environment are also important.
Scanning and monitoring features may collect information about devices, systems, software, events or activity, depending on the selected feature, Agent version and Customer configuration. Codenica provides the tool, but does not decide for the Customer whether monitoring is necessary, proportionate or lawful.
A Customer that monitors computers or people's activity is responsible for defining the purpose and legal basis, limiting the scope to that purpose, meeting information obligations toward employees and other people, setting retention and complying with employment and other applicable laws. Monitoring data is Customer Data and receives the same protection as other data entered into the system.
If we identify a personal data breach, we will take the actions required of us under the applicable processing model, including assessing whether we must notify the Customer, a supervisory authority or the relevant Data Subjects. With On-Premise, the Customer is responsible for breaches resulting from its infrastructure and configuration, while Codenica cooperates within the agreed support scope.
We retain account, contact, contract and billing data for as long as needed to manage the relationship with the Customer and then for as long as required to comply with legal obligations, defend claims or establish and pursue them. The period depends on the type of data and the specific purpose.
We retain Customer Data in Codenica Cloud for the duration of the Service and according to the agreement and configuration. Unless the agreement or order provides otherwise, after the Service ends the Customer has 30 days to download the data made available by the system. After that period, active data may be deleted, subject to legal obligations, agreed retention and backups.
With On-Premise, the Customer is responsible for the retention period, export, deletion and backups of Customer Data because the data is stored in its environment. Data provided to Codenica for agreed support is retained only for as long as needed to handle the matter or as required by law.
If Codenica is the Data Controller for your data, you may request access to it, rectification, erasure, restriction of processing or data portability, or object to processing, within the scope and on the terms set out in the GDPR. You may also withdraw consent if processing is based on consent.
If your data is stored in Codenica Cloud or On-Premise as Customer Data, you should first direct your request to the Customer, who determines the purposes of processing. Codenica helps the Customer exercise Data Subject rights where this follows from the agreement, the Service scope and the system's technical capabilities.
Before handling a request, we may ask for information needed to verify your identity. We respond without undue delay and generally within the period provided by the GDPR. If we cannot fulfil a request, we explain why to the extent permitted by law.
The website uses cookies necessary for its operation, session management, remembering settings and security. Optional analytics tools, including Google Analytics, may be activated only after the relevant consent has been given, according to the settings in the cookie banner.
You can change your consent settings in the available privacy tools or in your browser settings. A separate Cookies Policy describes cookie categories, purposes, retention periods and providers. If the website settings or the list of tools changes, the Cookies Policy should be updated accordingly.
In the Cloud, data location and the involvement of particular providers depend on the selected environment, configuration and contractual arrangements. Codenica should provide Customers with up-to-date information about Sub-processors, the activities entrusted to them and processing locations.
If personal data is transferred outside the European Economic Area, we use a mechanism permitted by the GDPR, such as an adequacy decision, Standard Contractual Clauses or another required safeguard. We do not state a particular region or mechanism for every environment without confirming the current Service configuration.
With On-Premise, Codenica does not determine the location of data stored in the Customer's infrastructure. Any transfer to an external provider results from the Customer's configuration, for example an enabled email, calendar or OAuth integration.
The Data Controller for personal data is Codenica. For matters concerning this Policy, data that Codenica processes as Data Controller or the exercise of rights, you can contact us at the email address available in the website footer.
If you believe that we process data unlawfully, you can contact us and you may also lodge a complaint with the competent supervisory authority. For people whose data is processed in Poland, this authority is the President of the Personal Data Protection Office.
This Policy may be updated when laws, system features, the way we provide Services or our organisational measures change. For material changes, we will take the information steps required by law and state the date on which the new version takes effect. Simply continuing to use the website does not replace an information obligation or consent where consent is required.
Codenica may allow you to connect a Google account with a Codenica account. The scope of access depends on the feature enabled by the user or the Customer's administrator and on the consent given on the Google screen. We do not request permissions broader than those needed for the selected integration.
For sign-in or account linking, the openid, profile and email scopes may be used to identify the account, confirm identity, link it to a Codenica account and display basic profile information. We do not use this information for advertising or database sales.
If the user enables message sending, Codenica may use the gmail.send scope to send messages through Gmail within the scope configured in the system. This scope is not used to read the inbox.
The Email-to-Ticket feature requires the separate gmail.modify scope. When enabled, the system may search for unread messages in the configured mailbox, retrieve the message content to create a ticket and mark the message as read after successful processing. The message content, attachments and sender data may become Customer Data in the ticket that is created. We do not use this permission for general inbox scanning, advertising, data sales or training general-purpose AI models.
The Google Calendar integration may use the calendar.calendarlist.readonly and calendar.events scopes. This allows the system to read the list of available calendars, read events and create, update, delete and synchronise events in calendars selected by the user or configured by the Customer's administrator.
Google Data is used only to provide the enabled feature, maintain its operation, ensure security and comply with legal obligations. We do not sell Google User Data, use it for advertising or advertising profiles or share it with other entities unless this is necessary to operate the selected feature, ensure security, comply with law or is expressly authorised by the user or Customer.
Data obtained from Google is retained only as needed to operate the configured feature, handle tickets, synchronise data, maintain security, provide auditability or comply with legal and contractual obligations. Access is limited to authorised accounts, systems and people who need it for their tasks. Credentials and OAuth tokens are protected by appropriate technical and organisational measures proportionate to the risk.
You can disconnect the Google integration in Codenica settings or revoke its access in your Google account settings. Revoking access stops further data retrieval, but does not automatically delete information previously stored in the system as part of Customer Data. Deletion follows the configuration, agreement and retention rules.
Codenica uses data received through Google APIs in accordance with the Google API Services User Data Policy, including the Limited Use requirements.
Would you like to try the Codenica application in your company?
Create a free business account and see how the software works in practice.
