Scope of this policy
This policy explains how Codivo Labs (“Codivo Labs”, “we”, “us”) handles personal information in connection with the website at codivolabs.com and our business correspondence. Codivo Labs is the data controller for that information.
Our published applications are covered by their own policies, because they behave differently from a website. For Declutta: Free Up Space, see the Declutta: Free Up Space Privacy Policy.
When we process data on behalf of a client during an engagement, we act as a data processor under that client's instructions and our contract with them, not as a controller. See client code and confidentiality below.
Cookies and analytics
This website can run Google Analytics 4 (property G-8H23Q4KRB9), so
that we can see how many people read a page and which pages are worth keeping. It is
the only third-party script on the site, and the only reason the site would set
cookies.
Nothing happens until you say yes
The first time you visit, a notice at the bottom of the page asks whether analytics is alright with you. Until you press Accept:
- No analytics cookie is written to your device
- The Google Analytics script is not even downloaded, so Google is not contacted and does not learn that you visited
- Consent is signalled to Google as denied through Google Consent Mode, which governs the tag's behaviour if it ever does load
Declining and ignoring the notice have exactly the same effect. We do not ask again on every page, we do not make the notice harder to dismiss than to accept, and the site works identically either way.
If you accept, what that means in practice
-
Google Analytics stores two first-party cookies in your browser -
_gaand_ga_8H23Q4KRB9- which hold a randomly generated identifier so that several page views in a row are counted as one visit rather than several. They expire after two years unless you clear them sooner - Google receives your IP address, the page you are on, the page or search that sent you, your approximate location derived from that IP address, and your device, browser and language. Google uses the IP address to work out a coarse location and then discards it; GA4 does not make IP addresses available to us
- We see aggregate reports only - visit counts, popular pages, referrers, countries, device types. We cannot see who you are from them, and we do not try to
- We have not enabled Google Signals, advertising features, remarketing or cross-device tracking, so your analytics data is not linked to a Google account or used to target ads to you
What this website still does not do
- It contains no advertising, retargeting or conversion pixels
- It embeds no third-party fonts, videos or social media widgets, and runs no script other than the analytics tag described above
- It does not fingerprint your browser or device
- It has no contact form, so nothing you type is transmitted anywhere
- It never sells or shares your information for advertising
Changing your mind
Your answer is remembered in your browser's local storage, under the key
codivo:analytics-consent, so that we do not ask on every visit. It is not a
cookie, it is not sent anywhere, and it identifies nothing beyond the answer itself.
To change it, use Cookie settings at the foot of any page. Withdrawing
consent is as easy as giving it: choosing Decline stops collection immediately and
deletes the _ga cookies from your browser there and then.
These also work, and none of them break the site:
- Install Google's official Analytics opt-out browser add-on, which blocks the tag on every site you visit
- Block or clear cookies and site data for this site in your browser settings, or use a private window
- Use any content blocker or a browser that blocks trackers by default
One thing worth knowing: “Do Not Track” and Global Privacy Control signals do not switch Google Analytics off on their own, because Google does not act on them. On this site that does not matter - analytics stays off until you accept - but it is not true of most sites you visit. You can also write to us and we will confirm what, if anything, we hold.
Information we process
Information you send us
The website invites you to email us. If you do, we receive your email address, your name if your mail client includes it, your message, and any attachments - for example a repository link, a code sample or a document. If we go on to work together, we will also hold ordinary business contact and billing details for your organisation.
Technical information from hosting and analytics
Serving a web page necessarily involves your device's IP address. See hosting and server logs. Separately, our analytics tag sends page and device information to Google - see cookies and analytics.
What we never ask for
We do not ask for, and would prefer not to receive, special category data (such as health, biometric, political or religious information), government identity numbers, or payment card details by email.
Hosting and server logs
This website is a set of static pages hosted on Cloudflare's global network. Like any web host, Cloudflare processes your IP address, the requested URL, your user agent string and the timestamp in order to route and serve the request, and to protect against attacks and abuse.
These logs are generated and retained by Cloudflare as our hosting provider and processor, for a limited period, for security and operational purposes. We do not use them to identify individual visitors, and we do not combine them with our analytics data or with any other information. Cloudflare's privacy documentation is available at cloudflare.com/privacypolicy.
Our email is handled by a third-party email provider, which processes messages in order to deliver and store them.
Why we process it, and on what basis
| What | Why | Lawful basis (UK / EU GDPR) |
|---|---|---|
| Your email and message | To answer your enquiry and scope possible work | Legitimate interests - responding to someone who contacted us; or steps prior to entering a contract |
| Business contact and billing details | To deliver an engagement, invoice for it and keep records | Performance of a contract; and legal obligation for tax records |
| IP address in server and email logs | To serve the site, and to prevent abuse and attacks | Legitimate interests - security and availability of our systems |
| Analytics cookies and page-view data | To measure how the site is used and decide what to write and fix next | Consent, given through the notice described under cookies and analytics, and withdrawable at any time from Cookie settings. No analytics processing takes place without it |
We do not use your information for automated decision-making or profiling, and we do not send marketing email to people who have not asked for it.
Who we share it with
We do not sell, rent or trade personal information, and we do not share it for cross-context behavioural advertising. We disclose it only to:
- Service providers who process it on our behalf under contract - our hosting provider, our email provider, our accounting software, and Google as our analytics provider
- Professional advisers such as accountants or lawyers, where necessary and under a duty of confidence
- Authorities, where we are legally required to do so, and after satisfying ourselves that the request is valid
If our business were ever transferred to another party, personal information could transfer with it; we would tell affected clients before that happened.
How long we keep it
- Enquiries that do not become work: up to 12 months, then deleted
- Support and client correspondence: up to 24 months after our last exchange
- Contracts and invoices: as long as tax and company law require, currently up to 8 years
- Client code and repository access: access is revoked and local copies deleted at the end of an engagement, unless the contract says otherwise
- Analytics, if you accepted: held by Google for the retention period
set on the property - GA4 offers 2 or 14 months for user-level and event data, after
which the underlying records are deleted. Aggregate totals in the standard reports
are not time-limited in the same way. The
_gacookies expire two years after your last visit, or immediately if you withdraw consent
International transfers
We work with clients worldwide, and our hosting, email and analytics providers operate globally. Personal information may therefore be processed in countries other than your own, including the United States - analytics data in particular is processed by Google on US infrastructure. Where information is transferred out of the UK, the EEA or India, we rely on the safeguards our providers have in place - typically the European Commission's Standard Contractual Clauses, the UK Addendum, or an adequacy decision - and we will describe the applicable mechanism on request.
Your rights
Subject to the conditions in the applicable law, you may ask us to give you access to the personal information we hold about you, correct it, delete it, restrict how we use it, or provide it in a portable form. You may object to processing we carry out on the basis of legitimate interests, and withdraw consent where we relied on consent.
We do not sell personal information, and we do not share it for cross-context behavioural advertising: the advertising and Google Signals features of our analytics are switched off. If you would nonetheless like to exercise a California opt-out, use any of the methods under cookies and analytics or write to us, and we will treat it as an opt-out request. We will not discriminate against you for exercising any right.
Write to privacy@codivolabs.com and we will respond within 30 days. We may need to verify your identity first, which usually means replying from the address we already hold.
If you are unhappy with our response you can complain to your data protection authority - in the UK the Information Commissioner's Office, in the EEA your national authority, and in India the Data Protection Board. We would appreciate the chance to put things right first.
Security
We keep our attack surface deliberately small: a static website with no database, no user accounts, and one third-party script - the analytics tag. Internally we use multi-factor authentication, full-disk encryption on work machines, a password manager, and least-privilege access to client systems.
No system is perfectly secure. If you believe you have found a vulnerability in anything we run or publish, please tell us privately at security@codivolabs.com before disclosing it publicly. We will acknowledge within 48 hours and credit you once the issue is fixed, if you would like us to.
Children
This website and our services are aimed at businesses and are not directed at children. We do not knowingly collect personal information from children under 13, or under the higher minimum age that applies where you live. If you believe a child has sent us personal information, contact us and we will delete it.
Client code and confidentiality
Auditing software means being trusted with it. Our standing commitments to clients are:
- Written confidentiality terms, signed before we are given repository access
- Least-privilege access - read-only where read-only is enough, scoped to the repositories in question, and revoked at the end of the engagement
- Client code is never used to train machine learning models, ours or anybody else's, and is not submitted to third-party services except tools named in the engagement documentation
- Findings and reports are shared only with the people the client nominates. We do not publish client names or case studies without written permission
- Intellectual property in delivered work is assigned to the client on delivery
- Where an engagement gives us access to personal data held by a client, we act as their processor under a data processing agreement and follow their instructions
Changes to this policy
August 16, 2026: we added Google Analytics to this website, behind a consent notice. Earlier versions of this policy said the site set no cookies and ran no analytics; that remains true unless you accept, and the cookies and analytics section above describes exactly what changes if you do. Nothing else about how we handle your information has changed, and our published applications are unaffected.
We will update the “Last updated” date at the top of this page whenever this policy changes, and we will describe material changes prominently, as above. Because we hold no accounts, we cannot notify visitors individually; if you rely on this policy, please check back periodically.
Contact us
If any part of this document is unclear, or you want to exercise a right described in it, write to us and a person will reply.
Email: privacy@codivolabs.com